Mon–Sat 10:00–18:00 London · UK
Remote & on-site ☎ 0207 096 0936
← Guides
Guide

How Long Should You Keep Business Data?

Keeping everything forever feels like the safe option and is not. A plain-English guide to data retention for a UK small business — what the rules actually say, and how to build a schedule you can follow.

Ask a small business how long it keeps data and the answer is usually some version of “we do not really delete anything”. Storage is cheap. Deleting feels irreversible. And nobody has ever been reprimanded for keeping a file too long.

That instinct is understandable, and it is wrong in both directions. Keeping everything forever breaches one rule. Deleting on a whim breaches several others. The way out is not a policy of hoarding or a spring clean — it is a short, boring document that says what you keep, for how long, and why.

The rules pull in two directions

UK GDPR contains a storage limitation principle, one of the handful of duties covered in our guide to the IT side of GDPR. Put plainly: do not keep personal data longer than you need it for the purpose you collected it for. What it conspicuously does not contain is a number. There is no “delete after five years” clause waiting to be looked up. You choose the period, you write down your reasoning, and you apply it consistently. That is the whole obligation, and it is more flexible than most owners fear.

Pulling the other way are rules that do set minimums. Tax and company records, employment records, and health and safety records all have expected retention periods, and some regulated sectors add their own on top. Insurers and professional bodies sometimes expect longer still.

So “keep everything forever” is not the cautious option people assume — it collides with storage limitation. And “clear the decks every couple of years” is not tidy — it collides with HMRC. You need a position per category, not a single rule for the business.

One important caveat before we go further. The specific statutory periods that apply to your business should be confirmed with your accountant or a solicitor. Retention periods are commonly quoted for tax and employment records, but they depend on your structure, your sector and your contracts. Treat this guide as a way to organise the question, not as legal advice, and never treat a retention table found online as authoritative.

Why holding on is a liability

Old data is not neutral. It carries three costs that only show up when something goes wrong.

Breach exposure. Everything you hold is something you can lose. A customer database with fifteen years of records makes a far worse incident than one with four, and the difference is data you had no business need for. Good cyber security reduces the chance of a breach; deleting what you do not need reduces the damage when one happens anyway.

Subject access requests. When someone asks for a copy of their personal data, you have to find all of it. Every dormant archive, every old export, every mailbox belonging to someone who left in 2019. A lean estate turns a stressful fortnight into an afternoon.

Cost and clutter. You pay to store it, back it up and protect it. And the more you keep, the harder it is to find the thing you actually need — which is its own quiet tax on everybody’s week.

Building a retention schedule

This does not need to be elaborate. A spreadsheet with four columns will do more good than a policy document nobody opens.

List the categories you genuinely hold. Not what a template says you might hold. Walk through it honestly: customer records, supplier records, employee files, unsuccessful job applicants, CCTV footage, email, quotes and proposals, invoices and accounts, contracts, marketing lists, website enquiry forms.

Pick a period for each. Some will be set by a legal minimum. Some by a real operational need — you keep quotes for a while because clients come back. Some are pure habit, and those are the ones to cut.

Write down the reason. One line. “Statutory, confirmed with accountant.” “Operational, clients often reorder within two years.” The reason matters more than the number, because it is what you would explain if asked.

Name an owner and a review date. A schedule with no owner ages badly. Diary a review once a year.

The parts everyone finds hard

Email is where everything hides. Contracts, personal data, complaints, bank details sent by a customer who should not have. Retention policies usually stop at the CRM and the file server, and email quietly holds a copy of it all. Deal with it explicitly, and remember that a mailbox belonging to someone who left three years ago is still a live store of personal data.

Backups keep what you deleted. This confuses people, and the confusion leads to bad decisions. Backups are meant to hold historic copies — that is their job. When you delete a record from the live system, older copies remain in the backup set until they age out on their own retention cycle. That is acceptable, provided you know how long the cycle runs and can say so. Whether you are backing up a server or using Microsoft 365 backup, write the backup retention period into your schedule alongside everything else. Do not start surgically carving records out of backup sets unless you have specific advice telling you to.

CCTV is the one kept far too long. Small businesses routinely hold months or years of footage because the recorder was set up once and never revisited. Footage is typically kept for a short number of days or weeks, long enough to review an incident, and then overwritten. Check what your system is actually set to. Most people have never looked.

Unsuccessful applicants. CVs and interview notes for people you did not hire are personal data with a short, defensible life — commonly a matter of months, to cover a discrimination claim window. Keeping a “talent pool” indefinitely needs a lawful basis and, realistically, consent.

Paper and old drives. Retention is not just a digital question. Shred paper properly rather than binning it. And when a laptop or server is retired, the drive needs wiping to a proper standard or physically destroying — an old disk in a drawer is an unlisted copy of everything on it. Ask for a certificate of destruction when a third party handles it.

Make it a habit, not a project

The schedule is worth an afternoon once, then an hour a year. Set the review date now, while it is on your mind.

If you want a second pair of eyes on where your data actually sits — including the archives nobody has opened in years — that sits squarely inside IT consultancy work. We can map it and help you build the schedule. The legal periods themselves, though, are a question for your accountant or solicitor, and we would always tell you to ask them.

Frequently asked questions

Does GDPR tell us exactly how long we can keep customer data?

No, and that surprises people. The storage limitation principle says you must not keep personal data for longer than you need it for the purpose you collected it for. It leaves the period to you. What matters is that you have decided on one, can explain the reasoning behind it, and actually apply it. A period you chose and documented will stand up far better than no period at all.

If we delete a record from our live system, is it gone from the backups too?

Not immediately. Backups hold historic copies by design, so a deleted record stays in them until that backup ages out of its own retention cycle. This is normal and expected. The sensible approach is to document how long your backup retention runs, put the deleted data beyond ordinary use so nobody restores it back into circulation, and let it expire naturally rather than tearing holes in your backup sets.

What is the risk of just keeping everything?

Three things, all real. Everything you hold is something that can be exposed in a breach. Everything you hold is something you must search when someone makes a subject access request. And everything you hold costs money to store, back up and protect. Old data you no longer need has no upside — it is pure liability sitting on a disk.

Related services

Free · no obligation

Want a hand with any of this?

Tell us what you're trying to sort out and we'll come back with a clear, no-obligation plan and price.