Retention of Personal Data in the UK: Common Pitfalls and How to Avoid Them

Martin Brazier
|
Senior Consultant at URM
|
|
PUBLISHED on
21
August
2026
Article Summary

In this blog, Martin Brazier, Senior Consultant at URM, explores the often-overlooked issue of personal data retention and explains why organisations must ensure they do not keep personal data for longer than necessary. He examines:

  • UK data protection law requirements around the retention of personal data
  • Retention policies and schedules and what these need to contain
  • The common retention mistakes that can lead to compliance, operational, and security risks
  • The impact that poor retention practices can have on DSARs, data breaches, and litigation
  • Key lessons from regulatory enforcement action and tribunal decisions.

For many organisations, data protection efforts tend to focus on the collection and security of personal data.  However, far less attention is often given to how long that data should be retained.  Retaining personal data indefinitely is not only poor practice, but can also create compliance, operational, and security risks.  A well-defined retention policy helps organisations demonstrate accountability, reduce costs, and minimise exposure to regulatory action.  The Information Commissioner's Office (ICO) is clear that organisations must not keep personal data for longer than necessary and should have documented retention periods wherever possible.

What Does UK Data Protection Law Require?

The UK General Data Protection Regulation (UK GDPR) does not prescribe fixed retention periods for personal data.  Instead, organisations must comply with the storage limitation principle in Article 5(1)(e), which requires personal data to be kept in a form that permits identification of individuals for no longer than is necessary for the purposes for which it is processed.  Organisations must be able to justify how long information is retained and should document standard retention periods wherever possible.

This obligation sits alongside the wider accountability requirements in Article 5(2) of UK GDPR.  You need to know what personal data you hold, why you hold it, how long it is needed, and what action will be taken when the retention period expires.  The ICO expects organisations to maintain retention schedules, undertake regular reviews, and erase or anonymise personal data that is no longer required.

Retention decisions should also take account of other legal and regulatory obligations.  For example, employment, tax, accounting, and health and safety legislation may require certain records to be kept for minimum periods.  However, once those obligations have been met, you need to assess whether continued retention remains necessary and proportionate.  Retaining personal data indefinitely simply because storage is inexpensive will not satisfy regulatory expectations.

Finally, UK GDPR gives individuals a number of rights that are closely linked to retention, including the right of access and, in certain circumstances, the right to erasure.  If your organisation lacks clear retention and deletion processes, you will likely find it far more difficult to respond to these requests efficiently and demonstrate compliance to regulators.

Retention Policies and Schedules

A simple retention policy can go a long way in setting out your organisation’s approach and commitment to the effective retention and disposal of information.  This helps embed good practices across the organisation while also demonstrating accountability to your customers, regulators and other stakeholders.  A well-designed policy will define roles and responsibilities, explain why data is retained, set out when and why it should be deleted and emphasise the importance of maintaining its accuracy, confidentiality and integrity.  The development of a retention policy and supporting schedule should be a collaborative exercise involving stakeholders from across your organisation drawing on their specialist knowledge and expertise.

A retention policy is usually supplemented by a retention schedule.  This is often presented in tabular form and lays out against each type of information:

  • Why the data was collected
  • The retention period
  • The justification for that retention period, including any references to best practice guides, legislative or regulatory requirements.  

It should also outline the triggers for reviewing and deleting information when it is no longer required, such as:

  • A date or amount of time elapsed
  • An event, such as the withdrawal of data subject consent
  • The end of the purpose for which it was collected
  • Fulfilment of an order
  • Closure of a customer account
  • An opt out of marketing
  • Closure of a complaint
  • An employee leaving the organisation.

The schedule should also state the action to be taken at the end of the retention period, such as a review, approval of deletion, anonymisation or automated deletion.

Common Retention Pitfalls

A common pitfall we observe is treating retention as a one-off exercise rather than an ongoing process.  Instead, retention should be embedded into day-to-day operations and integrated into broader organisational processes, such as workflows, project management activities, and documented procedures.  Particular attention should be given to events that trigger the review or deletion of information, including account closures, consent withdrawals, and staff offboarding.

Another issue is that organisations often create a policy but fail to review it when systems, processes, or legal requirements change.  Regular reviews are important to ensure retention schedules remain appropriate and aligned with business needs and evolving legislation and regulation.

Inconsistent deletion is another challenge frequently encountered.  Data may be removed from a core system but remain in shared drives, email folders, archived databases, or backup systems, which can be exacerbated by a lack of good records management practices.  This creates uncertainty over what information should be retained and increases compliance risks.  You need to ensure processes are in place that support secure and permanent disposal in accordance with retention schedules.

We also frequently see a lack of clear ownership.  Without defined responsibility, deletion activities are often delayed or overlooked altogether.  Retention and disposal processes should have named owners and be supported by appropriate governance and training.

Finally, organisations often rely on individuals to identify information that should be deleted and to take the necessary action. This assumes they have both the time and discipline to do so. Setting automatic deletion, where appropriate, means that action is not reliant on an individual.

The Impact of Getting it Wrong

As mentioned above, poor retention practices can significantly increase the effort required to respond to requests from data subjects to exercise their rights, such as data subject access requests (DSARs).  When a DSAR is received, all information held about the requester is in scope, regardless of whether that information could or should have been deleted prior to the request, or is an unauthorised copy retained after formal scheduled deletion of the original.  Importantly, deleting information after a DSAR has been received is a criminal offence.  When unnecessary data is retained, especially if combined with poor records management practice, it creates larger volumes of information that must be searched, reviewed, and disclosed, vastly increasing the time and effort required to respond to requests.  Legacy systems, unmanaged email archives, and duplicated records can make DSAR responses slower, more expensive, and more prone to error.  Failure to respond fully and within statutory timescales can result in complaints to the ICO and regulatory scrutiny.

Retaining excessive personal data also increases the consequences of a security incident.  If a database, file share, or email archive is compromised, the volume of exposed personal information may be far greater than necessary simply because old records were never deleted.

When a breach is reported to the ICO, organisations may find it more difficult to justify why affected data was still being retained.  Larger quantities of personal data can increase harm to individuals, raise the cost of breach response activities, and potentially lead to greater reputational damage and higher claims for compensation.  

Ultimately, organisations that routinely delete data they no longer need are often better placed to locate relevant records quickly, provide accurate responses, and can mitigate the risks of a breach of personal data.  Good retention practices reduce the amount of information at risk and support both data protection compliance and operational efficiency.  Sadly, many organisations do not learn these lessons until they receive a DSAR or suffer a breach.

Lessons From Enforcement and Information Tribunal Decisions

Both the ICO and the courts have repeatedly highlighted the risks of retaining personal data without a clear purpose or governance framework.  ICO investigations across both public and private sector organisations frequently identify poor records management and the absence of effective retention schedules as contributing factors to compliance failures.

First-Tier Tribunal and Upper Tribunal decisions indicate that retention is most likely to be challenged successfully where:

  • The original purpose has ended and no new lawful purpose exists
  • The data is no longer necessary for the organisation's functions
  • A legal hold or litigation justification cannot be evidenced
  • The data is inaccurate, excessive, or irrelevant
  • The controller cannot explain why retention remains proportionate.

However, they tend to support continued retention where there is clear evidence of regulatory obligations, safeguarding requirements, law enforcement needs, ongoing litigation risk and public protection considerations.

Tribunal and court decisions relating to DSARs also provide valuable lessons and illustrate the challenges organisations face when personal data is spread across multiple systems and repositories.  Claimants frequently challenge inadequate search processes which highlights the importance of being able to identify, locate and retrieve personal data efficiently, and shows how this can be supported by avoiding the retention of unnecessary data.

Employment tribunal litigation frequently reveals another practical problem.  Historic emails, informal messages and draft documents retained for years beyond their useful life can become disclosable evidence in disputes.  Organisations often discover that unnecessary data retention increases the volume of records requiring review during litigation, regulatory investigations and DSAR responses.  What may seem like harmless information storage can create significant legal costs and administrative burden in these circumstances.

Enforcement and tribunal cases reinforce that appropriately deleted data cannot be exposed in a breach, disclosed in a DSAR, or scrutinised during litigation.  Effective retention management reduces risk by limiting the amount of personal data an organisation holds and ensuring that information can be located and managed when required.

Closing Thoughts

An effective retention policy is about far more than just deleting old records; it is a core component of effective data governance.  Organisations need to maintain a clear retention schedule, review it regularly, automate deletion where possible, and ensure personal data is securely removed when it is no longer required.  By doing so, compliance risks are reduced, DSAR management is simplified, and the impact of potential data breaches is limited.  In an era of increasing regulatory scrutiny, good deletion practices are an essential part of effective data management.

Responsible organisations view personal data as a liability as well as an asset.  Every record retained must be protected, searched during DSARs, assessed during litigation, and potentially reported if compromised in a breach.  Organisations that maintain clear retention schedules, automate deletion where possible, and regularly review the data they hold are typically better positioned to demonstrate compliance, reduce operational costs, and minimise regulatory and legal risk.  As both ICO guidance and recent court decisions show, the key question is whether an organisation has a defensible reason for retaining personal data.  There is some truth in the adage that the easiest way to manage personal data is not to have it.

How URM Can Help

With extensive experience helping organisations achieve and maintain GDPR compliance, URM provides practical, expert-led support across all aspects of data protection.

Gap analysis and remediation support

Helping you understand your current compliance position and implement effective improvements:

  • Conducting a data protection gap analysis to assess your organisation's current compliance against UK GDPR requirements
  • Using information gathered during the GDPR gap analysis to provide prioritised recommendations and practical remediation plans to address identified compliance gaps
  • Assisting with key compliance activities and documentation, including Records of Processing Activities (ROPAs), data protection impact assessments (DPIAs), retention policies, retention schedules, privacy notices, etc.

DSAR, data breach and ongoing support

Providing specialist GDPR support to help you manage ongoing compliance obligations and respond effectively when issues arise:

  • Delivering expert DSAR support, helping you manage and respond to DSARs accurately, efficiently, and within statutory timeframes, applying all required exemptions and redactions
  • Assisting with personal data breach assessment, response, investigation, and regulatory notification requirements
  • Offering a Virtual Data Protection Officer (vDPO) service, providing you with access to experienced consultants for ongoing advice, oversight, and compliance support.

Training and workforce development

Building the knowledge and skills required to maintain effective data protection practices:

  • Delivering the Certificate in Data Protection (CDP) training course, providing delegates with a comprehensive understanding of data protection legislation and the opportunity to gain an industry-recognised qualification
  • Providing specialist 1-day DSAR training courses, as well as half-day DPIA and data transfer impact assessments (DTIAs) courses, equipping staff with the practical skills needed to manage key data protection obligations effectively.

Martin Brazier
Martin Brazier
Senior Consultant at URM
Martin is a highly experienced and knowledgeable GRC consultant at URM specialising in data protection. He holds BCS Certificates in Data Protection and Freedom of Information and achieved Certified Information Privacy Professional (Europe) (CIPP/E). He also holds BCS Certificates in Information Security Management Principles, Business Continuity Management and Information Risk Management.

Not sure where to begin with GDPR compliance?

We offer a free, no‑obligation call to help you understand your current data protection position and identify the most practical next steps
Thumbnail of the Blog Illustration
Data Protection
Published on
14/11/2025
ICO’s Appeal in Clearview AI Case Upheld

URM’s blog examines the impact of the latest ruling from the Upper Tribunal in the Clearview AI case, and the cross-border GDPR enforcement gap it exposes.

Read more
Thumbnail of the Blog Illustration
Data Protection
Published on
22/11/2024
Updated Data Protection Laws Introduced by Chile and India

URM’s blog explores the different requirements introduced by these new laws, and the likelihood of a subsequent UK/EU adequacy decision for each nation.

Read more
Thumbnail of the Blog Illustration
Data Protection
Published on
29/5/2024
First official European response to the Data Protection and Digital Information Bill

URM’s blog explores the first formal European response to the DPDI Bill, and how the Bill may jeopardise the UK’s adequacy status when it reforms the UK GDPR.

Read more
Great webinar with lots of information. All easy to understand.
Webinar 'ISO 27001:2022 – What’s new?'
contact US

Let us help you

Let us help you in your compliance journey by completing the form and letting us know how we can best support you.