This guide is maintained as a current resource for July 2026 and covers only the laws of England and Wales. Information is for general guidance, not legal advice. Consult a qualified solicitor for advice specific to your situation.
Employee Data Retention Schedules: Legal Requirements in England and Wales explained in detail. Covers UK GDPR rules, employment law limitation periods, payroll and HR record retention, deletion duties, and compliance risks for employers managing employee data.

Employee data retention schedules set out how long employers can lawfully keep staff-related information and when it must be deleted, anonymised, or archived. In England and Wales, retention obligations arise primarily from UK GDPR (Data Protection Act 2018), alongside employment law, tax legislation, and limitation periods for legal claims.
There is no single universal retention period for employee data. Instead, organisations must adopt a documented retention schedule based on legal obligations, business necessity, and regulatory guidance. Retaining data for longer than necessary can breach data protection law, while deleting it too early can create exposure to tribunal claims, tax penalties, and compliance failures.
Legal Framework Governing Employee Data Retention
UK GDPR and the Data Protection Act 2018
The central rule governing retention is the storage limitation principle under Article 5(1)(e) UK GDPR. It requires personal data to be:
kept no longer than is necessary for the purposes for which it is processed
This means employers must define clear retention periods for each category of employee data and be able to justify them. The Information Commissioner's Office (ICO) expects organisations to maintain a structured retention schedule rather than storing data indefinitely or inconsistently.
There is no fixed statutory retention period for most HR records under UK GDPR, but employers must demonstrate proportionality and necessity.
Employment law limitation periods
Retention schedules are heavily influenced by limitation periods for employment-related claims, particularly:
- Unfair dismissal claims (generally 3 months less 1 day)
- Wage and unlawful deduction claims (typically 3 months less 1 day, but can involve historic evidence needs)
- Breach of contract claims (up to 6 years in some cases)
- Personal injury claims (often 3 years)
Because claims can arise after employment ends, many organisations retain core employee records for up to 6 years as a defensive measure, particularly for tribunal disputes.
Tax, payroll, and statutory record requirements
Certain employee records must be retained to comply with HMRC and tax legislation. Common requirements include:
- PAYE records
- National Insurance contributions
- Payroll and deduction records
These are typically retained for at least 3–6 years, depending on statutory requirements and audit risk exposure.
Health and safety and regulatory obligations
Workplace safety laws also impose retention obligations, such as:
- Accident records (RIDDOR reportable incidents often retained for at least 3 years)
- Risk assessments and safety training logs
- Exposure records for hazardous substances
These records may need longer retention periods where industrial disease or long-tail injury risks exist.
What Is an Employee Data Retention Schedule?
An employee data retention schedule is a structured document that sets out:
- Categories of employee data
- Legal basis for retention
- Retention period
- Trigger point (for example, end of employment or last payroll date)
- Method of deletion or anonymisation
- Responsible department or system owner
Under UK GDPR principles, organisations must be able to demonstrate that retention decisions are documented, consistent, and reviewable.
Categories of Employee Data and Typical Retention Periods
Retention periods vary depending on the type of record and legal risk.
1. Core personnel records
Includes contracts, job history, disciplinary records, and performance documentation.
- Common retention: employment duration + 6 years
- Justification: limitation periods for employment tribunal and civil claims
2. Payroll and tax records
Includes payslips, PAYE information, and deductions.
- Common retention: 6 years (HMRC compliance standard)
- Purpose: tax audits and statutory reporting obligations
3. Right to work documentation
Includes immigration checks and eligibility evidence.
- Common retention: duration of employment + 2 years
- Purpose: immigration enforcement compliance
4. Health and sickness records
Includes occupational health reports and sickness absence records.
- Common retention: 3–6 years depending on sensitivity and claim risk
- Higher sensitivity data may require stricter access controls under UK GDPR
5. Recruitment records
Includes CVs, interview notes, and candidate assessments.
- Common retention: 6 months to 1 year for unsuccessful applicants
- Purpose: defending discrimination claims under the Equality Act 2010
6. Health and safety records
Includes accident logs and training records.
- Common retention: 3 years minimum for many safety records
- Longer where exposure-related risks exist
Legal Duties Linked to Data Retention Schedules
Data minimisation and storage limitation
Employers must only retain data that is:
- Necessary for a defined purpose
- Proportionate to that purpose
- Securely stored and regularly reviewed
Keeping data “just in case” is not compliant with UK GDPR.
Right to erasure and deletion obligations
Employees have rights under UK GDPR to request deletion of personal data in certain circumstances. Employers must balance this against legal obligations to retain records for tax, employment, or litigation purposes.
Subject access requests (SARs)
Employees can request copies of their data. Employers must respond within one calendar month, making accurate retention schedules essential for locating and managing data efficiently.
Data security and confidentiality duties
Retention schedules must align with obligations to:
- Protect sensitive employee data
- Restrict access to authorised personnel
- Ensure secure deletion or anonymisation
- Maintain audit trails where required
Common Compliance Risks in Retention Schedules
1. Indefinite storage of employee data
Keeping records without a defined retention period is a breach of UK GDPR storage limitation principles.
2. Over-retention of recruitment data
Holding applicant data for excessive periods increases exposure to discrimination claims and data protection complaints.
3. Inconsistent deletion practices
Different departments applying different retention rules creates compliance gaps.
4. Failure to document retention decisions
Without written justification, retention periods may be challenged by the ICO.
5. Poor offboarding processes
Employee exit procedures often fail to trigger structured deletion workflows.
Enforcement and Legal Consequences
Non-compliance with employee data retention requirements can lead to:
- ICO investigations and enforcement notices
- Administrative fines under UK GDPR
- Employment tribunal claims involving disclosure failures
- Civil claims for misuse or mishandling of personal data
- Reputational damage affecting recruitment and regulatory relationships
In serious cases, breaches of data protection law can result in significant financial penalties, particularly where systemic failures are identified.
Practical Steps for Employers
Develop a written retention schedule
Each category of employee data should have a defined retention period and justification.
Align HR, payroll, and IT systems
Retention rules must be consistently applied across all systems holding employee data.
Automate deletion where possible
HR software can reduce human error and ensure consistent compliance.
Conduct regular audits
Retention schedules should be reviewed periodically to ensure ongoing legal compliance.
Train HR and managers
Staff handling employee data must understand retention triggers and deletion requirements.
Final Thoughts
Employee data retention schedules are a core requirement of UK data protection and employment compliance frameworks. Employers must balance multiple legal obligations, including UK GDPR principles, tax rules, and limitation periods for legal claims.
A compliant retention schedule is not simply a record-keeping tool but a structured legal framework that governs how employee data is collected, stored, reviewed, and deleted. Failure to implement and maintain such schedules can lead to regulatory enforcement, tribunal exposure, and significant financial liability.