Employee Data Retention Schedules: Legal Requirements

Editorial Status & Legal Guidance

This guide is maintained as a current resource for July 2026 and covers only the laws of England and Wales. Information is for general guidance, not legal advice. Consult a qualified solicitor for advice specific to your situation.

Key Takeaways for Employee Data Retention Schedules: Legal Requirements

Employee Data Retention Schedules: Legal Requirements in England and Wales explained in detail. Covers UK GDPR rules, employment law limitation periods, payroll and HR record retention, deletion duties, and compliance risks for employers managing employee data.

Employer Compliance: Employers must comply with strict statutory duties regarding health, safety, and employee rights. Failure to comply leads to heavy litigation.

Employee data retention schedules set out how long employers can lawfully keep staff-related information and when it must be deleted, anonymised, or archived. In England and Wales, retention obligations arise primarily from UK GDPR (Data Protection Act 2018), alongside employment law, tax legislation, and limitation periods for legal claims.

There is no single universal retention period for employee data. Instead, organisations must adopt a documented retention schedule based on legal obligations, business necessity, and regulatory guidance. Retaining data for longer than necessary can breach data protection law, while deleting it too early can create exposure to tribunal claims, tax penalties, and compliance failures.

Legal Framework Governing Employee Data Retention

UK GDPR and the Data Protection Act 2018

The central rule governing retention is the storage limitation principle under Article 5(1)(e) UK GDPR. It requires personal data to be:

kept no longer than is necessary for the purposes for which it is processed

This means employers must define clear retention periods for each category of employee data and be able to justify them. The Information Commissioner's Office (ICO) expects organisations to maintain a structured retention schedule rather than storing data indefinitely or inconsistently.

There is no fixed statutory retention period for most HR records under UK GDPR, but employers must demonstrate proportionality and necessity.

Employment law limitation periods

Retention schedules are heavily influenced by limitation periods for employment-related claims, particularly:

  • Unfair dismissal claims (generally 3 months less 1 day)
  • Wage and unlawful deduction claims (typically 3 months less 1 day, but can involve historic evidence needs)
  • Breach of contract claims (up to 6 years in some cases)
  • Personal injury claims (often 3 years)
Related:  Legal Duties Around Shared Parental Leave

Because claims can arise after employment ends, many organisations retain core employee records for up to 6 years as a defensive measure, particularly for tribunal disputes.

Tax, payroll, and statutory record requirements

Certain employee records must be retained to comply with HMRC and tax legislation. Common requirements include:

  • PAYE records
  • National Insurance contributions
  • Payroll and deduction records

These are typically retained for at least 3–6 years, depending on statutory requirements and audit risk exposure.

Health and safety and regulatory obligations

Workplace safety laws also impose retention obligations, such as:

  • Accident records (RIDDOR reportable incidents often retained for at least 3 years)
  • Risk assessments and safety training logs
  • Exposure records for hazardous substances

These records may need longer retention periods where industrial disease or long-tail injury risks exist.

What Is an Employee Data Retention Schedule?

An employee data retention schedule is a structured document that sets out:

  • Categories of employee data
  • Legal basis for retention
  • Retention period
  • Trigger point (for example, end of employment or last payroll date)
  • Method of deletion or anonymisation
  • Responsible department or system owner

Under UK GDPR principles, organisations must be able to demonstrate that retention decisions are documented, consistent, and reviewable.

Categories of Employee Data and Typical Retention Periods

Retention periods vary depending on the type of record and legal risk.

1. Core personnel records

Includes contracts, job history, disciplinary records, and performance documentation.

  • Common retention: employment duration + 6 years
  • Justification: limitation periods for employment tribunal and civil claims

2. Payroll and tax records

Includes payslips, PAYE information, and deductions.

  • Common retention: 6 years (HMRC compliance standard)
  • Purpose: tax audits and statutory reporting obligations

3. Right to work documentation

Includes immigration checks and eligibility evidence.

  • Common retention: duration of employment + 2 years
  • Purpose: immigration enforcement compliance
Related:  How to Calculate the National Living Wage Correctly

4. Health and sickness records

Includes occupational health reports and sickness absence records.

  • Common retention: 3–6 years depending on sensitivity and claim risk
  • Higher sensitivity data may require stricter access controls under UK GDPR

5. Recruitment records

Includes CVs, interview notes, and candidate assessments.

  • Common retention: 6 months to 1 year for unsuccessful applicants
  • Purpose: defending discrimination claims under the Equality Act 2010

6. Health and safety records

Includes accident logs and training records.

  • Common retention: 3 years minimum for many safety records
  • Longer where exposure-related risks exist

Legal Duties Linked to Data Retention Schedules

Data minimisation and storage limitation

Employers must only retain data that is:

  • Necessary for a defined purpose
  • Proportionate to that purpose
  • Securely stored and regularly reviewed

Keeping data “just in case” is not compliant with UK GDPR.

Right to erasure and deletion obligations

Employees have rights under UK GDPR to request deletion of personal data in certain circumstances. Employers must balance this against legal obligations to retain records for tax, employment, or litigation purposes.

Subject access requests (SARs)

Employees can request copies of their data. Employers must respond within one calendar month, making accurate retention schedules essential for locating and managing data efficiently.

Data security and confidentiality duties

Retention schedules must align with obligations to:

  • Protect sensitive employee data
  • Restrict access to authorised personnel
  • Ensure secure deletion or anonymisation
  • Maintain audit trails where required

Common Compliance Risks in Retention Schedules

1. Indefinite storage of employee data

Keeping records without a defined retention period is a breach of UK GDPR storage limitation principles.

2. Over-retention of recruitment data

Holding applicant data for excessive periods increases exposure to discrimination claims and data protection complaints.

3. Inconsistent deletion practices

Different departments applying different retention rules creates compliance gaps.

4. Failure to document retention decisions

Without written justification, retention periods may be challenged by the ICO.

5. Poor offboarding processes

Employee exit procedures often fail to trigger structured deletion workflows.

Related:  Responding to Health and Safety Enforcement Inspections

Enforcement and Legal Consequences

Non-compliance with employee data retention requirements can lead to:

  • ICO investigations and enforcement notices
  • Administrative fines under UK GDPR
  • Employment tribunal claims involving disclosure failures
  • Civil claims for misuse or mishandling of personal data
  • Reputational damage affecting recruitment and regulatory relationships

In serious cases, breaches of data protection law can result in significant financial penalties, particularly where systemic failures are identified.

Practical Steps for Employers

Develop a written retention schedule

Each category of employee data should have a defined retention period and justification.

Align HR, payroll, and IT systems

Retention rules must be consistently applied across all systems holding employee data.

Automate deletion where possible

HR software can reduce human error and ensure consistent compliance.

Conduct regular audits

Retention schedules should be reviewed periodically to ensure ongoing legal compliance.

Train HR and managers

Staff handling employee data must understand retention triggers and deletion requirements.

Final Thoughts

Employee data retention schedules are a core requirement of UK data protection and employment compliance frameworks. Employers must balance multiple legal obligations, including UK GDPR principles, tax rules, and limitation periods for legal claims.

A compliant retention schedule is not simply a record-keeping tool but a structured legal framework that governs how employee data is collected, stored, reviewed, and deleted. Failure to implement and maintain such schedules can lead to regulatory enforcement, tribunal exposure, and significant financial liability.

James William Steven Parker
James William Steven Parker
James is the founder of UKLegalGuides.com and a former agent at the Ministry of Justice (UK). With a background in processing legal claims, he launched this platform to make the laws of England and Wales accessible to everyone.
Scroll to Top