Data protection
A retention schedule that actually disposes on time
Storage limitation is the data protection principle almost everyone agrees with and almost nobody honours. UK GDPR Article 5(1)(e) says it plainly: do not keep personal data for longer than you need it. The trouble is that a retention policy deletes nothing. You can write "customer records: six years" in a handsome document, file it, and still be sitting on twelve years of data, because a policy states a rule and a rule does not run itself. The batches keep arriving and nothing leaves.
A retention schedule that works has two halves that most attempts collapse into one: the policy that sets the rule, and the tracker that makes disposals actually happen. Get both, keep them linked, and deletion becomes a scheduled task instead of a good intention.
Setting the period by record type
Retention is set per record type, not per person and not per system. Group your data into the categories you genuinely hold - customer records, employee files, job applicants, supplier contracts, marketing consents, CCTV, accident records - and set a period for each. The periods are not arbitrary; each one should trace back to a reason:
- A statutory or regulatory minimum - payroll and tax records carry HMRC retention requirements; certain health and safety records have their own statutory periods. Where the law sets a floor, that floor is your answer.
- A limitation period - keeping contract records for the length of time a claim could be brought is a defensible business reason.
- An operational need - how long you actually use the record to do the thing you collected it for.
If you cannot name a reason for a retention period, that is the signal it is too long. "We might need it one day" is not a lawful basis; it is hoarding with better vocabulary.
The lawful basis for keeping it
Every retention period should record why you are allowed to hold the data that long. This is not the same as the lawful basis for collecting it in the first place - it is the justification for the duration. Legal obligation covers the statutory minimums. Legitimate interests can cover keeping a record for the length of a limitation period, if you have done the balancing. Recording the basis alongside the period turns your schedule from a list of guesses into a document you can defend when someone asks why an old record still exists.
What starts the clock
The detail that quietly breaks most schedules is the trigger. "Six years" from when? Retention periods almost never run from the date you collected the data. They run from an event:
- Employee records from the end of employment, not the start.
- Contract records from contract end, not signature.
- Customer records from the last transaction or the end of the relationship.
Name the trigger event for every record type. Without it, the disposal date is unknowable and the whole schedule is decorative.
From policy to disposal
Here is where the tracker earns its place. Once you have the rule (record type, period, trigger, lawful basis, disposal method), you apply it to specific batches of real data. A batch has its own trigger date - the day that particular employee left, the day that contract ended - and from that date plus the retention period the disposal-due date calculates itself.
Now the schedule can do something a policy never could: count down. Each batch has a status that decides itself - retain, due soon, overdue for disposal, or disposed - and a days-left figure that ticks down live. When a batch goes overdue it is flagged, in front of you, rather than buried in a document nobody reopens. Disposal stops being an annual scramble and becomes a short, regular job of clearing whatever the tracker has flagged.
Prove the disposal happened
Deleting the data is only half the obligation; being able to show you deleted it is the other half. Record the disposal method for each record type - secure deletion, shredding, anonymisation - and mark each batch disposed when it is done. A schedule that carries a trail of completed disposals is evidence of the storage-limitation principle in action, which is exactly what you want to be able to produce if you are ever asked.
A retention schedule is working when every record type has a period, a lawful basis, a named trigger and a disposal method, and every live batch is counting down to a date that calculates itself.
Retention periods and their lawful bases are a genuine judgement call, and the statutory minimums shift - a template gives you the structure and the countdown mechanics, but the specific periods for your organisation deserve a review by a suitably qualified professional. What the structure guarantees is that once you have set the rules, nothing sits past its date unnoticed. The policy stops being a filed document and starts being the thing that empties the shelves.
Policy and disposal in one file
A retention schedule that sets the rule for each record type, plus a disposal tracker that works out each batch's disposal-due date from its own trigger and counts it down live - status decides itself, overdue batches flagged on a dashboard. With a worked example.