Policy document; not a form.
- Download the DOCX for an editable Microsoft Word version you can email, print, or archive.
- Review this guidance carefully. For contracts, have a solicitor review before signing.
- Review the source chapter in the book for full context: see the chapter reference in the page header.
1. Purpose
This policy specifies the retention period for each type of data, the action at the end of the period, and the procedure for handling data subject requests.
2. Scope
This policy applies to all personal data processed by [Business Name], including customer data, staff data, and supplier data.
3. Retention periods
The retention periods are determined by the legal, regulatory, and operational requirements. The typical periods are:
— Customer data: 3 years from the last interaction (or longer if required by HMRC)
— Staff data: 6 years from the end of employment (per HMRC and HMRC guidance)
— Supplier data: 6 years from the end of the contract (per HMRC)
— Marketing data: until consent is withdrawn
— CCTV footage: 30 days (longer if required for an investigation)
4. Action at the end of the period
At the end of the retention period, the data is:
— Securely deleted from all systems (electronic and paper)
— Recorded in the data deletion log
— Verified as deleted (e.g. by checking the system or by a destruction certificate)
5. Data subject rights
The operator respects the data subject rights under the UK GDPR:
— Right of access (subject can request a copy of their data)
— Right of rectification (subject can request correction of inaccurate data)
— Right of erasure (subject can request deletion of their data, where applicable)
— Right to restrict processing (subject can request that processing is limited)
— Right to data portability (subject can request their data in a portable format)
— Right to object (subject can object to processing for direct marketing or other purposes)
6. Data subject request procedure
When a data subject makes a request:
1. Verify the identity of the requester (to prevent unauthorised disclosure).
2. Log the request in the data subject requests log.
3. Acknowledge the request within 1 month (extendable to 3 months for complex requests, with notice).
4. Respond to the request within the deadline. Provide the data in a portable format if requested.
5. Record the response in the data subject requests log.
7. Data breach response
If a data breach is identified:
1. Contain the breach (stop the unauthorised access).
2. Assess the risk to data subjects (low / high).
3. Notify the ICO within 72 hours if the risk is high.
4. Notify the affected data subjects if the risk is high.
5. Document the breach in the data breach log.
6. Review the incident and update the security measures.
8. Review
This policy is reviewed annually, or sooner if there is a change in the law or in the operator's data processing activities.
Date: [see DOCX]
Review: [see DOCX]
Live page: /handbook/book-resources/gdpr-data-retention-policy
QR target: https://visamomo.example/handbook/book-resources/gdpr-data-retention-policy