A retention schedule explains how long different information is kept and why. It should identify the event that starts the period and the action at its end. Avoid a single rule for every record: an unsuccessful enquiry, payroll record and active dispute file serve different purposes.
Bring legal, operational and system constraints into the decision. Record any justified hold and review it rather than suspending deletion indefinitely. Check whether deletion reaches exports and suppliers, and explain the controlled treatment of backups where immediate removal is not technically possible.
Choose categories that match business decisions
Start with an inventory of records that staff can recognise: unanswered enquiries, completed customer files, invoices, recruitment applications and complaint records. A category called miscellaneous business information is too broad to support consistent deletion. For each category, identify the purpose that remains after the immediate transaction finishes. Keeping evidence of an invoice is different from keeping every marketing note associated with the same customer, even if both currently sit in one account.
Separate statutory retention requirements from a justified business retention decision. The ICO's storage limitation guidance does not prescribe one universal period for all personal information. [1] Ask the relevant adviser which obligations apply to the record and which event starts the period. Avoid assuming that a tax record retention period automatically authorises keeping unrelated identity documents, old medical details or speculative sales notes for the same duration.
Define the clock and the action
Write a trigger that a system or employee can identify. Account closure, the last substantive enquiry and the end of an accounting period lead to different dates. Decide what happens when a customer returns: some records may become relevant again, but a new purchase should not automatically restart retention for every historic document. Explain how the business will distinguish a new active matter from an old closed file.
Specify whether the end action is deletion, genuinely effective anonymisation or transfer to a restricted archive for a continuing purpose. Removing a name alone may not anonymise a detailed case history. If an archive is justified, identify who can access it and what they may use it for. A folder called archive that remains searchable by every salesperson provides little practical separation from the live customer database.
Deal with copies and system limits
List the systems containing each category, including email attachments, scheduled exports and portable media. Ask the software owner whether deletion removes uploaded documents as well as the visible customer profile. Check supplier instructions and contract exit procedures. The guide to Deleting customer information securely addresses secure removal, while Keeping a record of processing activities helps connect record categories to the underlying processing activities and their responsible owners.
Backups need a realistic approach. Document their expiry cycle, access restrictions and how deleted information will be handled if a backup is restored. Do not promise immediate erasure from every backup if the system cannot deliver it. Equally, a backup label should not become a reason to preserve an ordinary working copy indefinitely. Test the restore process with synthetic information so staff understand the required follow-up action.
Manage holds and prove the process works
A dispute, investigation or specific obligation may justify preserving particular records. Record the scope, reason, decision-maker and review date for the hold. Avoid a blanket instruction to retain all customer information until further notice when only one matter is relevant. When the reason ends, remove the hold and apply the appropriate schedule rather than leaving the exception permanently attached to the record.
Before deploying automatic deletion, run a report showing what would be removed and review a sample with the responsible team. Check false matches, linked matters and important attachments. Keep a limited completion log showing the category, period and outcome without copying the content back into that log. This creates evidence of the control while respecting the purpose of reducing unnecessary information.
For Business privacy notice review, bring the draft category list, known obligations and actual software limitations. Ask for clear decisions on uncertain categories and a practical exception process. Set a review when a new service collects different information, when a system is replaced or when a legal obligation changes. The schedule should remain a working instruction that people can apply, not a policy whose dates nobody can translate into system settings.
Review one category before expanding the schedule
Pilot the schedule on unsuccessful sales enquiries. Select a small sample and identify when each enquiry genuinely ended, whether a complaint remains open and whether copies exist in individual mailboxes. Compare the proposed rule with what the system can select automatically. An account creation date may be easy to filter but may not represent the retention trigger you intended.
Record exceptions revealed by the pilot and decide whether they require a clearer rule or a different workflow. Then repeat the exercise for another category with a different purpose, such as completed project records. This exposes practical gaps before an automated deletion job affects a large collection, and gives the owner evidence that the written schedule can be implemented.
Illustrative scenario
A business deletes old enquiries from its customer system but keeps monthly exports in a shared drive. The schedule review identifies the exports as a second copy requiring control. The team assigns a deletion process and owner, then checks that the same information is not reintroduced during a later import.
Preparation checklist
- Group records by purpose and relevant obligation.
- Define start events, periods and deletion actions.
- Identify exports, archives and supplier copies.
- Record exceptions, owners and review dates.
Frequently asked questions
Is six years suitable for every customer record?
No universal period covers all personal information. Assess each category's purpose and applicable obligations; an invoice retention requirement does not automatically justify keeping every associated document.
What is a retention trigger?
It is the identifiable event from which a period runs, such as closing a matter. Define it consistently so staff and software do not calculate different deletion dates.
Can a dispute stop all deletion?
Preserve the information genuinely relevant to the dispute or obligation. Record a scoped hold and review it; avoid retaining unrelated records through an indefinite blanket exception.
How do we handle restored backups?
Plan how expired information is identified and prevented from returning to routine use. Record the backup cycle and test the restoration procedure rather than making an unsupported immediate-deletion promise.
Official sources
Sources checked: 8 September 2026. Check the linked guidance for subsequent changes.
General information only. The appropriate action depends on your circumstances and the applicable jurisdiction.
Report a correction