Right-to-work evidence should be stored securely and retained for the period required by the prescribed checking framework. The current employer guidance requires retention for employment and a further two years after it ends, with controlled access and secure disposal afterwards where appropriate.
Keep a reliable link to the employee record and actual check date. Retention should preserve readable evidence without creating unnecessary copies across personal devices.
Identify the evidence that must be retained
Right-to-work retention starts with the prescribed evidence, not an unrestricted copy of everything the employee provides. The Home Office guidance specifies the records for manual checks, online profiles and qualifying digital identity checks. The actual check date must be recorded, and the evidence must be available promptly if requested. A spreadsheet containing only a share code or passport number does not replace the required record. [1]
Separate the check evidence from other onboarding information such as bank details, emergency contacts and occupational health records. This helps apply the correct access and retention arrangements to each category. Keep supporting evidence that is needed to explain a check, such as a justified name link, within the controlled file rather than in an informal manager's folder.
Apply the retention period to the right record
The current employer guidance requires right-to-work evidence to be kept securely for the duration of employment and for two years afterwards, followed by secure destruction. Record the leaving date so that the retention period can be calculated accurately. Do not delete the evidence when a recruiter closes the vacancy or when a share code expires; those events do not end the employment retention requirement. [1]
Other employment, sponsorship or dispute records may have distinct requirements. Map those separately rather than applying the longest period to every item by default. If a specific legal hold or competing obligation affects disposal, obtain advice and document the reason and scope. The policy should explain what is retained, why, who reviews it and what event triggers deletion, so staff do not keep complete identity files indefinitely out of uncertainty.
Control access and protect the transfer of files
Use a system with individual accounts, appropriate access permissions and a secure method for receiving evidence. Limit full identity-file access to people who need it for their responsibilities. The ICO's security guidance emphasises measures appropriate to the risks, including both technical and organisational controls. Encryption alone does not solve a process in which identity documents are routinely sent to the wrong recipient. [2]
Check supplier arrangements where an HR platform, recruitment provider or outsourced administrator stores the records. Establish who can retrieve and export them, how access ends and what happens when the contract closes. Avoid relying on a provider's marketing statement as the whole security assessment. Our guide to Dealing with missing right-to-work records shows how lost portal access can turn an apparently completed check into an evidential gap.
Make records retrievable without unnecessary circulation
Use a consistent identifier and file structure so authorised staff can locate the evidence without searching multiple inboxes. Preserve the original saved result and keep later notes clearly dated. Restrict editing and record changes where the system permits. A manager arranging shifts generally needs the applicable work restriction and follow-up instruction, not an emailed copy of every identity document.
Test retrieval with a small, justified sample and check that the files remain readable after system changes. Backups should support recovery, while access to backups and exports also needs control. If the business merges systems or changes HR providers, plan evidence migration explicitly. The fact that employee names appeared in the new database does not prove that the attached check profiles and date records transferred successfully.
Build deletion and incident handling into the process
Create a scheduled disposal process for records that have reached the end of the applicable period, subject to any justified hold. Include exported copies and local downloads where practicable. Record that disposal occurred without retaining the sensitive document merely as proof of deletion. Staff should know how to report a misdirected email, lost device or unexpected access to a check file so the organisation can assess the incident promptly.
For help through Workforce immigration audit support, describe the types of records, systems, providers and the specific retention or access problem. Any immigration advice must come from an appropriately regulated or otherwise legally authorised adviser, while data-protection issues may require separate expertise. Start with an anonymised process description rather than uploading a complete staff identity archive. This allows the scope of the review and secure evidence requirements to be agreed first.
Give the retention policy an owner who can coordinate HR, IT and legal input when a record falls into more than one category. Clear responsibility prevents two opposite errors: deleting prescribed evidence too early and retaining unnecessary personal material long after its purpose has ended.
Illustrative scenario
A business centralises check results in a restricted HR system and records leaving dates for retention review. Managers receive only the information needed to manage work restrictions.
Preparation checklist
- Link evidence to the employee
- Restrict access
- Track employment end dates
- Apply a controlled retention review
Frequently asked questions
How long should ordinary right-to-work evidence be kept?
The current employer guidance specifies the duration of employment plus two years, followed by secure destruction. Assess distinct record duties or justified legal holds separately.
Is retaining the share code enough?
No. Keep the required employer-facing check result and date information. A code gives access to a service; it is not the complete evidence of the check performed.
Should line managers receive full identity files?
Usually they need the operational restriction and next action. Full-document access should be limited to people with a justified need for their role.
What should be checked when changing HR systems?
Confirm that evidence attachments, actual check dates, restrictions and follow-up information transfer correctly and remain readable and retrievable by authorised staff.
Official sources
Sources checked: 8 September 2026. Check the linked guidance for subsequent changes.
- Home Office: Employer right-to-work guide (26 June 2025; current before 1 October 2026)
- ICO: A guide to data security
General information only. The appropriate action depends on your circumstances and the applicable jurisdiction.
Report a correction