Developing a retention schedule is a key part of preserving records until it is time to archive them or destroy them. In this article we will explore the key elements to developing a retention schedule and how to get started.
Contents
Why Have a Retention Schedule?
A retention schedule or retention period tells you how long to keep information depending on its type. Once the retention period is up you can then make a decision on whether to archive or destroy the record in question.
This is an important part of records management, which is the framework under which organisational records are curated.
Further Reading
-
learn more about records management here.
-
find out about destroying data and information here.
-
understand archiving records here.
-
you can find an introduction to information security here.
Understanding Retention Requirements
In the realm of information governance, the bedrock of a robust retention schedule lies in a clear comprehension of the legal and regulatory landscape that surrounds data management. Let’s delve into the intricacies of this foundational aspect.
The Legal and Regulatory Framework
At the heart of retention scheduling are the legal frameworks and regulations that govern data across various industries and jurisdictions. An understanding of these legal obligations is important for crafting a retention schedule that not only aligns with the law but also stands as a bulwark against legal pitfalls.
Data Protection Laws
Regulations such as the General Data Protection Regulation (GDPR) set stringent requirements for the handling and retention of personal data. Familiarity with the principles embedded in these laws is essential for compliance.
It is important, as part of GDPR compliance requirements, to know how long you will retain personal data for. You should also make appropriate arrangements for disposing of personal data when it is no longer needed.
Industry-Specific Regulations
Different sectors, from healthcare to finance, have industry-specific regulations governing data retention. Navigating this intricate web of rules ensures that the retention schedule is tailored to the unique demands of a particular business domain. These can provide guidance for your own organisation’s retention schedule. For example, the Department of Health and Social Care has a retention schedule for healthcare related data, which is available here.
Industry-Specific Compliance
The second layer of understanding retention requirements involves delving into industry-specific compliance standards. Many industries have their own set of rules and norms dictating how data should be handled, stored, and ultimately, disposed of. For instance:
Financial Services
Financial institutions are subject to regulations like the Sarbanes-Oxley Act (SOX), which mandates specific retention periods for financial records. Adhering to these regulations is imperative for regulatory compliance.
Navigating this intricate terrain requires a keen eye for detail and a proactive approach to stay abreast of evolving legal and regulatory landscapes. A comprehensive understanding of the legal and regulatory framework surrounding data retention lays the groundwork for creating a retention schedule that is not just compliant but resilient in the face of legal scrutiny
Inventory of Information Assets
Once the legal and regulatory landscape is understood the next step in developing a retention schedule involves taking stock of an organisation’s information assets. This process is akin to creating an inventory, cataloging the diverse types of data in play.
Identifying Types of Information
The first task is to identify the various types of information that an organisation handles. This includes everything from customer data and financial records to internal reports, emails, and even metadata associated with different datasets. Examples of records types include:
Estates
Estates information includes things like building plans, CCTV footage, leases and records of maintenance work.
Communications
Communications records include public consultations, public facing information, press releases and visitor records to your website.
Staff Records
Staff records range from applications received to data around pensions and will include training records, sick records and tax information.
Categorising Data Sensitivity
Not all data is created equal, and recognising the sensitivity levels of different types of information is fundamental to crafting a nuanced retention schedule.
Confidential Information
This category encompasses sensitive information, such as trade secrets or proprietary data, that requires a heightened level of protection and careful consideration in retention decisions.
Compliance-Related Data
Information that directly relates to compliance with legal or industry-specific regulations often demands specific handling and retention procedures.
This inventorying phase lays the groundwork for the subsequent steps in the retention scheduling process. By categorising and understanding the various types of information an organisation manages, one can tailor retention periods and security measures to suit the unique attributes of each data category.
Determining Retention Periods
With a comprehensive understanding of the legal landscape and a detailed inventory of information assets, the next critical step in developing a retention schedule involves determining the appropriate retention periods for each category of data. This process is not only influenced by legal mandates but also demands a delicate balance with operational needs.
Balancing Business Needs
While legal mandates provide a foundation, the intricacies of operational requirements and business needs must be carefully considered. Striking a harmonious balance between compliance and operational efficiency involves:
Operational Value of Information
Assessing the ongoing operational value of information is crucial. Data that actively contributes to business processes or decision-making may warrant a longer retention period.
Space and Resource Constraints
The practical aspects of data storage, including costs and resource constraints, should be factored in. Retaining data indefinitely may not be operationally or economically feasible.
This phase of determining retention periods requires a nuanced understanding of both the external regulatory environment and the internal dynamics of the organisation. The goal is to create a retention schedule that not only meets legal requirements but also aligns seamlessly with the practical needs and objectives of the business.
Factors Influencing Retention Decisions
Numerous elements influence the decision to retain or dispose of data:
Operational Value of Information
The usefulness of information in ongoing operations is a key factor. Valuable data may warrant longer retention. unnecessary records can be destroyed quickly, freeing up space and other resources. The table below sets out some types of records that may need short or long term retention:
| Record | Retention Period |
| Shift patterns | Short |
| Board papers | Long |
| HR records | Long |
| Utility bills | Short |
| Contracts | Long |
Potential Legal Risks
Assessing legal risks associated with retaining certain types of information is vital. It’s a delicate dance between risk aversion and operational necessity.
For example retaining personal data for longer than is reasonable causes a legal risk around GDPR compliance. Conversely deleting data, like financial information, too soon could mean you are unable to mount a defence if you are subject to legal challenges
Crafting a Comprehensive Policy
A well-documented document retention policy is the cornerstone of effective retention management. The policy will document for all staff
-
statutory and regulatory compliance requirements
-
the organisation’s approach to paper and electronic records management
-
link to the records retention schedule
-
the potential consequences of non-compliance
Documenting Retention Guidelines
Clear guidelines on how different types of information should be handled streamline decision-making processes. Even if the content is the same the medium may mean different approaches are taken. Physical records need different management to electronic records, for example in records storage requirements.
Incorporating Stakeholder Input
Including input from various stakeholders ensures that the policy is practical, aligns with business goals, and considers diverse perspectives. Examples of stakeholders include:
-
customers
-
suppliers
-
industry bodies
-
colleagues of business areas which handle different types of data
Ensuring Accessibility and Security
Retained data should be both accessible and secure. That means it needs to be:
-
stored in a way that makes it easy to find – having the right filing system
-
restricted to those who need access to it, and no-one else
-
maintained by the record owner or other accountable person
Access controls in particular are key for information security.
Balancing Access Needs and Security Measures
Striking a balance between allowing necessary access for business purposes and maintaining robust security protocols is critical. Examples of information security include:
-
access controls, and logs of access to records
-
physical and electronic security such as locks on doors and filing cabinets
-
avoiding duplication of records and keeping one set of master records
Training and Communication
People need to both understand retention periods and related policies, and know where to fine them. The key to this is a combination of training and communication.
Educating Employees on Retention Policies
Training programs that educate employees about information governance are important because they will enhance information security and data protection. As part of this people need to be taught about retention periods, data deletion and information archiving.
Regular Communication and Updates
Consistent communication and updates about changes in retention policies foster a culture of awareness and responsibility. Reminding people of their responsibilities, where supporting information like policies can be found, and who can help them will provide an audit trail of compliance.
Learn More About Information Governance
X

Conclusion: Key Takeaways from Developing a Retention Schedule
Crafting a retention schedule is a meticulous process that demands a good understanding of legal landscapes, business needs, and technological solutions. It is a blueprint for responsible information management, ensuring that organisations navigate the complexities of data retention well. In an era where data is both a valuable asset and a potential liability, a well-developed retention schedule supports compliance, efficiency, and data stewardship.
- September 2026
- August 2026
- July 2026
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- September 2022
- August 2022
- June 2022
- May 2022
- March 2022
- February 2022
- January 2022
- December 2021
CONTACT US
Switchboard: 0330 221 0547
Training enquiries: 0330 221 0552
Email: hello@wudo.solutions
15 Warland Rd, London, SE18 2EX
Open every day 8am to 8pm except bank holidays.
Get the latest news, resources and special offers direct to your inbox: