P-91 Data Retention Policy
File Reference : P-91 Data Retention Policy
Date File Updated 14-09-26
File Format MS Word
No. of files 1
Category Policies
Tags: ISO 27001, UK GDPR, data retention, retention schedule, data protection
  • £2.50

  or  

Login to Download


Retention is where good intentions go wrong, because copies turn up in backups, inboxes and AI tools long after the live record has gone. This policy states how retention periods are decided and that they apply to every copy.

Effective Policy Templates

This policy template is supplied in fully editable MS Word format and can be easily customised and edited. The document uses pre-defined style formatting throughout, with all text in Calibri font for improved readability.
The following document labelling is included in the footer:

  • Policy number and title
  • Information-classification
  • Version
  • Page number / total pages
alphaZ documents - beautifully designed, tried and tested policy templates. No junk, jargon or unnecessary content. Simple and usable policy templates developed over 25 years through practical use in the real world.
Document Preparation
Logo Update Service *

Download this policy template with your company name and logo already added!
Document Preparation available with all document toolkits.

How to Download

To get access to this file please click on Add to Cart to purchase for immediate download. If you have an alphaZ Subscription just click on Download Files to view all the files available to download. This policy is also included in the GDPR / Data Protection Toolkit and the ISO 27001 toolkit and the integrated toolkits that include it, so the toolkit route gives you this file plus everything else you need in one download.

Implementation Support
Need Help Implementing?

If you'd like hands-on help setting retention periods and a personal data register for your organisation, our remote support services provide direct expert input from our team, by the day, by project, or on an ongoing basis.

File Formats

Data Retention Policy Template

A public data retention policy for stating how long your organisation keeps personal data and how it is disposed of. It sets out the commitment to keep only what is needed, how retention periods are decided, and where the retention schedule is kept.

What the Policy Covers

  • Our commitment - holding the minimum personal data needed, for no longer than needed
  • How we decide how long to keep personal data - the factors behind each retention period
  • Our retention schedule - kept on the personal data register, category by category
  • Every copy, not only the live record - backups, archives and copies held by service providers, including AI service providers
  • Deletion, anonymising and archiving - what happens when a period ends
  • Asking us to delete personal data - how a request for deletion is handled

An Optional Standalone Policy

The PP-1-16 Data Protection Policy Procedure already contains the data retention content in its section Personal Data Review and Retention (Data Retention Policy), so a company using the procedure does not need this separate file. It is here for organisations that want a standalone, publicly shareable policy on this one subject - to give to a customer or answer a questionnaire, for example. Where both are used, make sure the policy says the same as the procedure.

Who Needs a Data Retention Policy?

Any organisation asked to show how long it keeps personal data, whether by a customer, a tender panel or an individual. It is a straightforward way to evidence the storage limitation principle in a document that can be shared.

Included in the GDPR / Data Protection Toolkit

This policy is part of the GDPR / Data Protection Toolkit - the registers, forms, policies, procedure and guidance for documenting how you collect and process personal data, in one download, and is also included in the ISO 27001 toolkit.

Works with the Personal Data Register

The retention period for each category of personal data is recorded on the register - the F-IMS24 Personal Data Register or the ER21 Personal Data Register - so the policy states the approach and the register holds the detail.

Using the Policy

Add your company details and approval, check the policy matches the retention periods on your personal data register, and publish or share it as needed.

Why Every Copy Matters

Deleting the live record is not the end of it if copies remain in backups, email, shared drives or with a service provider. The policy covers these copies, including those held by AI service providers, so a retention period means the same thing wherever the data is held.

Deciding Retention Periods

The policy sets out the basis for each period - a legal or regulatory requirement, the life of a contract plus the time in which a claim could be brought, an ongoing business need, or consent - with the longest period applying where more than one does.

Related Documents

Other documents in the GDPR / Data Protection Toolkit that work alongside this one:

Would you rather we prepared it for you?

Our Personal Data Register and Privacy Notice Preparation service works through the personal data your organisation holds with you, including the AI tools in use, and prepares the register and privacy notice so they describe what actually happens to that data.

Personal Data Register and Privacy Notice Preparation

There are currently no comments for this document.

Add a Comment

Please Login or Subscribe to add Comments.