How Long Should You Keep Your Records?

How long should company records, financial data, healthcare records, legal documents, and more be kept. A guide to legally required records retention periods.

Whether you’re running a small business or working in healthcare, knowing how long to keep different records is crucial. Getting it wrong could lead to fines, financial problems or damage to your reputation.

This Record Keeping Guide explains the legal requirements for keeping different types of records, who can access them, and how to protect sensitive information from falling into the wrong hands … and when to must delete records.

Digital Records Management with Automated Retention and Deletion

Introduction to record keeping schedules and deadlines

Today, digital records management provides the most reliable way to preserve documents, protect them and retain them for mandated periods. However, there are also millions of documents stored as paper records. Wet signatures may still outnumber elctronic signatures, though the e-signature is catching up fast.

Regardless how records are kept – paper, electronic, audio or video – there are stricct rules about how long records are to be kept and, conversely, when they must be deleted, destroyed or struck from public record.

How long you must keep records depends on what type of documents they are and which sector you work in. Different countries have different rules, and even within the UK, requirements vary across industries.

If you’re dealing with:

  • Tax and financial records

    HM Revenue & Customs requires businesses to keep financial and accounting records for at least six years after the end of the financial year they relate to. This includes things like business bank account records, invoices, bank statements and receipts, and national insurance contributions, PAYE and income tax records. Keep your records to have the required information to hand in the event of an investigation or dispute. Enquires could require limited companies, sole traders and self employed workers to substantiate business expenses within the past six year accounting period.

  • Employment records

    You need to keep payslips, contracts and annual leave documents for a minimum of six years after an employee leaves. For redundancy situations or possible disputes, you might need to keep them longer under the Limitation Act 1980.

  • Medical records

    The NHS says adult patient records should be kept for at least eight years after treatment ends or the patient dies. For children and maternity records, this can be up to 25 years. Private healthcare providers follow similar guidelines.

  • Educational records

    Schools must keep student records for at least six years after the student leaves, but records about child protection concerns are kept for the lifetime of the individual.

  • Corporate records

    Companies House advises keeping company-related documents like meeting minutes and share registers for a minimum of ten years, which is the responsibility of company directors and the Company Secretary.

This isn’t a complete list of record keeping schedules, and if there’s a chance of legal action, you might need to keep documents for longer.

Criminal records retention legal requirements

How long are criminal records kept?

Criminal records in the UK are kept by the police on the Police National Computer (PNC). These include details of arrests, charges and convictions.

If you’re applying for a job, the Disclosure and Barring Service (DBS) is responsible for revealing criminal history. Under the Rehabilitation of Offenders Act 1974, some convictions become ‘spent’ after a certain period, which means you don’t need to mention them in most situations. For example, a prison sentence of less than six months becomes spent after two years, while sentences over four years never become spent.

However, if you’re applying for jobs working with vulnerable people or in security-sensitive areas, even spent convictions might show up in enhanced DBS checks, though there are filtering rules that were updated in 2020.

Criminal records stay on the PNC indefinitely from a legal standpoint. Even when a conviction is spent, it isn’t deleted – it just becomes less relevant in everyday situations. The idea is to balance protecting the public with allowing people to move on from past mistakes.

So, while criminal records are kept for life, they matter less over time, depending on why someone is checking them.

How long to keep legal documents

Legal records such as wills should be kept indefinitely. A will remains legally valid until it is updated or revoked, so it’s important to retain the original document in a safe, accessible place.

Even after the death of the person who created the will, the executor may need it for probate or legal purposes.

In some cases, questions about an estate can arise years later, making the availability of the original will crucial.

Keeping both physical and digital copies, with the original stored securely, helps ensure it’s available when needed.

Never destroy a will unless you’re certain it’s legally replaced or revoked.

Why is keeping records – and deleting them – important?

Keeping proper records serves several important purposes:

  • it ensures you’re following the law, protecting you from penalties during inspections or court cases
  • it helps your organisation run smoothly and make informed decisions

In healthcare, keeping detailed patient records ensures continuity of care. In education, long-term records can support research or prove qualifications. In business, historical data helps with planning and strategy.

But keeping everything forever isn’t practical or sensible.

There are risks if you keep records too long. You could face data breaches, pay more for storage, and break data protection rules. Under the UK General Data Protection Regulation (UK GDPR), you shouldn’t keep personal data longer than necessary.

This means you need a plan for both keeping and destroying records. Your organisation should have clear schedules for when records should be archived or destroyed. You need secure methods for disposal – like shredding paper files or using certified services to destroy digital information.

How to automate records retention and deletion

Document Logistix’s Document Manager is advanced automated records retention software designed to manage document lifecycles with precision and compliance.

It enables organisations to retain documents for legally stipulated periods and automatically delete them when retention deadlines are reached, as required by industry regulations.

The software supports customisable retention policies to ensure that each document type is handled according to specific legal and organisational requirements.

With audit trails, secure storage and automation, Document Manager reduces manual errors and enhances compliance. It streamlines record-keeping processes, saves storage costs and helps to protect businesses from legal risks associated with improper document handling or unauthorised retention.

See Automated Records Management in Action

Who can access my records?

Access to records is controlled by laws that try to balance transparency with privacy. Not all records are open to everyone, and many contain sensitive personal or business information.

If it’s your data – meaning you’re the person the information is about – you have the right to request access under Subject Access Requests (SARs). Under UK GDPR, organisations must respond within one month, giving you copies unless there are exceptions.

Government agencies may access records for compliance or investigations. For example, HMRC can look at financial records during tax audits, while bodies like the Care Quality Commission might access healthcare records during inspections.

Employees within an organisation can access records based on what they’re allowed to see. A manager might see your performance reviews, but not necessarily your medical information unless it’s appropriate.

Requests from third parties like insurers, lawyers or journalists need careful checking. Often, explicit consent or a legal obligation is needed before sharing.

How can I protect records from unauthorised access?

With the growing threat of cyberattacks and data breaches, protecting records has never been more important. Both digital and physical records need strong protection.

Access control is fundamental. This means making sure only authorised people can view or change sensitive documents. For digital systems, this includes multi-factor authentication and regular password changes.

Encryption adds another layer of protection, ensuring that even if data is stolen, it can’t be easily read or misused.

Physical security is equally important. Filing cabinets with sensitive files should be locked and in secure areas. Access to archives should be limited and monitored.

Data backups are essential to prevent loss due to hardware failure, cyberattacks or disasters. Backups should be encrypted and stored off-site or in the cloud, with regular testing to ensure they work.

Training staff is perhaps the most effective protection. Employees should understand the importance of data privacy and how to handle, share and dispose of records. Regular training and clear policies can reduce human error – a leading cause of data breaches.

What steps should my organisation take for responsible record management?

As the amount of data grows exponentially, so does the need for clear, legally sound, and ethical management of records. Organisations that prioritise structured retention and secure disposal not only comply with the law but also build trust with their customers, clients and employees.

Creating a records management policy tailored to your organisation’s size and sector is a proactive step. This policy should outline:

  • How long to keep different types of records
  • Who can access what information
  • What data protection measures are in place
  • Procedures for handling records and access requests or data breaches

In a world where data is both an asset and a liability, how we manage records is more than just an administrative concern – it’s a cornerstone of accountability and professionalism.

For more information on data protection, visit the Information Commissioner’s Office (ICO) website.

To find out more about compliant records management – automated regulatory retention and deletion – get in touch with Document Logistix, the digital document management experts.

The History of Document Management

Document Archiving

Can we help?

We will help you to solve your business process challenges with secure centralised data and AI-powered workflow routing.

End-to-end document control and information flow

Would you like to know more, get in touch today