How Long Should Businesses Keep Documents in the UK?
In the UK, most businesses should keep financial and company records for at least 6 years, while employment records are typically retained for up to 6 years after employment ends. Some documents, such as employer’s liability insurance records, may need to be kept for up to 40 years due to long-term legal risks. Businesses must also comply with UK GDPR, which requires that personal data is not kept longer than necessary.
Document Retention UK – 2026 Guide
Managing business records isn’t just about organisation — it’s a legal obligation, a data protection responsibility, and a key part of secure waste management. Following on from our recent guide on how to dispose of confidential waste, this article explains how long UK businesses should retain documents and what to do when they are no longer needed.
If your organisation handles sensitive information, understanding retention periods — and disposing of records securely — is essential for compliance and risk reduction.
1. Legal Retention Periods in the UK
Different types of documents are subject to specific retention requirements under UK law. Below is a simplified overview of commonly required retention timeframes:
Financial & Tax Records
-
- HMRC records (VAT, PAYE, accounts): Minimum 6 years.
-
- Company accounts & supporting documents: Typically 6 years
-
- Corporation tax records: At least 6 years
HMRC confirms that businesses must maintain accurate records and retain them for defined periods to meet tax obligations (HMRC record keeping guidance).
You can also refer to the official HMRC records management policy, which outlines how records should be retained and disposed of securely.
Employment Records
-
- Employee personnel files: Usually 6 years after employment ends
-
- Payroll records: Minimum 3 years from end of tax year
-
- Health & safety records (e.g. accidents): Up to 7 years (or longer if involving minors)
ACAS confirms that employers must retain certain employment records for at least six years (ACAS record keeping guidance).
Corporate Records
-
- Company registers & statutory records: Permanent (in many cases)
-
- Contracts & agreements: Typically 6 years after expiry (or 12 years if under seal)
Insurance & Legal Documents
-
- Employer’s liability insurance certificates: Minimum 40 years
-
- Public liability claims documentation: Often held for 6–12 years
Always check industry-specific regulations, as sectors such as healthcare, finance, and legal services often require longer retention periods.
2. GDPR & Data Minimisation Principles
Under the UK GDPR, businesses must follow the principle of data minimisation — meaning you should only collect and retain the data you actually need.
According to the ICO data minimisation guidance, personal data must be:
-
- Adequate
-
- Relevant
-
- Limited to what is necessary
In addition, the storage limitation principle states that:
Organisations must not keep personal data for longer than necessary (ICO storage limitation guidance).
What does this mean in practice?
-
- Only retain personal data for as long as it serves a legitimate purpose.
-
- Clearly define retention periods within your data protection policy
-
- Regularly review stored documents and delete outdated data
The law is clear:
Keeping data “just in case” is not compliant.
Retention policies should:
-
- Align with legal requirements
-
- Include clear deletion schedules
-
- Cover both physical and digital documents
Failure to follow GDPR guidelines can lead to enforcement action and significant fines.
3. Risks of Keeping Documents Too Long
Holding onto documents indefinitely might feel safe — but it creates serious risks.
Increased Data Breach Risk
The more data you hold, the greater the exposure if a breach occurs. Old records are often the most vulnerable.
GDPR Non-Compliance
Retaining personal data beyond its required period breaches data minimisation rules — potentially leading to fines and reputational damage.
Higher Storage Costs
Unnecessary storage (physical or digital) leads to:
-
- Increased archiving costs
-
- Wasted space
-
- Reduced efficiency
Operational Clutter
Outdated files make it harder to locate current, relevant information — slowing down operations.
Adopt a “retain only what you need” approach and schedule regular document audits.
4. Secure Disposal Guidance
Once documents reach the end of their retention period, they must be disposed of securely — especially if they contain confidential or personal data.
As outlined in our guide on confidential waste disposal, improper disposal is a leading cause of data breaches.
Secure Disposal Best Practices
1. Use Professional Confidential Waste Services
Partnering with a certified provider (like Waste Paper Solutions) ensures:
-
- GDPR-compliant disposal
-
- Secure collection and destruction
-
- Full audit trail and compliance certificates
2. Shred Documents Properly
-
- Cross-cut shredding is the minimum standard
-
- Avoid strip shredders for sensitive data
3. Maintain a Disposal Log
Keep records of:
-
- What was destroyed
-
- When and how it was disposed of
-
- Who authorised the destruction
4. Implement Secure Storage Prior to Disposal
Confidential waste should always be stored securely before destruction using:
-
- Locked consoles
-
- Sealed sacks
Certification Matters
Always ensure you receive a Certificate of Destruction — a key requirement for demonstrating compliance.
Understanding how long to keep business documents in the UK is just as important as knowing how to dispose of them. By combining clear retention policies with secure destruction practices, your business can:
-
- Stay compliant with UK laws and GDPR
-
- Reduce data breach risks
-
- Improve operational efficiency
-
- Protect your reputation
At Waste Paper Solutions, we help organisations across the UK manage confidential waste securely and responsibly — from collection to certified destruction.
Contact Us
Frequently Asked Questions
1. How long do businesses need to keep records in the UK?
Most UK businesses must keep financial and tax records for a minimum of 6 years, in line with HMRC requirements. Employment records are often retained for up to six years after an employee leaves, depending on the type of document.
2. What does GDPR say about document retention?
Under UK GDPR, businesses must follow the data minimisation and storage limitation principles, meaning personal data should only be kept for as long as necessary and securely deleted when no longer required.
3. Can you keep documents longer than the legal requirement?
Yes, but only if there is a valid legal or business reason, such as ongoing disputes or insurance claims. Otherwise, retaining data longer than necessary may breach GDPR requirements.
4. What is the safest way to dispose of confidential documents?
The safest method is to use a professional confidential waste disposal service that provides secure collection, shredding, and a Certificate of Destruction.
5. What are the risks of not destroying documents properly?
Improper disposal can lead to:
- Data breaches
- GDPR fines
- Identity theft risks
- Reputational damage

