Document Reference: P-DRP01 Dec 2025
Issue: 0 dated 19/12/2025
POLICY REVIEW RECORD
This Data Retention Policy was first issued in this format in December 2025.
| Issue | Revision no. | Date | Details |
|---|---|---|---|
| 0 | 19/12/2025 | P-DRP01 Dec 2025 |
1. Purpose
This policy establishes the framework for the retention, storage, and disposal of information and records handled by [Your Company Name]. It ensures compliance with:
- UK Data Protection Act 2018 and GDPR
- MOD and MOJ contractual security requirements
- Legal, regulatory, and operational obligations
The policy applies to all employees, contractors, and third-party service providers handling company or client data.
2. Scope
This policy covers all types of data, including:
- Project Documentation: Drawings, plans, specifications, reports
- Personnel Records: Employee records, security clearances
- Financial Records: Invoices, contracts, purchase orders
- Client Communications: Emails, meeting minutes, correspondence
- Sensitive Government Data: MOD/MOJ classified information, security risk assessments
3. Retention Principles
- Necessity: Data shall only be retained for as long as required to fulfil contractual, legal, or operational obligations.
- Confidentiality: All data must be stored securely, consistent with MOD/MOJ security classifications (e.g., OFFICIAL, OFFICIAL-SENSITIVE).
- Minimisation: Only necessary information should be collected and retained.
- Regular Review: Data will be reviewed periodically to determine if it should be retained, archived, or securely destroyed.
4. Retention Periods
| Data Type | Retention Period | Reference/Notes |
|---|---|---|
| MOD/MOJ Project Documentation | 6 years after project completion | Aligns with MOD/MOJ contractual obligations |
| Financial Records | 7 years | HMRC requirement |
| Employee Records (including security clearance files) | 6 years after employment ends | ICO recommendation |
| Health & Safety Records | 40 years (for asbestos, hazardous materials) | HSE regulations |
| Emails and Correspondence | Permanently retained albeit archived after 2 years | Can be archived electronically |
| Incident Reports & Risk Assessments | 6 years | For insurance and compliance purposes |
| Contracts & Legal Agreements | 6 years after expiry | Statute of Limitations for contractual claims |
Note: MOD/MOJ may impose stricter retention or destruction requirements. Contract-specific rules override this policy.
5. Storage and Security
- Data shall be stored in secure systems, with access controlled based on the need-to-know principle.
- Classified information must comply with MOD Security Policy Framework (SPF) and MOJ security standards.
- Electronic storage must use encryption, strong passwords, and regular backups.
- Physical records must be stored in locked cabinets with restricted access.
6. Data Disposal
- Data must be securely disposed of when the retention period expires.
- Electronic data: Secure deletion methods (e.g., wiping, shredding virtual storage).
- Physical data: Shredding or secure destruction by an approved provider.
- Disposal of MOD/MOJ classified data must follow contractual and regulatory guidelines.
7. Responsibilities
- Management: Ensure compliance with this policy and legal obligations.
- Project Managers: Maintain accurate project records and ensure timely review.
- All Employees: Adhere to data retention, storage, and disposal requirements.
8. Policy Review
This policy will be reviewed annually or whenever:
- There are changes in legislation or contractual obligations
- MOD/MOJ security requirements are updated
- There is a significant change in company operations
Document Control:
- Last Reviewed: 22nd December 2025
- Next Review: 22nd December 2026