Data Retention Policy

Document Reference: P-DRP01 Dec 2025
Issue: 0 dated 19/12/2025


POLICY REVIEW RECORD

This Data Retention Policy was first issued in this format in December 2025.

Issue Revision no. Date Details
0 19/12/2025 P-DRP01 Dec 2025

1. Purpose

This policy establishes the framework for the retention, storage, and disposal of information and records handled by [Your Company Name]. It ensures compliance with:

  • UK Data Protection Act 2018 and GDPR
  • MOD and MOJ contractual security requirements
  • Legal, regulatory, and operational obligations

The policy applies to all employees, contractors, and third-party service providers handling company or client data.


2. Scope

This policy covers all types of data, including:

  • Project Documentation: Drawings, plans, specifications, reports
  • Personnel Records: Employee records, security clearances
  • Financial Records: Invoices, contracts, purchase orders
  • Client Communications: Emails, meeting minutes, correspondence
  • Sensitive Government Data: MOD/MOJ classified information, security risk assessments

3. Retention Principles

  1. Necessity: Data shall only be retained for as long as required to fulfil contractual, legal, or operational obligations.
  2. Confidentiality: All data must be stored securely, consistent with MOD/MOJ security classifications (e.g., OFFICIAL, OFFICIAL-SENSITIVE).
  3. Minimisation: Only necessary information should be collected and retained.
  4. Regular Review: Data will be reviewed periodically to determine if it should be retained, archived, or securely destroyed.

4. Retention Periods

Data Type Retention Period Reference/Notes
MOD/MOJ Project Documentation 6 years after project completion Aligns with MOD/MOJ contractual obligations
Financial Records 7 years HMRC requirement
Employee Records (including security clearance files) 6 years after employment ends ICO recommendation
Health & Safety Records 40 years (for asbestos, hazardous materials) HSE regulations
Emails and Correspondence Permanently retained albeit archived after 2 years Can be archived electronically
Incident Reports & Risk Assessments 6 years For insurance and compliance purposes
Contracts & Legal Agreements 6 years after expiry Statute of Limitations for contractual claims

Note: MOD/MOJ may impose stricter retention or destruction requirements. Contract-specific rules override this policy.


5. Storage and Security

  • Data shall be stored in secure systems, with access controlled based on the need-to-know principle.
  • Classified information must comply with MOD Security Policy Framework (SPF) and MOJ security standards.
  • Electronic storage must use encryption, strong passwords, and regular backups.
  • Physical records must be stored in locked cabinets with restricted access.

6. Data Disposal

  • Data must be securely disposed of when the retention period expires.
    • Electronic data: Secure deletion methods (e.g., wiping, shredding virtual storage).
    • Physical data: Shredding or secure destruction by an approved provider.
  • Disposal of MOD/MOJ classified data must follow contractual and regulatory guidelines.

7. Responsibilities

  • Management: Ensure compliance with this policy and legal obligations.
  • Project Managers: Maintain accurate project records and ensure timely review.
  • All Employees: Adhere to data retention, storage, and disposal requirements.

8. Policy Review

This policy will be reviewed annually or whenever:

  • There are changes in legislation or contractual obligations
  • MOD/MOJ security requirements are updated
  • There is a significant change in company operations

Document Control:

  • Last Reviewed: 22nd December 2025
  • Next Review: 22nd December 2026