Compliance document retention periods in the UK: how to set a defensible schedule
There is no single “keep compliance documents for seven years” rule. A RIDDOR record, COSHH health-surveillance record, right-to-work check and ordinary risk assessment have different legal bases, start dates and privacy implications. Some laws set a minimum period. Others require a business to decide and justify how long the record is needed. A workable schedule names the exact document, jurisdiction, duty, event that starts the clock, minimum or chosen period, owner, access controls and disposal action.
This guide gives a starting table for common UK business records and a method for turning it into your own schedule. The examples are not a blanket instruction to keep every file for the longest period shown. Check sector rules, contracts, a live claim or investigation and the current guidance before deleting a record.
Start with the record, not the folder
The first mistake is treating a “compliance file” as one document. An incident file can contain a RIDDOR entry, accident-book entry, witness statements, occupational health material, insurer correspondence and a worker's personal information. They may have different purposes, legal duties and access rules. A system that keeps the whole folder forever because one subrecord has a long minimum is likely to retain more personal data than necessary. A system that deletes the whole folder after three years may destroy evidence required under another law or a justified ongoing claim.
Create a record series for each purpose. Separate the authoritative record from convenience copies and distinguish: (1) a statutory minimum, which you may not undercut; (2) a business retention decision, justified by a real purpose; and (3) a legal hold, which pauses normal deletion for a specific dispute, investigation or order. Record the clock trigger exactly: the date an entry was made, the end of employment, the last health-record entry or the end of a tax year are not interchangeable.
The ICO's storage-limitation guidance says UK GDPR sets no universal period for personal data. Organisations must justify their periods, document standard periods where possible, review records and erase or anonymise personal data when no longer needed. A statutory minimum or active legal claim can justify longer retention, but “we might need it one day” is not a substitute for a defined purpose.
A practical starting table
| Record series | Current source and period | Clock / important limit |
|---|---|---|
| RIDDOR records of reportable incidents, diseases and specified over-three-day injuries | RIDDOR 2013 regulation 12 requires each entry to be kept at least three years. HSE lists what must be recorded. | Three years from the date the record entry was made. A separate claim or employment record may need a different decision. Do not call every accident “RIDDOR-reportable.” |
| COSHH health-surveillance health records | HSE's record-keeping guidance says the relevant regulations may specify 40 years, for example under COSHH. | Apply the relevant substance and regulation. The employer's health record is distinct from confidential medical records held by the occupational health professional. Do not put clinical notes in an ordinary personnel folder. |
| Asbestos health records for relevant work | HSE asbestos guidance says the health record is kept 40 years after the last entry. | Check the work category and exact applicable record. A site asbestos register or survey has a different function from an individual's health record. |
| Right-to-work check copies | The current Home Office employer checklist says keep securely for employment plus two years, then securely destroy. | Two years runs after the person stops working. Retain the check date and required copy in the prescribed way; follow-up checks have their own evidence. Do not confuse this with DBS data. |
| DBS certificate information | DBS guidance says destroy after a suitable period, usually no longer than six months; the DBS handling guidance discusses justified exceptions for disputes or safeguarding audits. | Not a universal six-month statute and not the same as keeping a record that a check was made. Restrict access and document any longer need. |
| PAYE/payroll records | HMRC says three years from the end of the tax year concerned. | The tax-year trigger matters. Other employment, pension, contractual or claim purposes may need separate records and periods. |
| VAT records | HMRC says at least six years, or ten years for specified OSS/MOSS records. | Check scheme and exceptions; do not call six years a universal period for all financial files. |
| Non-hazardous waste transfer notes | GOV.UK says both parties keep a copy two years; season ticket and schedule two years after the last transfer. | Waste guidance and devolved rules must be checked for the site and role. |
| Hazardous waste producer/holder records in England | GOV.UK says keep the register, including consignment notes and returns, three years at the premises. | This cited page expressly concerns England; a consignee/permitted site has other periods. Do not apply it unchanged across all UK nations or roles. |
| Employers' liability certificates | The former 40-year statutory certificate-retention duty was removed in 2008 by the amending regulations. GOV.UK still explains the current display duty. | Keeping past certificates and policy details can be prudent for later occupational disease claims, but do not present 40 years as today's universal legal certificate minimum. Set and justify your own period with insurance/legal advice. |
The table mixes Great Britain-wide, UK-wide and England-specific sources because the underlying regimes differ. For Scotland, Wales and Northern Ireland, verify the actual local rule and regulator before importing an English environmental period. A care home, school, transport operator or regulated financial business may have additional specialist records. The table is the starting point for a schedule, not the final schedule for every organisation.
How to build the schedule in six steps
1. Inventory actual record series
List where records live: document platform, email, shared drives, paper files, payroll, HR, occupational health provider and contractor portals. Include exports and backups. Describe what the record proves and who created it. “Health and safety” is too broad a category; “RIDDOR entry” and “worker COSHH health record” are useful categories.
2. Record the authority and the clock
For each series, put the statute or regulator guidance beside the proposed period and note whether the source is a minimum, good practice or a rule for a specific role. Note the trigger and the version/date checked. If no law fixes a time, write the purpose that justifies the period: evidence of training, performance of a contract, defence of a known claim or delivery of a regulated service. Do not copy an arbitrary period from a generic internet chart.
3. Apply a privacy test
Ask whether the file contains personal or special-category data, who can access it and whether a less intrusive record would meet the purpose. The ICO expects you to justify the period and review it. For example, an employer may need a record that a DBS decision was made while not needing the full certificate for the same length of time. Medical records and employer health-surveillance records have different custodians. Put confidentiality and access alongside retention in the schedule.
4. Check contracts, claims and sector rules
A client contract may require evidence to be available for a defined period. A pending claim, investigation or regulatory notice may require a documented hold even when normal deletion would otherwise occur. Identify the person who authorises and releases the hold. Resolve any conflict between a contractual request and data-protection necessity rather than assuming the longest period wins automatically.
5. Decide what happens at the end
At the scheduled review date, delete, anonymise or justify an extension. Ensure every copy and export follows the decision, including shared mailboxes and local downloads. Check backup architecture: a backup is a recovery control, not a permanent shadow archive. Record enough deletion evidence to show the schedule was actually applied without keeping the sensitive source data again.
6. Review after change
Assign an owner to check the schedule when law, guidance, contracts or the business changes. A short, dated review record is more useful than an undated spreadsheet of periods. Test retrieval and deletion periodically; a policy that no one can execute is not document control.
A simple register layout
Use one row per record series:
Record name | purpose | UK nation/site | legal or business basis | source URL and checked date | minimum | chosen period | clock trigger | owner | access level | legal-hold rule | disposal action | last review
For example, an England construction business might record a hazardous waste producer register with a three-year period and a specific premises/transfer trigger from the environmental guidance; it would not silently apply the same row to a hazardous waste consignee, whose duties differ. It might record right-to-work check copies as employment plus two years, with controlled HR access and secure destruction, while handling DBS information in a separate, shorter and more restricted series.
If you need a worked list of the types of job records worth preserving after completion, the existing Complys post-completion records guide addresses that task. This page addresses how to determine the period for each record. Keep those intents distinct.
Where document software helps, and where it does not
A document system can make a schedule easier to operate when it lets an authorised person attach a record type and owner, restrict access, find files by project or worker, export evidence and record review dates. Test those functions in the actual product and plan. A document expiry reminder is not automatically a lawful retention/deletion engine: a certificate's validity date, policy review date and legal retention date are three different clocks.
The observed UK Complys document-management page describes storage, tracking and audit-history features. Its detailed verification, historical-reconstruction and trial claims require implementation and commercial checking before any stronger CTA is used. This article does not claim Complys calculates statutory periods, erases files automatically or replaces legal judgement. If considering a platform, ask for a demonstration of access control, export, change history and disposition on one of your real record series.
Common retention mistakes
- “Everything for seven years.” It can under-retain health-surveillance records and over-retain sensitive recruitment data.
- Confusing validity with retention. An expired insurance certificate may still be evidence; a current certificate may contain personal data subject to its own purpose and access limits.
- Reusing a repealed rule. The old 40-year legal duty for employers' liability certificates was removed in 2008. That does not mean deleting historical cover evidence is wise.
- Applying an England waste rule across the UK. Check the nation, waste classification and whether you are producer, carrier or consignee.
- Giving everyone the whole file. Occupational medical records and DBS information need special controls.
- Deleting while a matter is live. A documented legal hold can override a scheduled disposal event for specified records.
- Keeping an unsearchable archive. Retention has little value if you cannot identify the version, worker, job and date when evidence is requested.
The direct answer
The correct UK compliance document retention period depends on the record and the duty that creates it. RIDDOR entries have a three-year minimum from entry; relevant COSHH health records can have a 40-year minimum; right-to-work check copies are held through employment and two more years; PAYE is generally three years after the tax year; and VAT records are generally at least six years. Other records need a justified schedule. Start with the specific primary source, document the trigger and purpose, protect sensitive information, then review and dispose of it when the legal and business need ends.
---
Writer-side source/claim and QA register — 5 October 2026
| Claim or check | Primary evidence | QA result / publication gate |
|---|---|---|
| No universal GDPR period; justify and review | ICO storage limitation | Supported; ICO notes guidance under review after Data (Use and Access) Act. Recheck before publication. |
| RIDDOR three years from entry | RIDDOR 2013 regulation 12; HSE records | Supported; applies specified entries, not every accident. |
| COSHH and asbestos health record | HSE health surveillance; HSE asbestos FAQ | Supported with record-type and last-entry caveats. |
| Right-to-work and DBS | Home Office checklist; DBS employer guidance | Distinct data sets and clocks; verify most current Home Office guidance on publication day. |
| PAYE and VAT | HMRC payroll; HMRC VAT | Supported with tax-year and special-scheme caveats. |
| Waste records | Non-hazardous transfer notes; England hazardous producer/holder | England role/nation limits stated; local check still required. |
| Employers' liability certificate change | 2008 amendment | Repeal verified; do not repeat obsolete 40-year legal rule. |
| Owner and internal links | Post-completion record guide; UK document-management page | Distinct search task. UK .co.uk money host observed. Confirm canonical and no unpublished collision. |
| Product truth | Public money-page assertions only | No untested Complys feature, automatic deletion or plan claim made. Whole money-page feature/trial gate open. |
| Writer-side copy, metadata and CTA | Direct answer, actionable table, method, example, limitations, primary links | Scoped writer QA passed. Independent legal, canonical, product, link and whole-page QA remain open; nothing published. |
Complys helps you keep this organised and current. See Compliance Document Management Software; confirm current capabilities for your use before relying on any specific feature.