Build a compliance-record retention schedule with named owners
A shared drive can tell you where a record was saved, but not why it is still there. A retention schedule answers a different question: for each category of evidence, who decides how long it is needed, what starts the period, and what happens at the end? This is a governance task, not a universal list of statutory periods.
UK organisations hold different kinds of compliance evidence: contractor approvals, training records, vehicle inspections, property certificates, incident investigations and supplier contracts. Some contain personal data; some have sector-specific requirements; some may be needed while a dispute or claim is open. The ICO's storage-limitation guidance says personal data should be kept no longer than necessary for its purpose and reviewed. It does not provide one period that fits every compliance document.
Inventory by purpose, not by file extension
Start with a manageable list of record categories. A “PDF” category is too broad: a current insurance certificate and a closed incident report may have different purposes, access rules and retention triggers. For each category, record the business purpose, relevant legal or contractual basis, owner, storage location, people who may access it and whether it contains personal data.
Identify duplicate copies. If one signed record is the authoritative version, say where it lives and whether copies in email or local folders should be removed after a handover. A schedule that applies only to the main platform while uncontrolled copies remain elsewhere cannot reliably govern the information.
Set a trigger and a justified period
The retention clock might start at completion of work, expiry of a certificate, end of employment, closure of an incident or termination of a contract. Write the trigger explicitly. “Keep for six years” is ambiguous without a start event and reason. Ask the relevant legal, records or sector lead to confirm any statutory or contractual minimum for the category, then record the source and review date. Do not copy a period from an unrelated organisation's template.
Where no fixed period applies, decide what is necessary for the stated purpose and document the rationale. The ICO advises organisations to review whether they still need personal data at the end of a standard period, and earlier where appropriate. Build an exception for active claims, investigations or legal holds; those exceptions need an owner and a date to review, not an indefinite “retain forever” flag.
Give every category a decision owner
The team that creates a record may not be the team authorised to delete it. A fleet manager can identify operational use for a defect record; a legal or privacy owner may need to confirm a hold or personal-data implication. The schedule should name a primary owner and consultation route. Avoid assigning the entire schedule to “compliance” without saying who makes the practical decision for each record type.
Create a small table with columns for category, purpose, trigger, period or review rule, source of requirement, owner, access group, storage location, disposal action and exception route. Add a last-checked date. This is enough to make a future review possible without turning the schedule into an unmaintainable legal encyclopedia.
Review, dispose and prove the decision
At review, confirm whether the purpose still exists, whether a legal hold applies and whether the record is still the authoritative copy. Decide to retain with a new review date, erase, anonymise or transfer to a controlled archive where justified. Moving personal data offline is still processing: the ICO notes that simply taking it offline does not remove storage-limitation obligations. Record the decision and who made it.
Check backups, exports and local copies in the disposal process. The organisation may not be able to remove every historical trace immediately, but it should understand how its systems handle deletion and what can be retrieved. Test the process with one low-risk category before claiming it works for every record type.
Keep the schedule current
New products, jurisdictions, clients and record types can change the retention rationale. Review the schedule when a process changes and periodically according to risk. The ICO's documentation guidance says records of processing should reflect the current situation; treat the retention schedule as a living control rather than a one-off spreadsheet.
For teams assessing record organisation, see Complys compliance document management software. Ask for a demonstration of the current record and access workflow; this guide does not claim the product automatically determines retention law or deletes every copy at a scheduled date.
Example: one project, several retention triggers
A contractor project closes in March, an insurance certificate expires in June and an incident investigation remains open until November. Keeping all three records under “project closed” would start the wrong review clock for at least some purposes. The records owner should assign each category its own purpose and trigger, check any legal or contractual requirements, and document why the chosen period is necessary. If a claim begins before a scheduled disposal date, a named legal-hold owner can suspend disposal for relevant evidence and set a date to review the hold. When the hold ends, the records team returns to the ordinary schedule; it does not leave the whole project permanently frozen.
How to test the schedule
Choose a category due for review and ask someone who did not design the policy to find the authoritative copy, determine the trigger and identify who can approve disposal. If they cannot, the schedule is not yet operational. Check one backup or export path as well. This small test exposes ambiguous ownership before thousands of records accumulate.