Data Retention for Ex-Employees: A Hidden Risk
Are you keeping leavers’ data too long? Learn what the law says and how to reduce legal exposure.
Many organisations store former employee data indefinitely — just in case. But UK GDPR doesn’t allow for “just in case” retention.
Key retention timelines to know:
- Personnel files: typically 6 years for legal claims
- References and disciplinary records: 6 years max unless legally challenged
After this period, data should be deleted or anonymised. Keeping more than you need increases liability and invites enforcement action.
Tip: Create a leavers’ checklist that triggers data review and deletion automatically.
