A woman using her phone at a desk, surrounded by art supplies and a laptop, in a creative workspace.
| |

Data Retention for Ex-Employees: A Hidden Risk

Are you keeping leavers’ data too long? Learn what the law says and how to reduce legal exposure. Many organisations store former employee data indefinitely — just in case. But UK GDPR doesn’t allow for “just in case” retention. Key retention timelines to know: After this period, data should be deleted or anonymised. Keeping more…

Are you keeping leavers’ data too long? Learn what the law says and how to reduce legal exposure.

Many organisations store former employee data indefinitely — just in case. But UK GDPR doesn’t allow for “just in case” retention.

Key retention timelines to know:

  • Personnel files: typically 6 years for legal claims
  • References and disciplinary records: 6 years max unless legally challenged

After this period, data should be deleted or anonymised. Keeping more than you need increases liability and invites enforcement action.

Tip: Create a leavers’ checklist that triggers data review and deletion automatically.

Related

  • |

    Is Your Email Archive a GDPR Liability? Probably.

    Email systems are often the biggest data retention risk. Here’s what compliance and IT need to fix. Email is often overlooked in data retention strategies — yet it’s where the most unstructured personal data lives. Archived emails may contain salary details, medical information, and candidate records — often held for years without review. UK GDPR…

  • | |

    Breach Risk Increases With Ageing Data

    The older the data, the more dangerous it becomes. Here’s why ageing data is a hidden security risk. Most cyber breaches don’t happen with fresh data — they happen with old, forgotten, poorly protected files. Why? Retention = risk control. Regularly deleting old personal data significantly reduces the impact of a breach — both legally…

  • |

    Data Retention Risks: What Your ROPA Should Reflect

    Your Record of Processing Activities (ROPA) should include clear retention rules. Here’s how to get it right. The Record of Processing Activities (ROPA) is a GDPR requirement — but many organisations miss a critical piece: retention periods. Why this matters: Tips for improvement: Think of ROPA as your data retention blueprint. If it’s vague, so…