How long to keep contracts and legal documents, what to store, risks of getting it wrong, and practical retention strategies for UK small businesses

Knowing how long to keep contracts, invoices, employment records and other legal documents isn’t just good business hygiene – it’s a legal necessity. Get it wrong and you risk fines, failed audits, or losing vital evidence in a dispute. This in-depth guide lays out exactly what UK law requires, what best practice looks like, and how to set up a retention policy that protects your business and keeps you compliant. Whether you’re just starting out or need to overhaul your filing, this is everything you need to know.
For small businesses, the question of how long to keep contracts and legal documents isn’t simply a matter of office tidiness. There are direct legal obligations set by HMRC, Companies House, the Information Commissioner’s Office (ICO), and various industry regulators. These bodies can demand access to certain records for years after a transaction or employment relationship ends. Failure to comply can result in fines, tax penalties, or even criminal prosecution in extreme cases.
But the risks aren’t just regulatory. If you can’t produce a contract or agreement when a dispute arises – whether with a client, supplier, or former employee – you may find yourself unable to defend your position or recover money owed. Well-structured retention policies also help businesses respond swiftly to audits, due diligence requests, or legal claims. In short, record retention is both a compliance issue and a practical risk-management tool.
It’s also about data protection. Under the UK General Data Protection Regulation (UK GDPR), keeping personal data longer than necessary is itself a breach. So, you need to know not just how long to keep things, but also when and how to destroy them securely. The right approach balances legal minimums, business needs, and data privacy requirements.
Different documents have different retention periods under UK law. For example, Companies House requires company records to be kept for a minimum of six years, while HMRC expects tax records to be retained for at least five years after the 31 January filing deadline for the relevant tax year. Employment records and health & safety documentation come with their own retention rules, often governed by statutory limitation periods for legal claims.
The real challenge is that there is no single law or regulation setting universal retention periods for all business documents. Instead, you need to navigate a patchwork of requirements, set out in legislation such as the Companies Act 2006, the Taxes Management Act 1970, the Limitation Act 1980, and employment regulations. For contracts and legal documents, the key consideration is often the legal time limit for bringing claims (the 'limitation period'), which can range from 3 to 12 years depending on the type of contract.
It's essential to understand that these periods are minimums – in some cases, you may wish or need to keep documents for longer due to ongoing disputes, warranties, or regulatory investigations. Failing to do so could leave your business dangerously exposed.
| Document Type | Minimum Retention Period | Governing Law/Body |
|---|---|---|
| Company accounts & records | 6 years from end of financial year | Companies Act 2006 |
| VAT records | 6 years | HMRC |
| PAYE records | 3 years (after tax year end) | HMRC |
| Contracts under seal (deeds) | 12 years after completion | Limitation Act 1980 |
| Other contracts (simple contracts) | 6 years after completion | Limitation Act 1980 |
| Health & safety accident records | 3 years after incident | RIDDOR 2013 |
| Personnel files & employment contracts | 6 years after employment ends | Limitation Act 1980 |
| Insurance policies | Permanent or as long as a claim could arise | Best practice |
The Limitation Act 1980 sets out that most contractual claims must be made within 6 years (simple contracts) or 12 years (deeds) of the cause of action. This underpins many retention policies.
Contracts are at the heart of business relationships, and the retention period depends on how the contract was executed. 'Simple contracts' (most day-to-day business agreements) must generally be kept for at least 6 years after completion, as this is the limitation period for bringing most contractual claims. If the contract was executed as a deed (for example, property leases, some financing agreements), the period extends to 12 years.
It’s important to count the retention period from the date the contract is completed or terminated, not from when it was signed (unless it’s a one-off arrangement). For ongoing contracts, keep all relevant amendments and correspondence, as these can become crucial evidence if a dispute arises.
In practice, many businesses opt to keep key contracts for longer than the statutory minimum. This is particularly true where there are long-term warranties, indemnities, or where the contract relates to property or intellectual property rights. When in doubt, err on the side of caution, but always balance this against UK GDPR requirements not to keep personal data longer than necessary.
Electronic copies are generally acceptable as evidence in UK courts, provided authenticity and integrity can be demonstrated. Use secure, backed-up systems and retain audit trails.
Personnel records are subject to a complicated mix of employment, tax, and data protection laws. As a baseline, you should keep employment contracts, pay records, and personnel files for at least 6 years after the employment ends, as this is the time limit for most contractual and discrimination claims. Certain records, such as those relating to accidents or exposure to hazardous substances, require longer retention.
HMRC requires PAYE records (including wage sheets and deductions) to be kept for 3 years after the end of the tax year, while National Minimum Wage documentation must be retained for 3 years. Health and safety accident books must be kept for at least 3 years from the date of the last entry, but records of exposure to hazardous substances (e.g., asbestos) should be kept for up to 40 years.
Dismissal, redundancy, and grievance records should be kept for 6 years after employment ends, or longer if a dispute could arise. Medical records, particularly those involving statutory sick pay or workplace injuries, attract stricter retention under specific regulations. Always anonymise or securely destroy records when no longer needed, to comply with data protection law.
Holding on to personal data longer than necessary is a breach of UK GDPR. Regularly review and securely destroy HR records that are no longer needed.
For limited companies, the Companies Act 2006 and HMRC set clear minimums for financial record retention. All accounting records and supporting documents must be kept for at least 6 years from the end of the financial year to which they relate. This includes invoices, receipts, bank statements, and VAT records. If you submit late tax returns or are under investigation, you may need to keep records for longer.
Sole traders and partnerships are also subject to record-keeping obligations. For self-assessment, HMRC requires you to keep records for at least 5 years after the 31 January submission deadline for the relevant tax year. VAT-registered businesses must keep VAT records for 6 years, or 10 years if using the VAT MOSS scheme (now largely obsolete for UK businesses post-Brexit).
Always keep records for longer if you suspect a tax enquiry or legal dispute. If your company is dissolved or ceases trading, you must still retain records for the statutory period after the final accounting period. Failure to keep records can result in HMRC penalties of up to £3,000, or unlimited fines in the case of deliberate destruction.
HMRC and Companies House accept electronic copies of documents, provided they are complete, legible, and can be reproduced for inspection. Scanning is acceptable, but ensure you back up files securely.
Some sectors face additional requirements. For example, FCA-regulated firms must keep certain records (e.g., client agreements, financial promotions) for periods ranging from 3 to 7 years. Construction and property businesses may need to retain documents related to building control, planning permissions, or asbestos exposure for up to 40 years. Charities and care providers also face enhanced retention obligations for safeguarding and client records.
If your business handles health data, special category personal data, or sensitive customer records, you must follow both the general retention rules and any sector-specific requirements. For example, care home providers must keep client records for at least 8 years after the last entry. The Information Commissioner’s Office (ICO) and relevant professional bodies publish sector-specific guidance, which you should always consult.
Bear in mind, even if a statutory retention period has expired, you may need to keep some records for longer if required by contract, regulatory investigation, or ongoing litigation. Always document the reason for extended retention in your policy.
| Sector | Key Documents | Retention Requirement |
|---|---|---|
| Financial services | Client files, anti-money laundering records | 5-7 years (FCA rules) |
| Construction | Asbestos records, site safety logs | 40 years (HSE) |
| Care providers | Client care records | 8 years (CQC, NHS) |
| Charities | Gift aid declarations | 6 years (HMRC) |
| Food businesses | Traceability records | 5 years (FSA) |
A robust record retention policy isn’t just a compliance checkbox. It’s a tool for saving time, reducing storage costs, and proving your legal position if challenged. The key is to create a policy that is clear, tailored to your business, and actually followed in practice. Start by mapping out the types of documents you generate and referencing the legal requirements for each.
Assign clear responsibility for managing records – in a small business, this may be the business owner or a key admin staff member. All staff should be trained on the basics, especially when handling personal data or legal documents. Your policy should cover how documents are stored (physical and electronic), how access is controlled, and the process for secure destruction when the retention period ends.
Finally, schedule regular reviews of your records and retention policy at least annually. This helps ensure you remain compliant as laws change, and avoids the risk of building up a costly and risky backlog of unnecessary files.
When retention periods end, records must be destroyed securely. For paper documents, this means cross-cut shredding or using an accredited confidential waste provider. For electronic files, use secure deletion tools that ensure data cannot be recovered. Simply deleting a file or emptying the recycle bin is not enough, especially where personal data is involved.
Under UK GDPR, you must be able to demonstrate that personal data has been deleted in line with your retention policy. Keep a log of what was destroyed, when, and by whom, in case of regulatory inspection. Never destroy records that may be required for ongoing or foreseeable litigation, regulatory investigation, or audit – in these cases, retention trumps destruction.
If you use third-party storage or destruction providers, ensure they are reputable and provide a certificate of destruction. Always check their compliance with data protection and confidentiality requirements, as you remain responsible for the data as its controller.
One of the most frequent mistakes UK small businesses make is keeping documents for too long, often out of fear or lack of clarity. This exposes you to data protection risks, unnecessary storage costs, and the potential for information leaks. Another common error is failing to keep documents for the minimum required period, particularly after staff leave or contracts end.
Don’t assume electronic records are risk-free. Corrupted files, accidental deletion, and lack of backups can leave you unable to produce vital evidence. Similarly, failing to update your retention policy as laws change – for example, after Brexit, or when new data protection rules are introduced – can catch you out during an audit.
Finally, beware of outsourcing document destruction or storage to unvetted third parties. If they mishandle your data, your business is still liable. Always check for accreditations such as ISO 27001 (information security) or BS EN 15713 (secure destruction of confidential material).
If you know or suspect your business may face a legal claim or regulatory investigation, immediately suspend normal destruction processes for all relevant records. This is known as a 'litigation hold'.
With the shift to cloud storage and hybrid working, retention policies must reflect new risks and realities. Digital records can be easier to organise and search, but they are also more vulnerable to hacking, accidental deletion, and access by unauthorised staff. You need clear protocols for naming, storing, and deleting digital files, as well as regular backups in secure, UK-based data centres where possible. See more about Cloud Storage, Cybersecurity, and Data Protection.
For businesses using cloud-based document management systems, check where your data is stored. UK GDPR requires you to ensure any overseas storage meets data protection adequacy standards. Remote workers must be trained in secure handling of both digital and physical documents, and you should have procedures for returning or destroying records when staff leave.
Don’t forget communications: contracts and agreements sent or signed by email, or via e-signature platforms, are legally binding and should be retained alongside traditional documents. Integrate these into your retention schedule, and ensure access controls are robust.
UK law recognises electronic signatures and digital contracts as legally binding, provided certain conditions are met. Store signed e-documents with full audit trails for the statutory retention period.

Ready for the next step? Open a business bank account to keep your finances organised.

Get 7,500 free points (worth £75) on your first transaction. No annual fee. Instant decision.
Affiliate disclosure: we may earn a commission via our links. This does not affect our editorial independence.


Affiliate links. We may earn a commission. Editorial independence maintained.