The RoadmapOperateLegal Compliance and Contracts

Record Retention Rules for Contracts and Legal Documents

How long to keep contracts and legal documents, what to store, risks of getting it wrong, and practical retention strategies for UK small businesses

6 minute read
Operate — Legal Compliance and Contracts
✓ Verified against GOV.UK
Raj Patel
Written by Raj Patel
Operations & Scale Editor · GuideToBusiness
Back to Operate

Knowing how long to keep contracts, invoices, employment records and other legal documents isn’t just good business hygiene – it’s a legal necessity. Get it wrong and you risk fines, failed audits, or losing vital evidence in a dispute. This in-depth guide lays out exactly what UK law requires, what best practice looks like, and how to set up a retention policy that protects your business and keeps you compliant. Whether you’re just starting out or need to overhaul your filing, this is everything you need to know.

Why Record Retention Matters for UK Small Businesses

For small businesses, the question of how long to keep contracts and legal documents isn’t simply a matter of office tidiness. There are direct legal obligations set by HMRC, Companies House, the Information Commissioner’s Office (ICO), and various industry regulators. These bodies can demand access to certain records for years after a transaction or employment relationship ends. Failure to comply can result in fines, tax penalties, or even criminal prosecution in extreme cases.

But the risks aren’t just regulatory. If you can’t produce a contract or agreement when a dispute arises – whether with a client, supplier, or former employee – you may find yourself unable to defend your position or recover money owed. Well-structured retention policies also help businesses respond swiftly to audits, due diligence requests, or legal claims. In short, record retention is both a compliance issue and a practical risk-management tool.

It’s also about data protection. Under the UK General Data Protection Regulation (UK GDPR), keeping personal data longer than necessary is itself a breach. So, you need to know not just how long to keep things, but also when and how to destroy them securely. The right approach balances legal minimums, business needs, and data privacy requirements.

Core UK Legal Requirements: How Long Must You Keep Records?

Different documents have different retention periods under UK law. For example, Companies House requires company records to be kept for a minimum of six years, while HMRC expects tax records to be retained for at least five years after the 31 January filing deadline for the relevant tax year. Employment records and health & safety documentation come with their own retention rules, often governed by statutory limitation periods for legal claims.

The real challenge is that there is no single law or regulation setting universal retention periods for all business documents. Instead, you need to navigate a patchwork of requirements, set out in legislation such as the Companies Act 2006, the Taxes Management Act 1970, the Limitation Act 1980, and employment regulations. For contracts and legal documents, the key consideration is often the legal time limit for bringing claims (the 'limitation period'), which can range from 3 to 12 years depending on the type of contract.

It's essential to understand that these periods are minimums – in some cases, you may wish or need to keep documents for longer due to ongoing disputes, warranties, or regulatory investigations. Failing to do so could leave your business dangerously exposed.

Document TypeMinimum Retention PeriodGoverning Law/Body
Company accounts & records6 years from end of financial yearCompanies Act 2006
VAT records6 yearsHMRC
PAYE records3 years (after tax year end)HMRC
Contracts under seal (deeds)12 years after completionLimitation Act 1980
Other contracts (simple contracts)6 years after completionLimitation Act 1980
Health & safety accident records3 years after incidentRIDDOR 2013
Personnel files & employment contracts6 years after employment endsLimitation Act 1980
Insurance policiesPermanent or as long as a claim could ariseBest practice
Limitation Periods in the UK

The Limitation Act 1980 sets out that most contractual claims must be made within 6 years (simple contracts) or 12 years (deeds) of the cause of action. This underpins many retention policies.

Key Retention Periods for Contracts and Legal Documents

Contracts are at the heart of business relationships, and the retention period depends on how the contract was executed. 'Simple contracts' (most day-to-day business agreements) must generally be kept for at least 6 years after completion, as this is the limitation period for bringing most contractual claims. If the contract was executed as a deed (for example, property leases, some financing agreements), the period extends to 12 years.

It’s important to count the retention period from the date the contract is completed or terminated, not from when it was signed (unless it’s a one-off arrangement). For ongoing contracts, keep all relevant amendments and correspondence, as these can become crucial evidence if a dispute arises.

In practice, many businesses opt to keep key contracts for longer than the statutory minimum. This is particularly true where there are long-term warranties, indemnities, or where the contract relates to property or intellectual property rights. When in doubt, err on the side of caution, but always balance this against UK GDPR requirements not to keep personal data longer than necessary.

  • Keep simple contracts for at least 6 years after completion/termination.
  • Retain contracts executed as deeds for at least 12 years.
  • Archive all variations, addenda, and key correspondence with the contract.
  • For ongoing contracts, restart the retention period when the contract ends or is terminated.
  • If litigation is likely or ongoing, keep all relevant records until the matter is resolved, regardless of general retention periods.
Best Practice for Electronic Contracts

Electronic copies are generally acceptable as evidence in UK courts, provided authenticity and integrity can be demonstrated. Use secure, backed-up systems and retain audit trails.

Employment, HR, and Health & Safety Records: What to Keep and For How Long

Personnel records are subject to a complicated mix of employment, tax, and data protection laws. As a baseline, you should keep employment contracts, pay records, and personnel files for at least 6 years after the employment ends, as this is the time limit for most contractual and discrimination claims. Certain records, such as those relating to accidents or exposure to hazardous substances, require longer retention.

HMRC requires PAYE records (including wage sheets and deductions) to be kept for 3 years after the end of the tax year, while National Minimum Wage documentation must be retained for 3 years. Health and safety accident books must be kept for at least 3 years from the date of the last entry, but records of exposure to hazardous substances (e.g., asbestos) should be kept for up to 40 years.

Dismissal, redundancy, and grievance records should be kept for 6 years after employment ends, or longer if a dispute could arise. Medical records, particularly those involving statutory sick pay or workplace injuries, attract stricter retention under specific regulations. Always anonymise or securely destroy records when no longer needed, to comply with data protection law.

  • Employment contracts and personnel files: 6 years after employment ends
  • PAYE and wage records: 3 years after tax year end
  • Accident books and report forms: 3 years after last entry
  • Records of exposure to hazardous substances: 40 years
  • Dismissal, redundancy, grievance records: 6 years after employment ends
Data Protection Risks

Holding on to personal data longer than necessary is a breach of UK GDPR. Regularly review and securely destroy HR records that are no longer needed.

Financial, Tax, and Company Records: Statutory Minimums and Practical Considerations

For limited companies, the Companies Act 2006 and HMRC set clear minimums for financial record retention. All accounting records and supporting documents must be kept for at least 6 years from the end of the financial year to which they relate. This includes invoices, receipts, bank statements, and VAT records. If you submit late tax returns or are under investigation, you may need to keep records for longer.

Sole traders and partnerships are also subject to record-keeping obligations. For self-assessment, HMRC requires you to keep records for at least 5 years after the 31 January submission deadline for the relevant tax year. VAT-registered businesses must keep VAT records for 6 years, or 10 years if using the VAT MOSS scheme (now largely obsolete for UK businesses post-Brexit).

Always keep records for longer if you suspect a tax enquiry or legal dispute. If your company is dissolved or ceases trading, you must still retain records for the statutory period after the final accounting period. Failure to keep records can result in HMRC penalties of up to £3,000, or unlimited fines in the case of deliberate destruction.

  • Limited company accounting records: 6 years from end of financial year
  • Self-employed tax records: 5 years after 31 January submission deadline
  • VAT records: 6 years (10 years for VAT MOSS)
  • Company registers and minutes: 10 years (best practice)
  • If under investigation, keep records until the matter is closed
Electronic Records and Scanning

HMRC and Companies House accept electronic copies of documents, provided they are complete, legible, and can be reproduced for inspection. Scanning is acceptable, but ensure you back up files securely.

Industry-Specific and Special Category Records: What Else Might Apply?

Some sectors face additional requirements. For example, FCA-regulated firms must keep certain records (e.g., client agreements, financial promotions) for periods ranging from 3 to 7 years. Construction and property businesses may need to retain documents related to building control, planning permissions, or asbestos exposure for up to 40 years. Charities and care providers also face enhanced retention obligations for safeguarding and client records.

If your business handles health data, special category personal data, or sensitive customer records, you must follow both the general retention rules and any sector-specific requirements. For example, care home providers must keep client records for at least 8 years after the last entry. The Information Commissioner’s Office (ICO) and relevant professional bodies publish sector-specific guidance, which you should always consult.

Bear in mind, even if a statutory retention period has expired, you may need to keep some records for longer if required by contract, regulatory investigation, or ongoing litigation. Always document the reason for extended retention in your policy.

SectorKey DocumentsRetention Requirement
Financial servicesClient files, anti-money laundering records5-7 years (FCA rules)
ConstructionAsbestos records, site safety logs40 years (HSE)
Care providersClient care records8 years (CQC, NHS)
CharitiesGift aid declarations6 years (HMRC)
Food businessesTraceability records5 years (FSA)

How to Set Up a Practical Record Retention Policy

A robust record retention policy isn’t just a compliance checkbox. It’s a tool for saving time, reducing storage costs, and proving your legal position if challenged. The key is to create a policy that is clear, tailored to your business, and actually followed in practice. Start by mapping out the types of documents you generate and referencing the legal requirements for each.

Assign clear responsibility for managing records – in a small business, this may be the business owner or a key admin staff member. All staff should be trained on the basics, especially when handling personal data or legal documents. Your policy should cover how documents are stored (physical and electronic), how access is controlled, and the process for secure destruction when the retention period ends.

Finally, schedule regular reviews of your records and retention policy at least annually. This helps ensure you remain compliant as laws change, and avoids the risk of building up a costly and risky backlog of unnecessary files.

Creating an Effective Record Retention Policy for Your Business

1
Identify document types and sources
List all contracts, invoices, HR files, tax records, emails, and sector-specific documents your business generates or receives.
2
Research and record legal retention requirements
For each document type, note the statutory or best-practice retention period, using guidance from HMRC, Companies House, the ICO, and sector regulators.
3
Draft a written retention policy
Set out how long each document type will be kept, where it will be stored, and who is responsible for compliance. Make sure it’s practical and understandable.
4
Implement secure storage and access controls
Store physical documents in locked cabinets and use encrypted digital systems for electronic files. Limit access to those who genuinely need it.
5
Schedule regular reviews and secure destruction
At least once a year, review what can be destroyed. Use shredding for paper and secure deletion for digital files. Record all disposals for audit purposes.

Destroying Records Securely: Meeting Legal and Practical Obligations

When retention periods end, records must be destroyed securely. For paper documents, this means cross-cut shredding or using an accredited confidential waste provider. For electronic files, use secure deletion tools that ensure data cannot be recovered. Simply deleting a file or emptying the recycle bin is not enough, especially where personal data is involved.

Under UK GDPR, you must be able to demonstrate that personal data has been deleted in line with your retention policy. Keep a log of what was destroyed, when, and by whom, in case of regulatory inspection. Never destroy records that may be required for ongoing or foreseeable litigation, regulatory investigation, or audit – in these cases, retention trumps destruction.

If you use third-party storage or destruction providers, ensure they are reputable and provide a certificate of destruction. Always check their compliance with data protection and confidentiality requirements, as you remain responsible for the data as its controller.

  • Use cross-cut shredders or professional confidential waste services for paper records.
  • Employ secure deletion software for electronic files, ensuring permanent erasure.
  • Keep an audit trail of all destruction activity, including date, method, and responsible person.
  • Never destroy records subject to a 'litigation hold' or ongoing regulatory enquiry.
  • Review and update destruction procedures as technology and legal requirements evolve.

Common Pitfalls, Mistakes, and What to Avoid

One of the most frequent mistakes UK small businesses make is keeping documents for too long, often out of fear or lack of clarity. This exposes you to data protection risks, unnecessary storage costs, and the potential for information leaks. Another common error is failing to keep documents for the minimum required period, particularly after staff leave or contracts end.

Don’t assume electronic records are risk-free. Corrupted files, accidental deletion, and lack of backups can leave you unable to produce vital evidence. Similarly, failing to update your retention policy as laws change – for example, after Brexit, or when new data protection rules are introduced – can catch you out during an audit.

Finally, beware of outsourcing document destruction or storage to unvetted third parties. If they mishandle your data, your business is still liable. Always check for accreditations such as ISO 27001 (information security) or BS EN 15713 (secure destruction of confidential material).

  • Keeping records indefinitely without review
  • Destroying records before the statutory period ends
  • Not having a written retention policy or schedule
  • Relying on single copies or non-backed-up digital files
  • Failing to document destruction or access to sensitive files
Litigation Holds: Do Not Destroy!

If you know or suspect your business may face a legal claim or regulatory investigation, immediately suspend normal destruction processes for all relevant records. This is known as a 'litigation hold'.

Adapting Retention Policies for Digital and Remote Working

With the shift to cloud storage and hybrid working, retention policies must reflect new risks and realities. Digital records can be easier to organise and search, but they are also more vulnerable to hacking, accidental deletion, and access by unauthorised staff. You need clear protocols for naming, storing, and deleting digital files, as well as regular backups in secure, UK-based data centres where possible. See more about Cloud Storage, Cybersecurity, and Data Protection.

For businesses using cloud-based document management systems, check where your data is stored. UK GDPR requires you to ensure any overseas storage meets data protection adequacy standards. Remote workers must be trained in secure handling of both digital and physical documents, and you should have procedures for returning or destroying records when staff leave.

Don’t forget communications: contracts and agreements sent or signed by email, or via e-signature platforms, are legally binding and should be retained alongside traditional documents. Integrate these into your retention schedule, and ensure access controls are robust.

  • Use strong access controls and encryption for cloud storage
  • Back up critical records regularly and test recovery processes
  • Maintain a central register of all document locations (physical and digital)
  • Train all staff on secure retention and destruction, especially when working remotely
  • Review SaaS and cloud providers for UK GDPR compliance
Electronic Signatures and Digital Evidence

UK law recognises electronic signatures and digital contracts as legally binding, provided certain conditions are met. Store signed e-documents with full audit trails for the statutory retention period.

Key Takeaways
  • Legal minimums depend on document type. There’s no one-size-fits-all rule – check statutory and best-practice periods for contracts, tax, HR, and sector records.
  • Contracts: 6 or 12 years is the norm. Most business contracts should be kept for 6 years after completion, or 12 years if executed as a deed.
  • Don’t keep personal data 'just in case'. UK GDPR requires you to destroy personal data when no longer needed – keeping it longer can lead to fines.
  • Tax and company records: 5-6 years minimum. HMRC and Companies House expect most financial records to be kept for at least six years.
  • Sector rules may require longer retention. Regulated industries (finance, construction, care) often have their own extended periods – always check.
  • Destruction must be secure and auditable. Use shredding or secure deletion, and keep logs of what was destroyed, when, and by whom.
  • Litigation or investigations override normal rules. Always keep relevant records if a claim or enquiry is live or foreseeable, even if the normal retention period has expired.
  • Regular policy reviews are critical. Laws and risks change – revisit your policy at least annually and train staff on their responsibilities.
⭐ Exclusive Partner Offers
Tide
Tide Business Account

Ready for the next step? Open a business bank account to keep your finances organised.

Code: REFER200
Claim £200 Free
Capital on Tap
Capital on Tap Card

Get 7,500 free points (worth £75) on your first transaction. No annual fee. Instant decision.

Code: SETTINGUP
Claim 7,500 Points

Affiliate disclosure: we may earn a commission via our links. This does not affect our editorial independence.