Data Retention and Records of Processing: A Plain-English Guide for Small Businesses
UK data protection law expects you to know what personal data you hold, why you hold it, and when you delete it. This means keeping a simple record of processing (ROPA), setting retention periods, and getting rid of what you no longer need. Done well, it lowers your risk and your workload — and it isn't as daunting as it sounds.
Why “keep everything forever” is a liability, not a safety net
Many small businesses treat data like a loft: box it up, shove it in the corner and forget about it. The trouble is that under UK data protection law — the UK GDPR and the Data Protection Act 2018 — the personal information you hold about customers, staff and suppliers isn’t just clutter. It’s a responsibility.
The more you keep, and the longer you keep it, the bigger the target you paint for criminals and the more you have to answer for if something goes wrong. Old customer lists, spreadsheets of card details that should never have been saved, ex-employees’ files still sitting in a shared drive — every one of these is a risk with no upside. This guide explains, in plain English, the three things the Information Commissioner’s Office (ICO) expects you to get right: knowing what data you hold, deciding how long to keep it, and collecting less of it in the first place.
What the law actually expects
You don’t need to memorise legislation. Three principles do most of the heavy lifting:
- Storage limitation — don’t keep personal data for longer than you need it.
- Data minimisation — only collect and hold what you genuinely need for a clear purpose.
- Accountability — be able to show how you meet these duties, not just claim you do.
That last one is the catch. It isn’t enough to be tidy; you have to be able to demonstrate you’re tidy. The good news is that a couple of simple documents cover most of it.
The ROPA: a plain register of what you do with data
A Record of Processing Activities (ROPA) sounds like a legal monster. It isn’t. It’s a list — usually a spreadsheet — that answers a handful of questions for each type of data you handle:
- What personal data do we hold? (e.g. customer contact details, staff payroll, CCTV footage)
- Why do we hold it? (the purpose — fulfilling orders, paying wages, security)
- Where does it live? (which system, cloud service or filing cabinet)
- Who can see it, and do we share it with anyone else? (your accountant, a booking tool, HMRC)
- How long do we keep it?
Businesses with fewer than 250 staff have a lighter obligation here, but the exemptions are narrow and fall away quickly — for example if your data handling is routine or involves sensitive information like health records. For most small firms, keeping a short ROPA is simpler than working out whether you’re exempt, and it doubles as a map when you need to answer a customer request or investigate a problem.
It isn’t enough to be tidy; you have to be able to demonstrate you’re tidy.
Start it in an afternoon. Walk through a typical week — a customer enquiry, an order, a payroll run, a supplier invoice — and note the data each one touches. You’ll capture eighty per cent of what matters in the first sitting.
Retention schedules: decide once, not every time
A retention schedule is simply the ROPA’s “how long” column, written down and agreed. Instead of agonising over whether to bin an old file, you set a period once and apply it consistently.
There’s no universal figure, because different records carry different legal duties. As a starting point:
- Tax and business records — HMRC generally expects these to be kept for around six years.
- Employee records — several categories, each with their own timescale; some tied to statutory limits.
- Marketing contacts — keep only while the relationship is live and consent stands; review regularly.
- CCTV and access logs — usually a short window, often weeks rather than years.
Write your chosen periods against each data type, note the reason (“HMRC requirement”, “limitation period”, “business need”), and set a recurring reminder to actually delete what’s expired. A retention schedule nobody acts on is just a wish list.
Deleting properly matters too. “Delete” means gone from live systems and from backups on their normal cycle — not dragged to a desktop recycle bin. If you’re not confident your backups age out old data sensibly, that’s worth checking, because a breach of a five-year-old backup is still a breach today.
Data minimisation: the easiest win of all
The cheapest data to protect is the data you never collected. Before adding a field to a form or a column to a spreadsheet, ask: do we actually need this to do the job? A plumber taking bookings rarely needs a customer’s date of birth. A newsletter sign-up needs an email address, not a home address.
Minimisation also means not letting data sprawl. Personal information copied into email attachments, saved to personal laptops, or pasted into a dozen spreadsheets is impossible to control and impossible to delete cleanly. Keeping a single, sensible home for each type of record makes both security and deletion far easier.
A sensible order to tackle this
You don’t need a consultant or a compliance department. Over a few short sessions:
- List your data — build the ROPA from a typical week’s activity.
- Set retention periods — add the “how long” and “why” to each entry.
- Delete the obvious dead weight — old spreadsheets, ex-staff files, lists you’ll never use.
- Trim your forms — stop collecting fields you don’t need.
- Diarise a yearly review — data grows; the record has to keep up.
This matters most in sectors handling sensitive or regulated information. If you’re an accountancy practice or a law firm, your clients’ data is your reputation, and demonstrable good housekeeping is part of the service you sell.
Where this sits alongside your security
Retention and records are the paperwork side of keeping data safe; strong technical controls are the other half. The two reinforce each other — there’s little point locking the door if you leave a decade of files piled behind it. Getting your broader cyber-security foundations in order at the same time is the efficient way to do this once and do it properly.
If the thought of untangling where your data lives feels overwhelming, that’s usually a sign it has sprawled further than you realise — which is exactly why it’s worth doing. A short conversation can turn a vague worry into a simple, prioritised plan. Get in touch and we’ll help you map what you hold and tidy it up without the jargon.
Frequently asked questions
Do small businesses really need a Record of Processing Activities (ROPA)?
Under UK GDPR, organisations with fewer than 250 staff have a lighter-touch obligation, but the exemptions are narrow — they fall away if your processing is regular, could affect people's rights, or involves special category data (like health information). In practice, almost every small business benefits from keeping a simple ROPA. Even where it isn't strictly required, the ICO expects you to understand and document your data, and a short record is the easiest way to prove you do.
How long should I keep customer and staff records?
There's no single answer — it depends on the type of record and any legal duty attached to it. HMRC generally expects business and tax records to be kept for around six years, and employment-related documents have their own timescales. The principle is to keep data only for as long as you have a genuine, documented reason, then delete it. Write your chosen periods down in a retention schedule so the decision is made once, not agonised over every time.
What is data minimisation in simple terms?
It means only collecting and keeping the personal information you actually need for a specific purpose. If a booking form doesn't need a date of birth, don't ask for one. If you no longer need an old supplier's bank details, delete them. Less data means less to protect, less to lose in a breach, and less to explain to the ICO if something goes wrong.
What happens if the ICO asks about our data and we have no records?
The Information Commissioner's Office can ask you to demonstrate how you comply with data protection law. If you can't show what data you hold, why, and how long you keep it, you're on the back foot — especially after a breach or a customer complaint. A modest ROPA and retention schedule are exactly the kind of evidence that shows you take your responsibilities seriously, which counts in your favour.
Dacros — led by Jordan Gilbert
Our guides are written and checked by the Dacros team, led by founder Jordan Gilbert. We run the IT and cyber security for UK small businesses — and hold our own systems to the same standard. About Jordan · About Dacros.
Related guides
The backup password on the laptop you're backing up
Recovery controls fail in a way audits miss: the control quietly depends on the very thing it is meant to recover you from. We found five in our own systems in a week — here's the one question that finds them, and a two-hour fix.
Read → GuideIT and Cyber Security for Charities and Non-Profits in the UK
A plain-English guide to IT and cyber security for UK charities: protecting donor and beneficiary data, controlling volunteer access, and Cyber Essentials on a tight budget.
Read → GuideIT & Cyber Security for Solicitors and Law Firms: A Plain-English Guide
A practical guide to IT security for UK law firms: client confidentiality, SRA-aligned controls, secure email and documents, DMARC, backups and staying compliant.
Read →Want this handled for you?
Dacros runs the IT and security for UK small businesses. Book a free review and we'll tell you what's worth doing — no jargon, no pressure.