UK GDPR and contract data retention: how long can you actually keep a contract?

UK GDPR doesn't give you a fixed number of years to keep contract data for. It gives you a principle - and leaves you to justify the number yourself. Here's how to actually land on one.

Not legal advice. This is a plain-English starting point for a genuinely common small-business question, not a substitute for advice from a data protection specialist on your own retention policy. Every figure below is sourced at the bottom of the page.

There's no fixed retention period - that's the whole point

UK GDPR's "storage limitation" principle (Article 5(1)(e)) says personal data can only be kept "for no longer than is necessary" for the purpose it was collected for. There's no table of numbers anywhere in the regulation itself - the obligation is to justify whatever period you actually choose, in writing, and be able to show your working if asked.

That's a genuine problem for a small business with no in-house legal team: "necessary" isn't a number you can put in a spreadsheet column. In practice, most UK businesses anchor their contract retention period to OTHER laws that DO specify a number - even though GDPR itself doesn't require it.

The numbers everyone actually uses

WhatHow longWhy
A standard signed contract (not a deed)6 yearsLimitation Act 1980, s.5 - the window to bring a breach-of-contract claim
A contract executed as a deed12 yearsLimitation Act 1980, s.8 - deeds get double the claim window
Accounting & tax records tied to a contract6 yearsCompanies Act 2006 technically only requires 3 - HMRC's own 6-year rule is what actually governs in practice

These are the clock a claim or an HMRC enquiry runs on, not a GDPR requirement - but "we might still need this to defend a claim" is exactly the kind of justification the storage limitation principle asks you to have ready. Counted from the end of the contractual relationship (or the relevant financial year for tax records), not the date it was signed.

The personal data inside a contract still needs its own answer

A commercial contract usually carries personal data alongside the commercial terms - a counterparty's named signatory, an email address, sometimes a phone number. That's what UK GDPR is actually regulating, not the contract's substance. Two things follow from that:

Keeping the contract is usually fine

If you can justify keeping the document (a live limitation-period claim risk, a tax obligation), the personal data riding along inside it is generally justified for the same period - you're not required to redact a signatory's name out of an old PDF the day the relationship ends.

Have an actual answer, not just a habit

The ICO has publicly criticised organisations for having no documented retention policy at all - not specifically for picking the "wrong" number. A short written policy (what you keep, why, for how long, who decides) is what turns "we've always just kept everything" into something you can defend.

A retention policy only works if you know what you're actually holding.

Agreemnt finds every contract already sitting in your Drive and inbox - including the old ones nobody's looked at in years - so "how long have we actually had this" stops being a guess. Not ready to connect anything yet? Try the free contract audit first - no account needed.

Start free

Start free - no card required.

Connect your inbox and Drive and see what's already there. Free for up to 10 contracts, and every plan includes your whole team.