UK GDPR and contract data retention: how long can you actually keep a contract?
UK GDPR doesn't give you a fixed number of years to keep contract data for. It gives you a principle - and leaves you to justify the number yourself. Here's how to actually land on one.
There's no fixed retention period - that's the whole point
UK GDPR's "storage limitation" principle (Article 5(1)(e)) says personal data can only be kept "for no longer than is necessary" for the purpose it was collected for. There's no table of numbers anywhere in the regulation itself - the obligation is to justify whatever period you actually choose, in writing, and be able to show your working if asked.
That's a genuine problem for a small business with no in-house legal team: "necessary" isn't a number you can put in a spreadsheet column. In practice, most UK businesses anchor their contract retention period to OTHER laws that DO specify a number - even though GDPR itself doesn't require it.
The numbers everyone actually uses
| What | How long | Why |
|---|---|---|
| A standard signed contract (not a deed) | 6 years | Limitation Act 1980, s.5 - the window to bring a breach-of-contract claim |
| A contract executed as a deed | 12 years | Limitation Act 1980, s.8 - deeds get double the claim window |
| Accounting & tax records tied to a contract | 6 years | Companies Act 2006 technically only requires 3 - HMRC's own 6-year rule is what actually governs in practice |
These are the clock a claim or an HMRC enquiry runs on, not a GDPR requirement - but "we might still need this to defend a claim" is exactly the kind of justification the storage limitation principle asks you to have ready. Counted from the end of the contractual relationship (or the relevant financial year for tax records), not the date it was signed.
The personal data inside a contract still needs its own answer
A commercial contract usually carries personal data alongside the commercial terms - a counterparty's named signatory, an email address, sometimes a phone number. That's what UK GDPR is actually regulating, not the contract's substance. Two things follow from that:
Keeping the contract is usually fine
If you can justify keeping the document (a live limitation-period claim risk, a tax obligation), the personal data riding along inside it is generally justified for the same period - you're not required to redact a signatory's name out of an old PDF the day the relationship ends.
Have an actual answer, not just a habit
The ICO has publicly criticised organisations for having no documented retention policy at all - not specifically for picking the "wrong" number. A short written policy (what you keep, why, for how long, who decides) is what turns "we've always just kept everything" into something you can defend.
Agreemnt finds every contract already sitting in your Drive and inbox - including the old ones nobody's looked at in years - so "how long have we actually had this" stops being a guess. Not ready to connect anything yet? Try the free contract audit first - no account needed.
Sources
- UK GDPR, Article 5(1)(e) - the storage limitation principle itself; no fixed period is specified in the legislation.
- Limitation Act 1980, sections 5 and 8 - the six-year limitation period for simple contracts and twelve-year period for contracts executed as a deed.
- How long should company records be retained for? - Crunch, 2026. Source for the Companies Act 2006 s.388 three-year baseline versus the six-year period HMRC's own rules actually require in practice. crunch.co.uk
- How Long Can Personal Data Be Stored Under UK GDPR? - Geldards LLP. Source for the ICO's documented criticism of organisations with no retention policy, and the storage-limitation enforcement risk. geldards.com
Spotted a source that's moved, been updated, or been superseded? Tell us at hello@agreemnt.co.uk and we'll correct it.
Start free - no card required.
Connect your inbox and Drive and see what's already there. Free for up to 10 contracts, and every plan includes your whole team.