HR4 Business Data Retention Schedule
This is the Data Retention Policy of HR4 Business Ltd
Introduction
We recognise that in the running of our business, we collect and process personal data from a variety of sources. This personal information is collated in several different formats including letters, emails, legal documents, employment records, operations records, images and statements. The personal data is held in both hard copy and electronic form. This policy covers all the personal data that we hold or have control over. It also covers data that is held by third parties on our behalf, for example cloud storage providers or offsite records storage.
Aims of the policy
HR4 Business Ltd will ensure that personal data that we hold is kept secure and that it is held for no longer than is necessary for the purposes for which it is being processed. In addition, we will retain the minimum amount of information to fulfill our statutory obligations and the provision of goods or/and services - as required by the data protection legislation, including the UK General Data Protection Regulation (UK GDPR).
Retention
This retention policy (with its schedule), is a tool used to assist us in making decisions on whether a particular document should be retained or disposed of. In addition, it takes account of the context within which the personal data is being processed and our business practices.
We will regularly monitor and audit compliance with this policy and update it when required.
Disposal
We will ensure that personal data is securely disposed of when it is no longer needed.
The method of disposal should be appropriate to the nature and sensitivity of the documents concerned and includes:
· Non-Confidential records: place in waste paper bin for disposal
· Confidential records: shred documents
· Deletion of Computer Records
· Transmission of records to an external body
· Cloud storage
· Cloud archive
The table below contains the retention period that we have assigned to each type of record. This will be adhered to wherever possible, although it is recognised that there may be exceptional circumstances which require documents to be kept for either shorter or longer periods.
| Type of record | Retention period | Where is it stored? | Reason | Method of deletion |
| Employment records: | ||||
| PAYE records | 5 years from end of fiscal year | Cloud Storage | Legal | Manual deletion |
| Medical and health records | 10 years after employment ceases | Cloud Storage | Legal | Manual deletion |
| Unsuccessful candidates | 6 months after last action | Cloud Storage | Legal | Manual deletion |
| Accident report forms | 5 years after last action | Cloud Storage | Legal | Manual deletion |
| Parental leave records | 18 years from birth of child | Cloud Storage | Legal | Manual deletion |
| Employment records: redundancy, equal opportunities; health & welfare records | 6 years after last action | Cloud Storage | Legal | Manual deletion |
| Employees that left the business: emergency contacts and bank account details | Delete immediately after making final salary payment | Cloud Storage | Legal | Manual deletion |
| Pay & tax: pay deductions, tax forms, payroll, loans | 6 years after last action | Cloud Storage | Legal | Manual deletion |
| Records of formal disciplinary actions in employee file | 6 years after last action | Cloud Storage | Legal | Manual deletion |
| Records of formal grievances in employee file | 6 years after last action | Cloud Storage | Legal | Manual deletion |
| Commercial contracts: | ||||
| Contracts with suppliers | 6 years after last action | Cloud Storage | Contractual | Manual deletion |
| Contracts signed as a deed | 10 years after last action | Cloud Storage | Contractual | Manual deletion |
| Guarantees and indemnities | The term of the guarantee plus 6 years | Cloud Storage | Contractual | Manual deletion |
| Purchase orders and invoices | 6 years after last action | Cloud Storage | Contractual | Manual deletion |
| Tax and Accounting Records: | ||||
| Tax returns | 10 years from end of fiscal year | Cloud Storage | Legal | Manual deletion |
| Accounting & financial management information | 10 years from end of fiscal year | Cloud Storage | Legal | Manual deletion |
| Stock transfer forms and share certificates | 20 years from purchase | Cloud Storage | Legal | Manual deletion |
| Marketing records: | ||||
| Mailing lists | 1 year after last action | Cloud Storage | Legitimate Interest | Manual deletion |
| Operational records: | ||||
| Policies/Procedures | 5 years | Cloud Storage | Legal | Manual deletion |
| Complaints | 6 years from end of fiscal year | Cloud Storage | Legal | Manual deletion |
| Insurance schedules | 10 years after last action | Cloud Storage | Legal | Manual deletion |
| Register of members | Life of company | Cloud Storage | Legal | N/A |
| Memorandum of association | Life of company | Cloud Storage | Legal | N/A |
| Register of directors and secretaries | Life of company | Cloud Storage | Legal | N/A |
| Employer’s liability insurance certificates | Life of company | Cloud Storage | Legal | N/A |
| Email records: | ||||
| Email correspondence | Archive emails after 2 years | Cloud Storage | Legal | M365 archive setting |