Record Retention Policy
Version 1.1 · Effective from August 2026 · Northbound Legal Ltd, company number 17402564, registered office Unit 82a James Carter Road, Bury St. Edmunds, England, IP28 7DE · hello@northboundlegal.co.uk
1PURPOSE AND SCOPE
1.1This policy sets out how long Northbound Legal Ltd ("Northbound Legal", "we", "us") keeps records containing personal information, and how we decide those periods. It applies to all personal information we hold as a controller (for example, about job applicants, marketing contacts, suppliers and our own personnel) and, subject to clause 4, explains how retention is handled for client matter data we process as a processor.
1.2It does not itself set the retention period for client matter data: that is governed by the Data Processing Agreement with the relevant client firm, as described in our Privacy Policy.
2THE LEGAL PRINCIPLE WE WORK TO
2.1UK GDPR Article 5(1)(e) requires that personal data be kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which it is processed. The accountability principle in Article 5(2) requires us to be able to demonstrate that we comply with this.
2.2This policy, and the schedule at clause 5, is how we do that. The periods in the schedule are defaults based on our assessment of legal, regulatory and operational need. We will delete or anonymise records sooner where we no longer need them and extend a period only where clause 8 applies.
3ROLES AND RESPONSIBILITIES
The person responsible for data protection queries, as named in our Privacy Policy, owns this policy, reviews it at least annually, and approves any departure from the retention schedule, including extensions for litigation holds or regulatory requests under clause 8.
4CLIENT MATTER DATA
Where we process a client firm's matter data as a processor, retention is governed by the Data Processing Agreement for that engagement, which provides for the return or deletion of matter data at the client firm's election on termination, subject to any longer period the client firm's own regulatory obligations require. We do not independently set retention periods for matter data, and this policy does not override the Data Processing Agreement.
5RETENTION SCHEDULE
| Category of records | Default retention period | Legal basis / rationale | Action at end of period |
|---|---|---|---|
| Client matter data (processed as processor) | Governed by the Data Processing Agreement for the relevant engagement; typically returned or deleted within 30 days of termination unless the client firm instructs otherwise | See clause 4. Retention is set by the client firm as controller, not by us. | Per the Data Processing Agreement |
| Corporate accounting records, invoices and VAT records | 6 years from the end of the financial year to which they relate | Companies Act 2006, s.388; HMRC record-keeping requirements for Corporation Tax and VAT | Securely destroyed |
| Contracts (client Orders, supplier agreements, the Data Processing Agreement) | 6 years after expiry or termination (12 years if executed as a deed) | Limitation Act 1980, ss.5 and 8 (time limits for bringing a claim for breach of contract or under a deed) | Securely destroyed |
| Personnel records (contracts, performance, disciplinary) | Duration of engagement plus 6 years after it ends | Limitation Act 1980, s.5; Equality Act 2010 and general employment-related claims | Securely destroyed |
| Payroll and tax records | 6 years from the end of the tax year to which they relate | Income Tax (PAYE) Regulations 2003; HMRC guidance for Corporation Tax and self-assessment enquiry windows | Securely destroyed |
| Right to work check records | Duration of engagement plus 2 years after it ends | Home Office statutory guidance on right to work checks | Securely destroyed |
| Recruitment records – unsuccessful candidates | 12 months after the recruitment decision | ICO and ACAS guidance; Equality Act 2010 time limits for discrimination claims | Securely destroyed, unless the candidate consents to a longer talent-pool period |
| Marketing contact and consent/opt-out records | For as long as we hold the contact for marketing purposes; opt-out and suppression records are kept indefinitely | Privacy and Electronic Communications Regulations 2003; UK GDPR Article 7(1) (need to evidence consent) | Suppressed contacts retained as a "do not contact" record only |
| Website enquiries with no resulting relationship | 12 months | Storage limitation principle – UK GDPR Article 5(1)(e) (no ongoing purpose) | Securely destroyed |
| Data subject rights requests and complaints | 3 years from resolution | UK GDPR Article 5(2) accountability principle; Data (Use and Access) Act 2025, s.103; Limitation Act 1980, s.5 | Securely destroyed |
| Personal data breach records | 6 years from the date of the incident | UK GDPR Article 33(5) (obligation to document all breaches, whether or not notified to the ICO) | Securely destroyed |
| Sanctions and financial-crime screening records | 6 years from the date of screening | Limitation Act 1980, s.5 and standard audit-trail practice; Sanctions and Anti-Money Laundering Act 2018 | Securely destroyed |
| Litigation and dispute records | Duration of the matter plus 6 years after final resolution (15 years where a professional negligence longstop applies) | Limitation Act 1980; Latent Damage Act 1986, s.1 (15-year longstop) | Securely destroyed, subject to clause 8 (litigation holds) |
| CCTV and premises access records (where applicable) | 30 days, unless retained for a specific incident | ICO guidance on CCTV and surveillance systems | Automatically overwritten |
| Supplier and vendor records | Duration of relationship plus 6 years | Limitation Act 1980, s.5; HMRC record-keeping requirements | Securely destroyed |
6SPECIAL CATEGORY AND CRIMINAL OFFENCE DATA
Where a retention period in the schedule covers special category data (for example, health information disclosed during a recruitment process) or criminal offence data (for example, right to work or recruitment check results), we apply the same period unless a shorter period is achievable, and we restrict access to that data to personnel who need it, consistent with Schedule 1 to the Data Protection Act 2018.
7ANONYMISATION AND SECURE DESTRUCTION
Where practicable, we anonymise or aggregate personal information instead of deleting it outright, where this meets our operational or statistical needs without keeping data in identifiable form. Where records are deleted, we do so securely: electronic records are deleted from live systems and backups are allowed to expire and overwrite in the ordinary course of our backup cycle; paper records are shredded or confidentially disposed of.
8LITIGATION HOLDS AND REGULATORY REQUESTS
We will suspend the scheduled deletion of specific records where we reasonably anticipate litigation, a regulatory investigation, or a data subject rights request to which those records are relevant, for as long as that need continues. A litigation hold overrides the default period in clause 5 for the affected records only.
9SOUTH AFRICA
Our delivery operations in South Africa are additionally subject to the Protection of Personal Information Act 2013 (POPIA), which contains a similar "no longer than necessary" retention principle (section 14, read with Condition 5). We apply this policy as the common standard across both jurisdictions.
10REVIEW
We review this policy at least annually, and whenever our processing activities, legal obligations or risk assessment change materially.