Record Retention Policy

Version 1.1 · Effective from August 2026 · Northbound Legal Ltd, company number 17402564, registered office Unit 82a James Carter Road, Bury St. Edmunds, England, IP28 7DE · hello@northboundlegal.co.uk

1PURPOSE AND SCOPE

  1. 1.1This policy sets out how long Northbound Legal Ltd ("Northbound Legal", "we", "us") keeps records containing personal information, and how we decide those periods. It applies to all personal information we hold as a controller (for example, about job applicants, marketing contacts, suppliers and our own personnel) and, subject to clause 4, explains how retention is handled for client matter data we process as a processor.

  2. 1.2It does not itself set the retention period for client matter data: that is governed by the Data Processing Agreement with the relevant client firm, as described in our Privacy Policy.

2THE LEGAL PRINCIPLE WE WORK TO

  1. 2.1UK GDPR Article 5(1)(e) requires that personal data be kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which it is processed. The accountability principle in Article 5(2) requires us to be able to demonstrate that we comply with this.

  2. 2.2This policy, and the schedule at clause 5, is how we do that. The periods in the schedule are defaults based on our assessment of legal, regulatory and operational need. We will delete or anonymise records sooner where we no longer need them and extend a period only where clause 8 applies.

3ROLES AND RESPONSIBILITIES

The person responsible for data protection queries, as named in our Privacy Policy, owns this policy, reviews it at least annually, and approves any departure from the retention schedule, including extensions for litigation holds or regulatory requests under clause 8.

4CLIENT MATTER DATA

Where we process a client firm's matter data as a processor, retention is governed by the Data Processing Agreement for that engagement, which provides for the return or deletion of matter data at the client firm's election on termination, subject to any longer period the client firm's own regulatory obligations require. We do not independently set retention periods for matter data, and this policy does not override the Data Processing Agreement.

5RETENTION SCHEDULE

Category of recordsDefault retention periodLegal basis / rationaleAction at end of period
Client matter data (processed as processor)Governed by the Data Processing Agreement for the relevant engagement; typically returned or deleted within 30 days of termination unless the client firm instructs otherwiseSee clause 4. Retention is set by the client firm as controller, not by us.Per the Data Processing Agreement
Corporate accounting records, invoices and VAT records6 years from the end of the financial year to which they relateCompanies Act 2006, s.388; HMRC record-keeping requirements for Corporation Tax and VATSecurely destroyed
Contracts (client Orders, supplier agreements, the Data Processing Agreement)6 years after expiry or termination (12 years if executed as a deed)Limitation Act 1980, ss.5 and 8 (time limits for bringing a claim for breach of contract or under a deed)Securely destroyed
Personnel records (contracts, performance, disciplinary)Duration of engagement plus 6 years after it endsLimitation Act 1980, s.5; Equality Act 2010 and general employment-related claimsSecurely destroyed
Payroll and tax records6 years from the end of the tax year to which they relateIncome Tax (PAYE) Regulations 2003; HMRC guidance for Corporation Tax and self-assessment enquiry windowsSecurely destroyed
Right to work check recordsDuration of engagement plus 2 years after it endsHome Office statutory guidance on right to work checksSecurely destroyed
Recruitment records – unsuccessful candidates12 months after the recruitment decisionICO and ACAS guidance; Equality Act 2010 time limits for discrimination claimsSecurely destroyed, unless the candidate consents to a longer talent-pool period
Marketing contact and consent/opt-out recordsFor as long as we hold the contact for marketing purposes; opt-out and suppression records are kept indefinitelyPrivacy and Electronic Communications Regulations 2003; UK GDPR Article 7(1) (need to evidence consent)Suppressed contacts retained as a "do not contact" record only
Website enquiries with no resulting relationship12 monthsStorage limitation principle – UK GDPR Article 5(1)(e) (no ongoing purpose)Securely destroyed
Data subject rights requests and complaints3 years from resolutionUK GDPR Article 5(2) accountability principle; Data (Use and Access) Act 2025, s.103; Limitation Act 1980, s.5Securely destroyed
Personal data breach records6 years from the date of the incidentUK GDPR Article 33(5) (obligation to document all breaches, whether or not notified to the ICO)Securely destroyed
Sanctions and financial-crime screening records6 years from the date of screeningLimitation Act 1980, s.5 and standard audit-trail practice; Sanctions and Anti-Money Laundering Act 2018Securely destroyed
Litigation and dispute recordsDuration of the matter plus 6 years after final resolution (15 years where a professional negligence longstop applies)Limitation Act 1980; Latent Damage Act 1986, s.1 (15-year longstop)Securely destroyed, subject to clause 8 (litigation holds)
CCTV and premises access records (where applicable)30 days, unless retained for a specific incidentICO guidance on CCTV and surveillance systemsAutomatically overwritten
Supplier and vendor recordsDuration of relationship plus 6 yearsLimitation Act 1980, s.5; HMRC record-keeping requirementsSecurely destroyed

6SPECIAL CATEGORY AND CRIMINAL OFFENCE DATA

Where a retention period in the schedule covers special category data (for example, health information disclosed during a recruitment process) or criminal offence data (for example, right to work or recruitment check results), we apply the same period unless a shorter period is achievable, and we restrict access to that data to personnel who need it, consistent with Schedule 1 to the Data Protection Act 2018.

7ANONYMISATION AND SECURE DESTRUCTION

Where practicable, we anonymise or aggregate personal information instead of deleting it outright, where this meets our operational or statistical needs without keeping data in identifiable form. Where records are deleted, we do so securely: electronic records are deleted from live systems and backups are allowed to expire and overwrite in the ordinary course of our backup cycle; paper records are shredded or confidentially disposed of.

8LITIGATION HOLDS AND REGULATORY REQUESTS

We will suspend the scheduled deletion of specific records where we reasonably anticipate litigation, a regulatory investigation, or a data subject rights request to which those records are relevant, for as long as that need continues. A litigation hold overrides the default period in clause 5 for the affected records only.

9SOUTH AFRICA

Our delivery operations in South Africa are additionally subject to the Protection of Personal Information Act 2013 (POPIA), which contains a similar "no longer than necessary" retention principle (section 14, read with Condition 5). We apply this policy as the common standard across both jurisdictions.

10REVIEW

We review this policy at least annually, and whenever our processing activities, legal obligations or risk assessment change materially.