![]() |
People Group Services Limited Company Number: 11570329 |
Data Retention Policy
Purpose
This Data Retention Policy sets out how People Group Services Limited (“the Company”, “we”, “us”, “our”) manages the retention, storage, archiving, and secure disposal of personal data and business records.
The Company is committed to compliance with:
- UK General Data Protection Regulation (UK GDPR)
- Data Protection Act 2018
- Companies Act 2006
- Income Tax (PAYE) Regulations
- HMRC statutory record-keeping requirements
- Employment legislation
- Financial Services and accounting obligations
We retain personal data only for as long as necessary to fulfil legal, contractual, regulatory and operational requirements.
Scope
This policy applies to:
- Employees and workers
- Contractors and temporary workers
- Agency partners
- End clients
- Job applicants
- Suppliers and service providers
- Website users
- Digital platform users (including payroll, umbrella, PEO and MSP systems)
This policy applies across all trading divisions and digital platforms operated by the Company.
Retention Principles
People Group Services Limited adheres to the following principles:
- Data will not be retained longer than necessary.
- Retention periods will reflect statutory requirements.
- Data required for HMRC or regulatory defence purposes will be retained in line with limitation periods.
- Data will be securely archived where appropriate.
- Data will be permanently and securely deleted when no longer required.
Retention Periods by Category
Payroll, PAYE & Tax Records
|
Record Type |
Retention Period |
Legal Basis |
|---|---|---|
|
PAYE records, RTI submissions, tax calculations |
6 years after tax year end |
HMRC PAYE Regulations |
|
National Insurance records |
6 years |
HMRC |
|
Apprenticeship Levy records |
6 years |
Finance Act requirements |
|
P60, P45 copies |
6 years |
HMRC |
|
Holiday pay calculations |
6 years |
Employment law limitation |
|
Pension auto-enrolment records |
6 years |
The Pensions Regulator |
Where Joint & Several Liability risks exist under Chapter 11 ITEPA 2003, records may be retained up to 7 years for compliance defence purposes.
Employment & Worker Records
|
Record Type |
Retention Period |
|---|---|
|
Employment contracts |
6 years after termination |
|
Right to Work documentation |
Duration of employment + 2 years |
|
Disciplinary & grievance records |
6 years |
|
Accident records (RIDDOR) |
3 years minimum |
|
Health & safety records |
6 years |
|
Statutory maternity/paternity records |
3 years after tax year |
Where litigation is anticipated, records may be retained until resolution.
Umbrella & PEO Records
|
Record Type |
Retention Period |
|---|---|
|
Assignment schedules |
6 years |
|
Timesheets |
6 years |
|
Payslips |
6 years |
|
Holiday accrual records |
6 years |
|
Expense claims |
6 years |
|
Client contracts |
6 years after termination |
Financial & Corporate Records
|
Record Type |
Retention Period |
Legal Basis |
|---|---|---|
|
Accounting records |
6 years |
Companies Act 2006 |
|
VAT records |
6 years |
HMRC VAT rules |
|
Bank statements |
6 years |
|
|
Audit reports |
6 years |
|
|
Insurance documentation |
6 years after expiry |
Safeguarding / DBS / Identity Records (where applicable)
|
Record Type |
Retention Period |
|---|---|
|
DBS status confirmation |
Duration of engagement |
|
ID verification logs |
6 years |
|
Safeguarding audit trail |
6 years |
Full DBS certificates are not retained unless legally permitted.
Recruitment Data
|
Record Type |
Retention Period |
|---|---|
|
Unsuccessful applicant data |
6 months |
|
Interview notes |
6 months |
|
Right to work checks |
As per employment section |
|
CV database |
12 months (unless renewed consent) |
Digital Platform & System Logs
|
Record Type |
Retention Period |
|---|---|
|
System access logs |
12 months |
|
Audit trails |
6 years |
|
API transaction logs |
6 years |
|
Cyber security logs |
12–24 months |
Special Category Data
Where special category data is processed (e.g. health data, trade union membership), retention will be:
- Strictly limited to statutory necessity
- Subject to additional access controls
- Deleted immediately when no longer required
Secure Storage & Archiving
People Group Services Limited:
- Uses encrypted digital storage systems
- Maintains Cyber Essentials Plus certification
- Conducts annual external security audits
- Applies role-based access controls
- Maintains offsite encrypted backups
- Applies disaster recovery planning
Archived data is stored in secure encrypted environments with restricted access.
Secure Disposal
When retention periods expire:
- Digital records are permanently deleted using secure deletion protocols
- Paper records are shredded via approved confidential waste providers
- Cloud storage records are purged from live and backup environments in accordance with system cycles
A destruction log may be maintained where required.
Litigation Hold
If litigation, HMRC enquiry, regulatory investigation or dispute is anticipated:
- Relevant data will be preserved beyond normal retention periods
- Deletion processes will be suspended
- Legal counsel may advise on extended retention
Data Subject Rights
Individuals may request:
- Access to their data
- Rectification
- Erasure (where legally permissible)
- Restriction of processing
Requests should be made to:
Data Protection Officer
People Group Services Limited
People Group House
Three Horseshoes Walk
Warminster
Wiltshire
BA12 9BT
Or via: compliance@peoplegroupservices.com
Review of Policy
This policy:
- Is reviewed annually
- May be updated in response to legislative change
- Is approved by Senior Management
Declaration
This Policy is approved by the Board of Directors of: People Group Services Limited Company Number: 11570329
Last updated: 20th February 2026

