People Group Services
JOINT
EMPLOYMENT
POLICY DOCUMENT LIBRARY
Company Policy Documents
People Group Services Limited
Company Number: 11570329

Data Retention Policy

Purpose

This Data Retention Policy sets out how People Group Services Limited (“the Company”, “we”, “us”, “our”) manages the retention, storage, archiving, and secure disposal of personal data and business records.

The Company is committed to compliance with:

  • UK General Data Protection Regulation (UK GDPR)
  • Data Protection Act 2018
  • Companies Act 2006
  • Income Tax (PAYE) Regulations
  • HMRC statutory record-keeping requirements
  • Employment legislation
  • Financial Services and accounting obligations

We retain personal data only for as long as necessary to fulfil legal, contractual, regulatory and operational requirements.

Scope

This policy applies to:

  • Employees and workers
  • Contractors and temporary workers
  • Agency partners
  • End clients
  • Job applicants
  • Suppliers and service providers
  • Website users
  • Digital platform users (including payroll, umbrella, PEO and MSP systems)

This policy applies across all trading divisions and digital platforms operated by the Company.

Retention Principles

People Group Services Limited adheres to the following principles:

  • Data will not be retained longer than necessary.
  • Retention periods will reflect statutory requirements.
  • Data required for HMRC or regulatory defence purposes will be retained in line with limitation periods.
  • Data will be securely archived where appropriate.
  • Data will be permanently and securely deleted when no longer required.

Retention Periods by Category

Payroll, PAYE & Tax Records

Record Type

Retention Period

Legal Basis

PAYE records, RTI submissions, tax calculations

6 years after tax year end

HMRC PAYE Regulations

National Insurance records

6 years

HMRC

Apprenticeship Levy records

6 years

Finance Act requirements

P60, P45 copies

6 years

HMRC

Holiday pay calculations

6 years

Employment law limitation

Pension auto-enrolment records

6 years

The Pensions Regulator

Where Joint & Several Liability risks exist under Chapter 11 ITEPA 2003, records may be retained up to 7 years for compliance defence purposes.

Employment & Worker Records

Record Type

Retention Period

Employment contracts

6 years after termination

Right to Work documentation

Duration of employment + 2 years

Disciplinary & grievance records

6 years

Accident records (RIDDOR)

3 years minimum

Health & safety records

6 years

Statutory maternity/paternity records

3 years after tax year

Where litigation is anticipated, records may be retained until resolution.

Umbrella & PEO Records

Record Type

Retention Period

Assignment schedules

6 years

Timesheets

6 years

Payslips

6 years

Holiday accrual records

6 years

Expense claims

6 years

Client contracts

6 years after termination

Financial & Corporate Records

Record Type

Retention Period

Legal Basis

Accounting records

6 years

Companies Act 2006

VAT records

6 years

HMRC VAT rules

Bank statements

6 years

 

Audit reports

6 years

 

Insurance documentation

6 years after expiry

 

Safeguarding / DBS / Identity Records (where applicable)

Record Type

Retention Period

DBS status confirmation

Duration of engagement

ID verification logs

6 years

Safeguarding audit trail

6 years

Full DBS certificates are not retained unless legally permitted.

Recruitment Data

Record Type

Retention Period

Unsuccessful applicant data

6 months

Interview notes

6 months

Right to work checks

As per employment section

CV database

12 months (unless renewed consent)

Digital Platform & System Logs

Record Type

Retention Period

System access logs

12 months

Audit trails

6 years

API transaction logs

6 years

Cyber security logs

12–24 months

 

Special Category Data

Where special category data is processed (e.g. health data, trade union membership), retention will be:

  • Strictly limited to statutory necessity
  • Subject to additional access controls
  • Deleted immediately when no longer required

Secure Storage & Archiving

People Group Services Limited:

  • Uses encrypted digital storage systems
  • Maintains Cyber Essentials Plus certification
  • Conducts annual external security audits
  • Applies role-based access controls
  • Maintains offsite encrypted backups
  • Applies disaster recovery planning

Archived data is stored in secure encrypted environments with restricted access.

Secure Disposal

When retention periods expire:

  • Digital records are permanently deleted using secure deletion protocols
  • Paper records are shredded via approved confidential waste providers
  • Cloud storage records are purged from live and backup environments in accordance with system cycles

A destruction log may be maintained where required.

Litigation Hold

If litigation, HMRC enquiry, regulatory investigation or dispute is anticipated:

  • Relevant data will be preserved beyond normal retention periods
  • Deletion processes will be suspended
  • Legal counsel may advise on extended retention

Data Subject Rights

Individuals may request:

  • Access to their data
  • Rectification
  • Erasure (where legally permissible)
  • Restriction of processing

Requests should be made to:

Data Protection Officer
People Group Services Limited
People Group House
Three Horseshoes Walk
Warminster
Wiltshire
BA12 9BT

Or via: compliance@peoplegroupservices.com

Review of Policy

This policy:

  • Is reviewed annually
  • May be updated in response to legislative change
  • Is approved by Senior Management

 

Declaration

This Policy is approved by the Board of Directors of: People Group Services Limited Company Number: 11570329

Last updated: 20th February 2026