How long to keep customer records
- Aug 29
- 3 min read
Updated: 4 days ago
Introduction
A business has every customer record it has ever created, going back to the first year of trading. Nobody decided to keep them; nobody decided to delete them either, and storage is cheap enough that the question never arose.
Every one of those records is a liability in the event of a breach, is within scope of any access request, and is being held without a current reason. Retention is one of the more straightforward obligations to meet and one of the most widely ignored, because deleting things feels riskier than keeping them. The opposite is true: every record retained without purpose is exposure carried for nothing.
1. How long to keep customer records depends on why you hold them
The organising principle.
There is no single answer. Each category has a purpose, and the retention period follows from that purpose plus any legal requirement to keep it longer. Data with no current purpose should not be retained at all. That single principle resolves most of the volume in a typical small business.
2. Start with legal minimums
The floor rather than the answer.
Accounting and tax records, employment records, and sector-specific requirements all have prescribed periods in most jurisdictions. Establish those first, because they set a minimum you cannot go below.
3. Consider the limitation period for claims
A legitimate reason to keep longer.
Records relevant to a potential dispute can reasonably be retained until claims become time-barred, which varies by jurisdiction and by type of claim. This is a defensible basis and it should be stated rather than assumed. Writing the reasoning down is what makes the period defensible if it is queried.
4. Set a period for each category
The practical output.
Enquiries that did not convert, customer transaction records, marketing contacts, supplier details, job applications, CCTV. Each gets a period and a justification, recorded in a short schedule.
5. Be much shorter with things you barely use
Where most of the excess sits.
Unsuccessful applications, expired enquiries, old event lists and correspondence. These are held out of inertia rather than purpose, and short periods here remove most of the volume. Unsuccessful applications alone frequently account for years of accumulated files.
6. Delete or genuinely anonymise
Not merely archive.
Moving data to an old drive is still holding it. Where you want to keep statistics, properly anonymised data falls outside most regimes entirely, and that is a better solution than retaining identifiable records.
7. Remember backups and secondary copies
The step almost everybody misses.
Deleting from the live system while backups, exports, spreadsheets and old mailboxes retain the data achieves little. The schedule needs to address every location identified in your data inventory.
8. Automate it where you can
Manual deletion does not happen.
Most systems support retention rules or at least reporting on record age. A rule applied automatically is the difference between a policy and an intention.
9. Write the schedule down and follow it
Both parts.
A documented retention schedule is expected in most frameworks, and applying it is what matters. A policy stating periods that are visibly not being followed is worse than having none.
Review it annually alongside your data inventory. Both documents describe the same thing from different angles, both go stale as systems change, and reviewing them together takes little longer than reviewing either alone.
Conclusion
Set a period for each category based on why you hold it, rather than keeping everything.
Establish the legal minimums that apply in your jurisdiction, consider the limitation period for potential claims as a defensible basis, record a period and justification for each category, apply much shorter periods to enquiries and applications you barely use, delete or properly anonymise rather than archiving, extend the schedule to backups and secondary copies, automate deletion where systems allow it, document the schedule and actually follow it, and review it annually with your data inventory.
.png)



Comments