GDPR Data Retention: A UK Guide for HR and IT Teams

GDPR Data Retention: A UK Guide for HR and IT Teams

You've probably got HR data in more places than your retention policy acknowledges. Candidate CVs sit in shared mailboxes, leaver documents remain in SharePoint folders, payroll records are copied into Dataverse and finance systems, and former employees still appear in Microsoft Entra ID. Everyone assumes someone else owns deletion.

That isn't a minor housekeeping problem. It creates a control gap that increases breach exposure, complicates Subject Access Requests, and leaves your organisation unable to demonstrate why it still holds particular records. GDPR data retention is an operational discipline, not a paragraph in a privacy notice.

The HR Data Retention Problem in Modern UK Workplaces

A typical mid-market HR estate rarely has one clean system of record. Recruitment happens through Outlook and Teams, documents move into SharePoint, employee data sits in Dataverse, payroll exports go to finance, and identity records remain in Entra ID after a worker leaves. Archives and backups add another layer, often outside the HR team's daily view.

The result is predictable. Different systems have different expiry dates, some records have no expiry date, and nobody can explain which copy should be deleted first. A board may never have formally approved the retention schedule, while HR administrators rely on calendar reminders and personal judgement.

A diagram illustrating HR data retention problems including scattered, redundant storage in shared mailboxes, SharePoint, Dataverse, and archives.

Why the risk stays hidden

Over-retention rarely produces an immediate alarm. The records remain searchable, users continue working, and deletion gets postponed for a more urgent project. The risk surfaces later, when an employee submits a Subject Access Request and the organisation must search mailboxes, Teams conversations, SharePoint sites, Dataverse tables, exports, and archives.

The ICO expects organisations to keep personal data only as long as needed, review it periodically, and erase or anonymise it when it's no longer required. It also expects an appropriate retention schedule that reflects business need and statutory requirements, as explained in the ICO storage limitation guidance.

Practical rule: If your team can't identify the system of record, the retention trigger, and the person responsible for disposal, the control isn't operational.

The fix has four connected parts: a policy that states the principles, a schedule that defines each record category, automation that enforces the schedule, and audit evidence showing what happened. The technology matters, but ownership matters first.

What UK GDPR Says About Keeping Personal Data

A former employee submits a Subject Access Request. HR must then search Outlook, Teams, SharePoint, Dataverse, exports, and archived files. If each system follows a different retention rule, the organisation cannot explain what it kept, why it kept it, or whether deletion was ever completed.

UK GDPR gives employers no universal deadline for deleting HR records. The rule is purpose-led: identify why the organisation holds the data, keep it only for as long as that purpose requires, review the decision, then delete or anonymise the records. Indefinite retention is restricted to purposes such as public-interest archiving, scientific or historical research, or statistical use with safeguards, as set out in the ICO's storage limitation guidance.

Your HR retention matrix should therefore record the purpose, trigger, retention period, system of record, owner, and disposal action. Map those rules to Dataverse tables, SharePoint libraries, Microsoft 365 mailboxes, and Entra ID objects. A policy that never reaches those services is documentation, not a control.

Retention is one part of the control framework

Storage limitation must operate with the other UK GDPR principles:

  • Purpose limitation: Use information for the defined purpose, not an unrelated future activity.
  • Data minimisation: Keep only the fields needed for that purpose.
  • Accuracy: Correct inaccurate records instead of preserving obsolete information.
  • Accountability: Retain evidence showing who approved the rule, how it was applied, and what disposal occurred.

A legal hold can pause ordinary deletion where records are needed for litigation, a tribunal matter, an investigation, or a regulator enquiry. Configure it for a named matter, defined records, and an accountable owner. “Keep everything just in case” is not a defensible hold.

Privacy notices should state retention periods. Where a fixed period cannot be given, they should explain the criteria used to decide how long information remains. Each HR category needs that rationale, whether the records sit in Dataverse, SharePoint, or Microsoft 365.

For governance planning, myhalo's IT compliance guide for 2026 offers wider IT control context. Use it alongside UK-specific ICO and employment guidance, not as a substitute for either.

Lawful Bases That Justify Holding HR Records

The six UK GDPR lawful bases are consent, contract, legal obligation, vital interests, public task, and legitimate interests. HR teams rely on only some of them regularly. Choosing the wrong basis creates uncertainty about retention, access, and deletion across Dataverse, SharePoint, Microsoft 365, and Entra ID.

Legal obligation supports records such as right-to-work evidence, PAYE information, pension administration, and other employment compliance records. The relevant external requirement sets the retention decision. HR should not shorten that period when an employee leaves, or extend it after the requirement ends without recording another lawful reason.

Contract covers processing needed to administer employment, including payroll, benefits, working arrangements, and contractual records. The employment relationship starts the analysis, but some records need a defined post-employment period for disputes, administration, or related obligations. Document that tail in the HR retention matrix rather than leaving it open-ended.

Legitimate interests may support security monitoring, access management, business records, and references where the organisation's interest is balanced against the individual's rights. Include the retention period in the legitimate interests assessment. If the purpose changes or weakens, review the basis and the controls applying to the record.

Legal claims and defence can justify controlled retention for former-employee records. Tribunal evidence, discrimination allegations, disciplinary history, and dispute correspondence may need preservation while a credible claim or investigation remains active. Apply a documented hold to defined records, assign an owner, and record the release decision before normal deletion resumes.

HR Record Category Primary Lawful Basis Retention Implication
Recruitment applications Legitimate interests, or consent for a talent pool Retain only for recruitment unless a separate future-use basis is documented
Payroll and benefits Contract and legal obligation Follow employment administration needs and applicable statutory requirements
Right-to-work evidence Legal obligation Retain for the documented immigration compliance purpose
Security and access logs Legitimate interests Keep proportionately for security monitoring and review the balancing assessment
Tribunal or disciplinary evidence Legal claims and defence Preserve under a specific hold, then release for deletion or anonymisation

Consent is a poor default for core employment processing because employees and candidates may not be equally able to refuse. It can work for optional activities, but withdrawal must trigger a review of whether another lawful basis supports continued retention. Vital interests rarely applies to ordinary HR administration. Public task generally concerns public bodies carrying out official functions.

Record each category's lawful basis in the retention schedule and, where relevant, the Records of Processing Activities. Do not assign one basis to an entire employee file when its records serve different purposes. A Dataverse employee table, SharePoint case folder, mailbox, or Entra ID object may therefore require separate retention rules and accountable owners.

Building a Retention Schedule That Stands Up to Audit

A retention schedule should be a working control, not a spreadsheet abandoned in a shared drive. The ICO expects organisations to identify records, assign responsibility, review the schedule, and support disposal, minimisation, pseudonymisation, or anonymisation decisions through documented governance. Its records management retention guidance also addresses what to do when technical deletion isn't possible, including restricting access and treating failure to delete as an incident.

Use the right columns

Every row should answer four questions: what is held, why it's held, when the clock starts, and what happens when the clock ends. I recommend these columns:

  • Data category: Describe the record in business language.
  • System of record: Name Dataverse, SharePoint, Exchange, payroll, SQL, or another platform.
  • Lawful basis: Record the basis for processing and retention.
  • Retention trigger: Define the event that starts the period.
  • Retention period: State the approved window or criteria.
  • End-of-life action: Delete, anonymise, archive, or review.
  • Accountable owner: Name the HR, IT, legal, or records-management owner.
  • Last review date: Show when the row was checked.

The trigger is often more important than the period. A leaver record might start from the termination date, an unsuccessful application from the point the recruitment exercise closes, and payroll material from the relevant accounting or reporting cycle. Without a trigger, automation can't calculate the disposal date consistently.

Column Purpose Example (Leaver Records) Audit Evidence
Data category Defines the scope Employee profile and employment history Approved schedule
System of record Shows where action occurs Dataverse Worker table System inventory
Retention trigger Starts the clock Date of Leaving Field definition and workflow
Retention period Sets the approved window Period approved by HR and legal Policy rationale
End-of-life action Defines the outcome Delete or anonymise Deletion log
Owner Assigns accountability HR Operations Manager Named approval
Last review date Demonstrates governance Recorded review date Review record

Review the full schedule annually. Run light-touch checks quarterly, and trigger an out-of-cycle review when legislation, a contract, a regulator request, or a business process changes. The ICO's accountability guidance expects the schedule to be based on business need and statutory requirements, identify responsibilities, and support regular review, as described in its records management and security framework.

Link each schedule row to the relevant RoPA entry, privacy notice, DPIA where needed, and Subject Access Request workflow. That creates a traceable chain from collection to disposal. For practical policy drafting, the document retention policy guide can help your team structure the internal document before configuration begins.

Manual Retention Versus Automated Controls in Microsoft 365

Manual retention isn't automatically wrong. It can work for a small HR team with one HR system, limited document storage, and administrators who follow a controlled process consistently. It fails when the estate spreads across SharePoint, Teams, Exchange, Dataverse, exports, and identity platforms.

Calendar reminders are not a retention control. They depend on one person remembering the task, finding every copy, applying the correct rule, recording the result, and handling exceptions properly. Shared mailboxes are particularly difficult because CVs and interview correspondence may be mixed with unrelated conversations.

Compare the operating models

Dimension Manual Retention Automated (Microsoft 365)
Trigger management Calendar reminders and administrator checks Rules linked to dates, labels, events, or workflows
Consistency Depends on individual behaviour Applies an approved rule repeatedly
SharePoint content Folder-by-folder review Retention labels and scoped policies
Dataverse records Manual filtering and deletion Power Automate controls and bulk-delete jobs
Entra ID objects Administrator-led disablement Lifecycle workflows and access reviews
Exceptions Often recorded in email Managed through an exception register and legal holds
Evidence Screenshots or recollection Job history, label reports, approvals, and logs
Change control Easy to drift Requires managed configuration and testing

Microsoft 365 automation can apply retention labels at item level, scope policies to SharePoint sites, and support controlled records-management workflows. Dataverse can use date fields and scheduled Power Automate flows to identify records for review, while Exchange controls can reduce uncontrolled mail retention. Entra ID lifecycle workflows can manage identity events, but they don't decide the HR purpose for holding employment records.

Automation removes repetitive judgement. It doesn't remove accountability.

The right answer is usually hybrid. Automate routine classification, flagging, deletion, and evidence collection. Keep human approval for legal holds, sensitive occupational health material, disputed records, and policy exceptions. Your implementation should also document what happens when a connector fails, a field is missing, or a record is copied into an ungoverned location.

The information governance guidance is useful when you need to connect Microsoft 365 configuration with broader ownership, policy, and audit requirements.

Configuring Automated Deletion Across Dataverse, SharePoint, and Entra ID

Start with the data model, not the flow. Automation can only enforce a retention rule if the relevant date, status, category, and exception state exist in a reliable field.

Dataverse

For employee records in Dataverse, add a controlled Date of Leaving field to the Worker table or equivalent employee entity. Make the field mandatory when a worker moves to a leaver status, validate the date, and prevent ordinary users from overwriting it without an approved change process.

A practical pattern is:

  1. Create a scheduled Power Automate flow that selects leaver records whose retention window has ended.
  2. Check for legal hold, active investigation, unresolved claim, or approved exception.
  3. Change the record to a pending-disposal state rather than deleting immediately.
  4. Notify the accountable HR or records owner for disposition approval.
  5. Run a Dataverse bulk-delete job using a restricted security role.
  6. Store the flow result, approval, timestamp, and failure details in an audit location.

Keep the deletion job separate from the identification flow. That separation gives HR an opportunity to review exceptions and gives IT a clear technical control boundary.

SharePoint

In Microsoft Purview, publish retention labels for the relevant HR sites and document libraries. Use event-based retention where the period should begin with an employment event, such as Employee Termination, rather than the upload date.

The event must be consistently recorded and associated with the correct employee or document set. Configure disposition review so that a named Records Manager receives the review, can confirm deletion, and can record a reason for extension. Don't rely on folder names to define retention. Folders change; labels, content types, and managed metadata provide stronger control.

Entra ID

Identity cleanup has a different purpose from HR record disposal. Use Entra ID lifecycle workflows to disable or remove guest accounts based on a defined trigger, and use separate access reviews to identify orphaned users, stale guest objects, and inappropriate access. Preserve identity and sign-in evidence only where the security or compliance purpose justifies it.

Alongside the configuration, maintain a deployment runbook, test plan, rollback approach, and exception register. Legal holds must be logged with scope, owner, start date, review date, and release decision.

The following visual shows the type of Power Automate configuration used to connect retention logic with Microsoft 365 controls.

Screenshot from https://docs.microsoft.com/en-us/microsoft-365/compliance/retention?view=o365-worldwide

Test with representative records, including a normal leaver, a missing termination date, a record under legal hold, a duplicate document, and a failed deletion action. Evidence of a successful flow matters, but evidence of how exceptions were handled matters just as much.

Sample Retention Matrix for Core HR Record Categories

A matrix gives HR, IT, legal, and the DPO one shared view of what should happen. It must remain a controlled starting point, not an automatic legal answer. The ICO does not prescribe one fixed timetable for UK employers, so validate each period against the relevant statutory requirement, business purpose, legal advice, and current guidance.

Record Category Lawful Basis Retention Trigger Retention Window End-of-Life Action
Recruitment applications Legitimate interests Recruitment exercise closes Approved recruitment period Delete application data, unless a separate future-opportunity basis applies
Interview notes Legitimate interests Recruitment exercise closes Same approved recruitment period as the application Secure deletion
Right-to-work evidence Legal obligation Employment ends or compliance purpose ends Period approved for immigration compliance Delete securely, unless another documented obligation applies
Employee personnel files Contract and legitimate interests Employment ends Defined post-employment period Review, then delete or anonymise
Payroll and pension records Legal obligation and contract Relevant employment or reporting cycle ends Statutory or business period approved for the record type Delete or archive under restricted access
Performance and disciplinary files Contract, legitimate interests, or legal claims defence Employment ends or matter closes Defined employment and claims-related period Delete, anonymise, or retain under a specific hold
Absence and occupational health notes Contract, legal obligation, or legitimate interests Employment ends or case closes Narrow period tied to the health or employment purpose Secure deletion with restricted access
Training records Contract or legitimate interests Employment ends or qualification relevance ends Defined operational or compliance period Delete or retain anonymised learning data
Leaver data Contract, legal claims defence, or legal obligation Date of Leaving Approved post-termination period Delete from Dataverse, SharePoint, exports, and connected stores

The matrix must account for platform differences. A SharePoint document may require a retention label and disposition review, while a Dataverse row may require a status change followed by a controlled bulk-delete job. Payroll exports may sit outside the HR platform and need a separate owner and disposal process.

Avoid the blanket employee-file rule

“Keep the whole personnel file for the same period” is convenient and usually wrong. Right-to-work evidence, sickness information, payroll records, training history, and disciplinary material serve different purposes and carry different risks.

Mark each category as active, pending disposal, under hold, archived, or deleted. Review the matrix annually against ICO guidance and relevant case law developments. HR, legal, IT, and the DPO should approve changes together, because a technically neat schedule can still fail if it ignores employment claims, tax administration, pensions, or immigration requirements.

Rolling Out Retention, Producing Audit Trails, and What to Do Next

A retention rollout should start with evidence, not configuration. Inventory the HR data estate across Dataverse, SharePoint, Teams, Exchange, Entra ID, payroll, finance exports, archives, and known third-party processors. Record the owner, purpose, lawful basis, data category, access route, and current disposal method for each location.

Use a controlled rollout sequence

  1. Baseline the estate: Find duplicate records, unlabelled sites, shared mailbox content, stale identity objects, and exports outside the HR platform.
  2. Secure DPO and legal approval: Approve the matrix, document exceptions, and confirm which periods derive from statutory obligations or claims risk.
  3. Pilot one HR workstream: Start with a contained process such as recruitment or leaver administration.
  4. Enable labels and jobs: Publish SharePoint labels, activate Dataverse flows and bulk-delete controls, and configure identity lifecycle workflows.
  5. Operate the audit trail: Review exceptions, record outcomes, test failures, and reassess the schedule on the agreed cadence.

A five-step infographic detailing the process for implementing a data retention rollout and audit strategy.

An ICO enquiry will expect more than a policy document. Keep the approved retention schedule, relevant DPIA extracts, deletion job logs, SharePoint label reports, Dataverse bulk-delete history, Entra ID access and sign-in retention evidence, legal-hold records, and proof of how Subject Access Requests and other data rights were handled.

Audit standard: A reviewer should be able to select a record category and trace its purpose, lawful basis, retention trigger, approval, disposal action, and exception history.

Review exceptions quarterly. Reassess the complete schedule annually and whenever a regulator requirement, business process, contract, or system architecture changes. The ICO's guidance requires regular review and notes that records should be erased or anonymised when no longer needed. If deletion isn't technically possible, restrict access, move the records out of ordinary use, and treat the failure as an incident requiring remediation.

The common failures are familiar: orphaned CVs in shared mailboxes, SharePoint sites without labels, leaver records retained without a documented reason, and identity objects left active after access should have ended. A Microsoft-centric organisation can address these issues without replacing every platform, provided it connects policy, metadata, workflows, permissions, and evidence.

This video provides additional practical context for building retention controls into Microsoft environments.

For teams implementing this across Dynamics 365 and Microsoft 365, audit logs and retention evidence should be designed into the solution rather than assembled after an incident. DynamicsHub works with organisations to configure HR retention controls across Dataverse, SharePoint, Power Platform, and Entra ID, with the schedule and exception process built around the client's operating model. Hubdrive's HR Management for Microsoft Dynamics 365 supports a hire-to-retire approach on Dataverse, while DynamicsHub delivers the implementation, customisation, and ongoing optimisation for UK organisations.


DynamicsHub can assess your HR data estate, create a practical retention matrix, and configure enforceable controls across Microsoft Dynamics 365, Dataverse, SharePoint, and Entra ID. Experience HR transformation built around your business. Contact DynamicsHub by calling 01522 508096 today, or send us a message to discuss your GDPR data retention requirements.

author avatar
Chris Pickles Director / Dynamics 365 and Power Platform Architect & Consultant
Chris Pickles is a Dynamics 365 specialist and digital transformation leader with a passion for turning complex business challenges into practical, high-impact solutions. As Founder of F1Group and DynamicsHub, he works with organisations across the UK and internationally to unlock the full potential of Dynamics 365 Customer Engagement, HR solutions, and the Microsoft Power Platform. With decades of experience in Microsoft technologies, Chris combines strategic thinking with hands-on delivery. He designs and implements systems that don’t just function well technically — they empower people, streamline processes, and drive measurable performance improvements. Known for his straightforward, people-first approach, Chris challenges conventional thinking and focuses on outcomes over features. Whether modernising customer engagement, transforming HR operations, or automating processes with Power Platform, his goal is simple: build solutions that create clarity, capability, and competitive advantage.

Related Posts

© 2026, DynamicsHub, AllRights Reserved