Governance and Compliance

Record Retention

Two forces pull in opposite directions. **Tax law requires seven years**, and corporate records are needed permanently. **Data protection requires personal data not be kept longer than necessary.** A retention schedule is where those are reconciled — and "keep everything forever" fails the second one.

Download as Word6 pages24 KBFree
[HEADER — replace with your organisation’s letterhead, if used]

Record Retention

What to keep, for how long, and what to delete

Two forces pull in opposite directions. Tax law requires seven years, and corporate records are needed permanently. Data protection requires personal data not be kept longer than necessary. A retention schedule is where those are reconciled — and "keep everything forever" fails the second one.

ItemDetail
Organisation[COMPANY NAME], [licence] [NUMBER]
Data protection regime[Federal PDPL / DIFC / ADGM]
Owner of this schedule[NAME], [DESIGNATION]
Tax retention baselineSeven years from the end of the tax period
Storage — physical[LOCATION]
Storage — digital[SYSTEM]
Deletion carried out[Annually, in ______]
Last review[DATE]

1. The Two Rules

RuleEffect
Keep it long enoughCorporate tax and VAT require seven years from the end of the relevant tax period. Corporate records are needed permanently. Employment and litigation records are needed while a claim is possible
Do not keep it too longPersonal data must not be retained beyond what is necessary. Indefinite retention breaches storage limitation and expands what must be protected in a breach
Where they conflictA legal obligation to retain generally prevails over an erasure request — but only for the data actually required, and only for as long as required

1.1"We keep everything" is not a policy. It fails storage limitation, it makes subject access requests expensive, and it means a breach exposes a decade of data instead of a year of it.

1.2Seven years runs from the end of the tax period, not from the transaction. An invoice from early in a financial year is retained for nearly eight years in practice.

Generated from www.helionerp.com1

5 more pages in the Word file

This is page 1 of the Word document, exactly as it appears when you open it. Fields shown like THIS are placeholders for you to complete.

Notes for use

These notes accompany the template and explain the drafting choices, the compliance points and the mistakes most often made with this document. They appear as a final page in the Word file, intended to be deleted before the document is executed.

Seven years runs from the end of the tax period

Not from the transaction date and not from the filing date. An invoice raised early in a financial year is effectively retained for close to eight years. Build the rule into the schedule rather than recalculating per document.

Keeping everything is not a policy

It fails the storage limitation obligation, makes subject access requests expensive to answer, and means a breach exposes a decade of personal data rather than a year. The schedule exists to make deletion deliberate.

Minimise health data specifically

Medical fitness results, insurance claims and sick leave certificates are sensitive category data held on every employee. Retain for a shorter period than the general personnel file, restrict access tightly, and delete on schedule.

Delete unsuccessful applicant records early

CVs, references and interview notes have no continuing purpose once the role is filled. Retaining them for years expands the data you must protect for no benefit and is among the easiest deletions to actually execute.

A legal hold overrides the schedule

Where litigation, an investigation, an audit or a regulator query is live or reasonably anticipated, suspend deletion for the affected records and record the decision. Deleting into a live dispute is a serious problem.

Be honest about backups

Backups cannot be selectively purged, so data persists for the rotation period after deletion from live systems. The policy should say so and confirm the data remains protected while it does. A deletion clause ignoring backups is breached the day it is written.

Corporate records are permanent

The notarised MOA and every amendment, resolutions, share transfers and approvals are requested at every financing, sale and bank review. Companies reconstruct these painfully and incompletely years later, and gaps in the amendment chain are genuinely hard to remedy.

Track cheques until they are returned

A post-dated or security cheque is a live liability until recovered, regardless of how old the underlying transaction is. Retain the log until every cheque is back and confirmed, then for a further period.

Keep QFZP evidence for the full period

Qualifying income analysis, de minimis workings and substance evidence support a position that may be examined years later. This is the material most likely to be discarded as working papers and most needed if the claim is tested.

Retain the breach register including non-notifiable incidents

The record of incidents assessed and determined not notifiable is what demonstrates the assessments were actually made. Organisations log notified breaches and keep nothing about the rest.

Your processors’ retention is your responsibility

Payroll bureaux, HR platforms and cloud providers hold your data on your instructions. Deletion instructions must reach them on the same schedule, and the processing agreement should require it.

Leavers’ mailboxes are the common failure

Kept indefinitely "just in case", they contain years of personal data about the leaver and everyone they corresponded with. Set a period, extract what is genuinely needed as a business record, and delete the rest.

Look beyond the main systems

Exports on individual laptops, spreadsheets on shared drives, data in personal cloud accounts and devices held by former employees all sit outside whatever the HR system does. Section 4 exists because that is where retention policies quietly fail.

Record what you deleted

Evidence that the schedule is operated is as important as the schedule itself. A log of deletion runs, what they covered and who authorised them is what demonstrates the obligation is met.

Current as of

Reflects UAE requirements current as of {{DATE OF USE}}. Tax retention periods, employment record requirements, AML retention for designated businesses and data protection storage limitation rules all change, and DIFC and ADGM apply their own regimes — confirm periods with the Federal Tax Authority, MOHRE and the relevant data protection regulator before finalising this schedule.

This is a ready-to-use template provided for convenience. Laws and requirements change, and every situation is different — please have it reviewed by a qualified professional (a lawyer, corporate secretary, or accountant as relevant) before you rely on it.