How Long Should Health & Safety Records Be Kept in the UK?
One of the most common problems with compliance records isn’t losing them.
It’s keeping everything forever.
Businesses can accumulate years of training certificates, assessments, employee information, inspection records and old versions of documents without having a clear rule for when anything should be reviewed, archived or deleted.
Unfortunately, there isn’t one universal retention period that applies to every health and safety document.
There is no single “keep everything for X years” rule
Different records can be subject to different statutory requirements, business needs and data-protection considerations.
The ICO specifically states that data-protection law does not prescribe one fixed period for retaining workers’ personal information. Organisations need to determine how long information is necessary for its purpose while taking account of applicable legal and regulatory requirements.
That makes a documented retention schedule far more useful than applying an arbitrary period to everything.
Start by identifying what you’re holding
Create a register of the major record categories your organisation maintains.
For example:
- risk assessments;
- training records;
- accident and incident documentation;
- inspection records;
- maintenance certificates;
- employee health and safety information;
- policies and procedures;
- contractor documentation; and
- audit records.
Then determine why each record is retained.
Separate legal requirements from business preference
Some records may be subject to specific statutory retention requirements.
Others may need to be retained because they provide evidence of previous decisions, training, inspections or actions.
And some records may no longer serve a meaningful purpose at all.
Don’t assume that because one H&S record needs a particular retention period, every other compliance record should be kept for the same length of time.
Don’t forget data protection
Health and safety administration frequently involves personal information.
Training records, accident information and employee-related records can all contain personal data.
The ICO’s storage-limitation principle requires organisations not to keep personal information for longer than necessary. Organisations should be able to justify retention periods and periodically review information, deleting or anonymising it when it is no longer needed.
“Keep everything just in case” is therefore not a good records-management strategy.
Build a retention schedule
A useful retention schedule might contain:
Record category | Purpose | Owner | Retention requirement | Review date | Disposal action
The ICO recommends that retention schedules identify the categories of information held, their purpose and intended retention periods.
Once established, the schedule should itself be reviewed periodically.
Version control is different from retention
A common mistake is confusing an obsolete document with a document that should immediately be destroyed.
When a policy is replaced, for example, you need a method of distinguishing the current approved version from previous versions.
Your document-control system might therefore mark something as:
Current → Superseded → Archived → Due for disposal
according to your organisation’s requirements.
Make disposal part of the system
Good records management covers the entire document lifecycle.
Creating documents is only the beginning.
A controlled system considers:
Creation → Approval → Use → Review → Superseding → Retention → Disposal
That prevents digital filing systems becoming permanent dumping grounds.
How Blackcrest Compliance can help
Blackcrest can help businesses establish and administer document registers, review schedules and structured record-management systems.
We don’t decide statutory retention requirements on behalf of clients where specialist advice is required. Instead, we help turn your agreed requirements into an organised administrative system that is easier to maintain.
If your compliance folders have become difficult to control, explore Blackcrest’s compliance administration services.
