Data retention schedule
FourWinds Digital · Version 1.0 · 20 August 2026 Owner: Oscar Cobbe · Review due: 20 August 2027
1. What this has to do
Article 5(1)(e) requires personal data to be kept in identifiable form no longer than necessary. Article 13(2)(a) requires the period, or the criteria for it, to be disclosed at collection. Article 30(1)(f) requires the envisaged time limits in the record of processing.
A schedule only works if every line carries four things:
- The category, narrow enough to act on.
- The period, or the trigger: "six years from the end of the financial year", never "as long as necessary".
- The justification: a statute, a limitation period, or a written business reason.
- The disposal action, and evidence it happened.
The trigger event is the column most schedules omit, and it is what makes this executable rather than decorative.
2. The schedule
Tax and financial
| Record | Keep for | From | Source |
|---|---|---|---|
| Income tax, corporation tax, CGT records | 6 years | Completion of the transactions | Taxes Consolidation Act 1997, s.886(4)(a)(i) |
| The same where the return was filed late | 6 years | End of the period in which the return was delivered | TCA 1997, s.886(4)(a)(ii) |
| VAT records, invoices, credit and debit notes | 6 years | Date of the latest transaction they relate to | VAT Consolidation Act 2010, s.84(3) |
| VAT on capital goods or immovable property | Interest + 6 years | End of the taxable interest | VATCA 2010, s.84(4)(a) |
| Payroll, PAYE, PRSI, USC | 6 years | End of the tax year | TCA 1997 s.886 and the PAYE regulations |
Company records
| Record | Keep for | From | Source |
|---|---|---|---|
| Accounting records | At least 6 years | End of the financial year containing the latest date the record relates to | Companies Act 2014, s.285 |
| Statutory registers and minutes | Life of the company | No trigger, kept for the life of the company | Companies Act 2014, Part 4 |
Dormant until incorporation, then live. Listed now so nothing is missed on the day the company is formed.
Employment
| Record | Keep for | From | Source |
|---|---|---|---|
| Working time: hours, rest, leave | At least 3 years | Date of making | Organisation of Working Time Act 1997, s.25(1) |
| Minimum wage records | At least 3 years | Date of making | National Minimum Wage Act 2000, s.22(1) |
| Written statement of terms | Employment + 1 year | End of employment | Terms of Employment (Information) Act 1994, s.3(5) |
| Parental and force majeure leave | 8 years | Date of the leave | Parental Leave Act 1998, s.27(2) |
| Notices under the Parental Leave Act | 1 year | Date of the notice | Parental Leave Act 1998, s.27(3) |
| Unsuccessful job applicants | 13 months | Date of the decision | Workplace Relations Act 2015, s.41(6) and (8), 6 months extendable to 12 |
Under-retaining the first two loses cases. Both the Organisation of Working Time Act s.25(4) and the National Minimum Wage Act s.22(3) reverse the burden of proof: if the records were not kept, the employer must prove compliance. That is an evidential trap, not a filing one.
The 13-month figure for applicants is derived from the limitation period, not from a statutory retention rule, and is labelled as such.
Health and safety
| Record | Keep for | From | Source |
|---|---|---|---|
| Reportable accidents and dangerous occurrences | 10 years | Date of the accident | SI 370/2016, Regulation 226(1) |
Dormant with no employees. Live from the first hire.
Client work
| Record | Keep for | From | Source |
|---|---|---|---|
| Contracts, statements of work, project correspondence | 6 years | End of the contract, not signature | Statute of Limitations 1957, s.11(1)(a) |
| Anything executed as a deed | 12 years | End of the contract | Statute of Limitations 1957, s.11(5)(a) |
| Tort claims generally | 6 years | Accrual | Statute of Limitations 1957, s.11(2)(a) |
| Personal injury | 2 years | Accrual | Civil Liability and Courts Act 2004, s.7 |
One deed silently doubles the retention obligation on that agreement. It is the most common error in schedules of this kind, so any agreement executed under seal is tagged at the point of signing rather than discovered later.
Marketing and enquiries
No Irish statute sets a period for a sales enquiry. Ours is built from the only hard number in Irish electronic marketing law.
| Record | Keep for | From | Reason |
|---|---|---|---|
| Marketing list entry | 12 months | Last purchase or last engagement, then re-permission or delete | SI 336/2011, Regulation 13(11)(d) |
| Consent evidence: timestamp, source, wording | Duration of marketing + 3 years | Last message | DPA 2018 s.147(2), the prosecution window |
| Unsubscribe suppression records | Indefinitely | No trigger, never deleted | Deleting one so that we re-market to that person is itself the offence |
| Enquiry that never became a client | 6 months | Last meaningful contact | Purpose ceases when the conversation is over |
Anything held beyond 12 months requires a written legitimate interests assessment, not a preference. No row here says "indefinitely" except the suppression list, and that one says it deliberately.
CCTV
We operate no CCTV. Recorded explicitly rather than omitted, because an auditor reads absence as oversight.
If that changes: 28 to 30 days is industry practice, not DPC guidance and not statute. The DPC's published position is only that recordings should be kept no longer than necessary for the original purpose. Any period we adopt carries a written justification, automatic overwrite at expiry, signage meeting Articles 13 and 14, and a logged extraction process for incident footage.
3. Data we hold as a processor
The period is set by the client, not by us. At the end of an engagement we delete or return everything at the client's choice, and delete our copies, under Article 28(3)(g).
Three things go wrong here and each is addressed by name:
- Backups. Deleting from a live database does not delete from backups. Our backups purge on a 35-day cycle, so deletion is complete at live-delete plus 35 days. Clients are told this in the agreement rather than discovering it later.
- Third-party systems. Deletion is pushed to Supabase, Vercel logs, Stripe, analytics, email and any AI vendor retention window. A deletion that only touches the primary database is not a deletion.
- Evidence. We issue a written deletion certificate, dated, listing the systems covered. That certificate is itself a record and is kept for six years, in line with the contract limitation period.
4. Deleting rather than anonymising
We delete by default.
Anonymisation is attractive for analytics and is harder than it looks. The DPC's position is that pseudonymised data remains personal data, and that if the source data is not deleted at the same moment the anonymised set is created, the anonymisation may be ineffective. Keeping the key defeats the exercise.
The standard is also moving: a September 2025 CJEU decision adopted a relative approach to whether pseudonymised data is personal, and the EDPB's draft anonymisation guidelines follow it. Those guidelines are in consultation until 30 October 2026 and are not settled.
Where we do anonymise instead of delete, we document the technique, document the re-identification risk, delete the source and any key at the same moment, and mark the row for review when those guidelines are final.
5. Disposal and review
Disposal is secure, covers physical and digital formats, and includes end-of-life hardware: drives, laptops and phones.
A retention review runs annually and is minuted. The minute is the evidence, and it is the first thing asked for after the schedule itself. An auditor tests this document against a live database export, not against the document.
Next review: 20 August 2027.