A disagreement resurfaces with a supplier over an order placed in 2019. Your solicitor asks for the email exchange in which the delivery date was renegotiated. You open Outlook, you search, and there it is: dated, complete, attachment included. Good news for the day.
Three months later, a candidate you did not hire writes to ask what you still hold about them. You open the same mailbox, you type their name, and there it all is: the CV, the exchange with two managers, an internal note written after the interview. A recruitment file closed in 2019, still fully present in 2026, without anyone ever having decided that it should be. Bad news for the day.
Same mailbox, same absence of a rule, two opposite outcomes. Keeping things for a long time protects you in one case and exposes you in the other. That is exactly why how long to keep business emails is never decided for the mailbox as a whole: it is decided category by category.
Quick answer: there is no single figure. How long to keep business emails is decided by category of document, under two opposing logics. On the record keeping side, the Companies Act 2006 requires a private company to preserve its accounting records for three years from the date they are made, and HMRC guidance tells a limited company to keep its records for six years from the end of the last company financial year they relate to. On the personal data side, the ICO publishes no general figure: the UK GDPR storage limitation principle says personal data must not be kept for longer than you need it, and asks you to justify and document the period you set.
What this article is, and what it is not. It describes the framework that applies in the United Kingdom, and only there: every figure quoted below comes from a UK provision or from UK published guidance, and none of them should be transposed to the United States, to Ireland, to Australia or to any other jurisdiction. It informs on what named, linked UK sources actually say, and on what you can do with that inside an Outlook mailbox. It does not give legal advice, it promises no compliance and it replaces nobody. No retention period is stated here without the text or the published guidance that carries it: where none exists, the article says so and refers you to your adviser. For a regulated activity, a live dispute or a specific situation, speak to your solicitor and your accountant.
🎯 Key takeaways
- There is no single figure: the period is decided per document category, never for the mailbox as a whole
- Three years for a private company and six years for a public one, from the date the accounting records are made, under the Companies Act 2006, section 388(4)
- Six years from the end of the last company financial year they relate to, for a limited company's records, under the HMRC guidance already cited in this article
- The Limitation Act 1980, section 5 six-year window is a limitation period, not a retention obligation: it says how long an action can still be brought, it orders you to keep nothing
- The ICO sets no fixed period: the matrix is filled in once, with your accountant for the tax and accounting lines and your solicitor for anything unusual, and the reason is written next to each line
- How long should you keep business emails?
- Two opposing logics, and nobody separates them
- The record keeping logic: what the UK rules actually require
- The opposite logic: personal data is not kept without a reason
- The matrix by document type
- The three lifecycle phases, brought down into Outlook
- Keeping everything forever is a risk, just like deleting too soon
- What deleting an email really means
- Who decides the period in a business with no data protection officer
- The leaver's mailbox: the question the other article left open
- Writing your rule: one page, six lines, a review date
- What an email assistant does, and does not do, with your old emails
- This article describes the UK framework
- Further reading
- FAQ: seven questions on email retention
How long should you keep business emails?
There is no single retention period for a business email. The period is decided by category of document. Some categories are governed by named record keeping rules, from the Companies Act and from HMRC. The rest follow the purpose you are keeping them for, and that purpose has an end.
That answer disappoints, because it does not fit into one number. It is also the only one that survives contact with a real mailbox. An inbox is not a homogeneous object: it holds, in the same folder, a supplier invoice, a contract negotiation, a speculative job application and an invitation to a webinar. Those four things have nothing in common when it comes to how long they should live. Treat them with a single rule and you get one of two outcomes: a mailbox that keeps everything as a precaution, or a mailbox that gets purged the day it runs out of space. Two bad decisions, taken without noticing.
So the useful question is not how long do I keep my emails. It is: which category does this message belong to, and what governs its life. The rest of this article answers in that order. First the two logics that pull against each other, then what the UK sources actually say, then the matrix by category, then the translation into a real Outlook mailbox.
Two opposing logics, and nobody separates them
Pages on this subject fall into one of two camps. On one side, tables of statutory retention periods, accurate but abstract, which talk about documents and never about a mailbox. On the other, archiving pitches, which explain that you should keep everything. The two families do not contradict each other by accident. They answer two different logics, and neither of them says so.
First logic: the record and the proof. An email is a written document. It carries a commitment, an order, a reservation expressed, a date agreed. The day a disagreement surfaces, that message is worth exactly what its preservation is worth. This logic pushes in one direction only: keep, keep for a long time, and keep intact. It is the logic of company record keeping, of tax record keeping and of limitation periods.
Second logic: personal data. That same email contains names, addresses, sometimes opinions about people. It is a processing of personal data, and processing is not kept indefinitely: it is kept for as long as it is needed for the purpose. This logic pushes in the exact opposite direction: erase when the reason for keeping has gone.
The point nobody writes down. Keeping everything forever is not the cautious position. It is a decision that exposes you, in the same way that deleting too early exposes you. The risk simply has a different shape: on one side, being unable to prove; on the other, holding data that nothing justifies holding any more. A business that has never decided is exposed to both at once.
These two logics do not reconcile through a number. They reconcile through sorting: category by category, you look at which of the two governs, and for how long. That is exactly what the matrix further down does.
The record keeping logic: what the UK rules actually require
Start with what is written down, because it is the floor of the whole exercise, and because these are the only figures this article will assert. There is no single UK law that says how long to keep an email. There are record keeping obligations that attach to what an email is or to what it carries, and they come from two different places.
The Companies Act 2006, and a figure lower than most people expect
Section 386 of the Companies Act 2006 places a duty on every company to keep adequate accounting records. Section 388 then deals with how long they last. Section 388(4) provides that accounting records that a company is required by section 386 to keep must be preserved for three years from the date on which they are made in the case of a private company, and six years from the date on which they are made in the case of a public company. The provision is set out on legislation.gov.uk, Companies Act 2006, section 388.
Three years, for a private company, from the date the record is made. Read on before you build anything on that number, because it is not the one that governs your day to day life.
HMRC record keeping, and the figures that actually bite
HMRC record keeping periods are separate obligations, and they run longer. GOV.UK guidance for a limited company states that you must keep records for six years from the end of the last company financial year they relate to, and longer in three named situations: where a transaction covers more than one of the company's accounting periods, where the company has bought something it expects to last more than six years such as equipment or machinery, and where the return was sent in late or is subject to a compliance check.
Four HMRC periods matter to a business of five to fifty people, and they are not the same.
- Limited company records: six years from the end of the last company financial year they relate to, per GOV.UK, Running a limited company: company and accounting records.
- VAT records: at least six years, or ten years if you use the VAT One Stop Shop scheme or used the VAT Mini One Stop Shop scheme, per GOV.UK, Charge, reclaim and record VAT: keeping VAT records.
- Self employed business records: at least five years after the 31 January submission deadline of the relevant tax year, per GOV.UK, Business records if you are self employed.
- PAYE and payroll records: three years from the end of the tax year they relate to, per GOV.UK, PAYE and payroll for employers: keeping records.
The two numbers that trip people up. The Companies Act preservation period for a private company's accounting records is three years from the date they are made. The HMRC period for a limited company's records is six years from the end of the last company financial year they relate to. They are not the same obligation, they do not start on the same day, and it is the longer one that decides what you can safely let go of. Write both into your rule, with the source next to each, and stop arguing about which one is the real one.
Take the reasoning rather than the figure. It is not the email that is targeted, it is what the email is or what it carries. A message saying "please find attached our invoice 2026-0412" is not an ordinary email, it is the vehicle of an accounting record. The distinction sounds academic. It is the heart of the method: you are not classifying emails, you are classifying what they contain.
Limitation periods are not retention obligations
This is the most widespread confusion on the subject, and it is worth clearing properly, because it produces recommendations that look reasonable and are not.
Section 5 of the Limitation Act 1980 provides that an action founded on simple contract shall not be brought after the expiration of six years from the date on which the cause of action accrued. That provision does not order you to keep anything at all. It tells you how long an action can still be brought.
The difference changes the nature of the decision. On accounting and tax records, the period is imposed on you and you comply with it. On commercial exchanges, you are the one arbitrating, and the date on which a cause of action accrued is a technical question that only your solicitor can settle in your situation. Anyone who tells you that a limitation period is a retention obligation has skipped that step.
Does an email hold up as evidence?
Documents are not disqualified in civil proceedings because they happen to be electronic. Two provisions of the Civil Evidence Act 1995 are worth knowing about. Section 8(1) provides that where a statement contained in a document is admissible as evidence in civil proceedings, it may be proved in either of two ways: by the production of that document, or, whether or not that document is still in existence, by the production of a copy of that document or of the material part of it, authenticated in such manner as the court may approve. The two routes stand side by side, and the second one exists precisely so that the disappearance of the original does not close the door. Section 9 provides that a document shown to form part of the records of a business may be received in evidence in civil proceedings without further proof, and that a document is taken to form part of those records if a certificate to that effect signed by an officer of the business is produced to the court.
That distinction is not academic when the document is an email. Producing "that document" means producing the message as it exists in the mail environment, with its headers and its date, not a screenshot pasted into a Word file. The authenticated copy route is the one that catches everything else, and it is the court that decides what manner of authentication it approves. Which is another way of saying that the quality of your filing decides which of the two routes stays open to you.
Read section 9 slowly, because the operative words are "the records of a business". The practical question is not whether an email can be evidence. It is whether the message you would produce can be shown to be part of the records of the business. A message sitting in one person's inbox, which that person can move, edit or delete at will, is not the most convincing candidate for that description, and how a specific document would be treated is a matter for your solicitor rather than for an article.
The operational conclusion is blunt enough to be useful, and it has nothing to do with law: whatever might have to serve as proof within the six-year limitation window of section 5 of the Limitation Act 1980 has no business living in an inbox. It belongs in the company records, where it is identified, backed up and findable by somebody other than its original recipient.
The opposite logic: personal data is not kept without a reason
We do not re-explain UK GDPR here, it is covered in our guide AI email and GDPR: the 2026 compliance guide. One point only concerns us on this page: what the ICO says about duration.
The ICO guidance on Principle (e): storage limitation states that UK GDPR does not set specific time limits for different types of data, that this is up to you and depends on how long you need the data for your specified purposes, and that personal data should be kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which it is processed. It adds two things that matter more than any table: data should not be retained on a just in case basis, and, to comply with the accountability principle, you need a policy that sets your retention periods.
That absence of a number is not a gap in the guidance. It is the rule itself, and it tells you two things. The first: nobody is going to hand you the retention period for your prospecting emails, because it depends on what you do with them. The second, less comfortable: the decision is yours, and not taking it is still a decision. The ICO puts the onus on you to consider why you need to retain personal data and to be able to justify it.
The sentence to use as a test. For each category of message, ask the question in this direction: what am I keeping this for, and until when does that reason hold? If you cannot answer in one sentence, the purpose has expired. A recruitment file closed without an offer seven years ago has no answer to that question. A 2021 supplier invoice does, and the answer is written in the HMRC guidance.
The matrix by document type
Here is the table that replaces the impossible question, how long do I keep my emails, with a series of questions you can actually answer. It reads line by line, and it is filled in once with your accountant and your solicitor. The right hand column is the one that matters most: it says where the message should live, not just how long it lives.
| Type of content | Governing logic | What the source says | Where it should live |
|---|---|---|---|
| Accounting record (invoice received or issued, expense claim, statement, supporting document) | Record keeping | Companies Act 2006, s.388(4): preserved three years from the date made for a private company, six for a public company. HMRC, for a limited company: six years from the end of the last company financial year they relate to | Out of the mailbox, in the company accounting records. The mailbox is only the delivery pipe |
| VAT record received or issued by email | Record keeping | GOV.UK, keeping VAT records: at least six years, or ten years under the VAT One Stop Shop or the former Mini One Stop Shop | In the accounting system, not in an individual mailbox |
| Sole trader business records arriving by email | Record keeping | GOV.UK, business records if you are self employed: at least five years after the 31 January submission deadline of the relevant tax year | In the business records, filed by tax year |
| PAYE and payroll records | Record keeping | GOV.UK, PAYE and payroll for employers: three years from the end of the tax year they relate to | In the payroll file, never in a manager's mailbox |
| Contract and commercial exchanges (accepted quote, negotiated terms, reservation expressed, agreed delivery date) | Evidence | No general retention obligation identified in the sources cited here. Limitation reference: six years for an action founded on simple contract, Limitation Act 1980, s.5, running from the date the cause of action accrued | Filed into the client or matter folder, with the rest of the file |
| Prospects and non client contacts | Personal data | No figure in the sources cited here. The ICO leaves the period to you, tied to the purpose, and asks you to record it in a policy | In the CRM, with a written period. Not in a mailbox with no end date |
| Applications and recruitment files (CVs, interviews, opinions) | Personal data | No figure in the sources cited here. Period to be set against the purpose, written down, and made known to candidates | In a dedicated folder with restricted access, with a purge date recorded on arrival |
| Emails about the employment relationship | Both, depending on content | The payroll part carries the HMRC period above. Beyond that, no figure is asserted here: employment law has its own rules and this category is settled with your solicitor and your payroll provider | In the employee file, never in a manager's mailbox |
| Day to day organisation (meetings, logistics, internal exchanges with nothing at stake) | Personal data | No obligation identified. The purpose expires within a few weeks | Active base, then deletion. This is the volume that leaves fastest and lightens everything else |
| Newsletters, notifications, automated alerts | None | No evidential value, no lasting purpose | Deletion, and preferably unsubscribing at source |
One remark on the right hand column, because it surprises people. For the first four rows, the right answer is not a period inside Outlook, it is an exit from Outlook. An invoice that has to live for six years should not live for six years in a mailbox. It should join the accounting records, where it is identified, backed up and findable by somebody other than the person who happened to receive it.
The three lifecycle phases, brought down into Outlook
The three phase model below is a working method, not a rule published by a UK authority, and it is presented as such. What is published is the requirement behind it: the ICO expects retention periods to be defined rather than left open, including for information you have archived or backed up, and expects deletion to be real rather than nominal. The three phases are simply the shape that requirement takes inside a mailbox.
| Phase | How you recognise it | Where in Outlook | Who may go in |
|---|---|---|---|
| Active base | Somebody is still acting on the file | Inbox and current working folders | The team, in the normal daily flow |
| Intermediate archive | Operationally finished, but a period is still running | A separate archive folder, an archive mailbox or a distinct storage location | Named people only, and only for a defined reason |
| Final archive or deletion | The period has run out, a decision is due | A document system outside the mail environment, or deletion including emptying deleted items | The person named in the rule as the owner of the gesture |
Phase 1, the active base: what is used day to day
In Outlook, this is your inbox and your current working folders. The membership test is simple and demanding: the file is alive, somebody is still acting on it. A message that calls for no action from anybody has no place there, whatever its future value.
The symptom of a badly kept active base is easy to spot: search becomes the only means of navigation. When nobody can find anything without going through the search bar, the active base has absorbed the other two phases. Our articles Piloting your inbox in 2026: the complete method and Optimize Your Email Inbox: 10 Methods to Stop Wasting Time deal with that part in detail.
Phase 2, the intermediate archive: no longer used, still has to be available
This is the phase small businesses skip, and it is the one that changes everything. A message can have no operational use left while still needing to be available, because a period is still running. It does not get deleted, but it has no business circulating in the daily flow either.
In Outlook that takes the form of a distinct space: an archive folder, an archive mailbox, a separate storage location. The important part is not the tool, it is the access regime. Archived messages are not open to everybody, and you only go in there for a defined reason. That restriction is what makes an archive an archive rather than a second inbox.
Three questions for your IT provider. Where are the mail archives physically stored? Who has access, by name? What happens when the machine belonging to the person concerned is replaced? An archive that lives in a local data file on one computer is not an archive. It is a single point of failure with an unknown expiry date.
Phase 3, the final archive or deletion
At the end of the period there are two outcomes, and you have to choose one explicitly. Either the document has a value that justifies long term preservation, in which case it joins a document system built for that, outside the mail environment. Or nothing justifies its presence any more, and it is deleted.
There is no third outcome. The apparent third outcome, leaving the message where it is because nobody knows, is the default state of most business mailboxes. It is not a phase of the lifecycle. It is the absence of a lifecycle.
Keeping everything forever is a risk, just like deleting too soon
This is the sentence pages on the subject do not write, because it contradicts the instinct of the owner and the pitch of the archiving vendor. It deserves to be demonstrated rather than asserted.
A mailbox that has kept everything for fifteen years produces four effects, none of them theoretical.
- It holds data that nothing justifies holding. The CV of a 2017 candidate, the personal contact details of a former contractor, a manager's written opinion about somebody who left long ago. The purpose has expired, the data is still there, and the ICO position on retaining data on a just in case basis is not ambiguous.
- It makes it hard to answer a request properly. The day somebody asks what you hold about them, you have to search fifteen years of unsorted messages with no idea what belongs to what. The sorting you did not do calmly, you will do under pressure, against a deadline.
- It enlarges the surface exposed in an incident. What no longer exists in a mailbox cannot be read by somebody who should not read it. That is the only reason this point appears here, and we do not turn it into an article: see CLOUD Act and professional email: the real risks in 2026 for the separate question of access to hosted data.
- It degrades the value of what actually matters. A mass of unsorted messages in which a few decisive exchanges are sleeping is an asset nobody can use. The day you go looking for those exchanges, you do not find them.
The opposite error is a brutal purge decided on a day of saturation, which destroys accounting records and newsletters with equal indifference. Both errors have the same cause: no categories. It is not volume that puts you in difficulty, it is undifferentiated volume.
That undifferentiated volume has a cost you can put a number on, and it is not a storage cost. It is the time your team spends every week digging through a mailbox that sorts nothing. Our savings calculator estimates, over a year and for your own headcount, what that time is worth to the business.
What deleting an email really means
A retention rule that does not come down to the actual gesture stays a Word document. Here is what deleting really covers, in the order things happen.
First stage: the message leaves the folder, it does not leave the mailbox. It moves to deleted items. At that point it is entirely readable, searchable and restorable. While a message is there, treat it as still being in your mailbox, because that is exactly what it is.
Second stage: the deleted items folder is emptied. The message becomes invisible in normal use. Depending on how your mail environment is configured, it may stay recoverable for a period set by your own settings and those of your provider. That window exists, it is configurable, and it is not the same everywhere. We deliberately quote no figure for it: that is a question for your IT provider, not something to assume from an article.
Third stage: the copies that live elsewhere. Your environment's backups, the local data files built up over the years on various machines, the export somebody made one day to help a colleague out. The ICO's material on disposal and deletion is direct on this: where personal data is deleted from a live system it should also be dealt with in the backups of that system, and where deletion is not technically possible you should at least put the data beyond use, which means not using it for any other purpose until the backup is replaced on a defined schedule.
And then there is the copy that escapes you entirely: the one sitting in your correspondent's mailbox. An email deleted at your end carries on existing at theirs. That changes nothing about your own rule, but it stops you telling yourself that deletion erases an exchange.
The practical consequence. A retention policy that says nothing about emptying deleted items and nothing about the fate of local data files is not applied, it is only written. Those two points are worth one line each in your rule, and one question to your IT provider at the moment you draft it.
Who decides the period in a business with no data protection officer
In a business of five to fifty people there is usually no data protection officer, no legal department and no internal IT person. So the question of who decides stays hanging, and that is precisely why nothing gets decided.
The answer is direct: you do. The ICO leaves the period to the organisation, tied to its purposes, and asks for it to be justified and set out in a policy. In a business of this size, that decision comes back to the owner. Nobody else will take it for you.
That does not mean taking it alone. The split that works fits into four lines.
- The owner arbitrates, settles the categories and signs the rule. They are the one accepting the risk, in either direction.
- The accountant covers the accounting and tax perimeter: which records, which start date, which format. This is the part where the periods are published, and the easiest to secure.
- The solicitor handles the specific cases: regulated activity, live dispute, long running contracts, employment law questions.
- The IT provider answers the implementation questions: where the archives are, who has access, what settings exist, what is technically possible in your environment.
An hour with the accountant and an hour with your solicitor is enough to fill in the matrix for an ordinary small business. This is not a project. It is a decision that has never been taken.
The leaver's mailbox: the question the other article left open
We published The work email account when an employee leaves: what to do, which describes the full sequence from the notice period to closing the account. That article says explicitly that it recommends no retention figure, and it does not deal with the evidential value of messages. That was not an oversight: neither question belongs to the leaving procedure, they belong to the category of the content. This page is the missing half.
The two articles fit together like this. The leaving procedure decides the fate of the account: when access is removed, who takes over, when the address is deleted. The matrix by category decides the fate of the messages: what joins the accounting records, what joins the client file, what goes into the intermediate archive, what gets deleted.
The consequence is clean. At the moment you close an account, the question is never how long do we keep the mailbox. It is what, inside this mailbox, belongs to a category that requires keeping it somewhere else. If that work has been done, closing destroys nothing, because nothing that mattered was still in the mailbox. On the filing mechanics that make those transfers possible without spending your days on them, see Automatic Email & Attachment Filing for Outlook: Complete 2026 Guide.
Writing your rule: one page, six lines, a review date
A retention policy that is useful in a small business fits on one page. Beyond that it will not be read, so it will not be applied. Here is the structure that works.
- The categories you keep, taken from the matrix and adapted to your activity. Five to eight lines, no more. A category nobody can recognise at a glance is one category too many.
- The period per category, with the source next to it where one exists. Where none exists, write the period you have decided and the reason in one sentence. A decided and reasoned period is worth infinitely more than no period at all.
- The destination: for each category, where the content lives. Accounting records, client file, restricted archive, deletion.
- The gesture and the owner: who does the transfer, at what moment, and who empties deleted items. A gesture with no name attached does not happen.
- The technical blind spots: the recovery window in your environment, the fate of local data files, the scope of backups. Three lines obtained from your IT provider.
- The review date: once a year, on a fixed date. A rule with no review date goes out of date in silence.
Date the document, sign it, and share it with the team. The value of a retention policy has nothing to do with its sophistication. It comes from the fact that it exists, that people know about it, and that it carries a date.
What an email assistant does, and does not do, with your old emails
Neston is an email assistant integrated with Outlook. It reads your messages to understand the context, files emails and attachments automatically into your folders, and prepares replies in your style that you read and approve before anything is sent. On the subject of this article it helps with one thing only, but that one thing is real: filing. The matrix above is worth nothing unless messages actually land in the right category, and that is precisely the work nobody has time to do by hand across the volume that arrives every day.
Now let us be explicit about what it is not, because this subject makes it necessary. Neston is not an archiving system with evidential status, and it keeps nothing on your business's behalf. It is not a digital safe, it does not guarantee the integrity of a document, and it does not stand in for any record keeping obligation. Your emails stay in your own mail environment, under your responsibility and your provider's. Neston decides no retention period, deletes nothing on its own initiative, and replaces neither your accountant nor your solicitor. It is not a security product either.
What it does, it does under human validation: nothing is sent, and nothing is filed for good, without you having seen it. Neston works today with Outlook on Windows 10 and 11. Gmail support is announced and is not available yet. On hosting and data processing, we deal with the question separately in France-hosted AI email assistant: the 2026 guide.
Neston files what needs filing.
The assistant plugs into Outlook, files your emails and attachments into your folders, and prepares your replies, which you read and approve before they are sent.
Discover Neston →Windows 10/11 · Outlook · Optional Mistral EU
This article describes the UK framework
Everything above rests on UK material: provisions published on legislation.gov.uk, HMRC guidance published on GOV.UK, and guidance from the Information Commissioner's Office. It describes the framework that applies in the United Kingdom and no other. The fact that a page is written in English says nothing about which law governs your mailbox.
So do not transpose the figures. The Companies Act preservation period, the HMRC periods, the six year limitation reference under the Limitation Act 1980 and the two routes of the Civil Evidence Act 1995 are British rules. They have no equivalence, term for term, in the United States, in Ireland, in Australia, in Canada or anywhere else. A business established outside the United Kingdom that applies this table as it stands is applying the wrong numbers with full confidence, which is worse than applying none.
The method, on the other hand, travels without difficulty: decide by category rather than for the mailbox as a whole, separate the active base from the intermediate archive, take out of the mail environment whatever has to live a long time, write the rule on one page and put a date on it. Those are management gestures, not rules of law. If your business sits outside the United Kingdom, keep the method, replace every figure, and check the legal side with your own data protection authority and your local advisers before you apply anything.
Further reading
- The work email account when an employee leaves: what to do, the full sequence from the notice period to closing the account, which this article completes on the question of periods
- Automatic Email & Attachment Filing for Outlook: Complete 2026 Guide, how messages and attachments reach the right category without manual work
- Piloting your inbox in 2026: the complete method, the working frame that keeps an active base genuinely active
- Optimize Your Email Inbox: 10 Methods to Stop Wasting Time, the organising techniques that hold up over time
- AI email and GDPR: the 2026 compliance guide, the data protection frame when software reads your emails
- CLOUD Act and professional email: the real risks in 2026, what the debate on extraterritorial access to mailboxes actually covers
FAQ: seven questions on email retention
🔬 Sources
- Companies Act 2006, section 388: accounting records required by section 386 must be preserved for three years from the date on which they are made in the case of a private company, and six years in the case of a public company
- Companies Act 2006, Part 15, Chapter 2: section 386, duty to keep accounting records
- GOV.UK, Running a limited company: company and accounting records: keep records for six years from the end of the last company financial year they relate to, longer where a transaction covers more than one accounting period, where an item is expected to last more than six years, or where the return was late or is subject to a compliance check
- GOV.UK, Charge, reclaim and record VAT: keeping VAT records: keep VAT records for at least six years, or ten years if you use the VAT One Stop Shop scheme or used the VAT Mini One Stop Shop scheme
- GOV.UK, Business records if you are self employed: how long to keep your records: at least five years after the 31 January submission deadline of the relevant tax year
- GOV.UK, PAYE and payroll for employers: keeping records: keep payroll records for three years from the end of the tax year they relate to
- ICO, Principle (e): storage limitation: UK GDPR sets no specific time limits; personal data must not be kept longer than necessary for the purposes; data should not be retained on a just in case basis; a policy setting retention periods is needed for the accountability principle
- ICO, records management toolkit: disposal and deletion: deletion from a live system should extend to backups of that system, and where deletion is not technically possible the data should be put beyond use
- Limitation Act 1980, section 5: an action founded on simple contract shall not be brought after the expiration of six years from the date on which the cause of action accrued. A limitation period, not a retention obligation
- Civil Evidence Act 1995, sections 8 and 9: section 8(1) allows a statement contained in a document to be proved by the production of that document, or, whether or not that document is still in existence, by the production of a copy of that document or of the material part of it, authenticated in such manner as the court may approve; section 9 allows a document forming part of the records of a business to be received in evidence without further proof, on a certificate signed by an officer of the business
Published 3 September 2026 · Reading time: 29 minutes · approx. 7,300 words