Last updated: 22 July 2026.
1. Introduction
Penelope is committed to complying with the law and regulations in all our business activities, including applicable Data Protection Laws. We are committed to using all appropriate technical and organisational measures to ensure the protection of both customer and employee personal data. This policy, and the associated policies, set out the expected behaviours of our employees, contractors and third parties in relation to the retention, storage destruction of all data held within the business (including personal data). This policy should be read in conjunction with our Data Protection policy.
2. Scope
Maintaining business data in a systematic and reliable manner is essential to comply with our legal and regulatory requirements. It also reduces the costs and risks associated with retaining unnecessary information. A vital part of our Data Protection Policy and practice is that personal data is retained for the appropriate period of time, neither too long nor too short. It is paramount that the retention period allows us to meet our legal and regulatory requirements but that the rights of data subjects are also protected. This policy has been developed to help employees properly manage Personal Data in a consistent manner which sets out: How long personal data should be retained How records should be disposed of Unless otherwise stipulated, the policy refers to both hard copy and electronic documents. This document should be read in conjunction with our Data Protection Policy.
3. Definitions
4. Roles and Responsibilities
All employees, including contractors and third parties who process data on our behalf are responsible for complying with the requirements of this policy. The Data Protection Officer (DPO) is responsible for maintaining the policy. Our DPO can be contacted via email at dpo@callpenelope.ai, or by post to Data Protection Officer, Penelope, Western Gateway, Wrexham, LL13 7ZB. All Department Heads are responsible for ensuring that documented procedures are in place to comply with the requirements of this policy. It is the responsibility of all employees to ensure that they have read the most up to date version of this policy.
5. Policy
Information/records (hard copy and electronic) will be retained for at least the period specified in our Data Retention Guidelines (see Appendix 1). All information must be reviewed before destruction to determine if there are special factors that mean destruction should be delayed, for example, potential litigation, complaints or on-going cases. Hard copy and electronically held records, documents and information must be deleted at the end of the retention period or when requested in accordance with the appropriate Data Protection legislation. Each department should periodically review and determine whether they have records in their control which should be destroyed pursuant to this policy. Personal data will only be retained where there is a valid business, contractual, operational or legal requirement.
5.1 Suspending the destruction date
If a claim, audit, investigation, subpoena, or litigation has been asserted or filed by or against Penelope, or is reasonably foreseeable, we have an obligation to retain all relevant records, including those that otherwise would be scheduled for destruction under the records retention schedule.
5.2 How long should we keep our data?
Data should be kept for as long as it is needed to meet the terms of our agreement with our customers and any applicable legal requirements. Our Data Retention Guidelines have been agreed following as assessment of our data and the requirements of all our Regulators, together with our obligations under Data Protection Laws.
5.3 Methods of Destruction
All data, whether hard copy or electronic should be destroyed in a secure manner, preserving the confidentiality of all personal data. All hard copy data must be disposed of in the confidential waste bins which are located in every area of the business. Under no circumstances should confidential or personal data be put into normal waste bins. We will maintain records of the secure destruction of all waste which is put into the confidential waste. Our IT department will ensure that all electronic data is securely destroyed in a way which cannot be restored. They will also be responsible for ensure that any electronic equipment is securely wiped, and where appropriate securely disposed of, when it is no longer required by the business.
5.4 Sharing of Information
Unnecessary duplicate information should be destroyed. Where information has been regularly shared between business areas care should be taken to ensure that all copies of the data are destroyed in line with the Data Retention Guidelines.
6. Training
All employees will have their responsibilities under this policy outlined to them as part of their induction training. All employees will complete an annual refresher of this training. Penelope will provide further training and guidance if there are any updates made to this policy and/or the associated policies and procedures.
7. Monitoring Compliance
As a minimum the following will be monitored to ensure compliance with this policy:
- An annual Data Protection Compliance Audit which will, at the minimum assess:
- Compliance with policy in relation to the protection of personal data, including;
- Correct storage of personal data
- Deletion of personal data in accordance with the schedule
Key business stakeholders will devise a plan with a schedule for correcting any identified deficiencies within a defined and reasonable time frame. Any major deficiencies identified will be reported to and monitored by the DPO.
8. Review
This policy is owned by the DPO and will be reviewed at least annually. Any changes applied to the policy will be tracked and, where appropriate refresher training/updates will be cascaded to all appropriate individuals
9. Related Documents
- Data Protection Policy
- Privacy Notice
- Data Breach Notification Procedure
- Information Security Policy
Schedule 1 - Data Retention Guidelines Client Personal Data
Where Penelope acts as the Data Controller all data will be protected, retained and deleted in accordance with our agreed contractual agreements as well as in line with Data Protection legislation.
Where Penelope acts as the Data Processor all data will be protected and treated in accordance with contractual agreements with the Data Controller as well as in line with Data Protection legislation.
As referenced within our Data Protection Policy and our Privacy Notice; personal and sensitive data will only be retained whilst it's required to deliver a service (based on contractual agreement) or until such time we are instructed to delete it, whichever is the soonest.
Where data is processed solely for marketing purposes, any information we use for this purpose will be kept until you notify us that you no longer wish to receive this information, or until the data is deleted in accordance with our Marketing guidelines (further information on this can be obtained from our DPO either by email dpo@callpenelope.ai or by post to Data Protection Officer, Penelope, Western Gateway, Wrexham, LL13 7ZB) whichever is earliest.
As part of ensuring we are providing the right services to you we may use your data to pursue our legitimate interests in a way which would reasonably be expected as part of running our business and supplying services, this will be done in a way that does not materially impact your rights, freedom or interests.
Central business records
Where Penelope acts as the Data Controller all data will be protected, retained and deleted in accordance with our agreed contractual agreements as well as in line with Data Protection legislation.
Where Penelope acts as the Data Processor all data will be protected and treated in accordance with contractual agreements with the Data Controller as well as in line with Data Protection legislation.
For Accounting and Financial Records, we will retain for 6 years, unless contractual agreements specify differently.
For Complaints records we will retain for 1 year following the resolution of the complaint. For records relating to legal cases or claims notified to the business, retention periods will be agreed on a case by case basis, in accordance with Data Protection legislation (see 5.1 above).
HR records
Penelope will retain all personal data using current Chartered Institute of Personal and Development Guidelines (CIPD) as a benchmark.
We will keep all records for the following sensitive personal data types for 3 years after the year it relates to:
- Income Tax
- National Insurance
- HMRC correspondence
- Statutory Sick Pay
- Statutory Maternity pay
- Parental leave records
We will keep all records for the following sensitive personal data types for 6 years after the year it relates to:
- Salary details
- Retirement benefits schemes events (for example a change in minimum contribution levels)
- Redundancy records Pension records
- Application forms and interview notes captured as part of the application process will be kept for 6 months for any unsuccessful applicant, after which any personal sensitive data will be securely removed.
If further information is required this can be obtained from our DPO either by email dpo@callpenelope.ai or by post to Data Protection Officer, Penelope, Western Gateway, Wrexham, LL13 7ZB.