The honest answer is that there is no number, and the reason the question keeps coming back is that everybody is hoping there is one. The ICO states the position plainly: the UK GDPR does not set specific time limits for different types of data, and how long you keep it depends on what you need it for.
Which sounds like a non-answer and is actually a specification. It means the number is yours to set, yours to write down, and yours to justify — and that a period you set and never apply is worse than having none at all.
The ICO's guidance on storage limitation asks organisations to establish and document standard retention periods for the different categories of information they hold, wherever they can. Smaller organisations doing low-risk processing may not need a formal written policy, but are still expected to review and delete what they no longer need.
Holding personal data indefinitely on the basis that it might be useful one day is specifically ruled out. The purpose has to be real and current.
At the end of a retention period the expectation is that you look again, and either delete the data or anonymise it, unless there is a clear justification for keeping it longer. Anonymisation is a legitimate alternative to deletion — genuinely anonymised data falls outside the storage limitation rules entirely.
Future legal claims are an acceptable reason to keep some information — but the ICO's own framing is that you could still delete anything that could not possibly be relevant to such a claim. “We might get sued” justifies a defined subset, not the whole database.
An unplaced applicant from a role that closed in 2021 and a contractor you place four times a year are both “candidates” in your database and are nothing alike in purpose. The retention answer is different for each, so treat them as different categories rather than looking for one number that covers both.
Many agencies assume consent, because a candidate sent them a CV. Legitimate interests is commonly relied on for keeping a candidate on file for future roles, and it behaves very differently: it requires you to have weighed your interest against theirs and to be able to show that reasoning, and it gives the candidate a right to object rather than a right to withdraw. If you genuinely are relying on consent, then withdrawal has to actually remove the basis for holding the record — which is a much sharper commitment than most agencies intend to make.
Placed workers are the common case. Payroll, tax and working-time records carry their own statutory retention requirements that have nothing to do with recruitment, and those obligations sit on top of anything you decide. Right-to-work check evidence is retained on its own footing too. Do not fold these into a single “candidate” period — they are separate categories with separate clocks.
Health information from a fitness-to-work check, and criminal records information from a DBS check, are treated with more care than a CV and are usually kept for a shorter period. Common practice for criminal records information is to record the outcome and the date rather than retaining the certificate itself. If your compliance file holds both, they should not share a retention rule with the covering CV.
This is the question that decides whether the policy is real. If your retention notice says three years, something has to find the records that reached three years and do something about them. A period that lives only in a PDF on the shared drive is a statement you are already failing to meet, in writing, with a date on it.
Deleting a CV file while the candidate's name, history, notes and email thread remain is not deletion. The obligation is about personal data, not about the document it arrived in — and in most systems the document is the easiest part to remove and the least of what you hold.
When someone asks for a copy of what you hold, the response deadline is short, and it applies to everything — including consultant notes about them. Agencies discover the true scope of their own data at exactly the moment they have the least time to deal with it.
Restarting somebody's clock because they clicked something, or because a consultant touched the record, means nobody is ever deleted. If your last-activity field is written by your own marketing, it is not measuring the candidate's interest in you.
And the fourth: a candidate whose record you delete entirely can apply again next week and be re-entered by a consultant who does not know they objected. If somebody asks not to be contacted, the record of that request usually has to survive the deletion of everything else — which is a genuinely awkward thing to build and a genuinely necessary one.
None of what follows sets your retention period. It is the set of things that make a period you have chosen enforceable rather than aspirational.
An account owner can produce a full export of the organisation from inside the product: a CSV per table, a manifest of exactly what was written, and the stored documents. When somebody makes a subject access request, the month you have is not spent waiting on a support queue.
Consent to share a candidate's documents with a client is recorded as a grant, with who granted it and when, and a withdrawal is recorded alongside rather than erasing it. A withdrawn consent that has been deleted cannot answer the only question that ever gets asked about it, which is what the position was on the day the documents went out.
Not at the point of upload, but at the point a candidate's file is submitted to a client — which is the moment the data actually leaves.
Compliance files are stored outside the web root under randomised names in a directory the web server owns, and are never linked to directly. Downloading one requires the stricter permission, not the one that lets a consultant read an expiry date — knowing that somebody's right to work lapses in March is an operational fact; holding a copy of their passport is a different order of thing.
Inactive free candidate accounts can be archived as a reversible soft delete of both the account and the candidate record together, inside one transaction, so a failure can never leave half of somebody behind.
There is a single organisation boundary in the system and nothing crosses it. Candidate records are never pooled between agencies and are never used to fill anybody else's roles — which is a retention question as much as a competitive one, because data you cannot see is data you cannot delete.
This page is a working reference, not legal advice. We build recruitment software; we are not lawyers or data protection advisers, and nothing here should be relied on as a statement of your obligations. Data protection guidance changes, and how it applies depends on your agency, your sectors and what you actually do with the data. The primary sources are the ICO's own guidance on storage limitation and on employment practices and data protection — read those, and take your own advice. If you spot something here that has moved on, tell us at sales@ats-engine.com and we will correct it.
The eight credential regimes UK agencies actually have to track, the renewal cycle for each, and the trap in every one.
Six things that break when a temporary desk is run on software built for permanent placement.
What exports cleanly, what never does, and the checklist to work through before you give notice.