Data protection conversations in care homes tend to focus on who can access records and what residents can request to see. Just as important, and much less discussed, is the other end of the record's life: how long it should be kept, and when — and how — it should eventually be destroyed. Getting retention wrong in either direction creates real problems, whether that's holding sensitive data indefinitely with no lawful basis, or destroying records that might later be needed for a safeguarding investigation or legal claim.
Why Retention Periods Exist
UK GDPR requires that personal data isn't kept for longer than necessary for the purpose it was collected for — but "necessary" in a care context is shaped heavily by other legal obligations, particularly the potential for future claims, inquests, or safeguarding investigations that might need to draw on historic records. This is why care records generally have much longer retention periods than routine business paperwork, and why a generic "delete after two years" policy borrowed from an unrelated industry is likely to be non-compliant.
The NHS Records Management Code of Practice
Most UK care providers align their retention schedules with the NHS Records Management Code of Practice, even though care homes sit outside the NHS directly, because it's the most authoritative and widely recognised standard for health and care record retention. Under this framework, adult care records are typically retained for a minimum of eight years after the last entry or after death, whichever is relevant, though records relating to residents who lacked capacity, or where safeguarding concerns were raised, may need to be kept considerably longer given the potential for delayed disclosure or litigation.
Different Record Types, Different Rules
Not every document a care home holds follows the same retention clock. Medication administration records, safeguarding investigation files, accident and incident reports, and staff training records covering care delivered to a specific resident often need to be retained longer than general correspondence or day-to-day communication logs. Financial records, including personal allowance transaction logs, typically follow standard financial retention rules (often six years) rather than the longer clinical retention period. A care home's retention policy should set out these distinctions explicitly rather than applying one blanket period to every type of document.
Retention After Death or Discharge
A common area of confusion is what happens to a resident's care records once they've died or moved to a different provider. Records shouldn't be destroyed simply because the resident has left the service — the retention clock generally starts from the point of the last entry or the resident's death, not from admission, and providers need a clear, documented process for what happens to the physical or digital records at that point, including where they're stored and who retains responsibility for them.
Secure Destruction
Once a retention period has genuinely expired, records need to be destroyed securely — cross-cut shredding for paper records, and certified secure deletion for digital records, not simply archived indefinitely because destruction feels administratively easier than deciding what to do. Keeping records well past their retention period isn't a safer default; it's itself a data protection risk, since it increases the amount of sensitive personal data a home is responsible for protecting, and increasing the potential harm if a data breach ever occurs.
Documenting the Policy Itself
Providers should have a written retention schedule specifying, by document type, how long each category is kept and the basis for that period, reviewed periodically to stay aligned with current guidance. This isn't just good practice — CQC and ICO both expect providers to be able to demonstrate they've actively thought through retention, rather than simply keeping everything forever by default or deleting things inconsistently.
Subject Access Requests and Retained Records
Retention policy and subject access requests intersect directly — a resident or their representative can only request access to records that still exist, so a provider's retention schedule effectively determines how far back a subject access request can reach. This is a further reason to document retention decisions clearly and consistently, since an inconsistent or informally applied retention practice can make it genuinely difficult to respond confidently and completely to a legitimate access request.
Frequently Asked Questions
How long should a care home keep a resident's care records?
Typically a minimum of eight years after the last entry or death, aligned with the NHS Records Management Code of Practice, though safeguarding-related records may need to be kept longer.
Should care records be destroyed when a resident moves to another provider?
No — the retention period generally runs from the last entry or death, not from admission, so records shouldn't be destroyed simply because the resident has left the service.
Is it safer to just keep all records indefinitely?
No. Keeping records beyond their retention period is itself a data protection risk, increasing the volume of sensitive data a home is responsible for protecting.
Good retention practice sits alongside the wider data protection obligations covered in our guide to subject access requests and GDPR, and connects to information security more broadly in our Cyber Essentials and data security guide. For structured training on information governance, see Learnsignal's CPD courses.
This page was last updated:
Learnsignal Education Team
Expert Tutor at Learnsignal
Qualified professional with years of experience in teaching and helping students achieve their accounting qualifications.
View all posts by Learnsignal Education Team


