Records and Information Management: A Practical Workplace Guide
Retention schedules, version control and secure disposal explained in plain terms — a practical guide to good records and information management for every employee.
Most people think "records management" means someone in a basement archiving paper files. In a modern workplace it means something far more everyday: what you do with the email you just sent, the spreadsheet you saved to the shared drive, the contract PDF sitting in your downloads folder, and the customer file you're about to close. Good records and information management (RIM) isn't a specialist compliance function bolted onto the business — it's a set of habits every employee practises, whether or not they realise it. Getting it right protects the organisation legally, makes everyone's job easier to do, and — done as part of good continuing professional development — is a genuinely useful skill to carry between employers.
Why records management matters beyond "tidiness"
Records management sounds administrative, but it sits underneath almost everything a business does. If a client disputes an invoice, the paper trail proves who agreed what and when. If a regulator asks for evidence of a decision, the record is the evidence. If a colleague leaves and someone else has to pick up their work, well-organised, findable records are the difference between a smooth handover and weeks of guesswork. Poorly managed records cost time (searching for the "real" version of a document), create legal exposure (keeping data you no longer have a lawful reason to hold, or being unable to produce a record you're required to keep), and increase the damage a data breach or ransomware attack can do — the more scattered, duplicated and un-classified your information is, the harder it is to know what was actually exposed. That last point is also why RIM and workplace cybersecurity awareness go hand in hand: a well-managed record is also a more secure one.
The "keep everything forever" trap
Faced with the anxiety of "what if we need this one day", the instinctive response is to keep everything, indefinitely, on every drive available. It feels safe. It isn't. Hoarding records — especially records containing personal data — is itself a compliance and security risk, not a hedge against one.
Under UK GDPR, the storage limitation principle requires organisations to keep personal data "in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed," as the Information Commissioner's Office (ICO) sets out in its guidance on the data protection principles. In practice that means an organisation should be able to explain why it's still holding a piece of personal data, not simply default to keeping it because deleting it takes effort. Every extra file you keep past its useful life is: more data to secure, more data a breach could expose, more data someone has to sift through to find what actually matters, and — for personal data specifically — a potential data protection compliance gap. "We might need it someday" is not, on its own, a retention justification.
Building a simple retention schedule
A retention schedule is simply a list of record types and how long each should be kept before it's reviewed and, where appropriate, securely destroyed. You don't need to invent this from scratch — many categories already have a legal minimum retention period attached, and your organisation's finance, HR or legal team should set the official schedule. As an employee, it helps to understand the shape of it:
| Record type | Typical driver | What employees should know |
|---|---|---|
| Core accounting and tax records | Companies Act 2006 and HMRC requirements | UK company law and tax rules set minimum retention periods for accounting records — generally several years — so financial documents shouldn't be deleted informally just because a project or client relationship has ended. |
| Contracts and agreements | Limitation periods for legal claims | Kept for the life of the contract plus a defined period afterwards, in case a dispute arises later. |
| HR and employee records | Employment law and internal policy | Retention varies by record type (payroll, disciplinary, recruitment) — check your HR policy rather than assuming one rule fits all. |
| General correspondence and working files | Business need, not law | Usually the shortest retention period — most day-to-day email and drafts have no ongoing purpose once a matter is closed. |
If your organisation doesn't have a documented schedule you can point to, that's worth raising — it's a gap, not a reason to invent your own rules file by file.
Version control: one source of truth
"Final_v2_reallyfinal_JS_edits.docx" is a joke because it's so recognisable. Multiple versions of the same document circulating by email, each slightly different, is one of the most common everyday records failures — and it gets worse as more tools generate drafts, including AI writing assistants. If your team uses generative AI to help produce documents, treat the output the same way as any other draft: it needs a clear place in the version history, not a parallel copy nobody else can see. (For the wider do's and don'ts of using these tools at work, see our guide to responsible generative AI use in the workplace.)
Good version control habits are simple but need discipline: work from a single shared location (a shared drive or document management system) rather than emailing copies back and forth; use built-in version history instead of renaming files with "v1", "v2", "final"; agree who owns the master copy of a document; and archive or delete superseded drafts once a document is finalised, rather than letting them accumulate alongside the real one.
Secure disposal: destruction is a process, not a delete key
Getting rid of records isn't just tidying up — done properly, it's an active part of good information management, and done badly it can create the exact risk retention schedules exist to prevent. Deleting a file from a shared drive doesn't necessarily remove it from backups, and moving something to the recycling bin doesn't make it unrecoverable. For anything containing personal or commercially sensitive data:
- Use your organisation's approved secure deletion or confidential waste process — for paper, that means a shredder or a confidential waste bin, not the general recycling.
- Don't dispose of records informally just because they're "old" — check the retention schedule first; premature destruction of a record you were required to keep can be as much of a problem as keeping it too long.
- Remember that disposal applies to physical media too — old USB drives, backup tapes and retired laptops need proper data wiping before disposal or resale, not just a factory reset.
- Log significant destructions of records where your policy requires it, so there's an audit trail showing what was destroyed, when, and under what authority.
Records management and data protection: related, not the same
It's easy to conflate records management with GDPR compliance because they overlap so heavily, but they're answering different questions. Records management asks: what information do we hold, where does it live, how is it organised, and how long should we keep it, for any and all records — financial, operational, contractual. Data protection law asks a narrower question: is our handling of personal data (data that identifies a living individual) lawful, fair and secure. A good retention schedule is one of the practical tools that helps you meet the UK GDPR storage limitation principle, but data protection compliance also covers things records management alone doesn't — lawful basis for processing, individual rights requests, breach notification. If you want the fuller picture on the data protection side, our UK GDPR essentials guide covers it in depth; this post focuses on the records discipline that sits alongside it.
Practical habits for shared drives, email and cloud storage
Most records problems are habit problems, not technology problems. A few habits make a disproportionate difference:
- File where it belongs, not where it's quickest. Save to the correct shared folder or system at the time, rather than your desktop or downloads folder "for now" — "for now" tends to become permanent.
- Use consistent, descriptive file names (client, subject, date) rather than personal shorthand only you understand.
- Treat email as a message, not a filing cabinet. If an email or its attachment is a record that needs to be kept, save it into the proper system; don't rely on your inbox as the long-term archive.
- Don't create shadow copies in personal cloud storage (personal Google Drive, Dropbox, iCloud) — it fragments the record, puts data outside company control, and is a common route for accidental data loss when someone leaves.
- Apply access permissions sensibly — not everyone needs edit access to every folder, and restricting access is itself a records-management control, not just an IT one.
- Review, don't just accumulate. If your team has a periodic clear-out of old shared drive folders, take part properly rather than treating it as someone else's job.
FAQ
Do I need to keep every email I send at work?
No. Most day-to-day email has no ongoing business purpose once the matter it relates to is resolved. Keep emails that constitute a genuine record — a decision, an instruction, an agreement — and don't treat your inbox as a permanent archive for everything else.
Who decides how long we keep a record for?
Your organisation's retention schedule, usually set by a combination of legal/compliance, finance and HR, based on legal minimums and genuine business need. As an employee your role is to follow it and flag records that don't obviously fit any category, not to set your own rules.
Is deleting old files the same as GDPR compliance?
Not on its own. Timely deletion supports the UK GDPR storage limitation principle, but data protection compliance also requires a lawful basis for holding personal data in the first place, proper security, and the ability to respond to individual rights requests — records management is one part of a bigger picture.
What's the risk of keeping too much rather than too little?
Excess data increases what's exposed in a breach, slows down searches and audits, can breach the storage limitation principle for personal data, and makes it harder to find the genuine, current version of anything. "Keep everything" feels cautious but usually creates more risk than it removes.
Good records and information management is a practical skill, not a compliance chore — and like most workplace skills, it's worth building deliberately rather than picking up by accident. Learnsignal's CPD courses cover workplace compliance topics like this one in more depth, helping you build the kind of practical, evidence-based skills that hold up when it matters.
This page was last updated:
Learnsignal Education Team
Expert Tutor at Learnsignal
Qualified professional with years of experience in teaching and helping students achieve their accounting qualifications.
View all posts by Learnsignal Education Team


