All articles
    Compliance

    Data Retention and GDPR in Academy Trust Governance: What You Need to Know

    OneGovs Team
    2 October 2025
    6 min read

    Governance records contain some of the most sensitive personal data in any academy trust. Governor names, addresses, DBS reference numbers, financial interests, meeting attendance — all of it falls under GDPR. Yet most trusts don't have a documented retention policy for governance data, and many are keeping records far longer than they should.

    What Governance Data Is Covered by GDPR

    Every piece of personal information about a governor, trustee, or member is subject to data protection law. This includes:

    • Personal contact details (addresses, phone numbers, email)
    • DBS disclosure reference numbers and check dates
    • Register of business interests (including details about employers and financial interests)
    • Meeting attendance records
    • Training records and certificates
    • Correspondence related to appointments, resignations, or removals

    Under GDPR's data minimisation principle, trusts should only retain personal data for as long as there is a clear, documented purpose. "We might need it someday" is not a valid retention justification.

    ICO Guidance on Retention Periods

    The Information Commissioner's Office (ICO) doesn't prescribe specific retention periods for governance records, but sector guidance from the Information and Records Management Society (IRMS) provides a framework that most trusts follow:

    • Governor appointment records: Retain for the duration of the appointment plus 6 years
    • Meeting minutes (approved): Permanent retention (these are corporate records of decisions)
    • Attendance records: Duration of appointment plus 6 years
    • DBS records: Should be destroyed once the check has been verified (typically within 6 months)
    • Register of interests: Duration of appointment plus 6 years
    • Training records: Duration of appointment plus 6 years

    The Risks of Keeping Data Indefinitely

    Many trusts default to keeping everything forever, reasoning that storage is cheap and deletion feels risky. But indefinite retention creates several genuine problems:

    Regulatory non-compliance. GDPR requires that personal data is not kept longer than necessary. An ICO audit or subject access request could expose the absence of a retention policy.

    Data breach amplification. If a breach occurs, the volume of affected personal data is a key factor in the severity assessment. Retaining records from governors who left a decade ago unnecessarily increases exposure.

    Operational clutter. Outdated records obscure current information, making it harder to produce accurate governance reports and increasing the risk of errors.

    Implementing a Retention Policy Without a Data Audit Project

    The prospect of implementing a retention policy can feel daunting, particularly for trusts with years of accumulated records. The practical approach is to start prospectively — applying retention rules to current and future records — while working through historical data gradually.

    Managing governance across your MAT? See how OneGovs handles data retention with configurable policies, dry-run previews, and automated GDPR compliance.

    Book a Free Demo

    Dry-Run Previews: The Safe Approach

    One of the most common barriers to implementing retention policies is fear of deleting the wrong records. This is a legitimate concern — and it's why dry-run functionality is so important. Before any deletion takes place, governance teams should be able to preview exactly which records would be affected, review the list, and confirm before anything is permanently removed.

    This approach combines GDPR compliance with operational safety, giving trusts the confidence to implement proper data lifecycle management without the anxiety of irreversible mistakes.

    Share
    OneGovs

    OneGovs Team

    OneGovs is a governance management platform purpose-built for UK multi-academy trusts, local authorities, and governing bodies. We write about governance best practice, compliance, and sector developments.