No statute sets that period for a care provider. Regulation 17 requires the records to exist, CQC’s guidance on it says they must be destroyed “in line with current legislation and nationally recognised guidance”, the Code is the national guidance for health and adult social care records, and UK GDPR forbids keeping personal data longer than it is needed. This guide sets out the periods for the records a care home or home care service holds, when each clock starts, when a record must not be destroyed, and how to record the destruction.
The rule: Regulation 17, the Code and storage limitation
No Act or regulation sets a retention period for adult social care records; the period comes from the Records Management Code of Practice, published by NHS England, which “provides guidance on how to keep records, including how long to keep different types of records”. Its scope is explicit: “The guidelines in this Code apply to NHS and adult social care records”, including “adult service user records who receive social care support”, staff records and complaints records. For private providers it is guidance rather than a rule – “Whilst not strictly covered by this guide, private providers can also use this Code for guidance in relation to their records management” – but it names “independent care providers providing an element of NHS or nursing care” among those it applies to, and although CQC’s guidance does not name a schedule, the Code is the national one for health and adult social care.
That pointer is in CQC’s guidance on Regulation 17 (good governance). The regulation requires a registered provider to “maintain securely an accurate, complete and contemporaneous record in respect of each service user”, and records about staff and the management of the service. CQC’s guidance says care records must “be created, amended, stored and destroyed in line with current legislation and nationally recognised guidance” and “be kept secure at all times and only accessed, amended, or securely destroyed by authorised people”, and that records about staff and management “must be created, amended, stored and destroyed in accordance with current legislation and guidance”. Our guide to CQC record keeping requirements covers what the records must contain; this one is about how long they last.
The third rule pulls the other way. Under the storage limitation principle in UK GDPR, which the Data Protection Act 2018 supplements, personal data must be “kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed”. The ICO’s storage limitation guidance puts it plainly: “You must not keep personal data for longer than you need it.” Keeping every care file forever is therefore a breach, not a safe default. The ICO notes that, because of changes made by the Data (Use and Access) Act, this guidance “is under review and may be subject to change”, so check the date on the ICO page before relying on its wording.
The retention periods for a care provider’s records
The Code’s Appendix II retention schedule is long; these are the rows a care home or home care service uses most, with the minimum period and the Code’s disposal action. All periods are minimums: the schedule says they “must always be considered the minimum period”.
- Adult social care records (including care plans): 8 years; “Review and destroy if no longer required”. Treat daily notes, risk assessments, MAR charts and the care plan’s supporting documents as part of the care record unless your schedule says otherwise, so they take the same period.
- Mental health records, including records under the Mental Health Act 1983: 20 years, or 10 years after death.
- Integrated records, where several organisations contribute to a single shared record: “Retain for period of longest speciality”.
- Complaints case files: 10 years.
- Incidents: not serious, 10 years; serious, up to 20 years; in each case “retention begins from the date of the Incident; not when the incident was reported”.
- Staff record: “Keep until 75th birthday”, including “evidence of right to work, security checks and recruitment documentation for the successful candidate”.
- Staff training records: statutory and mandatory training records “to be kept for ten years after training completed”; clinical training records until the 75th birthday or six years after the staff member leaves, whichever is longer; other training records six years after training completed.
- Disciplinary records: 6 years, beginning “once the case is heard and any appeal process completed”.
- Duty rosters: 6 years from the close of the financial year; original timesheets 2 years from creation.
- Risk registers: 6 years. Policies and procedures: life of the organisation plus 6 years.
- Equipment maintenance logs and inspection of equipment records: 11 years. Exposure monitoring information for staff: “40 years or 5 years from the date of the last entry made in it”, the longer period where the record shows the exposures of identifiable employees.
- Subject access requests and the response: 3 years; where there has been an appeal, 6 years from the end of the financial year they relate to.
- CCTV: no fixed period; “The length of retention must be determined by the purpose for which the CCTV has been used.”
- Destruction certificates, or the electronic stub that shows a record was destroyed: 20 years.
One statutory period sits outside the Code. A record of an incident reportable under RIDDOR “must be kept for at least three years from the date on which it was made” under regulation 12 of RIDDOR 2013; the Code’s 10-year incident period is longer and satisfies it. Finance, payroll and company records follow their own statutory periods, covered in our guides to a data retention policy and employee records.
When the clock starts, and when it resets
The start date matters as much as the number. The Code: “Retention periods begin when the record ceases to be operational. This is usually at the point of discharge from care when the record is no longer required for current on-going business, or the patient or service user has died.” For a care home that means the day the resident moved out or died, not the day the file was opened and not the date of the last routine entry while they still lived there. Some entries run from creation instead, marked with an asterisk in the schedule, and some from a stated event, such as an incident date or the close of a financial year.
Two rules then stretch the minimum. “If a record comes back into use during its retention period, then the retention period will reset and begin again from the end of the second period of use” – a resident who leaves for hospital, is discharged home and returns to the home two years later starts a new 8 years when they finally leave. And the Code allows a longer period where it is justified: “Generally, where there is justification, records may be retained locally from the minimum period set in this Code, for up to 20 years from the last date at which content was added.” It also requires the justification to be written down: “Decisions for continued retention beyond the periods laid out in this Code must be recorded, made in accordance with formal policies and procedures by authorised staff and set a specific period for further review.”
Before anything is destroyed, the Code asks for a review that considers “serious incidents which will require records to be retained for up to 20 years”, “use of the record during the retention period which could extend its retention” and potential archival value. In a care home, typical reasons to keep a file past 8 years include a known claim, an unresolved complaint, a safeguarding enquiry and a death that went to the coroner.
When a record must not be destroyed
The Code lists the situations in which information “cannot be destroyed or disposed of” even when its period has passed:
- “if it is subject to a form of access request, for example, subject access request (SAR), FOIA request”; the Code adds that “it would not be acceptable to dispose of a record that is part way through being processed for an access request because the minimum retention period has been reached”;
- “if it is required for notified legal proceedings, for example, a court order, or where there is reasonable prospect of legal proceedings commencing”;
- “if it is required for a coroner’s inquest”;
- “if it is of interest to a public inquiry”. The Code lists inquiries that have asked large parts of the health and social care sector not to destroy records within their remit; the list changes, so check the current version before a destruction run.
Records about a person who has died stay confidential. The Code notes that “where a patient or service user has died the UK GDPR no longer applies”, but that the duty of confidence remains, “so records cannot be accessed by anyone who does not have a lawful basis to view a record”, and that “in general, health and social care information will remain confidential after death”. Requests from relatives and personal representatives need their own process, and a subject access request from a living person, including a former member of staff, has to be answered from whatever the provider still holds, which our guide to a subject access request policy covers.

Destroying records, and proving it
A retention schedule is only real if something is destroyed at the end of it, and the destruction is itself a record. The Code’s section 5.3: “If as a result of appraisal, a decision is made to destroy or delete a record, there must be evidence of the decision. It is good practice to get authorisation for destruction or deletion from an appointed committee or group with a designated function to appraise records, working to a policy or guidelines.” Where the destruction process is new or changes, “such as a change of provider, or the method used”, a data protection impact assessment “must be completed and signed off by the organisation”.
In the schedule, “destroy” means “the confidential and secure destruction of the record with proof of destruction”. For paper that is a certificate from the shredding contractor, kept for 20 years. For electronic records, the Code says that where a record has reached its period and been approved for destruction, it “should be deleted if the system allows that function. A separate record should be kept of what record has been deleted.” Where a care system cannot delete, “all reasonable efforts must be made to remove the record from normal daily use”, and it should be marked so that anyone opening it can see it is dormant. The Code’s note on electronic patient record systems asks for “a log kept of destruction”. Check with your care software supplier whether it can delete one person’s record at the end of its period and leave a stub that shows what went.
A simple destruction log for a care home has five columns: the record (by person code, never by name in the log itself), the record type and its period, the date the period ended, who authorised destruction and when, and the method and certificate reference.
The care record nobody put on the schedule
Every period above assumes the provider knows where its records are. Most of what is said about a resident on a given day is now said in messages. The night carer tells the team in the staff group that Mrs B has refused her tablets again. The deputy messages the GP practice’s care co-ordinator about a change in her medication. Her son texts the senior carer’s personal phone to ask how she is, and gets a reply. Some of that reaches the care record; much of it never does.
Those messages are information about Mrs B held by the provider’s staff in the course of their work, and the retention schedule has no row for them. They are kept in two ways at once, both wrong: on every phone in the group, with no end date, after staff leave and after Mrs B has died; and nowhere at all, because the provider cannot search, retain or destroy them. When her son makes a subject access request in year three, or a coroner asks in year five what the home knew about the refused medication, the answer depends on whose phone survived.
The fix is not a ban on messaging; it is to give work messages about residents a place the provider controls, where everyone in the conversation is told it is on the record and the provider’s own retention rules apply. ComplyChat provides that kind of work channel; on paid plans the lasting record files into the provider’s own Microsoft 365 under the retention policies the provider sets there. It is not a care records system and it does not hold care plans, MAR charts or daily notes; those belong in your care software, with the periods above.
A question for the next governance meeting: if a former resident’s family asked tomorrow for every record the home holds about their mother, would the search include the staff group chat – and could the home either produce it or show that it was destroyed on schedule?
Questions people ask
How long should a care home keep records after a resident dies?
A care home should keep an adult social care record for at least 8 years after the resident’s death, the period in the Records Management Code of Practice for adult social care records, which says retention usually begins at discharge from care or when the person has died. Keep it longer where there is a documented reason, such as a claim, a complaint, a coroner’s inquest or an inquiry.
What records need to be kept for 7 years?
None of the main care provider records in the Records Management Code of Practice has a 7-year period: adult social care records are kept for at least 8 years, complaints and non-serious incidents for 10, and staff records until the 75th birthday. The nearest common rule is for company records, which GOV.UK’s guidance on company and accounting records says must be kept “for 6 years from the end of the last company financial year they relate to”.
How long do you keep staff training records in a care home?
Under the Code’s schedule, statutory and mandatory training records are kept for ten years after the training was completed, clinical training records until the staff member’s 75th birthday or six years after they leave, whichever is longer, and other training records for six years after completion. The main staff record is kept until the 75th birthday.
What are the data retention rules in the UK?
UK GDPR sets no fixed periods: it requires personal data to be kept no longer than necessary for its purpose, and the ICO says organisations need “a policy setting standard retention periods wherever possible” and should “periodically review the data you hold, and erase or anonymise it when you no longer need it”. Sector guidance and other laws then set the periods, which for health and adult social care is the Records Management Code of Practice.
Official guidance and your next step
The primary sources are the Records Management Code of Practice and its Appendix II retention schedule, CQC’s guidance on Regulation 17, the ICO’s storage limitation guidance and regulation 12 of RIDDOR 2013. NHS England updates the schedule from time to time, so read the live web version rather than a saved copy; local authority and NHS contracts may also set retention terms of their own.
This guide is a practical summary for adult social care providers in England, not legal advice about a particular record, claim or request.
Then do one thing: list every place the service keeps information about residents and staff – the care software, the paper archive, the shared drive, the email accounts, the staff group chat – and write the retention period beside each. Any place with no period is the one to fix first.
We build ComplyChat for the work conversations organisations need to keep. A retention schedule only works for records the provider can find, and the messages staff send about residents are the records it most often cannot. Explore Free personal messaging, or compare the paid plans if your service needs a lasting Microsoft 365 archive under your own retention rules.
Sources
Every document this guide quotes or links to, in the order it first cites them.
- Records Management Code of Practice digital.nhs.uk
- Regulation 17 (good governance) cqc.org.uk
- Storage limitation guidance ico.org.uk
- Appendix II retention schedule digital.nhs.uk
- Regulation 12 of RIDDOR 2013 legislation.gov.uk
- Company and accounting records gov.uk




