LoginBook a demo
Blog / Operations

How Long Should UK Employers Keep Employee Training Records?

C
The Cademi Team
6 min read
How Long Should UK Employers Keep Employee Training Records?

How long should you keep an employee's training records? The careful UK answer is: long enough for the purpose and any applicable requirement, but not indefinitely by default.

There is no single retention period that applies to every training record held by every employer. A fire-safety attendance record, an external professional certificate, an equipment authorisation and a development-course history may have different purposes and risks. The correct period can also depend on sector rules, contractual conditions, insurance, claims exposure and the needs of the worker.

The objective is a documented retention schedule that the organisation can explain and apply consistently.

Why “keep everything for six years” is not a complete policy

Online guidance sometimes repeats a blanket period, often without naming the law or the record type. That may feel safe, but it can create two problems:

  1. useful evidence can be deleted too early because a specific rule or live purpose was missed;
  2. personal data can be held for longer than needed because nobody assessed the purpose.

The ICO's storage-limitation guidance says organisations must not keep personal data for longer than necessary and should justify standard retention periods. The ICO's employment-record guidance also emphasises clear retention policies, regular review and secure disposal.

Neither principle means “delete quickly”. It means decide deliberately.

Use a five-question retention test

Apply the following test to each category of training record, not to the entire LMS as one block.

1. What is the record?

Name the category precisely. Examples include:

  1. training assignment and completion;
  2. attendance at an in-person session;
  3. assessment score or answer detail;
  4. competence observation or manager sign-off;
  5. professional licence or external certificate;
  6. reasonable-adjustment information;
  7. training exception or exemption decision;
  8. content version and policy acknowledgement.

Different data within the same learning activity may need different rules. You might retain the fact and date of completion longer than detailed quiz answers, for example.

2. Why do you hold it?

Link each category to one or more purposes:

  1. proving that a requirement was assigned and completed;
  2. deciding whether refresher activity is needed;
  3. verifying authorisation or competence for current work;
  4. supporting an audit, tender or regulated-service review;
  5. responding to an incident, complaint or claim;
  6. maintaining a professional or contractual credential;
  7. supporting the person's development history.

Write the purpose in plain English. “For compliance” is too broad to guide deletion.

3. Is there a specific rule or defensible reference point?

Check the law, regulator guidance, sector framework, contract and insurance terms that actually apply. Record the source and its scope. If no source sets a period, use a documented risk and purpose assessment rather than borrowing a number from an unrelated record type.

4. When does the retention clock start?

Possible start points include completion, expiry, replacement by a newer record, end of employment, end of a project, loss of an authorisation, conclusion of an investigation or expiry of a contract. A schedule that says “retain for five years” but omits the start event is ambiguous.

5. What should happen at the end?

Choose a disposal action:

  1. securely delete the full record;
  2. retain a reduced evidence record and delete unnecessary detail;
  3. anonymise data for trend analysis;
  4. suspend deletion because of a documented legal hold or active investigation;
  5. review manually where the purpose cannot be determined automatically.

A practical retention-schedule structure

Use a table with these fields:

FieldExample content
Record categoryEquipment competence sign-off
Data elementsPerson, role, equipment type, assessor, date, result, evidence file
PurposeConfirm current authorisation and evidence the competence decision
Lawful basisTo be completed by the data-protection owner for the actual processing
Source or rationaleRisk assessment, operating procedure and approved retention decision
TriggerAuthorisation ends or employment ends, whichever is later, subject to review
Retention periodOrganisation-defined period after the trigger
DisposalDelete evidence file; retain only what a continuing purpose requires
OwnerHealth and Safety Manager
Review dateAnnual, and after a material regulatory change

The example is a structure, not a prescribed period. Your data-protection and subject-matter owners should complete it for the organisation's circumstances.

Records for current employees

For a current employee, the purpose is often active. Managers may need to see whether the person can undertake a task, what is expiring, whether a refresher is due and what happened after a competence concern.

That does not justify keeping every underlying detail. Ask whether managers need:

  1. the current status and completion date;
  2. the content version or learning outcome;
  3. the score, or simply pass/fail;
  4. a full answer history;
  5. an uploaded certificate;
  6. notes that could reveal health or other sensitive information.

Keep access role-based. A line manager may need current status without seeing sensitive adjustment information or unrelated development history.

Records after employment ends

Do not use employee departure as an automatic delete or keep-everything event. Apply the schedule to each category.

Some evidence may remain relevant to an incident, claim, regulated service, professional record or contractual obligation. Other data, such as detailed learning preferences or obsolete recommendations, may have no continuing purpose. Record the end-of-employment trigger, reduce the data where possible and restrict access to the people who still need it.

If litigation, an investigation or another formal process is reasonably anticipated, seek appropriate legal and data-protection advice before scheduled deletion. A legal hold should be documented, scoped and reviewed, not used as a reason to retain all learning data indefinitely.

What about certificates?

A certificate can be useful evidence, but it does not answer every question. Record what the certificate establishes, who issued it, its dates, the person or credential it relates to and whether authenticity was checked.

Where only the validity and identifier are needed, consider whether retaining the entire document is necessary. Where the document is the authoritative evidence, protect it from unauthorised access and accidental alteration.

Make the policy work in your systems

A retention schedule fails if nobody can apply it. Before choosing or configuring an LMS, ask:

  1. Can retention rules differ by record category?
  2. Can the organisation export its data in a usable format?
  3. Are deletion, correction and access actions logged?
  4. Can sensitive records have more restricted permissions?
  5. Can historical evidence be separated from active learner views?
  6. What happens to data in backups and after the supplier relationship ends?

The ICO's guidance on IT supplier relationships is a useful prompt for clarifying security responsibilities, contracts and exit arrangements.

Cademi supports the import and export of training histories, but your organisation remains responsible for its record purposes and retention decisions. Include those decisions in migration mapping rather than moving every legacy field automatically.

A simple implementation plan

  1. Inventory training-record categories across the LMS, HR system, shared drives, email and paper files.
  2. Remove exact duplicates without losing provenance.
  3. Assign a business owner and data-protection reviewer to each category.
  4. Complete the five-question test and approve the schedule.
  5. Configure or document deletion, reduction and legal-hold processes.
  6. Test a sample of current staff, leavers and external qualifications.
  7. Review annually and when law, service or system design changes.

Frequently asked questions

Is six years the legal retention period for all employee training records?

No universal six-year rule applies to every training record. A particular context may justify that or another period, but the organisation should identify the source, purpose, trigger and data involved.

Can we keep training records forever because storage is cheap?

Cheap storage is not a purpose. Indefinite retention can increase privacy, security and discovery risk. Keep what is necessary, explain why and review it.

Should employees receive a copy when they leave?

Consider professional certificates or portable records, but do not assume every internal record should be disclosed or transferred. Follow your data-protection process and verify identity.

Does an LMS set our retention policy for us?

No. A supplier can provide controls, but the employer must decide the purposes and rules that apply to its processing.

Share this article
LinkedIn
X
Email
Copy link
Keep reading

More resources.

Employee Training Matrix: Build a Role-Based Template That Stays Current
Operations
Employee Training Matrix: Build a Role-Based Template That Stays Current
How to Save Money and Drive Results
LMS
How to Save Money and Drive Results
How do you defend your learning budget?
L&D leadership
How do you defend your learning budget?

Try Cademi.
Today.

Book a demoSee Cademi in action
Employee Training Record Retention in the UK | Cademi