The risk isn’t only losing a file. It’s keeping the wrong one for too long, then finding out too late that GDPR, Revenue, or an audit expected something else.

That problem gets messier when your records sit in filing cabinets, SharePoint, inboxes, finance systems, and archived boxes at the same time. A good document retention policy for an Irish business brings all of that into one workable set of rules.

What a good policy needs to do

A decent policy is more than a list of dates. It tells staff what counts as a record, where the official version lives, how long it stays there, who can see it, and how it gets destroyed when the time comes.

For Irish organisations, the policy also has to balance two pressures that pull in opposite directions. Revenue and company law may require you to keep records for years, while GDPR says personal data should not be kept longer than necessary. The EU’s guidance on storage limitation and the Data Protection Commission FAQ both point to the same practical rule: keep data for a defined reason, then remove it when that reason ends.

Keep records long enough to meet legal, tax, contractual and operational need, then dispose of them in a way you can prove.

If you’re writing a document retention policy for an Irish business, include five core parts:

  1. A scope that covers paper, email, shared drives, cloud apps, off-site storage, laptops, mobiles, and backup copies.
  2. A retention schedule by document type, with the trigger date clearly stated.
  3. Named owners for each record category, such as Finance, HR, Operations, or Company Secretary.
  4. Rules for legal holds, audits, Subject Access Requests, disputes, and Revenue enquiries.
  5. Approved destruction methods for paper and digital files, plus a log of what was destroyed and when.

Keep the language plain. If staff have to read it three times, it won’t work.

Set retention periods by record type, not by habit

Many businesses fall back on a blanket rule like “keep everything for seven years”. It sounds safe, but it’s sloppy. Some records need less time, others need more, and some should be kept permanently.

Revenue’s general record-keeping guidance and its VAT retention rules give the baseline for tax records. GDPR then adds the storage limitation test for anything containing personal data.

This quick reference shows what that usually looks like.

Record categoryTypical minimum retentionTriggerNotes
Financial, tax and accounting records6 yearsEnd of tax year or return periodRevenue baseline for most business records
VAT records6 years, or 10 years for OSS/MOSSEnd of relevant periodCross-border digital supplies can need longer
Payroll records6 yearsEnd of tax yearKeep longer if tied to a dispute or investigation
Working time, breaks and leave records3 yearsDate of record or relevant periodOrganisation of Working Time rules apply
Accident and health and safety records10 yearsDate of incidentSome sectors may need longer
Statutory books, board minutes, incorporation recordsPermanentNot applicableKeep as part of the company’s permanent record

That table is only a starting point. In practice, a mixed-records business will usually add categories such as unsuccessful recruitment files, often kept for about one year; parental and force majeure leave records, often eight years; and employment contracts, often for the duration of employment plus six years. Many employers keep core employee files for seven years after employment ends because claim and tax issues don’t always arrive neatly on schedule.

The trigger matters as much as the period. “Six years” from the wrong date is still wrong. Some periods run from the end of the tax year, others from employment end, incident date, contract expiry, or the end of a service relationship.

A good schedule also records the legal or business reason, the system where the file sits, the record owner, and the destruction method. If a dispute, complaint, audit, litigation, or Revenue review starts, normal deletion must stop for the affected records until the matter is closed.

Make paper and digital records work as one system

Mixed environments go wrong when paper and digital versions drift apart. One folder gets updated, the other doesn’t, and nobody knows which copy is the real one.

Start by naming the “system of record” for each document type. Supplier invoices may live in the finance platform. HR files may live in your HR system or a restricted SharePoint library. Signed board minutes may have both a paper original and a locked digital copy. Once that rule is set, staff stop saving the same item in five places.

Scanning needs a written standard. When paper arrives, decide whether the scanned copy becomes the official record. If it does, scan clearly, run OCR so the file is searchable, capture key metadata, and carry out a quick quality check before anyone destroys the original. Many businesses use PDF/A for long-term storage where their system supports it.

A simple naming rule helps more than people expect. Use a sortable date, document type, party name, and version number. For example, 2026-07-03_Supplier-Invoice_ABC-Ltd_45821.pdf is far easier to find than scan003_final_final.pdf.

Version control matters too. Drafts should not sit beside signed contracts with almost identical names. Keep one official final version, and make old drafts easy to identify or auto-delete after a short period.

For paper-heavy teams, Kefron’s guide to physical records is a useful reminder that plenty of legal obligations still start with physical documents. Still, don’t assume every paper original must stay forever. Some do, such as records with a real operational or legal need for the original form. Others can move safely to digital once your process is reliable and checked.

Build controls around access, backups and destruction

Retention is not only about keeping and deleting. It’s also about control while the record exists.

Access should follow the “least privilege” rule. HR and payroll files should not sit in a broad shared folder. Finance records should not be open to every manager. Use role-based permissions, multi-factor authentication for sensitive systems, and regular access reviews, especially after role changes or staff departures.

Audit trails matter because they show who viewed, edited, exported, or deleted a file. That matters for internal investigations, Subject Access Requests, and plain old accountability. If your document management system or Microsoft 365 environment can log activity, turn that on for high-risk record sets.

Backups need their own rules. A backup is for recovery, not for everyday filing and not as a lazy substitute for retention management. Keep backup copies encrypted, test restore procedures, and know how deleted records age out of backup sets. If old personal data lives forever in snapshots, your live system may be tidy while your backup estate is not.

Destruction needs the same discipline as storage. Paper should go into locked confidential bins or secure shredding, with a certificate or destruction report where needed. Digital records should be deleted from the live system, removed from recycle bins, and purged from connected repositories where your platform allows it. Old laptops, phones, printers with hard drives, and USB devices also need secure wiping or certified destruction.

If you want a practical benchmark for end-of-life handling, Shred-it’s retention guide is useful for disposal planning. The key point is simple: if you can’t show how records are destroyed, you haven’t finished the job.

Review the policy, then train people to use it

Even a smart policy fails if it only lives in a binder or on the intranet. Staff need short, role-based training that matches the work they actually do.

Show Finance how to file invoices and statements. Show HR how to manage leaver files and recruitment records. Show front-desk or admin staff what to scan, where to save it, and when paper can move to archive or destruction. Home-working staff also need rules for printed papers, local downloads, and mobile photos of documents.

Review the policy at least once a year. Review it sooner if you buy another business, add a new SaaS platform, move archive providers, or change your HR or finance system. Keep an eye on what the policy produces in real life, such as overdue archive boxes, duplicate files, failed restores, or shared folders packed with old personal data.

This is practical guidance, not legal advice. If your business is in healthcare, financial services, legal services, construction, education, or another regulated sector, ask your solicitor, accountant, DPO, or compliance lead to check the schedule against the rules that apply to you.

A policy people can follow

A strong retention policy is clear on three things: what the record is, how long it stays, and what happens at the end. That’s what keeps mixed paper and digital environments under control.

For Irish businesses, the hardest part is rarely the legal principle. It’s turning that principle into daily habits that staff can stick to. Get the schedule right, assign owners, and keep the process simple enough that compliance becomes normal office work, not a rescue job.