Guide and template

Data retention schedule template for universities

A retention schedule answers a simple question for every type of record: how long do we keep it, and what happens then? For universities the answer has to reconcile the GDPR's storage limitation principle with archives law, public access rules and research needs. This guide explains the rules, shows how Sweden and the UK handle the interplay, gives example periods taken from published sources, and includes a free Word template.

Published 7 October 2026 · Sources checked 7 October 2026

The short version

Contents

  1. What the GDPR requires
  2. Why archives law changes the picture
  3. Sweden: arkivlagen, public access and university disposal rules
  4. United Kingdom: records management code and university schedules
  5. How to build the schedule
  6. Example periods from published sources
  7. Research data
  8. Vendors, backups and deletion in practice
  9. Common mistakes
  10. The template
  11. Sources
  12. About this page

1. What the GDPR requires

Article 5(1)(e) GDPR, the storage limitation principle, says personal data must be "kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed". It continues: data may be stored for longer insofar as it will be processed solely for archiving in the public interest, scientific or historical research or statistical purposes in accordance with Article 89(1), with appropriate technical and organisational measures.

Several other provisions depend on retention decisions:

The UK ICO's guidance on storage limitation adds practical points: establish and document standard retention periods for different categories of information, review data at the end of the period, erase or anonymise it unless retention is justified, and do not keep data indefinitely "just in case".

2. Why archives law changes the picture

Universities that are public bodies usually have duties under national archives and public access law. Those duties can require records to be kept for a set time, or permanently, and can prohibit destruction without authority. Recital 158 GDPR recognises that public authorities and bodies holding records of public interest may have legal obligations to acquire, preserve, appraise and provide access to records of enduring value.

Validemic's analysis The practical consequence is that a university retention schedule has two sources of truth that must agree: the data protection view (how long is the data necessary for this purpose?) and the records view (what does archives law require or allow?). Where archives law requires preservation, the GDPR does not override it, but the records kept for archiving should be protected and used only for that purpose. Where archives law permits disposal after a period, storage limitation is a reason to actually dispose of the records at that point rather than keeping them by default.

3. Sweden: arkivlagen, public access and university disposal rules

Most Swedish higher education institutions are state agencies, so the Archives Act (arkivlag 1990:782) applies to them. Its key provisions for retention are:

In practice, state universities dispose of records under regulations issued by the National Archives (Riksarkivet). Its regulations RA-MS 2017:39 on return and disposal at universities and university colleges were most recently amended by RA-MS 2026:31, decided on 22 June 2026 and in force from 29 June 2026. The appendix lists record types, the disposal period ("gallringsfrist") and exceptions. Some examples appear in section 6 below.

Swedish data protection law preserves this framework. Chapter 1, section 7 of the Data Protection Act (dataskyddslagen 2018:218) says the GDPR and the Act do not apply to the extent that they would conflict with the Freedom of the Press Act or the Fundamental Law on Freedom of Expression. Chapter 3, section 6 allows sensitive personal data to be processed for archiving in the public interest where necessary to comply with archives rules.

University privacy notices reflect this. Stockholm University explains that, because it must follow the rules on public records under the Freedom of the Press Act and the Archives Act, some personal data may be kept permanently. Uppsala University's data protection policy states that personal data is kept only as long as the purpose requires or as required by law, and refers to the Freedom of the Press Act, the Archives Act and the National Archives' regulations.

4. United Kingdom: records management code and university schedules

In the UK, section 46 of the Freedom of Information Act 2000 requires a code of practice giving guidance to relevant authorities on the keeping, management and destruction of their records; the Act, as amended, gives that function to the Secretary of State. Universities that are public authorities under Schedule 1 of the Act fall within this framework. Retention periods themselves are mostly set by each institution, drawing on legal requirements such as immigration, tax and employment rules.

The University of Edinburgh is a published example. Its student records retention schedule (version 23, October 2025) is organised by record, with the owner of the "golden copy", the retention period, the trigger that starts the period, the disposition (archive, destroy, transfer) and an explanation. The university states that its schedules set out the minimum time it needs to keep records, and asks colleges and schools to use the schedule as a guide to create their own definitive schedules. It also publishes a separate "core archival student record" defining which student data is kept permanently.

The UK sector has also used shared higher education retention guidance. We could not access Jisc's pages on the check date, so this guide does not describe them; if you use them, check the current version directly.

Reviewing a vendor right now? Validemic checks the vendor's documents against GDPR and the EU AI Act and cites every finding. Try the demo workspace

5. How to build the schedule

  1. Start from functions and record series. Admissions, student records, assessment, research, HR, finance, library, IT, estates. Within each, list record series (for example "unsuccessful applications" or "exam scripts"), not systems.
  2. Record the authority for each period. A statute, an archives regulation, a contract or funder condition, a limitation period, or an internal decision with a written reason. The authority column is what lets you defend the period later.
  3. Define the trigger. "Seven years" means nothing without a starting point: end of studies, date of decision, end of contract, end of project, publication.
  4. Define the end action. Destroy, anonymise, transfer to the archive, return to the person, or review. Say who does it and how it is recorded.
  5. Map to systems and vendors. For each series, note where the records live, including cloud services. Deletion has to happen in each place.
  6. Connect to the rest of the compliance set. Use the same periods in privacy notices, the record of processing activities and data processing agreements.
  7. Assign owners and review. Each series needs an owner who confirms the period and triggers disposal. Review the schedule when law or processes change, and at least periodically.

6. Example periods from published sources

The periods below are quoted from published sources as read on 7 October 2026. They show how real schedules express periods and triggers. They are not recommendations: Swedish periods apply to Swedish state universities under Swedish rules, and Edinburgh's periods are one institution's decisions.

RecordPeriod and triggerEnd actionSource
Applications with attachments, first and second cycleMay be disposed of 2 years after the admission decision, if the application is registered in the admissions or student registerDisposalRA-MS 2017:39 as amended by RA-MS 2026:31 (Sweden)
Written exam answers on paper not returned to the student; electronic exam answersMay be disposed of 2 years after gradingDisposal; one copy of the exam paper is kept (with an exception for question banks)RA-MS 2026:31 (Sweden)
Audio and video recordings of examinationsMay be disposed of 2 years after the examinationDisposalRA-MS 2026:31 (Sweden)
Course evaluationsMay be disposed of 2 years after a summary has been preparedDisposal; the summary is preservedRA-MS 2026:31 (Sweden)
Applications for degree or course certificatesMay be disposed of 2 years after issue or refusal, if registeredDisposal; degree and course certificates themselves are preservedRA-MS 2026:31 (Sweden)
Core student information, including nameIn perpetuity, from completion of studiesArchive, to verify degrees awardedUniversity of Edinburgh student records schedule (UK)
Library information2 years from completion of studiesDestroyUniversity of Edinburgh (UK)
Student academic appeal case records5 years from end of caseDestroyUniversity of Edinburgh (UK)
Student funding applicationsSuccessful: 7 years; unsuccessful: 1 year; from completion of studiesDestroyUniversity of Edinburgh (UK)

Two patterns stand out. First, both sources separate the core record (kept long-term or permanently) from supporting documents (disposed of after a short period once the core record is registered). Second, both tie the period to a clear trigger. The template uses the same structure.

7. Research data

Research is where storage limitation and archiving meet most often. Article 5(1)(e) allows longer storage for research and archiving with Article 89(1) safeguards, and Article 89(1) requires that data which no longer needs to identify people should not do so. In practice that suggests layered periods within one project:

In Sweden, the university disposal rules refer to separate National Archives regulations on records in state agencies' research activities, and advise that applications and decisions on granted research funding should be exempted from disposal. Whatever the national rules, the periods must also appear in the participant privacy notice: see our research participant privacy notice guide.

8. Vendors, backups and deletion in practice

Most university records now live partly in vendor systems: the learning platform, the exam tool, the survey service, the CRM. A schedule that says "delete after 2 years" is only effective if:

Our DPA checker highlights the deletion and return clause, and the vendor assessment guide includes retention questions for suppliers. When a data subject asks for erasure, the schedule also tells you whether an Article 17(3) exception applies: see our guide to data subject requests.

9. Common mistakes

  1. "As long as necessary". Not a period. WP260 says it is not sufficient in a privacy notice, and it gives staff nothing to act on.
  2. No trigger. Periods without a starting event cannot be applied consistently.
  3. Systems instead of records. The learning platform holds many record series with different periods.
  4. Ignoring archives law. Deleting public records without authority can breach archives rules; keeping everything forever breaches storage limitation.
  5. Schedule never executed. No owner, no disposal routine, no disposal log.
  6. Pseudonymised treated as anonymous. The ICO notes pseudonymised data usually still permits identification.
  7. Inconsistent periods. Different numbers in the schedule, the privacy notice and the ROPA.
  8. Vendors forgotten. The schedule says 2 years, the vendor keeps data for the life of the contract.

10. The template

The retention schedule template for universities is a Word document containing:

Example periods in the template are illustrations, not recommendations. Set your own periods with your records manager, archivist, legal office and DPO, under the law that applies to your institution. The template is not legal advice.

Sources

  1. Regulation (EU) 2016/679 (GDPR), Articles 5, 13, 14, 17, 28, 30 and 89 and Recital 158, Official Journal text (retrieved 7 October 2026).
  2. Article 29 Working Party, Guidelines on transparency (WP260 rev.01), endorsed by the EDPB, Annex (retrieved 7 October 2026).
  3. ICO: Principle (e): Storage limitation (retrieved 7 October 2026).
  4. Arkivlag (1990:782), sections 3 and 10 (retrieved 7 October 2026).
  5. Lag (2018:218) med kompletterande bestämmelser till EU:s dataskyddsförordning, chapter 1 section 7 and chapter 3 section 6 (retrieved 7 October 2026).
  6. Riksarkivet, RA-MS 2026:31, amending RA-MS 2017:39 on return and disposal at universities and university colleges, in force 29 June 2026 (retrieved 7 October 2026).
  7. Kommittédirektiv Dir. 2026:5, on the organisational form of state universities (retrieved 7 October 2026).
  8. Stockholm University: Personuppgiftsbehandling vid Stockholms universitet (retrieved 7 October 2026).
  9. Uppsala University: Dataskyddspolicy (retrieved 7 October 2026).
  10. Freedom of Information Act 2000, section 46 (retrieved 7 October 2026).
  11. University of Edinburgh: University retention schedules and Student Records Retention Schedule, version 23, October 2025 (retrieved 7 October 2026).

About this page

Sources checked on 7 October 2026. The legal text was read in its Official Journal version; Swedish law on riksdagen.se; the Riksarkivet regulation and the Edinburgh schedule in their published PDF versions. Example periods are quoted from those sources and are not recommendations. Statements labelled as Validemic's analysis are our interpretation. This page is not legal advice. If you spot an error, or a schedule we cite has changed, please contact us and we will correct it.

Frequently asked questions

Does the GDPR set retention periods?

No. Article 5(1)(e) says personal data must be kept in identifiable form no longer than necessary for the purposes. Concrete periods come from national law (archives, accounting, employment, immigration), sector rules and the controller's own justified decisions.

Do archives rules override the right to erasure?

Article 17(3) lists situations where the right to erasure does not apply, including where processing is necessary to comply with a legal obligation or for archiving in the public interest under Article 89(1). In Sweden, for example, Stockholm University explains that public records rules mean some personal data may be kept permanently.

What should a retention schedule contain?

For each record series: a description, the personal data involved, the retention period, the event that starts the period (the trigger), the action at the end (destroy, anonymise, archive, transfer), the authority or reason for the period, the owner and the system where the records are held.

Can we keep data just in case it is useful later?

The ICO says you should not keep personal data indefinitely just in case, or if there is only a small possibility that you will use it. Longer retention needs a reason, such as a legal obligation, a limitation period or an Article 89 archiving or research purpose with safeguards.

Is pseudonymised data outside the retention schedule?

No. The ICO notes that pseudonymised data usually still permits identification, so storage limitation continues to apply. Only properly anonymised data falls outside the GDPR.

Where should retention periods appear besides the schedule?

In privacy notices (Articles 13(2)(a) and 14(2)(a)), in the record of processing activities where possible (Article 30(1)(f)), in data processing agreements with vendors, and in research data management plans.