Skip to main content
Categories
< All Topics
Print

Data Retention & Destruction Policy

1. Purpose

The purpose of this policy is to ensure that all research data, information assets, records and documentation created, received, processed or retained by the organisation are managed in a manner that protects confidentiality, privacy, information security and legal compliance. This policy establishes the principles governing the retention, storage, archiving and destruction of information throughout its lifecycle and supports compliance with applicable data protection legislation, including the UK GDPR, EU GDPR where applicable, and ISO 20252 requirements for documentation and records management.

2. Scope

This policy applies to all employees, contractors, moderators, researchers, fieldworkers, data processors, subcontractors and third parties who create, access, process or manage information on behalf of the organisation. It applies to all formats of information, including digital records, databases, survey responses, audio recordings, video recordings, transcripts, project files, reports, emails, paper records and backup media. The policy covers both personal data and non-personal data generated during market, opinion and social research activities.

3. Policy Statement

The organisation recognises that information should not be retained for longer than necessary. Personal data and research records shall only be retained for legitimate business, contractual, regulatory, quality assurance, audit or legal purposes. Retention periods shall be defined, documented and communicated to relevant parties, including clients, participants and subcontractors where appropriate. At the end of the applicable retention period, records shall be securely destroyed, deleted or anonymised in a manner that prevents unauthorised access, disclosure or recovery.

The organisation shall maintain records in a secure manner throughout their lifecycle and protect them against accidental loss, alteration, corruption, misuse or unauthorised disclosure. Records management processes shall support confidentiality, privacy, security and data integrity.

4. Primary Research Records

Primary research records are the original source materials generated during the conduct of research and are the first documented evidence of information collected from participants or observations made during a study. These records may include completed questionnaires, interview notes, interviewer observation sheets, discussion guides containing participant responses, audio recordings, video recordings, transcripts, raw survey data, online response files, observational records and other original data collected directly from participants.

Primary research records differ from processed or analytical records because they contain the original information collected during the research activity before coding, cleaning, editing, weighting, analysis or reporting has taken place. They form an important part of the audit trail and may be required to demonstrate research quality, project traceability and methodological integrity. Under ISO 20252, primary records should be retained for a minimum period of twelve months unless a different period has been agreed with the client.

5. Retention of Research Records

The organisation shall retain project research activity records necessary to demonstrate project traceability, transparency and replicability for a minimum period of twenty-four months following project completion, unless a longer or shorter period has been contractually agreed with the client or required by law. Project records may include proposals, methodologies, sampling specifications, fieldwork instructions, questionnaires, coding frames, data processing records, analysis documentation, quality control records and final deliverables.

Primary research records shall be retained for a minimum period of twelve months following completion of the project unless otherwise agreed with the client. Where legitimate quality assurance, complaint investigation, legal, regulatory or contractual requirements exist, the retention period may be extended.

Information that directly identifies participants shall only be retained for as long as necessary to fulfil the purposes for which it was collected, including project administration, incentive fulfilment, participant support, audit activities and quality control procedures. Once these purposes have been fulfilled, identifying information shall be deleted, anonymised or otherwise rendered unusable unless continued retention is legally required or supported by valid participant consent. 

6. GDPR Principles

The organisation shall apply the GDPR principle of storage limitation by ensuring that personal data is kept in identifiable form only for as long as necessary to fulfil the stated research purposes. Retention decisions shall consider contractual obligations, participant expectations, legal requirements, information security risks and the potential impact on individual rights and freedoms. Data minimisation principles shall be applied throughout the retention lifecycle. 

Participants shall be informed, through privacy notices and participant information materials, of the categories of personal data collected, the purposes of processing, any intended retention periods or retention criteria, and any circumstances in which data may be archived, anonymised or reused. ISO 20252 specifically requires participants to be informed regarding proposed uses, retention and reuse of personal data.

7. Secure Storage and Archiving

All retained records shall be stored within approved organisational systems and protected through appropriate technical and organisational security measures. Electronic records shall be protected through access controls, authentication mechanisms, encryption where appropriate, backup arrangements and monitoring processes. Physical records shall be stored in secure facilities with controlled access and appropriate safeguards against loss, theft or damage.

Archived records shall remain subject to the same confidentiality and security controls as active records. Access shall be restricted to authorised personnel with a demonstrable business need. 

8. Destruction of Records

When a retention period expires, records shall be securely destroyed in a manner appropriate to the sensitivity of the information. Electronic records shall be permanently deleted using approved secure deletion methods so that recovery is not reasonably possible. Physical records containing confidential or personal information shall be cross-shredded, pulped, incinerated or destroyed through an approved confidential waste provider. Evidence of destruction may be retained where required for audit or compliance purposes.

The organisation shall take reasonable measures to ensure that destruction methods preserve the confidentiality of participants and satisfy GDPR requirements, including the ability to support the right to erasure where applicable.

Appendix 1: Retention Schedule

Record TypeMinimum Retention Period
Project research activity records24 months unless otherwise agreed with client
Primary research records12 months unless otherwise agreed with client
Participant identifying informationOnly for the period necessary for administration, quality control or agreed purposes
Final reports and deliverablesAs required by contract and business needs
Audit and compliance recordsAccording to legal, contractual and certification requirements

The minimum 24‑month retention period for project research activity records and 12‑month retention period for primary research records are specified within ISO 20252.

Table of Contents