
How Long to Keep Tenant Records After a Tenancy — A Schedule You Can Run
Open a five-row keep-vs-delete calendar, stamp tenancy-end the day keys return, write a keep-until date and reason, then weed yearly.
Rental operations notes from the IziRento team. Not legal advice.
Key takeaways
A tenant-record retention schedule is a keep-vs-delete calendar for this let: one row per record type with a keep-until date and a plain-English reason. UK GDPR does not set a year figure; the ICO says you justify how long from purpose, then review and erase or anonymise. Stamp tenancy-end the day keys return. Book a yearly review. Delete or anonymise rows with no live dispute. Sit the one-pager next to the folder, not as a second copy of every PDF.
Keys are back. The crate — or Drive dump — is labelled keep forever. There is no tenancy-end stamp, no keep-until date per record type, and no review day. Open one keep-vs-delete calendar for this let today: five rows, stamp yesterday as tenancy-end, write a keep-until date and a reason on each row, and pick a yearly weed date. UK GDPR does not set how many years; you write the period you can justify.
Sunday, one let in Preston. Keys came back yesterday. Clem has a crate of every AST — the assured shorthold tenancy agreement — rent screenshot, repair WhatsApp, notice, and two unsuccessful-applicant packs, labelled keep forever. The problem is no tenancy-end date and no review day. Typical mistake: leaving the crate shut because digital takes no space. The risk is a former tenant asking what is still held.
UK GDPR does not set a retention period in years. The ICO’s storage-limitation page — Article 5(1)(e) — is explicit: no specific time limits; that is up to you. Justify how long from purpose, document standard periods by category, then review and erase or anonymise. Do not keep indefinitely just in case.
Disclaimer: IziRento is operations software, not legal advice. Local tenancy rules vary; check a qualified adviser for binding decisions.
How do you open a keep-vs-delete calendar?
A keep-vs-delete calendar is one sheet for this let, not a second Drive of every PDF. Write record type, a start date, keep until, a plain-English reason, live dispute yes or no, and the action at review. Sit it next to the property folder. Do not photocopy the crate.
Do write those columns today. The ICO retention toolkit wants each category documented: how long, why, and the action after. Tag a retention date. Article 30 documentation, if you keep records, wants retention schedules for different categories — granular, not one dump. For example, Clem’s crate is not a schedule. The problem a forever label creates is that nothing has an end date.

Keep forever is not a purpose
Digital taking no space is not a reason to hold names. The ICO forbids keeping personal data indefinitely just in case.
Which five rows do you write?
Write one row each for the tenancy agreement, the rent and deposit money trail, repairs correspondence, notices, and the unsuccessful-applicant pack. Each row needs a period you can justify and a reason in plain English. Unsuccessful applicants are not former tenants. They get their own shorter row.
Do write five different clocks. ICO small-org storage advice uses Claire: a quote not taken up, so she deleted the details. Do not park viewing-week ID packs on the former-tenant clock. The signed current agreement lives in the tenancy agreement folder; this row is when that file’s keep-until hits. A dated export from an outgoing agent is the handover property file, not this calendar.

Keep-vs-delete calendar for this let
| Record type | Start date | Keep until | Reason | Live dispute? | At review |
|---|---|---|---|---|---|
| Tenancy agreement | keys returned | your date | show the tenancy existed and ended | yes/no | keep/delete/anonymise |
| Rent and deposit trail | same stamp | your date | show what was paid, protected or returned | yes/no | keep/delete/anonymise |
| Repairs correspondence | same stamp | your date | show what was reported and done | yes/no | keep/delete/anonymise |
| Notices | same stamp | your date | show notice given or received | yes/no | keep/delete/anonymise |
| Unsuccessful applicant pack | let filled / offer withdrawn | earlier date | selection-process complaint only | yes/no | keep/delete/anonymise |
When to stamp the tenancy-end date?
Stamp the date keys returned on the former-tenant rows the same day. If last-slept differs from keys-back, write both. Keep-until is then a calendar day, not whenever you next open the crate. Unsuccessful-applicant start date is not keys-back. It is the day it was clear no tenancy would proceed.
Do write yesterday on Clem’s agreement, rent, repairs and notices rows. After a relationship ends you may need a record that it existed and has ended; delete what you are unlikely to need again. Do not leave keep-until as a vague period after whenever. Workflow: stamp keys-back → write period and reason → keep-until date → yearly weed → delete or anonymise.

How do you write a keep-until date?
Turn each documented period into a calendar date: start date plus the period you can justify from purpose. UK GDPR sets no year figure. If another law you already follow requires a set period, put it in that row’s reason cell only.
Do write a date you can defend. The ICO: justify how long; industry guidelines are a starting point only and do not guarantee compliance. A small possibility of future use is not enough. If another legal requirement says keep a record, write that period in the reason cell. In practice: Clem writes a keep-until date on each row today. Do not invent a UK GDPR year-clock.
What to do on the yearly review day?
Pick a fixed day each year and put it in the diary. Walk every row — paper, Drive, email, phone. If keep-until has passed and live dispute is no, delete or anonymise. If a dispute is open, extend that row only, with a new date and a one-line reason.
Do set one review day. The ICO has no firm rule on how often — justify frequency from resources and privacy risk. Peter the newsagent (ICO small-org example) writes a period, shreds at the end, and annually checks. Typical mistake: freezing the whole crate because one deposit row is in dispute. A live claim is a hold on that row. The right to erasure is not absolute where you still need the data to defend legal claims. The open deposit file itself is the deposit dispute evidence pack.
Offline is still holding the data
A labelled loft box is still personal data. Deletion means beyond use, including backups. Key-coding names is not anonymising.
What to keep beside the folder?
The schedule is a one-pager next to the property folder: types, purposes, how long, action after. It is not a second copy of every PDF. Tag the folder. Delete means beyond use, including backups. Anonymise only if people are no longer identifiable.
Do file the one-pager beside the folder, not as a photocopy of the crate. ICO anonymisation guidance: anonymous information is not personal data; key-codes with a lookup still identify people. Success bar: Sunday opens one sheet — five rows, keys-back stamp, keep-until dates, a yearly weed in the diary. Verify that checklist, then stop. An IziRento workspace can hold this calendar and folder tags as related records on this let.
Run the keep-vs-delete calendar
Open one calendar for this let
Record type, start date, keep until, reason, live dispute, action at review. Sit it next to the folder.
Write five rows
Agreement, rent and deposit, repairs, notices, unsuccessful applicant. Write how long and why.
Stamp tenancy-end the day keys return
Write that date on former-tenant rows the same day. Applicants: stamp the day no tenancy would proceed.
Turn each period into a keep-until date
Start date plus the period you can justify from purpose. Do not copy a blog’s year table as UK GDPR.
Book a yearly review day
If keep-until has passed and there is no live dispute, delete or anonymise. If a dispute is open, extend that row only.
Put expired data beyond use
Delete live copies and backups, or anonymise so people are no longer identifiable.
FAQ
Do I keep unsuccessful applicants as long as former tenants?
No. Separate, shorter row. Stamp the day no tenancy would proceed, not keys-back. The ICO’s job-application analog: do not keep them beyond the period a selection claim may be brought, unless you write a clear reason.
What if a deposit dispute is still open when the date hits?
Do not shred that row on autopilot. Extend it only, with a clear justification for defending legal claims. See the deposit dispute evidence pack.
Can I keep everything just in case?
No. The ICO: do not keep indefinitely just in case. Write a period and a reason, review yearly, delete or anonymise what has no live dispute.
Does boxing files in the loft count as deletion?
No. Offline storage is still processing. Deletion means putting the data beyond use, including backups.
Is key-coding names the same as anonymising?
No. Anonymise only if people are no longer identifiable. A lookup held separately is still personal data.
How often must I review the schedule?
There is no firm statutory anniversary. Review at the end of each standard period and at regular intervals. A yearly weed is a workable default for one let.
Keep the calendar on this let
Hold the keep-vs-delete sheet and folder tags on this property.
Try the workspaceOpen a five-row keep-vs-delete calendar, stamp tenancy-end the day keys return, write a keep-until date and reason, then weed yearly.
Sources
Next steps
Related articles

How to Assemble Material Information for a Rental Listing Before It Goes Live

What Rent You Can Take Before Move-In — After the Agreement Is Signed

How to Advertise One Asking Rent and File the Decline of Any Bid Above It

How to File a Mutual Surrender When a Tenant Wants to Leave Before Notice Runs

Tenant Swap in a Shared House: File the Named-Tenant Change Without Crossing Out a Name

What to Include in a Reference for a Former Tenant (Facts You Can Evidence)
This material is for information only and is not legal advice.