HMRC has issued a paper outlining the outlining its records management and retention and disposal policy, which must also be supported by any third parties handling HMRC documentation
HMRC says the principles have been developed to provide a consistent approach to managing records throughout their lifecycle and regardless of their format. The aim is to ensure the effective delivery of services, as well as documenting HMRC’s principle activities and maintaining the corporate memory.
A record can be defined as information created, received, and maintained as evidence and information by an organisation, in pursuance of legal obligations or in the transaction of business.
The policy states that information created by staff on behalf of HMRC belongs to the department and must be reviewed and disposed of routinely and in accordance with line of business retention and disposal schedules.
All systems and records must have designated owners throughout their lifecycle, while digital continuity must be considered for the systems and formats that are used to store digital records. All records must be traceable and retrievable.
The default standard retention period for HMRC records is six years plus current, otherwise known as six years + one. This is defined as six years after the last entry in a record followed by first review and/or destruction to be carried out in the additional current (+ 1) accounting year.
Records must only be retained beyond the default HMRC retention period if their retention can be justified for statutory, regulatory, legal or security reasons or for their historic value. The disposal periods for records retained for extended duration must be included within line of business retention schedules.
The maximum retention period for HMRC records identified as having historic value is defined as 20 years after the last entry in the record, with an additional one calendar year for final review and transfer or destruction.
Storage and destruction of records can be undertaken by third parties contracted for those purposes, provided that it is compliant with the DPA 1998 and the government-wide policy on offshoring. All parties must agree on what data is shared, levels of information security, who should have access, what the disposal arrangements are, and who has ownership. Processes must be in place to ensure that records pending audit, litigation or investigation are not destroyed.
Records must be securely destroyed in accordance with departmental security policy. Processes must be in place to ensure that all backups and copies are included in the destruction of record.
HMRC lines of business must audit and monitor the secure disposal of their own records as well as those of any third parties that share or produce records on their behalf.
HMRC records management and retention and disposal policy is here.