DBS record keeping and certificate retention
An employer can make a sound recruitment decision and still leave behind a weak DBS record. One file may contain an unprotected scan of a certificate. Another may contain only a tick saying “DBS done”, with no evidence of which worker, role, certificate type or decision the tick describes. Both make later review difficult. The aim is to keep enough information to explain the check and the decision, while protecting and disposing of certificate information that no longer has a justified purpose.
There is an important distinction at the centre of this task. A record that a check was carried out is not the same as the certificate or a copy of its contents. The DBS sample handling policy allows a limited record of the issue date, subject's name, type of certificate requested, position, certificate reference number and recruitment decision. It also explains secure handling, limited retention and disposal of the certificate information itself. Employers should read the whole policy. Quoting only the disposal paragraph can produce the misleading claim that no certificate can ever be retained for any period or purpose.
The Information Commissioner's Office guidance on criminal offence data adds another layer. Even a record of a clear criminal-record check can involve criminal offence data. Collecting less information reduces risk, but it does not remove the need to identify and document the lawful basis, relevant authorisation and safeguards for the information actually processed. A recruitment team should agree the record design with its privacy lead before it scales the workflow across staff, volunteers and contractors.
Start with the decision the record must support
Before deciding which fields to save, ask what a future reviewer must be able to establish. They may need to confirm that the check related to the person who started work, that the level was appropriate for the actual duties, that a decision maker reviewed the result and that any later review was considered under the organisation's policy. A date alone cannot answer all of that. Nor is an unstructured certificate scan a suitable substitute for a decision record.
Separate three events. First, the organisation decides whether the role is eligible for a check and what type it may lawfully request. Second, the certificate is issued and the employer reviews it for the recruitment or engagement decision. Third, the organisation may set a later review or recheck date under its own policy or sector requirements. Those events should not collapse into one “expiry date” field. DBS employer guidance says a DBS certificate has no official expiry date. It is a snapshot at issue. An internal review date is a management decision, not a claim that the certificate legally expires then.
The current DBS eligibility guidance supports the first decision. This page owns the record after a lawful check has been requested. It cannot turn an ineligible role into an eligible one through tidy paperwork. If the team is unsure about the level or barred-list element, resolve that question before recording the check as satisfactory.
What belongs in a limited check record?
The DBS sample policy identifies a narrow group of details an organisation may record after certificate information is disposed of: the date of issue, the name of the person, the type of certificate requested, the position, the unique certificate reference number and the details of the recruitment decision. That list is a useful core. An employer may also need to record who checked the evidence, when, and which internal policy version governed the later review. Those extra workflow details are a proposed operational design, not a DBS permission to keep the certificate's disclosure contents. The privacy lead should decide whether each field is necessary.
| Record field | Why a reviewer may need it | Boundary |
|---|---|---|
| Worker identity | Match the record to the right person. | Do not place the record against another worker with a similar name. |
| Actual position or assignment | Explain the duties for which the check was requested. | A broad job title cannot prove eligibility on its own. |
| Certificate type and issue date | Show the check obtained and its age when assessed. | Do not relabel the issue date as a statutory expiry date. |
| Certificate reference | Support a later audit trail where justified. | Restrict access because this is still sensitive check information. |
| Decision and decision date | Show that a responsible person considered the check for the role. | Avoid copying conviction or police-information text into a general worker profile. |
| Reviewer and policy review date | Make the internal handoff and next review clear. | These are employer process fields, not details promised by every software product. |
The decision entry deserves care. “Certificate clear” may be accurate in some cases, but a check can reveal information that the employer considers through a fair recruitment process. Record the outcome and the reason at the level necessary for accountability. If detailed reasons involve criminal offence information, keep them in the restricted decision file with a documented retention basis. Do not add them to a broad personnel dashboard merely to make an audit convenient. The applicant should have a fair opportunity to discuss relevant information under the organisation's recruitment process.
An employer should also avoid making the certificate reference the only proof that a review occurred. A reference number without a named decision maker, role and date does not explain whether the employer actually saw and considered the certificate. Conversely, a manager's note saying “satisfactory” with no evidence of which check was reviewed may be difficult to defend months later. The right design connects identity, duties, certificate details and decision without retaining the entire disclosure as a default.
May an employer keep a certificate copy?
The answer is conditional. The DBS sample policy says certificate information is kept no longer than necessary after the recruitment or other relevant decision. It recognises time needed to deal with disputes or complaints and to complete safeguarding audits. It also notes that organisations inspected by CQC or Ofsted, and certain Welsh inspected establishments, may be legally entitled to retain a certificate for inspection. It identifies possible retention for safer recruitment evidence in safeguarding audits, subject to data-protection and human-rights requirements and the organisation's written policy. “May” is not a blanket permission for every employer or every certificate.
At the end of the justified period, the sample policy calls for secure destruction and says no photocopy, image or representation of the certificate contents should remain. The limited record of check can remain where properly justified. That sequence is different from both extremes: automatic permanent storage of every certificate and an assertion that even temporary or specifically justified retention is forbidden. The organisation must determine its own sector obligation, purpose, lawful basis, period and safeguards. A privacy or legal specialist should review any proposed exception before it becomes routine.
An employer that claims an inspection reason should be precise. Which regulator may inspect the service? What evidence does its current guidance require? Does it ask for a certificate copy, a record that the certificate was seen, or a wider recruitment record? Who will be able to access it? When will the reason end? A generic statement that “auditors might ask” is a poor retention policy. If the team cannot answer those questions, it should not create an indefinite archive of certificate images.
The same discipline applies to a live dispute. A complaint about the recruitment decision can make short retention necessary while the complaint is handled. The file should identify the complaint and the relevant information, the person authorising retention and the next review date. When the matter closes, reassess rather than allowing the certificate to drift into a general personnel file. If litigation or another legal obligation changes the retention decision, obtain case-specific advice and document it.
Written policy, lawful basis and authorisation
The DBS handling guidance says its code of practice requires registered bodies to have a written policy on the correct handling and safekeeping of certificate information. It also says a registered body should ensure an organisation on whose behalf it countersigns applications has a policy. The sample policy covers use, storage, access, retention, disposal and the people who may see the information. An employer using an umbrella body should confirm which party holds what and how the policy applies at each handoff.
A handling policy should describe a real workflow, not a promise that the team cannot meet. Name the decision maker, the approved storage location, the people with access, the default disposal trigger and the procedure for an exception. Say how records are protected when someone leaves the recruitment team. State how paper certificates are returned or securely destroyed and how electronic copies are removed from controlled stores. Include a way to review accidental copies in inboxes, shared folders and backups under the organisation's data governance process.
The ICO explains that criminal offence data needs a general lawful basis and official authority or a relevant Data Protection Act 2018 Schedule 1 condition. Its guidance says organisations may also need an appropriate policy document for the condition they rely on. That document covers compliance measures and retention. Do not assume that an applicant's consent to a DBS application is automatically the employer's lawful basis for every later use or storage decision. The ICO's conditions guidance expressly distinguishes these questions.
The law, DBS code and DBS sample policy have different roles. The law sets data-protection and disclosure restrictions. The code sets obligations for registered persons. The sample policy is a model organisations can adapt. A sector regulator may impose additional evidence expectations. The employer should map each statement in its own policy to the source that supports it. That mapping helps prevent a copied template from becoming an inaccurate claim about every organisation.
Control access while the information is held
The DBS sample policy says certificate information should be kept in secure, lockable, non-portable storage, with access limited to people entitled to see it for their duties. Paper that is left on a desk or placed in ordinary confidential-waste sacks awaiting collection does not meet the intended control. For digital handling, the employer should apply equivalent restricted access, secure transfer and a deletion process that can be evidenced. The source does not prescribe a specific software vendor or encryption design for every organisation, so technical controls need an internal risk assessment.
Map the journey of the information. The candidate may show a certificate to a recruiting manager. A central HR team may check identity and issue details. A safeguarding lead may need to review relevant information. An umbrella body may have handled the application without holding the same information as the employer. Each person should know what they may see and record. The DBS policy says a record should be kept of people to whom certificate information has been revealed. Avoid emailing a copy to everyone involved merely because the final decision needs several approvals.
If a worker changes role, re-examine whether the existing check fits the new duties before reusing the record. A change of workforce or barred-list eligibility can make an old check unsuitable. This is a question for the current DBS guidance on accepting a previous certificate and the eligibility guidance. The record-keeping system should flag a new decision rather than silently carrying “approved” from one assignment to another. A record of a valid decision for one role is not a universal clearance for all work.
Set disposal triggers that can actually be followed
“Delete when no longer needed” is a sound principle but a poor operational instruction on its own. Define the ordinary event that starts disposal. It may be completion of the recruitment decision plus a policy period justified for a dispute, complaint or safeguarding audit. Define who checks whether an exception applies. Then define the method: secure destruction for paper, controlled deletion for digital information and an auditable completion record. Do not leave a paper certificate in a waste bin while waiting for destruction. The DBS sample policy specifically warns against insecure storage while disposal is pending.
Retention periods vary with the purpose and sector. Do not turn one example into a universal statutory rule. The Department for Education's school record-management guidance lists a six-month period for copies of DBS certificates in its school staff-record table. That is a school-specific guidance example, not proof that every UK employer must keep copies for six months. Some organisations may need less; an evidenced exception may require a different period. Ask the sector and privacy owner to approve the schedule and the precise trigger.
A defensible disposal record does not need to repeat the disclosure. It can show the category of information destroyed, the relevant worker record identifier, the date, the authorised person and the reason the retention period ended. If the organisation keeps a limited check record after disposal, access and retention for that remaining record still need review. The fact that DBS permits certain metadata in its sample policy does not make indefinite storage automatically necessary under data-protection principles.
Build a review date without inventing DBS expiry
Recruiters often need a prompt to review a check, particularly for long-running roles or repeated assignments. Set the date from the organisation's policy and any sector rule, and label it “next review” or “next recheck”. Record the reason for the chosen interval. Do not tell workers that a DBS certificate becomes legally invalid at a universal two-year or three-year point. DBS employer guidance says there is no official expiry date and advises considering the issue date when deciding whether to request a newer check.
The official DBS Update Service may support status checks for eligible Standard and Enhanced certificates where its conditions are met and the individual consents. A subscription is not a permanent green light. The employer must ensure the level, workforce and other conditions match the actual role and understand what a status result means. Complys has no verified Update Service integration. A manually entered date in a worker record does not show that a live DBS status check occurred.
Create a review queue with a named owner. Before the date arrives, confirm the worker still performs the duties for which the check was assessed. At the review, decide whether a fresh DBS application, an eligible Update Service status check or a documented decision to continue under policy is appropriate. Record what was actually done. A reminder is only a prompt to make a decision. It is not the decision itself and it does not refresh the underlying certificate.
Three cases that test the policy
A small charity recruits a volunteer. The manager sees an eligible certificate, records the person's identity, role, certificate type, issue date and the recruitment decision, and sets a policy review date. A scan arrives by email from the volunteer. The team should not leave that image in an unrestricted inbox. It should decide whether a specific short retention purpose exists, move any justified copy into controlled storage and remove the stray attachment according to policy. If there is no justified reason to keep the image, dispose of it securely while preserving the limited record. Volunteer fee status and check eligibility remain separate questions under the DBS volunteer guidance.
A school prepares for inspection. The safeguarding team says it needs evidence that checks were undertaken. It first identifies what current school guidance and its inspector actually require. The Department for Education table gives a school-specific period for certificate copies, while the DBS sample policy recognises possible inspection retention. The team documents the basis, restricts access, sets a destruction date and maintains the appropriate check record. It should not extrapolate the school's practice to an unrelated business. Current school safeguarding guidance governs the school recruitment process.
An agency sends a worker to a new placement. The agency's old record shows a check, but the receiving organisation needs assurance that the worker, duties, workforce and level match the new assignment. The parties agree what evidence each can lawfully share and who makes the acceptance decision. They do not solve the handoff by sending an unrestricted certificate image to a general site mailbox. The agency and receiving organisation must assess the placement decision separately; this page covers the resulting record and retention controls.
Where software helps and where it stops
Complys can link generic document records to a worker and support configured date reminders. Label a DBS review date as a policy review, never as certificate expiry. A team may use those dates to track its own review policy. The current product evidence does not verify dedicated structured fields for DBS level, workforce, barred-list element, certificate reference or recruitment decision. It does not verify an Update Service status integration, application service or DBS-specific export. An employer that needs those fields should establish where they are captured and how they are protected before saying its DBS record is complete.
The existence of a document upload option is not a reason to upload a certificate. The employer decides whether any actual certificate content should be retained, for how long and in which approved restricted store. That decision needs the DBS handling policy and the privacy analysis above. Keep disclosure details out of broad dashboards, routine evidence packs and sales demonstrations. If a product workflow cannot enforce the agreed restriction and deletion schedule, use a more suitable controlled location for the exceptional material.
The practical value of a tracker is visibility of people, dates and assigned reviews. It can help a manager see which worker record needs attention. It cannot decide DBS eligibility, make a recruitment judgement, query the Update Service or convert a policy date into a statutory expiry. Organisations evaluating worker records or review reminders should ask the product owner to demonstrate the exact workflow and fields before importing sensitive DBS information.
A concise audit of your current records
Take a sample of recent recruitments and existing workers. For each one, try to answer: Which person and role did the check relate to? Why was that check type appropriate? When was the certificate issued and reviewed? Who made the decision? What limited metadata remains? Does any certificate image still exist, including in email or shared storage? If it does, what specific reason and deadline support that retention? Who can access it? What policy review date is next? A missing answer is a useful repair task, not proof that the worker is unsuitable.
Next compare the answers with the written handling policy. If practice and policy diverge, fix the workflow, train the people handling certificates and schedule a follow-up sample. Do not create more copies to compensate for missing metadata. Do not fill gaps with an invented expiry date. Where the correct legal basis, sector rule or retention exception is disputed, involve the privacy, safeguarding and legal owners before changing records in bulk.
For an employer establishing a new process, begin with the DBS handling guidance and the ICO criminal offence data guidance. Agree the limited record, access list, exception test, disposal trigger and review owner. Then test the process on real recruitment cases. A record is defensible when it explains the decision and respects the person's information throughout its life.
Not sure which level applies?
Our free DBS eligibility guidance checker walks you through the official criteria and points you to the guidance to confirm against. It is guidance, not a legal determination.
Open the DBS eligibility checker →Official sources and further guidance
- Department for Education school record keeping. Sector guidance. The six-month certificate-copy entry is a school example only. Confirm current KCSIE and local policy before school-specific use.
This guidance is maintained by the Complys team and reviewed against the primary DBS and GOV.UK sources listed above, and it was last reviewed on 24 September 2026. It is general information, not legal advice, and DBS rules can change, so always confirm against the official sources.
Related DBS guides
- DBS checks (hub)What a DBS check is, the Basic, Standard, Enhanced and Enhanced-with-barred-list levels, who is eligible, employer responsibilities and the 2026 regulated-activity change, a plain-English UK guide.
- DBS checks for employersHow UK employers establish eligibility, request the correct level of DBS check through the proper route, check identity, handle certificates lawfully and keep safer-recruitment records.
- DBS Update ServiceHow the DBS Update Service works for employers: it covers Standard and Enhanced certificates only, needs the individual's consent and your legal entitlement, and what a status check does and does not tell you.
- DBS compliance softwareSoftware to help organisations get DBS compliance right and keep it right, establish the correct check level for each role, record that checks were completed, keep review reminders, and hold an audit-ready safer-recruitment record within the official handling rules.