Phone SeizedUnited KingdomHow long police can keep your phone data
How long police can keep your phone data
What you must do, what you can refuse, and what they can do
Every claim below links to the law it comes from, with the wording quoted so you can check it yourself.
Limits on them
A rule that constrains them, or a remedy you can use.
Personal data processed by police for law enforcement purposes must be processed lawfully and fairly.
Data Protection Act 2018, s.35(1)
“The first data protection principle is that the processing of personal data for any of the law enforcement purposes must be lawful and fair.”
Read it at legislation.gov.ukquote checked 2026-09-08
Personal data processed by police for law enforcement purposes must be adequate, relevant and not excessive for the purpose it is processed for.
Data Protection Act 2018, s.37
“The third data protection principle is that personal data processed for any of the law enforcement purposes must be adequate, relevant and not excessive in relation to the purpose for which it is processed.”
Read it at legislation.gov.ukquote checked 2026-09-08
Personal data processed by police for law enforcement purposes must be kept for no longer than is necessary for the purpose it was processed for.
Data Protection Act 2018, s.39(1)
“The fifth data protection principle is that personal data processed for any of the law enforcement purposes must be kept for no longer than is necessary for the purpose for which it is processed.”
Read it at legislation.gov.ukquote checked 2026-09-08
Data revealing things like racial or ethnic origin, political opinions, religious beliefs or trade union membership is treated as a more sensitive category of personal data under the Act.
Data Protection Act 2018, s.35(8)(a)
“In this Part , “ sensitive processing ” means— the processing of personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs or trade union membership”
Read it at legislation.gov.ukquote checked 2026-09-08
Anything seized under PACE, or produced under a production requirement, may be retained only for as long as is necessary in all the circumstances — not for a fixed period.
Police and Criminal Evidence Act 1984, s.22(1)
“anything which has been seized by a constable or taken away by a constable following a requirement made by virtue of section 19 or 20 above may be retained so long as is necessary in all the circumstances.”
Read it at legislation.gov.ukquote checked 2026-09-08
PACE Code B tells officers that anything seized may be retained only for as long as is necessary.
PACE Code B (2023), para 7.14
“anything seized in accordance with the above provisions may be retained only for as long as is necessary”
Read it at assets.publishing.service.gov.ukquote checked 2026-09-08
Information extracted from a device and found not relevant must be deleted, unless there's a lawful basis to keep it.
Extraction of Information from Electronic Devices: Code of Practice (Oct 2022), para 138
“Information which is extracted and deemed not relevant must be deleted unless there is a lawful basis to retain it.”
Read it at assets.publishing.service.gov.ukquote checked 2026-09-08
The ICO found police data-extraction practices vary across forces, with excessive amounts of personal data often extracted, stored and made available to others without an appropriate basis in existing data protection law.
ICO, Mobile phone data extraction by police forces in England and Wales (June 2020)
“police data extraction practices vary across the country, with excessive amounts of personal data often being extracted, stored, and made available to others, without an appropriate basis in existing data protection law.”
Read it at ico.org.ukquote checked 2026-09-08
The ICO recommended the Government strengthen the legal framework with a statutory code, to make the law sufficiently clear and foreseeable.
ICO, Mobile phone data extraction by police forces in England and Wales (June 2020), Recommendation 1
“The Government should strengthen the current legislative framework by producing a statutory code or other equivalent measure to ensure the law is sufficiently clear and foreseeable.”
Read it at ico.org.ukquote checked 2026-09-08
The general data protection duty
Separately from any specific power to seize or extract, the Data Protection Act 2018 imposes its own baseline rules on how police handle personal data for law enforcement purposes. Processing has to be lawful and fair. It has to be adequate, relevant and not excessive for the purpose it is used for. And it has to be kept for no longer than is necessary for that purpose.
Some categories get extra weight: data revealing things like racial or ethnic origin, political opinions, religious beliefs or trade union membership is treated as a more sensitive category under the Act — relevant given how much of that kind of information an ordinary phone can hold.
PACE's own version of the same test
PACE has its own retention rule, running alongside the data protection one: anything seized, or produced under a production requirement, may be retained only for as long as is necessary in all the circumstances. PACE Code B gives officers the identical instruction. Neither sets a number of days, weeks or months — “necessary” is judged against the facts of the individual case, not a clock.
What has to be deleted after an extraction
Where a phone’s data has actually been extracted under the voluntary-agreement power, the rule tightens further: information that is extracted and found not relevant must be deleted, unless there is a lawful basis to retain it. Nothing in the materials this site relies on sets a deadline for when that deletion has to happen — only that it must, eventually, if there is no lawful basis to keep the material.
The regulator's own verdict
None of this is theoretical. The Information Commissioner’s Office reviewed how forces were actually applying these rules and found that practices varied across the country, with excessive amounts of personal data often extracted, stored, and made available to others without an appropriate basis in existing data protection law. Its recommendation was a proper statutory code — not more guidance layered on top of what already existed.
Last reviewed 2026-09-08. Next review due 2027-03-08. No lawyer has reviewed this page — see [email protected] if you think something here is wrong.