ResourcesArticles

Five Years, Not Forever: Data Retention Under MAR

Home addresses, phone numbers and ID numbers may appear on insider lists. This article explains what MAR requires, how long records must be kept, and what the EU removed from the regime in 2026.

22 September 2026

8 minutes

data protection

Introduction

Home addresses, personal phone numbers and dates of birth are among the personal data that may need to be retained under the Market Abuse Regulation (MAR).

This creates a tension between MAR and data protection law. MAR imposes a five-year retention requirement. By contrast, the UK and EU GDPR require personal data to be kept no longer than necessary.

Deleting records too early can leave a firm unable to produce the required audit trail. The Financial Conduct Authority (FCA) has said it expects firms to respond to information requests within two business days. However, keeping records indefinitely “just in case” can create a separate GDPR storage-limitation breach.

Firms should therefore apply clear retention periods to MAR records and delete personal data once the relevant retention requirement has expired. They should also ensure that personal data collected for MAR purposes is not retained unnecessarily on other, non-MAR lists.

The following explains what MAR and its subsequent amendments require, and how those duties can be aligned with data protection law.

What data needs to be retained and for how long

Article 18(5) of MAR requires issuers to retain each insider list for a period of at least five years after it is drawn up or updated. This applies to both the EU and UK MAR. An insider list that changes every time someone gains or loses access is not one document with a single five-year deadline. Each update starts its own five-year period running from the date of that update, which in practice means a live, frequently amended list never really reaches its retention deadline while it stays active. The obligation only starts counting down properly once a version stops being touched.

FCA guidance is specific about what is required for insider lists, and it goes beyond names and job titles. The mandatory template sets out national identification numbers (National Insurance numbers, for most UK nationals), dates of birth, personal telephone numbers and a full personal home address, and Market Watch 71 confirms the regulator uses that detail to cross-reference against transaction reports when it investigates suspected market abuse. That is exactly the kind of data GDPR treats with the most caution, which is precisely why the retention question cannot be answered by MAR alone.

Because the clock restarts on every update, the practical requirement is not to keep a single spreadsheet with old rows overwritten. It is to keep the version history: who was on the list on any given date, what changed and when. A regulator investigating a leak from eighteen months ago needs the list as it stood then. An overwritten file cannot answer that question, however current it looks.

Where does GDPR fit in?

GDPR's storage limitation principle says personal data should be kept no longer than is necessary for the purpose it was collected for, which sounds like it sits in tension with a regulation ordering five years of retention on National Insurance numbers and phone numbers. It is not, provided the retention stays inside its purpose.

MAR's mandatory retention period gives issuers a lawful basis for holding that data under Article 6(1)(c) of the UK GDPR: processing necessary for compliance with a legal obligation. Retention becomes a GDPR problem the moment it runs past what MAR requires, whether that is a list kept for eight years because nobody set a deletion date, data retained on a list that is not considered an insider list for purposes of MAR or contact details for a contractor kept on file long after their engagement and their five-year window both ended. The FCA's own guidance (found here, in MW 71) points to a workable middle ground: firms can store personal data separately from the substantive insider list and consolidate the two only when a request comes in, which limits day-to-day exposure of sensitive fields without weakening the record the regulator will eventually see.

Listing Act changes

The Listing Act (for further reading, have a read here) left the five-year retention duty alone, and that part has not changed: five years remains the number. What has changed is the type of data that is required to be collected. The EU's wider set of MAR amendments in the Listing Act package, including a narrower disclosure duty for protracted processes and a reworded test for delayed disclosure, took effect on 5 June 2026. The insider list format followed close behind: the European Commission adopted Implementing Regulation (EU) 2026/1291 on 12 June 2026, replacing the old templates with a single, lighter one for every issuer rather than only those on SME growth markets, effective from 5 July 2026. The new EU template drops personal home addresses and personal telephone numbers from the mandatory fields, and asks for a national identification number or, failing that, a date of birth, rather than both. A lighter requirement for data collection.

What happens to lists drawn up before 5 July 2026 is left unaddressed by the new regulation itself, and no briefing on it has filled that gap either. One could reason that Article 18(5)'s five-year clock attaches to the record as it was drawn up or updated. Nothing requires reformatting a historic list or stripping fields out of it early, and doing so would undercut the same version-history logic this piece already makes. The forward-looking obligation is simpler: any entry added or list updated in the EU from 5 July 2026 follows the new, lighter template, and once an old version's own five-year window lapses, it is deleted like any other expired version, just without ever having been forced to shed its old fields sooner.

What about confidential lists?

Confidential lists are not regulated under MAR, so Article 18's five-year duty never attaches to one. A confidential list, also called a project list, sensitive list or grey list, is market practice rather than law: a private record of who has access to information that is not yet inside information but might become so, kept to remind those people of their confidentiality obligations before there is a statutory reason to. Nothing in MAR names it, requires it or sets a retention period for it, and no regulator has published guidance filling that gap, because the tool sits outside MAR's scope.

That absence does not make retention a non-issue. A confidential list's purpose can be that its contents often graduate into inside information, at which point everyone on it moves onto the statutory insider list, and from that moment their record does fall under the five-year duty, running from the date of that conversion. A company that cannot show when someone was added to the confidential list, and why, weakens its own ability to demonstrate exactly when access began, which is usually the first question an investigator asks. Separately, without MAR's legal obligation to lean on, GDPR's storage limitation principle governs confidential list data on its own terms rather than as a mandated period. There is no five years to borrow, so a retention period has to be set and justified by purpose, how long the record genuinely needs to exist to evidence the company's own information controls, rather than fixed by habit or by analogy with the insider list sitting next to it.

So the sensible default is to set a retention period for confidential lists deliberately and separately from insider lists, generally shorter than five years, with one exception: once a person's entry converts to a statutory insider list record, Article 18's clock takes over from that point.

Final thoughts and practical tips

Firstly, it is necessary to set a deletion policy that tracks the update, not the list. Every time an insider list changes, that version's five-year clock starts on that date, so a single blanket "delete after five years" rule applied to the whole file will delete active records too early. Keep the full version history rather than an edited master copy, since that is the only form a regulator's request can be answered from. Separate the sensitive personal data from the rest of the record where practical, consolidating it only when it is needed, and build the deletion date for each version into whatever system tracks the list in the first place, so retention stops depending on someone remembering. Give confidential or other non-MAR lists their own, shorter retention period rather than inheriting the insider list's five years by default, and flag the point at which an entry should migrate onto the statutory list.

That is the manual overhead insider list software exists to remove. InsiderList has a data retention module that keeps every version of every list with its own dated history and applies retention automatically, so the record a regulator asks for is the one you actually have, and nothing sits on the server a day longer than MAR requires.

Leading compliance teams use InsiderList.

Schedule a product demo to see why.