Document summary
This policy defines retention scheduling, review, legal holds, secure disposal, backups, and execution evidence without publishing unapproved periods.
Principles
Data is not retained merely because storage is convenient. Each record has a purpose, owner, classification, period, start and end trigger, and disposal method. The shortest suitable period is used unless contract, obligation, or dispute requires otherwise.
Retention schedule
An internal register manages category, system, basis, period, start event, and exceptions. This page does not publish unapproved fixed periods. Applicable periods appear in a product notice, contract, or consent register where needed.
Typical categories
Categories include account and security data, requests and tickets, Council content, contracts and invoices, files, audit logs, privacy requests, and consents. Each has separate rules and no single period applies to all data.
Legal holds
A documented legal hold pauses disposal for defined records during a dispute, investigation, or obligation. It records owner, scope, reason, and review date and does not become indefinite retention. Details are restricted to authorized staff.
Disposal and anonymization
The method matches media and sensitivity, such as secure deletion, irreversible cryptographic erasure, or anonymization preventing reasonable re-identification. Hiding a record from the interface is not disposal.
Backups
Backups follow a separate encrypted, restricted lifecycle. A deleted record is not reintroduced from an older backup without applying the post-restore deletion list. Restore and disposal are tested periodically.
Disposal runs and evidence
Execution starts with a dry run listing affected records, exceptions, and holds. The run records success, failure, count, time, and approval without copying sensitive data into a permanent log.
Relationship to rights requests
A destruction request is reviewed against schedule, obligation, and hold. We explain what was deleted and retained and why. The retention policy is not used to reject a request without assessing the specific record.
Review
Data owners review periods when purpose, system, contract, or risk changes. Extending a period requires a reason and approval and is not applied retroactively to data promised for deletion without a suitable basis.
Official references
References used to prepare this content
Links point to official legal or guidance sources. Applicability depends on the organization, product, and contract.
Versions
Change log
- Version 1.0.0
Published the first operational version with clear scope, responsibilities, rights, and escalation routes.