DATA RETENTION POLICY WITH SCHEDULE
of
Myco Design Limited
Introduction
As part of the day-to-day running of our business, we collect and process personal data from a variety of sources. This personal information is collated in several different formats including letters, emails, legal documents, employment records, operations records, images and statements. The personal data is stored both as a hard copy and in electronic form.
Aims of the policy
Our business will ensure that the personal data that we hold is kept secure and that it is held for no longer than is necessary for the purposes for which it is being processed. In addition, we will retain the minimum amount of information to fulfil our statutory obligations and the provision of goods or/and services – as required by data protection legislation, including the General Data Protection Regulation (GDPR).
Retention
This retention policy (along with its schedule), is a tool used to assist us in making decisions on whether a particular document should be retained or disposed of. In addition, it takes account of the context within which the personal data is being processed and our business practices.
Decisions around retention and disposal are to be taken in accordance with this policy.
As and when the retention period for a specific document has expired, a review is always to be carried out prior to the disposal of the document. This does not have to be time-consuming or complex. If a decision is reached to dispose of a document, careful consideration is to be given to the method of disposal.
Responsibility
Clair Hunt is responsible for keeping this retention schedule up to date in order to reflect changing business needs, new legislation, changing perceptions of risk management and new priorities for our business.
Clair Hunt is responsible for determining (in accordance with this Policy) whether to retain or dispose of specific documents.
Disposal
Our business must ensure that personal data is securely disposed of when it is no longer needed. This will reduce the risk that it will become inaccurate, out of date or irrelevant.
The methods of disposal are to be appropriate to the nature and sensitivity of the documents concerned and include:
- Non-Confidential records: shred documents
- Confidential records: shred documents
- Deletion of Computer Records
- Transmission of records to an external body
- Cloud storage
The table below contains the retention period that we have assigned to each type of record. This will be adhered to wherever possible, although it is recognised that there may be exceptional circumstances which require documents to be kept for either shorter or longer periods.
Exceptional circumstances should be reported to Clair Hunt Office Manager/Data Officer without delay.
Date created: 18.10.2024
Date of review: 20.10.2024
Appendix 1: Document retention schedule
Commercial contracts:
Type of record | Retention period | Where is it stored? | Reason | Method of deletion |
Contracts with suppliers | 6 years after last action | Secure server | Services contract | *Electronic files deleted |
Purchase orders and invoices | 7 years after last action | Secure server | Financial audits | *Electronic files deleted |
Tax and Accounting Records:
Type of record | Retention period | Where is it stored? | Reason | Method of deletion |
Tax returns | n/a | Accounting software/Accountants/HMRC | n/a | n/a |
Accounting & financial management information | n/a | Accounting software/Accountants | n/a | n/a |
Operational records:
Type of record | Retention period | Where is it stored? | Reason | Method of deletion |
Closed circuit television recordings | Destroy 4 weeks from the date recorded except where required as evidence | Secure server | Security for the office | *Delete the electronic files |
Fire Risk Assessments | Retain until superseded | Secure server | Legal requirement | *Delete the electronic files |
Policies/Procedures | 7 years | Secure server | Updated annually, legal requirement | *Delete the electronic files |
Complaints | 6 years from end of fiscal year | Secure server | To refer back to, training, CPD | *Delete electronic files |
Building (i.e. lease/deeds) | Destroy 6 years after property is no longer occupied | Secure server/folders | Legal requirement | *File deleted/paper files shred |
Maintenance contracts | 15 years from last action | Secure server | Work guarantee | *File deleted/paper files shred |
Property plans and surveys | 25 years | Secure server | Legal requirement | *File deleted/paper files shred |
Insurance schedules | 10 years after last action | Secure server | Legal requirement | *File deleted/paper files shred |
Pat tests, fire hazard tests | Retain until superseded | Secure server | Legal requirement/H&S | *File deleted/paper files shred |
Register of members | Life of company | Companies House | Legal requirement | n/a |
Memorandum of association | Life of company | Companies House | Legal requirement | n/a |
Register of directors and secretaries | Life of company | Companies House | Legal requirement | n/a |
Employer’s liability insurance certificates | Life of company | Secure server/Insurance company | Legal requirement | n/a |
Email records:
Type of record | Retention period | Where is it stored? | Reason | Method of deletion |
Email correspondence | Archive emails after 6 months | Secure server | To refer to if required | n/a |
*Recycle bin emptied – electronic files