Is there anything tricky about a Data Retention Policy? Does anyone get a headache thinking about what to include in the policy and what outcomes it will help achieve? Is drafting a Data Retention Policy a simple matter of slapping a few policy statements into a document and calling it a “Data Retention Policy”? Or is there more?
To answer these questions, we’ve had to put on our curiosity hat. We’ve had to reflect on all the conversations we’ve had with clients over the years about data retention, data deletion, and retention schedules. We’ve had to stubbornly pursue (as any good lawyer would) a number of helpful answers so that we can give you an overview.
Here we are, then, about to plunge into the icy waters of the Data Retention Sea…
What is a Data Retention Policy?
Conventional wisdom says a Data Retention Policy is a collection of policy statements about an organisation’s stance on data retention. It is typically an internal policy that tells employees (and perhaps contractors and other third parties) why an organisation retains information and why it no longer retains it. The policy can also be external, although, in a data protection context, people usually use a Privacy Policy to speak to an external audience about data retention.
Generally, a Data Retention Policy addresses an organisation’s retention of personal information, but it can also cover confidential information or other types of information. People usually use the policy to address data protection law requirements about how long organisations may keep the personal information they process. Additionally, some policies we’ve encountered also address data deletion and set out the organisation’s general stance.
How does a Retention Schedule fit into the picture?
From what we’ve seen, the trouble starts with the generic, principles-based provisions in most data protection laws (such as section 14 of POPIA) about how long an organisation may keep information. Most of these laws tell you to keep information only as long as necessary and delete it as soon as it is no longer needed. These laws speak about you keeping the information for the original purpose for which you collected it (except in the case of lawful further processing, of course). The two main exceptions to this general requirement are that you may keep it if a law allows you to, or if you have the data subject’s consent.
Most of these laws will usually only tell you that you should keep information for as long as is necessary and delete it as soon as keeping it is no longer necessary.
This, while seemingly simple, is often the part that gives people headaches. They create Retention Schedules to set out the different laws that require them to keep information for specific periods. But these Retention Schedules have a potentially fatal flaw: how does an organisation find out about and consolidate these laws? The answer is especially tricky when you consider that laws change, and that some apply to all organisations while others apply only to organisations in certain sectors or industries.
Is managing data retention an impossible mission?
We say no. You can create a useful Retention Schedule. You don’t need to be Tom Cruise to do it. Our experience shows it’s tricky but doable. The answer starts with deciding whether to use data protection software or do it manually. We can help you choose the best software for your organisation. Just complete this software requirements form, and we will be in touch with the next steps.
The manual route is harder to travel, but we can help you there too. It involves a good amount of research, to be sure, but it’s not a road that’s impossible to navigate.
So, are you ready to jump with us into the icy waters of the Data Retention Sea?