DATA RETENTION POLICY
ProfileAbility seeks to ensure that it retains only data necessary to effectively conduct its program activities and work in fulfilment of its mission. The need to retain data varies widely with the type of data and the purpose for which it was collected. ProfileAbility strives to ensure that data is only retained for the period necessary to fulfil the purpose for which it was collected and is fully deleted when no longer required. This policy sets forth ProfileAbility’s guidelines on data retention and is to be consistently applied throughout the organization.
Scope
This policy covers all data collected by ProfileAbility and stored on ProfileAbility owned or leased systems and media, regardless of location. It applies to both data collected and held electronically (including photographs, video and audio recordings) and data that is collected and held as hard copy or paper files. The need to retain certain information may be mandated by federal or local law, federal regulations and legitimate business purposes, as well as the EU General Data Protection Regulation (GDPR).
Reasons for Data Retention
ProfileAbility retains only that data that is necessary to effectively conduct its program activities, fulfill its mission and comply with applicable laws and regulations.
Reasons for data retention include:
- Providing ongoing service to the data subject (e.g. sending a newsletter, publication or ongoing program updates to an individual, ongoing training or participation in ProfileAbility’s programs, processing of employee payroll and other benefits)
- Compliance with applicable laws and regulations associated with financial and programmatic reporting by ProfileAbility to its funding agencies and other donors
- Compliance with applicable labor, tax and immigration laws
- Other regulatory requirements
- Security incident or other investigation
- Intellectual property preservation
- Litigation
Data Duplication
ProfileAbility seeks to avoid duplication in data storage whenever possible, though there may be instances in which for programmatic or other business reasons it is necessary for data to be held in more than one place. This policy applies to all data in ProfileAbility’s possession, including duplicate copies of data.
Retention Requirements
ProfileAbility has set the following guidelines for retaining all personal data as defined in the Institute’s data privacy policy.
Data Destruction
Data destruction ensures that ProfileAbility manages the data it controls and processes it in an efficient and responsible manner. When the retention period for the data as outlined above expires, ProfileAbility will actively destroy the data covered by this policy. If an individual believes that there exists a legitimate business reason why certain data should not be destroyed at the end of a retention period, he or she should identify this data to his/her supervisor and provide information as to why the data should not be destroyed. Any exceptions to this data retention policy must be approved by ProfileAbility’s data protection offer in consultation with legal counsel. In rare circumstances, a litigation hold may be issued by legal counsel prohibiting the destruction of certain documents. A litigation hold remains in effect until released by legal counsel and prohibits the destruction of data subject to the hold.