Retention Policy
Data Retention Policy for Active Photographic Ltd
I. Purpose
The purpose of this Data Retention Policy is to establish clear guidelines for the retention, storage, and disposal of personal data collected by Active Photographic Ltd. This policy ensures compliance with data protection regulations, including the General Data Protection Regulation (GDPR), and protects the rights of individuals.
II. Scope
This policy applies to all employees, contractors, and volunteers involved in the collection, processing, and storage of personal data within Active Photographic Ltd. It encompasses all types of data, including but not limited to:
- Photographs of students and staff
- Names and contact details
- Order information
- Payment details
III. Data Retention Guidelines
A. General Principles
1. Data Minimisation: Only data necessary for specific purposes will be collected.
2. Retention Periods: Data will be retained only for as long as necessary to fulfill its intended purpose or as required by law.
B. Specific Retention Periods
1. Photographs:
- Active Use: Digital images will be retained for a period of 12 months for reorders and customer enquiries.
- Archiving: After 12 months, images will be archived securely for 3 additional years for potential retrieval related to inquiries or support.
- Anonymisation: After 3 years, identifying data will be removed, and images will be stored in a non-identifiable format for potential historical or educational use.
2. Order Information:
- Retained for a period of 6 years to comply with financial and tax regulations.
3. Payment Details:
- Credit card and payment information will be securely deleted immediately after processing transactions. Transaction records will be retained for 6 years for auditing purposes.
4. Contact Information:
- Retained for the duration of the relationship with the client or until the individual requests deletion. If inactive for 3 years, contact information will be deleted.
C. Special Categories of Data
If Active Photographic Ltd collects any special categories of data (e.g., health-related information), such data will be retained only for the duration necessary to fulfill it's purpose and in compliance with applicable laws.
IV. Data Disposal Procedures
When the retention period expires, personal data will be securely disposed of according to the following procedures:
1. Electronic Data:
- Data stored electronically will be deleted using secure data destruction methods to ensure it cannot be recovered.
- Backup copies will also be deleted or anonymized as per the retention schedule.
2. Physical Records:
- Paper records will be shredded or otherwise destroyed to prevent unauthorized access to personal information.
V. Review and Updates
This policy will be reviewed annually or whenever there are significant changes to regulations or business practices. Employees will be informed of any updates or changes.
VI. Responsibilities
All staff members are responsible for adhering to this Data Retention Policy. The Data Protection Officer (DPO) will oversee compliance and provide training and guidance as necessary.
VII. Contact Information
For questions regarding this Data Retention Policy or to request data deletion, please contact the Data Protection Officer at admin@activephoto.co.uk.
---
This Data Retention Policy is effective as of 10/08/2024. All staff must comply with this policy to ensure the responsible management of personal data within Active Photographic Ltd.
I. Purpose
The purpose of this Data Retention Policy is to establish clear guidelines for the retention, storage, and disposal of personal data collected by Active Photographic Ltd. This policy ensures compliance with data protection regulations, including the General Data Protection Regulation (GDPR), and protects the rights of individuals.
II. Scope
This policy applies to all employees, contractors, and volunteers involved in the collection, processing, and storage of personal data within Active Photographic Ltd. It encompasses all types of data, including but not limited to:
- Photographs of students and staff
- Names and contact details
- Order information
- Payment details
III. Data Retention Guidelines
A. General Principles
1. Data Minimisation: Only data necessary for specific purposes will be collected.
2. Retention Periods: Data will be retained only for as long as necessary to fulfill its intended purpose or as required by law.
B. Specific Retention Periods
1. Photographs:
- Active Use: Digital images will be retained for a period of 12 months for reorders and customer enquiries.
- Archiving: After 12 months, images will be archived securely for 3 additional years for potential retrieval related to inquiries or support.
- Anonymisation: After 3 years, identifying data will be removed, and images will be stored in a non-identifiable format for potential historical or educational use.
2. Order Information:
- Retained for a period of 6 years to comply with financial and tax regulations.
3. Payment Details:
- Credit card and payment information will be securely deleted immediately after processing transactions. Transaction records will be retained for 6 years for auditing purposes.
4. Contact Information:
- Retained for the duration of the relationship with the client or until the individual requests deletion. If inactive for 3 years, contact information will be deleted.
C. Special Categories of Data
If Active Photographic Ltd collects any special categories of data (e.g., health-related information), such data will be retained only for the duration necessary to fulfill it's purpose and in compliance with applicable laws.
IV. Data Disposal Procedures
When the retention period expires, personal data will be securely disposed of according to the following procedures:
1. Electronic Data:
- Data stored electronically will be deleted using secure data destruction methods to ensure it cannot be recovered.
- Backup copies will also be deleted or anonymized as per the retention schedule.
2. Physical Records:
- Paper records will be shredded or otherwise destroyed to prevent unauthorized access to personal information.
V. Review and Updates
This policy will be reviewed annually or whenever there are significant changes to regulations or business practices. Employees will be informed of any updates or changes.
VI. Responsibilities
All staff members are responsible for adhering to this Data Retention Policy. The Data Protection Officer (DPO) will oversee compliance and provide training and guidance as necessary.
VII. Contact Information
For questions regarding this Data Retention Policy or to request data deletion, please contact the Data Protection Officer at admin@activephoto.co.uk.
---
This Data Retention Policy is effective as of 10/08/2024. All staff must comply with this policy to ensure the responsible management of personal data within Active Photographic Ltd.