Data Retention Policy Gdpr Template

Hence this policy should be applicable on a company wide basis for all the employees.
Data retention policy gdpr template. Therefore some mention must be made as to the data processors retention of consumer data and what will happen to the data upon termination of the project or contract. The document is optimized for small and medium sized organizations we believe that overly complex and lengthy documents are just. Data protection policy 11 appendix 2 data retention schedule summary 1. It explains the gdprs requirements to employees and states the organisations commitment to compliance.
Sample data protection policy template. Purpose of this document. This policy sets the required retention periods for specified categories of personal data and set out the minimum standards to be applied when destroying certain information within a company. A data protection policy is an internal document that serves as the core of an organisations gdpr compliance practices.
Data retention deletion. We provide example gdpr document templates and also a complete set of gdpr templates in order. A vital part of the colleges data protection policy and practice is that personal data is retained for the appropriate period of time neither too long nor too short. White fuse has created this data protection policy template as a foundation for smaller organizations to create a working data protection policy in accordance with the eu general data protection regulation.
This data retention policy is designed primarily to set out the limits that apply to the various types of personal data held by a business to establish the criteria by which those limits are set and to set out how personal data should be deleted or disposed of. Most organizations implementing the gdpr consider retention policies or retention rules necessary to achieve this. The gdpr requires that a data processor must delete or return all consumer data after the business arrangement has ended. The gdpr comes with a set of rules and regulations for the protection of personal data inside and outside the european union eu and affects all companies that save personal data from european citizens.
The gdpr contains explicit provisions about documenting your processing activities. You may be required to make the records available to the ico on request. You must maintain records on several things such as processing purposes data sharing and retention.