Records Retention Policy¶
| Field | Value |
|---|---|
| Reference | POL-007 |
| Type | Policy |
| Version | 1.00 |
| Status | Approved |
| Owner | Data Protection Lead |
| Approver | Board |
| Approval Reference | MIN-2026-08-02 |
| Effective Date | 2026-08-05 |
| Next Review | 2027-08-05 |
| Review Requirements | As defined in STD-001 |
| Classification | Internal |
Purpose¶
To set out how long BRSA keeps different categories of records, and why - so that records are kept no longer than actually needed (the UK GDPR storage limitation principle, for personal data), while still meeting legal, financial, and governance obligations that require keeping some records for a set period.
Scope¶
Applies to all BRSA records, not only personal data - membership records, financial records, Committee Minutes, correspondence, and backups. The Privacy Policy (POL-004) gives members and website visitors a short public summary of personal data retention; this document is the fuller internal schedule behind it.
Retention Schedule¶
| Category | Retention Period | Basis |
|---|---|---|
| Membership records (active members) | Duration of membership, plus [2 years - to be confirmed by Committee] after it ends | Re-engagement, dispute resolution |
| Financial records (invoices, expenses, bank records) | 6 years from the end of the financial year they relate to | Standard UK practice for financial record-keeping |
Committee Minutes (MIN-) |
Retained permanently | The organisation's own historical governance record |
Confidential Minutes (CONF-) |
[To be confirmed - see note below] | Varies by content; some categories (e.g. safeguarding) may need longer retention than others |
| DSAR request records | 3 years after the request is closed | Evidencing compliance with UK GDPR |
| Breach records (PROC-003) | Retained permanently | UK GDPR Article 33(5) requires all breaches to be documented; no statutory time limit, but ongoing evidence of accountability is good practice |
| Website/contact form submissions | As long as needed to resolve the enquiry, subject to the form provider's own settings | Data minimisation |
| Backups | Governed by the existing OCI Object Storage lifecycle policy (Archive tier after 7 days, deleted after 180 days) | Operational, set independently of this policy - see infrastructure documentation |
| General correspondence (email) | As long as operationally useful, subject to mailbox provider retention settings | No specific legal requirement identified |
Note on Confidential Minutes: unlike Committee Minutes, not every category of confidential business should necessarily be kept indefinitely - some (for example, safeguarding matters) may have specific legal or best-practice retention requirements that are longer than BRSA's general default, and others may warrant earlier review or redaction once a matter is resolved. This needs a considered decision by the Committee, ideally with reference to guidance for the specific category involved, rather than a single blanket period.
Disposal¶
Records past their retention period should be deleted or securely disposed of, not simply left in place indefinitely by default. Where practical, disposal should be logged (for example, as part of a periodic Committee review) so there is a record that data minimisation is actually being carried out, not just documented as a policy.
Related Documents¶
- POL-001 Data Protection Policy
- POL-004 Privacy Policy
- PROC-003 Data Breach and Incident Response
- PROC-004 Data Subject Access Requests
Review Requirements¶
As defined in STD-001.
Change History¶
| Version | Date | Author | Summary |
|---|---|---|---|
| 0.10 | 2026-07-23 | DC | Initial draft |
| 0.50 | 2026-07-24 | DC | Version -> 0.50; Status -> Review |
| 1.00 | 2026-08-05 | DC | Version -> 1.00; Approval Reference -> MIN-2026-08-02; Status -> Approved; Effective Date -> 2026-08-05; Last Reviewed -> 2026-08-05; Next Review -> 2027-08-05 |