Skip to content

Records Retention Policy

Field Value
Reference POL-007
Type Policy
Version 1.00
Status Approved
Owner Data Protection Lead
Approver Board
Approval Reference MIN-2026-08-02
Effective Date 2026-08-05
Next Review 2027-08-05
Review Requirements As defined in STD-001
Classification Internal

Purpose

To set out how long BRSA keeps different categories of records, and why - so that records are kept no longer than actually needed (the UK GDPR storage limitation principle, for personal data), while still meeting legal, financial, and governance obligations that require keeping some records for a set period.

Scope

Applies to all BRSA records, not only personal data - membership records, financial records, Committee Minutes, correspondence, and backups. The Privacy Policy (POL-004) gives members and website visitors a short public summary of personal data retention; this document is the fuller internal schedule behind it.

Retention Schedule

Category Retention Period Basis
Membership records (active members) Duration of membership, plus [2 years - to be confirmed by Committee] after it ends Re-engagement, dispute resolution
Financial records (invoices, expenses, bank records) 6 years from the end of the financial year they relate to Standard UK practice for financial record-keeping
Committee Minutes (MIN-) Retained permanently The organisation's own historical governance record
Confidential Minutes (CONF-) [To be confirmed - see note below] Varies by content; some categories (e.g. safeguarding) may need longer retention than others
DSAR request records 3 years after the request is closed Evidencing compliance with UK GDPR
Breach records (PROC-003) Retained permanently UK GDPR Article 33(5) requires all breaches to be documented; no statutory time limit, but ongoing evidence of accountability is good practice
Website/contact form submissions As long as needed to resolve the enquiry, subject to the form provider's own settings Data minimisation
Backups Governed by the existing OCI Object Storage lifecycle policy (Archive tier after 7 days, deleted after 180 days) Operational, set independently of this policy - see infrastructure documentation
General correspondence (email) As long as operationally useful, subject to mailbox provider retention settings No specific legal requirement identified

Note on Confidential Minutes: unlike Committee Minutes, not every category of confidential business should necessarily be kept indefinitely - some (for example, safeguarding matters) may have specific legal or best-practice retention requirements that are longer than BRSA's general default, and others may warrant earlier review or redaction once a matter is resolved. This needs a considered decision by the Committee, ideally with reference to guidance for the specific category involved, rather than a single blanket period.

Disposal

Records past their retention period should be deleted or securely disposed of, not simply left in place indefinitely by default. Where practical, disposal should be logged (for example, as part of a periodic Committee review) so there is a record that data minimisation is actually being carried out, not just documented as a policy.

  • POL-001 Data Protection Policy
  • POL-004 Privacy Policy
  • PROC-003 Data Breach and Incident Response
  • PROC-004 Data Subject Access Requests

Review Requirements

As defined in STD-001.

Change History

Version Date Author Summary
0.10 2026-07-23 DC Initial draft
0.50 2026-07-24 DC Version -> 0.50; Status -> Review
1.00 2026-08-05 DC Version -> 1.00; Approval Reference -> MIN-2026-08-02; Status -> Approved; Effective Date -> 2026-08-05; Last Reviewed -> 2026-08-05; Next Review -> 2027-08-05