Cookies & Privacy

We use cookies to keep the site working, understand how it is used and improve your experience. You can accept all or choose which ones to enable.Cookie Policy.

Back to About

Policy

Data Retention Policy

FORFIRM applies Data Retention and Secure Disposal principles to ensure data is retained only for as long as necessary and securely disposed of when no longer needed.

Purpose

FORFIRM is committed to ensuring that information is retained, managed and securely disposed of in accordance with business needs, legal requirements and data protection principles. The purpose of this policy is to: • establish principles for the retention and disposal of company information; • ensure that data is retained only for as long as necessary; • prevent unnecessary storage of outdated or irrelevant information; • protect confidential information and personal data throughout its lifecycle; • ensure compliance with applicable legal, regulatory and contractual obligations. Effective data retention supports business continuity, information security and responsible management of company resources.

Applicability

This policy applies to all FORFIRM employees at all levels of the organisation, including managers and senior management. The principles of this policy apply to all information managed by FORFIRM, including: • employee personal data; • customer and client information; • supplier and partner information; • contracts and agreements; • financial and administrative records; • project documentation; • electronic files and databases; • physical documents and records. Where applicable, this policy also applies to contractors, consultants, temporary workers and third parties authorised to process or access FORFIRM information. This policy should be read in conjunction with: • Internal Privacy Policy; • Data Protection and Confidentiality Policy; • Clean Desk and Physical Data Protection Policy; • Information Security Policy; • Acceptable Use Policy.

Definitions

Data Retention The process of keeping information for a defined period of time according to legal, contractual, operational or business requirements. Retention Period The period during which information must or may be maintained before being reviewed, archived or securely deleted. Data Disposal The secure destruction, deletion or removal of information when it is no longer required. Personal Data Any information relating to an identified or identifiable individual. Record Any document, file, electronic information or physical document created, received or maintained by FORFIRM as part of its business activities. Legal Hold A temporary suspension of normal data deletion requirements when information must be preserved due to legal proceedings, audits, investigations or regulatory requirements.

Roles and Responsibilities

Employees are responsible for managing information appropriately and ensuring that documents and data are retained only according to business requirements. Line Managers are responsible for ensuring that information managed by their teams is properly maintained, reviewed and disposed of when no longer required. Human Resources (HR) is responsible for managing employee-related records according to applicable requirements and confidentiality principles. IT Department is responsible for supporting technical retention, backup, storage and deletion processes. Management is responsible for ensuring that appropriate retention practices and controls are implemented across the organisation. All employees share responsibility for preventing unnecessary retention, unauthorised storage or inappropriate disposal of information.

Standard of Conduct

Employees must: • retain information only when there is a legitimate business, legal or contractual reason; • store information using approved FORFIRM systems and locations; • protect retained information from unauthorised access; • regularly review information under their responsibility and remove outdated material where permitted; • follow company procedures for secure disposal of documents and electronic information. Employees must not: • keep unnecessary copies of documents or files; • store company information on unauthorised personal devices or storage platforms; • retain personal data longer than required; • delete information that is subject to legal, contractual or investigation requirements; • dispose of confidential information using inappropriate methods.

Procedures

Information Classification and Retention FORFIRM retains information according to: • legal requirements; • contractual obligations; • business needs; • operational requirements; • data protection principles. Information should be classified and managed according to its sensitivity and importance. Examples of information requiring retention management include: • employment records; • customer contracts; • project documentation; • financial records; • supplier documentation; • personal data. Storage and Management of Records Employees must store company information only in approved locations. Electronic records must be stored using authorised systems, including company-approved platforms and databases. Physical records must be managed according to the requirements established in the Clean Desk and Physical Data Protection Policy. Employees must ensure that: • documents are correctly named and organised; • access is limited to authorised individuals; • obsolete versions are removed where appropriate; • confidential information remains protected. Review and Disposal of Information Information must be periodically reviewed to determine whether it is still required. When information is no longer necessary, it must be securely deleted or destroyed. Secure disposal methods include: • approved electronic deletion processes; • secure destruction of physical documents; • authorised disposal services where applicable. Confidential documents must not be disposed of in ordinary waste bins. Backup and Recovery FORFIRM may maintain backups of information to support business continuity and system recovery. Backup retention periods may differ from operational data retention periods due to technical and security requirements. Access to backup information must be restricted to authorised personnel. Legal Hold and Investigation Requirements Normal deletion processes must be suspended when information is required for: • legal proceedings; • regulatory requests; • audits; • internal investigations. Employees must preserve relevant information and follow instructions provided by authorised FORFIRM personnel. Personal Data Retention Personal data must not be retained longer than necessary for the purpose for which it was collected. FORFIRM will ensure that personal data is: • reviewed periodically; • securely stored; • deleted or anonymised when no longer required. Employees handling personal data must follow the requirements established in the Internal Privacy Policy. Non-Compliance Failure to comply with this policy may result in disciplinary action. Examples of non-compliance include: • retaining unnecessary confidential information; • storing company data in unauthorised locations; • deleting information without authorisation; • failing to protect retained information.