Data & privacy
Data Retention & Records Management Policy
Retention periods applied to categories of records held by the firm, the basis for those periods and the secure disposal process.
- Document reference
- FGL-LEG-06
- Version date
- 1 July 2026
- Applies to
- Fratres Limited
1.Purpose and scope
1.1
This Data Retention and Records Management Policy (this Policy) sets out the periods for which Fratres Limited (the Company), a company registered in England and Wales, retains Records, the basis on which those periods are fixed, and the manner in which Records are reviewed, preserved and destroyed at the end of their retention period.
1.2
The objectives of this Policy are to ensure that the Company:
- (a)retains Records for no longer than is necessary for the purposes for which they are processed, as required by Article 5(1)(e) of the UK GDPR;
- (b)retains Records for at least as long as is required by any applicable statutory, regulatory, contractual or evidential obligation;
- (c)is able to demonstrate compliance with the storage limitation principle, as required by Article 5(2) of the UK GDPR;
- (d)destroys Records at the end of their retention period by a method appropriate to their sensitivity and medium;
- (e)preserves Records that are, or may become, relevant to litigation, arbitration, regulatory investigation or law enforcement enquiry; and
- (f)maintains an auditable record of what has been destroyed, when, by whom and under which retention rule.
1.3
This Policy applies to all Records created, received or held by the Company in the course of its business, in whatever form and on whatever medium, including paper documents, electronic documents, electronic mail, instant and mobile messaging, structured database entries, audio and video recordings, system logs, backups and archives.
1.4
This Policy applies to every director, officer, employee, secondee, consultant, contractor, agent and intern of the Company (together, Personnel), and to any third party that holds Records on the Company’s behalf.
1.5
This Policy applies to the Company’s operations in the United Kingdom and to its activities in the People’s Republic of Bangladesh and any other jurisdiction in which it operates. Where the law of another jurisdiction imposes a retention obligation that differs from a period stated in this Policy, clause 13 applies.
1.6
This Policy is to be read with the Company’s Privacy Policy, Cookie Policy, International Data Transfer Statement, Anti-Money Laundering and Counter-Terrorist Financing Policy, and Client Due Diligence and Know Your Customer Standard. Where this Policy and another policy of the Company address the same Record, the longer retention period prevails.
2.Interpretation and definitions
In this Policy, the following terms have the following meanings.
- Anonymisation
- The irreversible removal or alteration of identifiers such that a natural person is no longer identifiable, directly or indirectly, by the Company or by any other person, with the result that the resulting information is no longer Personal Data.
- CDD Records
- Records created or obtained in the course of client due diligence, identification and verification, beneficial ownership enquiry, sanctions and politically exposed person screening, source of funds and source of wealth enquiry, and ongoing monitoring.
- Destruction Register
- The register maintained under clause 11 recording the destruction or permanent deletion of Records.
- Engagement File
- The body of Records relating to a single client engagement, including the engagement letter, scope documents, advice, work product, correspondence with the client and counterparties, working papers and the closing file.
- Legal Hold
- A written direction issued under clause 8 requiring the preservation of identified Records and the suspension of any scheduled destruction affecting them.
- Personal Data
- Has the meaning given in Article 4(1) of the UK GDPR, and includes Special Category Data as defined in Article 9(1).
- Record
- Any recorded information, in any form and on any medium, created, received or maintained by the Company as evidence of its activities or because of a legal obligation, together with any Personal Data contained in it.
- Records Owner
- The individual holding the role designated under clause 4.3 as accountable for a category of Records set out in the retention schedule at clause 6.
- Retention Period
- The period specified in clause 6 for a category of Records, running from the applicable Trigger Event determined under clause 7.
- Trigger Event
- The event identified in clause 7 from which the Retention Period for a category of Records begins to run.
- UK GDPR
- The retained EU law version of Regulation (EU) 2016/679 as it forms part of the law of England and Wales, Scotland and Northern Ireland, read together with the Data Protection Act 2018.
2.1
A reference to a statute, statutory instrument or regulation is a reference to it as amended, extended, consolidated or re-enacted from time to time, and includes any subordinate legislation made under it.
2.2
The words including, includes and in particular are to be construed without limitation, and any words following them are illustrative only.
2.3
The words shall and must impose an obligation which Personnel are required to observe. The word may confers a discretion which must be exercised consistently with the principles in clause 3.
2.4
Clause headings and the contents list do not affect the interpretation of this Policy. References to months and years are to calendar months and calendar years, and a period expressed in years runs from the Trigger Event to the corresponding date in the relevant later year.
3.Records management principles
3.1
The Company retains Personal Data in a form which permits identification of data subjects for no longer than is necessary for the purposes for which that Personal Data is processed. This is the storage limitation principle at Article 5(1)(e) of the UK GDPR, and it governs every period stated in this Policy.
3.2
In applying this Policy, the Company observes the following principles:
- (a)Necessity. A Record is retained only where a continuing business, legal, regulatory or evidential need for it can be articulated. Retention on the basis that a Record may one day prove useful is not a legitimate ground.
- (b)Proportionality. Where a shorter period would satisfy the identified need, the shorter period is applied.
- (c)Data minimisation. Where only part of a Record is required for the identified need, the Company shall where practicable retain that part and destroy or redact the remainder.
- (d)Anonymisation in preference to retention. Where the continuing need is statistical, analytical or historical, the Company shall anonymise rather than retain identifiable Personal Data, and anonymised information falls outside the Retention Periods in clause 6.
- (e)Consistency. Records within the same category are retained for the same period and destroyed on the same cycle, irrespective of the individual or system that holds them.
- (f)Defensible disposition. Destruction takes place under an established rule, applied uniformly and documented, and never on an ad hoc basis or in response to an anticipated request, claim or investigation.
- (g)Integrity and confidentiality. For the whole of the Retention Period a Record shall be held securely, in accordance with Articles 5(1)(f) and 32 of the UK GDPR and clause 12.
- (h)Accountability. The Company shall be able to evidence, for any category of Record, the period applied, the basis for that period and the fact and manner of destruction.
3.3
No Record shall be retained indefinitely except where this Policy expressly so provides, or where the Company is required to do so by law.
3.4
Where two or more Retention Periods apply to the same Record, the longest applies to the whole of that Record. Where a Record can be severed, each severed part is governed by its own Retention Period.
3.5
The periods in clause 6 are maximum periods as well as minimum periods. Retention beyond a stated period is permitted only under a Legal Hold issued under clause 8, or where an extension has been approved and documented under clause 9.3.
The controlling rule
A Record is kept for the longer of (i) the statutory or regulatory minimum, (ii) the period necessary for the Company to establish, exercise or defend legal claims, and (iii) the period during which the Record serves the purpose for which it was created. When the last of those periods expires, the Record is destroyed.
4.Roles and responsibilities
4.1
The board of directors of the Company is accountable for this Policy. The board approves the retention schedule at clause 6, approves any amendment to it, and receives an annual report on compliance with this Policy.
4.2
The board has appointed a director with responsibility for data protection and records management (the Data Protection Lead). The Data Protection Lead shall:
- (a)maintain this Policy and the retention schedule, and keep both under review under clause 9.5;
- (b)maintain the record of processing activities required by Article 30 of the UK GDPR, including the envisaged retention period for each category of processing;
- (c)issue, maintain and release Legal Holds under clause 8;
- (d)maintain the Destruction Register under clause 11;
- (e)approve any retention of a Record beyond its Retention Period; and
- (f)act as the point of contact for enquiries made under clause 16.6 and for correspondence with the Information Commissioner’s Office.
4.3
Each category of Record in clause 6 is assigned to a Records Owner. The Records Owner is responsible for the completeness and accuracy of that category, for conducting the review required by clause 9, and for authorising destruction in accordance with clause 10.
4.4
CDD Records, internal suspicion reports and any disclosure made to the National Crime Agency are the responsibility of the officer appointed under the Company’s Anti-Money Laundering and Counter-Terrorist Financing Policy. Those Records shall be held separately from Engagement Files, with access restricted to that officer and the Data Protection Lead, and shall not be destroyed without that officer’s written authority.
4.5
All Personnel shall:
- (a)file Records in the systems approved by the Company, and not in personal accounts, personal devices, local drives or unmanaged storage;
- (b)refrain from creating duplicate or shadow copies of Records outside those systems;
- (c)apply the correct category and Trigger Event when closing a matter;
- (d)comply immediately with any Legal Hold notified to them; and
- (e)report to the Data Protection Lead any Record they believe has been retained beyond its Retention Period, destroyed prematurely, or lost.
4.6
A copy of a Record held outside an approved system does not create a separate Retention Period. Any such copy shall be deleted on discovery, save where it is subject to a Legal Hold, in which case it shall be preserved and reported to the Data Protection Lead.
4.7
Personnel who leave the Company shall, before their last working day, transfer all Records in their possession into the approved systems and confirm in writing that no Record remains in their personal possession or control.
5.Storage limitation and lawful basis for retention
5.1
Retention is itself a form of processing. The Company shall not retain Personal Data unless a lawful basis under Article 6 of the UK GDPR continues to apply throughout the Retention Period and, in the case of Special Category Data, a condition under Article 9(2) of the UK GDPR and, where required, a condition in Schedule 1 to the Data Protection Act 2018.
5.2
The lawful bases the Company relies upon to retain Personal Data are:
- (a)compliance with a legal obligation to which the Company is subject, principally under the Companies Act 2006, the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017, the Proceeds of Crime Act 2002, the Terrorism Act 2000 and applicable tax legislation;
- (b)performance of a contract with the data subject, or steps taken at the data subject’s request prior to entering into a contract;
- (c)the legitimate interests of the Company in maintaining a complete and reliable record of its advice and dealings, in defending claims, and in demonstrating compliance with its own controls, where those interests are not overridden by the interests or fundamental rights and freedoms of the data subject; and
- (d)consent, where retention rests on consent alone, in which case the Record shall be destroyed on withdrawal of that consent unless another basis in this clause then applies.
5.3
Where retention rests on legitimate interests, the Data Protection Lead shall record the balancing assessment supporting the Retention Period and shall review it whenever the schedule at clause 6 is amended.
5.4
Retention for the purpose of establishing, exercising or defending legal claims is calibrated to the limitation periods under the Limitation Act 1980. The Company adopts six years as its standard evidential period, that being the period within which an action founded on simple contract or on tort must generally be brought under sections 5 and 2 of that Act, and twelve years where the relevant instrument is executed as a deed, under section 8.
5.5
The record of processing activities maintained under Article 30 of the UK GDPR shall state, for each category of processing, the envisaged retention period. That statement shall be reconciled to clause 6 at each annual review, and any divergence shall be corrected in favour of the shorter period unless a legal obligation requires otherwise.
5.6
The privacy information provided to data subjects under Articles 13 and 14 of the UK GDPR shall state the Retention Period, or the criteria used to determine it, consistently with this Policy.
6.The retention schedule
6.1
This clause sets the Retention Period for each category of Record. Each period runs from the Trigger Event identified in clause 7. Where a Record falls within more than one category, clause 3.4 applies.
6.2
Enquiry and prospect records. Enquiries submitted through the form at fratresgroup.com/contact, business card and introduction records, and correspondence with prospective clients that does not result in an engagement, are retained for twenty-four months from the date of last meaningful contact. Where an enquiry is declined at the outset, the enquiry is retained for twelve months together with a short note of the reason for declining, so that the Company can evidence the consistency of its acceptance decisions. Records of consent to receive electronic marketing, and of any withdrawal of that consent, are retained for the duration of the consent and for a further twenty-four months, as evidence of compliance with regulation 22 of the Privacy and Electronic Communications (EC Directive) Regulations 2003. Suppression records are dealt with at clause 15.4.
6.3
Client engagement files. Engagement Files, including the engagement letter, scope and variation documents, advice given, work product, working papers and correspondence, are retained for six years from the end of the engagement, in line with clause 5.4. Where the engagement documents are executed as a deed, or where the Company has given an indemnity or warranty capable of being enforced under a deed, the period is twelve years. Where an engagement relates to a project with a construction, concession or licence life exceeding the standard period, the Records Owner may extend retention to the date falling six years after the expiry of the relevant instrument, with the extension recorded under clause 9.3.
6.4
Due diligence and know your customer records. CDD Records are retained for five years beginning on the date on which the business relationship comes to an end or, in the case of a one-off transaction, the date on which the transaction is completed. That period is the period specified in regulation 40 of the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017, which the Company applies as its standard across all engagements. At the end of that period the Personal Data contained in CDD Records shall be deleted, unless the Company is required to retain it by another enactment or for the purposes of court proceedings, or the data subject has given express consent to its retention. Retention beyond ten years from the Trigger Event is not permitted otherwise than under a Legal Hold.
6.5
Suspicion reports and financial crime records. Internal reports of knowledge or suspicion of money laundering or terrorist financing, the decision-making record relating to each such report, and any disclosure made to the National Crime Agency under the Proceeds of Crime Act 2002 or the Terrorism Act 2000, are retained for six years from the date of the report or disclosure, or for such longer period as the National Crime Agency or a law enforcement agency requests. These Records are subject to the restrictions on disclosure in section 333A of the Proceeds of Crime Act 2002 and section 21D of the Terrorism Act 2000, and shall not be filed with, or referenced in, the Engagement File to which they relate.
6.6
Financial and accounting records. Accounting records kept under section 386 of the Companies Act 2006, together with invoices, receipts, bank statements, expense claims, ledgers and supporting vouchers, are retained for six years from the end of the financial year to which they relate. Section 388 of the Companies Act 2006 requires a private company to preserve its accounting records for three years from the date on which they are made; the Company applies the longer period of six years because paragraph 21 of Schedule 18 to the Finance Act 1998 requires company tax records to be preserved for six years from the end of the accounting period, and paragraph 6 of Schedule 11 to the Value Added Tax Act 1994 requires value added tax records to be preserved for the same period. Annual accounts, directors’ reports and auditors’ reports as filed are retained for the life of the Company.
6.7
Corporate and statutory records. The register of members, the register of directors, the register of directors’ residential addresses, the register of people with significant control, the certificate of incorporation and the articles of association are retained for the life of the Company and for six years following its dissolution. An entry relating to a former member may be removed from the register of members after the expiry of ten years from the date on which that person ceased to be a member, in accordance with section 121 of the Companies Act 2006. Minutes of directors’ meetings are retained for at least ten years from the date of the meeting under section 248 of the Companies Act 2006, and records of resolutions and meetings of members are retained for at least ten years under section 355 of that Act. The Company’s practice is to retain both for the life of the Company.
6.8
Employment records. The following periods apply:
- —Personnel files, including contracts of employment, variations, appraisals, disciplinary and grievance records and termination documents: six years from the end of employment or engagement.
- —Pay records sufficient to establish compliance with the National Minimum Wage Act 1998: six years from the end of the pay reference period, as required by regulation 59 of the National Minimum Wage Regulations 2015.
- —Pay As You Earn records, including deductions and payments to His Majesty’s Revenue and Customs: not less than three years after the end of the tax year to which they relate, as required by regulation 97 of the Income Tax (Pay As You Earn) Regulations 2003.
- —Working time records: two years from the date on which they were made, as required by regulation 9 of the Working Time Regulations 1998.
- —Copies of documents evidencing the right to work in the United Kingdom: the duration of the employment and a further two years from the date employment ends, being the period for which the statutory excuse under the Immigration, Asylum and Nationality Act 2006 requires the evidence to be available.
- —Records of unsuccessful job applicants, including application forms, interview notes and assessment scores: twelve months from notification of the outcome, to allow the Company to respond to any claim under the Equality Act 2010.
- —Pension auto-enrolment records: six years from the date to which they relate, and four years in the case of opt-out notices.
- —Records of reportable injuries, diseases and dangerous occurrences: three years from the date of the entry, as required by regulation 12 of the Reporting of Injuries, Diseases and Dangerous Occurrences Regulations 2013.
- —Records of training completed under the Company’s compliance programme, including anti-bribery, sanctions and data protection training: six years from the end of employment or engagement.
6.9
Compliance registers and conduct records. The gifts and hospitality register, the register of conflicts of interest, records of sanctions and politically exposed person screening, records of any report made to the Office of Financial Sanctions Implementation, records of third-party intermediary due diligence, and records evidencing the procedures maintained under section 7 of the Bribery Act 2010 and sections 45 and 46 of the Criminal Finances Act 2017 are retained for six years from the end of the financial year in which the entry was made. Statements published under section 54 of the Modern Slavery Act 2015, and the underlying assessment supporting each statement, are retained for the life of the Company. Reports made under the Company’s Whistleblowing and Speak-Up Policy, and the investigation record relating to each, are retained for six years from closure of the matter, having regard to the protections conferred by the Public Interest Disclosure Act 1998, and are held under restricted access.
6.10
Correspondence. Correspondence forming part of an Engagement File takes the Retention Period of that file. General business correspondence that does not form part of an Engagement File, a compliance register or a statutory record is retained for three years from the date of the last item in the exchange. Correspondence with a regulator, a government authority or a law enforcement agency is retained for six years from the conclusion of the matter to which it relates. Instant and mobile messaging shall not be used to conduct business that creates a Record; where it nonetheless occurs, the message shall be exported into an approved system and the exported Record then takes the period applicable to its subject matter.
6.11
Website and technical records. Web server access logs, including internet protocol addresses, are retained for twelve months from the date of the entry. Security event logs, authentication logs and records of access to systems containing Personal Data are retained for twenty-four months, that period being necessary to investigate incidents that come to light after a delay. Records relating to a personal data breach, including the assessment and any notification made to the Information Commissioner’s Office under Article 33 of the UK GDPR, are retained for six years from the date of the breach. Cookie consent records are retained for twelve months from the date consent was given or refused, and analytics data is retained for the period stated in the Company’s Cookie Policy. Backup media are dealt with at clause 10.4.
6.12
Insurance, property and supplier records. Professional indemnity and other liability insurance policies, together with schedules and records of claims, are retained for the life of the Company, because liability under such policies may be asserted many years after the policy period. Leases, licences and other agreements relating to premises are retained for twelve years from termination. Supplier and processor contracts, and the due diligence supporting them, are retained for six years from the end of the contract.
6.13
Where a Record does not fall within any category in this clause, the Records Owner shall refer it to the Data Protection Lead, who shall determine the applicable period by analogy with the closest category and shall add the new category to the schedule at the next review. Pending that determination the Record shall be retained and shall not be destroyed.
7.Commencement of the retention period
7.1
A Retention Period runs from its Trigger Event and not from the date the Record was created, unless this Policy states otherwise. Correct identification of the Trigger Event is the responsibility of the Records Owner.
7.2
The Trigger Events are:
- Enquiry and prospect records
- The date of the last meaningful contact between the enquirer and the Company, being the later of the last substantive communication sent or received and any subsequent update to the record.
- Client engagement files
- The date on which the engagement ends, being the date of the final deliverable, the date of the closing letter, or the date of termination of the engagement letter, whichever is the latest.
- Due diligence and know your customer records
- The date on which the business relationship comes to an end or, for a one-off transaction, the date on which the transaction is completed, determined in accordance with the Client Due Diligence and Know Your Customer Standard.
- Financial and accounting records
- The end of the financial year to which the record relates.
- Employment records
- The date on which the employment or engagement ends, save where clause 6.8 specifies a different starting point for a particular record.
- Compliance registers
- The end of the financial year in which the entry was made.
- Correspondence
- The date of the last item in the exchange, or the conclusion of the matter where the correspondence relates to a defined matter.
- Technical and log records
- The date on which the entry was written.
7.3
Where more than one Trigger Event could apply to a Record, the latest applies.
7.4
A matter is treated as closed, and its Trigger Event as having occurred, only when the Records Owner has confirmed that no further work is contemplated, all fees have been rendered and settled or written off, and the closing file has been completed. A matter on which there has been no activity for twenty-four months shall be reviewed by the Records Owner and either closed or documented as remaining open, with reasons.
7.5
For the purposes of scheduling destruction under clause 9, a Retention Period is treated as expiring on 31 December of the calendar year in which it would otherwise expire. This allows destruction to be carried out in a single annual exercise, and does not extend any statutory maximum period, which continues to be applied by reference to its own terms.
7.6
Where a Retention Period has already expired in respect of a Record identified on migration of a system, or on the discovery of an unmanaged repository, the Record shall be destroyed within thirty days of identification unless it is subject to a Legal Hold, and the destruction shall be entered in the Destruction Register.
8.Legal holds and litigation preservation
8.1
A Legal Hold suspends the operation of the retention schedule in respect of the Records it identifies. While a Legal Hold is in force, those Records shall not be destroyed, deleted, altered, moved out of the Company’s control, or allowed to expire under any automated deletion rule, notwithstanding any provision of clause 6.
8.2
A Legal Hold shall be issued as soon as the Company knows or reasonably anticipates that:
- (a)litigation, arbitration or an employment tribunal claim has been commenced or is reasonably in prospect, whether by or against the Company;
- (b)a regulator, government authority or law enforcement agency has commenced or notified an investigation, audit or enquiry;
- (c)a court order, production order, information notice, search warrant or restraint order has been served on the Company;
- (d)a request has been made by the National Crime Agency or another agency to preserve material;
- (e)a complaint has been made under the Complaints Handling Procedure that is reasonably likely to lead to a claim; or
- (f)a concern raised under the Whistleblowing and Speak-Up Policy requires investigation.
8.3
Only the Data Protection Lead may issue, vary or release a Legal Hold, acting on the advice of the Company’s legal advisers where appropriate. A Legal Hold shall be issued in writing and shall state the matter to which it relates, the categories, custodians, systems and date ranges within its scope, the date it takes effect, and the obligations of each recipient.
8.4
On receipt of a Legal Hold, each recipient shall preserve every Record within its scope in their possession or control, including material held in personal email, personal devices and messaging applications, and shall confirm compliance in writing to the Data Protection Lead within five business days. Recipients shall notify the Data Protection Lead of any further custodian or repository that may hold Records within scope.
8.5
The Data Protection Lead shall procure that automated deletion, retention rules, mailbox expiry policies and backup rotation are suspended in respect of the Records within scope, and shall obtain written confirmation of that suspension from any processor or supplier holding relevant Records.
8.6
Where proceedings are before the courts of England and Wales, the Company’s preservation obligations under Part 31 of the Civil Procedure Rules and Practice Direction 57AD on disclosure in the Business and Property Courts take precedence over this Policy, and the Legal Hold shall be framed to give effect to them.
8.7
A Legal Hold remains in force until released in writing by the Data Protection Lead. On release, the Records within its scope revert to their Retention Period, and any period that expired while the hold was in force is treated as expiring on the date of release, so that the Records fall into the next destruction cycle.
8.8
The Data Protection Lead shall maintain a register of Legal Holds recording the matter, the date of issue, the scope, the recipients, the confirmations received, and the date and authority for release. That register is retained for six years from release of the hold.
8.9
Destroying, concealing, falsifying or disposing of a Record which a person knows or suspects to be relevant to a money laundering investigation may constitute an offence under section 342 of the Proceeds of Crime Act 2002, and equivalent conduct in relation to a terrorist property investigation may constitute an offence under section 39 of the Terrorism Act 2000. Personnel shall treat any request or suggestion to destroy Records outside this Policy as a matter to be reported immediately under clause 16.4.
9.Periodic review and disposition
9.1
The Company shall conduct a records review in the first quarter of each calendar year. The review shall identify every Record whose Retention Period expired on or before 31 December of the preceding year and shall determine its disposition.
9.2
The permitted dispositions are:
- (a)destruction in accordance with clause 10, which is the default disposition;
- (b)anonymisation, where a continuing statistical, analytical or historical need exists and identification is not required to meet it;
- (c)return or transfer to the client, or to a successor adviser, where the client is entitled to the Record and has requested its return, against a written receipt;
- (d)transfer to closed archive, where the Retention Period has not in fact expired because a longer period applies under clause 3.4; and
- (e)extension of retention under clause 9.3.
9.3
Retention beyond a Retention Period requires the written approval of the Data Protection Lead. The approval shall identify the Records concerned, the reason for the extension, the lawful basis relied upon, and the date on which the extended period expires, which shall not exceed twelve months without renewal. Extensions shall be recorded and reported to the board at its next meeting.
9.4
Before any destruction is carried out, the Records Owner shall confirm in writing that no Legal Hold applies to the Records identified, and the Data Protection Lead shall check the register maintained under clause 8.8. Destruction shall not proceed without both confirmations.
9.5
The Data Protection Lead shall review this Policy and the retention schedule at least annually, and in any event promptly following any material change in the law, the introduction of a new category of Record, a change of processor or system, or a personal data breach. The outcome of each review shall be reported to the board, and any amendment to the schedule takes effect only on board approval.
9.6
The Data Protection Lead shall test compliance with this Policy at least annually by sampling each principal category of Record, and shall report the results of that testing, together with any remedial action taken, to the board.
10.Secure destruction and disposal
10.1
Records shall be destroyed by a method that renders reconstruction of their content impracticable, having regard to their sensitivity and medium, and consistently with the obligation to ensure appropriate security under Article 32 of the UK GDPR.
10.2
The following methods shall be applied:
- —Paper Records: cross-cut shredding to a security level of at least P-4 under DIN 66399 (ISO/IEC 21964), or incineration or pulping by a contractor engaged under clause 10.5. Records containing Special Category Data, CDD Records and suspicion reports shall be shredded to at least P-5.
- —Electronic documents and mailboxes: deletion from the live system followed by purge from all recovery, recycle and retention stores, so that the item cannot be restored through ordinary administrative means.
- —Structured data: deletion of the record and of any derived copy, together with the anonymisation of any residual index entry required for referential integrity.
- —Storage media being retained for reuse: cryptographic erasure of the encryption key, or overwriting in accordance with a recognised media sanitisation standard such as NIST Special Publication 800-88.
- —Storage media being retired, and any media that cannot be reliably sanitised: degaussing or physical destruction, evidenced by a certificate of destruction identifying each item by serial number.
- —Portable media and mobile devices: remote wipe where available, followed by physical destruction where the device is not to be reissued.
10.3
Pending destruction, Records awaiting collection or processing shall be held in a locked container or a restricted-access repository. Records shall not be placed in general waste, general recycling, or any unsecured collection point in any circumstances.
10.4
Backups are retained for operational resilience and are overwritten on the Company’s ordinary backup cycle. A Record deleted from the live system may persist in backup media until that cycle completes. The Company shall not restore a Record from backup for any purpose once it has been deleted from the live system under this Policy, save where required by a Legal Hold, a court order or a request from a law enforcement agency. Where a restoration is performed for an unrelated reason, Records whose Retention Period has expired shall be re-deleted immediately on completion of the restoration.
10.5
Where destruction is carried out by a contractor:
- (a)the contractor shall be engaged under a written contract containing the terms required by Article 28(3) of the UK GDPR where the destruction involves Personal Data;
- (b)the contract shall specify the method and security level of destruction and require destruction within a defined period of collection;
- (c)the contractor shall provide a certificate of destruction identifying the consignment, the date and the method, which shall be filed with the Destruction Register;
- (d)the Company shall comply with its duty of care in respect of the transfer of waste under section 34 of the Environmental Protection Act 1990, and shall obtain and retain the corresponding waste transfer documentation; and
- (e)the Company shall satisfy itself, before first engagement and at each contract renewal, that the contractor’s facilities and personnel meet the standards required by this clause.
10.6
Records held in Bangladesh or any other jurisdiction shall be destroyed to the standards set out in this clause. Where local facilities cannot meet those standards, the Records shall be transferred securely to a location where they can be, subject to clause 13.
10.7
No person shall destroy a Record otherwise than in accordance with this clause and on the authority given under clause 9.4. Informal destruction, including deleting material to tidy a mailbox or a drive, is a breach of this Policy.
11.Records of destruction
11.1
The Data Protection Lead shall maintain the Destruction Register. Every destruction of a Record carried out under this Policy shall be entered in it, whether the destruction is of paper, electronic material or media, and whether carried out by the Company or by a contractor.
11.2
Each entry shall record:
- (a)a description of the Records destroyed, sufficient to identify the category and, where applicable, the matter or file reference, without reproducing the content destroyed;
- (b)the date range of the Records and their volume, expressed in files, boxes, items or bytes as appropriate;
- (c)the medium on which the Records were held and the system or location from which they were removed;
- (d)the category in clause 6 and the Retention Period applied;
- (e)the Trigger Event and the date on which the Retention Period expired;
- (f)confirmation that the checks required by clause 9.4 were carried out, and by whom;
- (g)the role of the individual who authorised the destruction and the date of authorisation;
- (h)the method of destruction applied under clause 10.2;
- (i)the date on which destruction was completed; and
- (j)where a contractor was used, the identity of the contractor and the reference of the certificate of destruction.
11.3
The Destruction Register shall not contain Personal Data beyond that necessary to identify the Records destroyed and the individuals who authorised and carried out the destruction.
11.4
The Destruction Register and the certificates filed with it are retained for the life of the Company. Entries shall not be amended or deleted; a correction shall be made by a further entry cross-referring to the entry corrected.
11.5
The Destruction Register is the Company’s evidence that a Record no longer exists, that its destruction took place under an established rule rather than in response to a claim or investigation, and that the Company has complied with the accountability obligation in Article 5(2) of the UK GDPR. It shall be produced to the Information Commissioner’s Office, to a court, or to an auditor on request.
11.6
Where a Record cannot be located and is believed to have been destroyed without an entry in the Destruction Register, the Records Owner shall report the matter to the Data Protection Lead, who shall record the loss, assess whether it constitutes a personal data breach requiring notification under Article 33 of the UK GDPR, and identify the control failure that permitted it.
12.Storage, security and access
12.1
For the whole of the Retention Period, Records shall be held only in systems approved by the Company, shall be encrypted in transit and at rest where the medium permits, and shall be protected by access controls appropriate to their sensitivity.
12.2
Access to Records shall be granted on the basis of need. CDD Records, suspicion reports, whistleblowing reports, employment records and Special Category Data shall be held under restricted access, and access to each shall be logged.
12.3
Paper Records shall be held in locked storage and shall not be removed from Company premises other than in a manner approved by the Data Protection Lead. Records shall not be left unattended in a public place, a vehicle or a shared workspace.
12.4
Personnel shall not store Records in personal email accounts, personal cloud storage, unmanaged messaging applications or personal devices that are not enrolled in the Company’s device management arrangements.
12.5
Closed files may be moved to an archive with reduced access, provided the archive applies the same security standard as the live system, the Retention Period continues to be enforced against the archived Record, and the Record remains retrievable within a reasonable period so that the Company can respond to a request under Article 15 of the UK GDPR or to an order of a court.
12.6
Any actual or suspected loss of, unauthorised access to, or unauthorised disclosure of a Record shall be reported immediately to the Data Protection Lead, who shall assess it against the notification thresholds in Articles 33 and 34 of the UK GDPR and, where the threshold is met, notify the Information Commissioner’s Office without undue delay and, where feasible, not later than seventy-two hours after becoming aware of the breach.
13.Records held outside the United Kingdom
13.1
The Company’s activities in Bangladesh generate Records that may be created, held or accessed outside the United Kingdom. This Policy applies to those Records in full.
13.2
Any transfer of Personal Data outside the United Kingdom shall be made only in accordance with Chapter V of the UK GDPR and the Company’s International Data Transfer Statement, using an approved transfer mechanism and supported by a transfer risk assessment. The existence of a Retention Period does not authorise a transfer that would otherwise be unlawful.
13.3
Where the law of a jurisdiction in which the Company operates requires a Record to be retained for longer than the period stated in clause 6, the longer period applies to the copy held in that jurisdiction. Requirements of this kind may arise, among other sources, under the Companies Act 1994 and the Money Laundering Prevention Act 2012 of Bangladesh. The Records Owner shall identify any such requirement before the Record is created and shall notify the Data Protection Lead, who shall record the divergence in the retention schedule.
13.4
Where the law of another jurisdiction would require destruction of a Record before the expiry of a Retention Period fixed by a legal obligation to which the Company is subject in the United Kingdom, the conflict shall be referred to the Data Protection Lead before any action is taken, and legal advice shall be obtained in both jurisdictions.
13.5
Remote access to Records held in the United Kingdom from another jurisdiction constitutes a transfer for the purposes of clause 13.2 and shall be permitted only through the Company’s controlled access arrangements.
13.6
Destruction carried out outside the United Kingdom shall be evidenced in the Destruction Register in the same manner as destruction carried out within it.
14.Processors, suppliers and third parties
14.1
Where a third party processes Personal Data on the Company’s behalf, the written contract required by Article 28(3) of the UK GDPR shall provide that the processor retains Personal Data only for the period specified by the Company, and that at the Company’s election it deletes or returns all Personal Data at the end of the services and deletes existing copies unless required by law to retain them.
14.2
On termination or expiry of any such contract, the Data Protection Lead shall obtain written confirmation of deletion or return, specifying the date on which it was completed and the treatment of any backup copies, and shall file that confirmation with the Destruction Register.
14.3
A processor shall not appoint a sub-processor to store or archive Records without the Company’s prior written authorisation, and any authorisation shall be conditional on the sub-processor being bound by equivalent retention and deletion obligations.
14.4
Where the Company instructs lawyers, accountants, auditors, insurers or other professional advisers who act as controllers in their own right, those advisers retain Records under their own obligations. The Company shall nonetheless satisfy itself that the adviser operates a documented retention policy, and shall not treat an adviser’s file as a substitute for its own Record.
14.5
Before appointing any supplier that will hold Records, the Company shall assess the supplier’s retention, deletion, security and location arrangements, and shall record that assessment. The assessment shall be repeated at each renewal.
14.6
Where a supplier ceases to trade, is acquired, or migrates the Company’s data to a different platform, the Data Protection Lead shall verify that Records have been transferred completely and that the legacy environment has been purged, and shall record the verification.
15.Data subject rights and their effect on retention
15.1
A data subject may request erasure of their Personal Data under Article 17 of the UK GDPR. The Company shall give effect to such a request unless an exception applies, in particular where processing is necessary for compliance with a legal obligation under Article 17(3)(b), or for the establishment, exercise or defence of legal claims under Article 17(3)(e), or where an exemption in Schedules 2 to 4 to the Data Protection Act 2018 applies.
15.2
CDD Records, suspicion reports and statutory financial and corporate records may not be erased before the expiry of the periods stated in clauses 6.4 to 6.7. Where erasure is refused on that basis, the Company shall inform the data subject of the reason, of the period for which the Records will be held, and of their right to complain to the Information Commissioner’s Office. Where an erasure request relates to Records connected with a report made to the National Crime Agency, the response shall be framed so as not to contravene the restrictions on disclosure referred to in clause 6.5.
15.3
Where a data subject exercises the right to restriction of processing under Article 18 of the UK GDPR, the Records concerned shall be marked so that they are retained but not otherwise processed, and shall be excluded from the destruction cycle until the restriction is lifted.
15.4
Where a data subject objects to direct marketing under Article 21(2) of the UK GDPR or withdraws consent given for the purposes of the Privacy and Electronic Communications (EC Directive) Regulations 2003, the Company shall retain the minimum identifying information necessary to give effect to the objection on a suppression list. That information is retained for as long as the Company conducts marketing activity, because deleting it would cause the individual to be contacted again, and it shall not be used for any other purpose.
15.5
A request for access under Article 15 of the UK GDPR does not extend any Retention Period. Records shall not be destroyed in order to avoid disclosing them. Altering, defacing, blocking, erasing, destroying or concealing information with the intention of preventing disclosure of all or part of the information to which a person would have been entitled may constitute an offence under section 173 of the Data Protection Act 2018.
15.6
Requests under this clause, and any question about the periods for which the Company holds a particular category of Record, should be submitted through the enquiry form at fratresgroup.com/contact. Requests are acknowledged within five business days and answered within one month of receipt, extendable by a further two months where the request is complex or numerous, in which case the data subject will be informed within the first month.
16.Breach of this Policy, governance and enquiries
16.1
Compliance with this Policy is a condition of employment and of engagement. Breach by an employee shall be dealt with under the Company’s disciplinary procedure and may amount to gross misconduct, in particular where a Record has been destroyed in breach of a Legal Hold, retained deliberately beyond its Retention Period, removed from the Company’s systems, or disposed of insecurely.
16.2
Breach by a consultant, contractor, agent, supplier or processor is a breach of contract and may result in suspension of the engagement, termination without notice and a claim for any loss suffered by the Company.
16.3
Conduct that breaches this Policy may also give rise to personal liability. In particular, retaining Personal Data without the consent of the controller after obtaining it may constitute an offence under section 170 of the Data Protection Act 2018; preventing disclosure to a person entitled to it may constitute an offence under section 173 of that Act; and destroying or concealing material relevant to an investigation may constitute an offence under section 342 of the Proceeds of Crime Act 2002 or section 39 of the Terrorism Act 2000.
16.4
Personnel who become aware of a breach of this Policy, or who are asked to act in a manner inconsistent with it, shall report the matter immediately to the Data Protection Lead. A report may instead be made through the channels in the Whistleblowing and Speak-Up Policy, and a person who makes such a report in good faith shall not suffer detriment for having done so, consistently with the protections conferred by the Public Interest Disclosure Act 1998. The Company applies this Policy without discrimination and consistently with its obligations under the Equality Act 2010.
16.5
This Policy is owned by the Data Protection Lead and approved by the board. It is reviewed in accordance with clause 9.5. The version date shown at the head of this document is the date of the version currently in force, and it supersedes all earlier versions. Superseded versions are retained for six years so that the Company can evidence the rules that applied at any given time.
16.6
Enquiries about this Policy, including requests for information about the retention period applied to a particular category of Record, should be submitted through the enquiry form at fratresgroup.com/contact and will be acknowledged within five business days.
16.7
A data subject who is dissatisfied with the Company’s handling of a matter under this Policy may complain to the Information Commissioner’s Office, the supervisory authority for data protection in the United Kingdom. The Company asks to be given the opportunity to address the concern first.
16.8
This Policy and any dispute or claim arising out of or in connection with it are governed by the law of England and Wales, and the courts of England and Wales have exclusive jurisdiction, without prejudice to any mandatory requirement of the law of another jurisdiction in which the Company operates.
Summary of the operating rule
Records are kept for a fixed period, tied to a defined event, for a stated reason. They are reviewed once a year, destroyed by a method matched to their sensitivity, and the destruction is written down. Nothing is kept because it might be useful, and nothing is destroyed because it might be inconvenient.
Related policies
Privacy PolicyHow Fratres Limited collects, uses, shares and protects personal data, and the rights available to data subjects under the UK GDPR.FGL-LEG-04Cookie PolicyThe cookies and similar technologies used on this website, their purposes, and how consent may be given or withdrawn.FGL-LEG-05International Data Transfer StatementThe safeguards applied where personal data is transferred outside the United Kingdom, including to Bangladesh and other jurisdictions.FGL-LEG-07
Full legal register