Data retention policy
In the absence of a request for data removal, data will be retained indefinitely.
Data archiving and removal policy
- Hardcopy Records: Must be shredded when disposed of.
- Electronic Media: Must be destroyed or made unusable before decommissioning, with destruction methods approved by the CTO.
- Computer Equipment: Before disposal, donation, or recycling, the CTO or their designee must validate that sensitive information has been removed.
Data storage policy
Must be stored on a server that is backed up daily, with system or disk-level redundancy required.
App/service has sub-processors
Guidelines for sub-processors