1. Purpose
This policy outlines how The YMCA Gisborne Inc. manages the retention, review, and secure disposal of personal and business information. It ensures compliance with the Privacy Act 2020, Tax Administration Act 1994, Employment Relations Act 2000, and other applicable laws while safeguarding client and staff data.
2. Scope
This policy applies to all records, including electronic and physical documents, collected and maintained by The YMCA Gisborne Inc. It covers client information, employee records, financial records, health and safety data, and other business-related documentation.
3. Data Retention Periods
Records shall be retained for the following periods unless otherwise required by law or contractual obligations:
| Type of Data | Retention Period | Legal Basis |
|---|---|---|
| Client Personal Information | Retained only as long as necessary for service provision, then securely deleted | Privacy Act 2020 (IPP 9) |
| Financial & Tax Records | Minimum 7 years | Tax Administration Act 1994 |
| Employee Records (Contracts, Leave, Wage Records) | Minimum 6 years after employment ends | Employment Relations Act 2000 |
| Health & Safety Records | Minimum 5 years | Health and Safety at Work Act 2015 |
| Incident Reports (Serious Harm) | Minimum 10 years | WorkSafe NZ Requirements |
| Health & Medical Records | Minimum 10 years after last contact | Health Information Privacy Code 2020 |
| Legal & Contractual Documents | Minimum 6 years after contract expiration | Limitation Act 2010 |
4. Data Review Process
Data will be reviewed at least annually to identify records that are eligible for disposal. A Data Retention Officer (DRO), designated by senior management, will oversee the review process to ensure compliance.
5. Secure Disposal Methods
Once data has exceeded its retention period, it must be securely disposed of as follows:
- Paper records: Shredded or securely incinerated.
- Electronic records: Permanently deleted using data wiping software to prevent recovery.
- Backups: Regularly purged according to the IT data retention schedule.
All disposals must be documented in a Data Destruction Log, recording the type of data, date of disposal, and method used.
6. Data Security & Access Control
To protect sensitive information, the YMCA Gisborne Inc. implements:
- Role based access controls (RBAC) to limit access to authorised personnel only.
- Encryption for stored and transmitted electronic data.
- Secure physical storage for paper records with restricted access.
7. Data Breach & Compliance Monitoring
- Any unauthorised access or data breach must be reported immediately to the Privacy Officer.
- The Privacy Officer will ensure compliance with the Privacy Act 2020, including mandatory notification of serious breaches to the Office of the Privacy Commissioner and affected individuals.
8. Policy Review & Updates
This policy will be reviewed annually to ensure ongoing compliance with legal requirements and best practices. Updates will be approved by senior management.
Reviewed: 12 March 2025 | Next review date: 12 March 2027 | Approved by: Lara Meyer (Interim CEO)
