We are valued by our community and work to reduce inequalities and create life-enhancing opportunities for the growth and development of all people in body, mind and spirit.

447 Childers Road, Gisborne 4010 ygym@ymcagisborne.nz
(06) 867 9259
Follow Us
Image Alt

Data Retention & Disposal Policy

1. Purpose

This policy outlines how The YMCA Gisborne Inc. manages the retention, review, and secure disposal of personal and business information. It ensures compliance with the Privacy Act 2020, Tax Administration Act 1994, Employment Relations Act 2000, and other applicable laws while safeguarding client and staff data.

2. Scope

This policy applies to all records, including electronic and physical documents, collected and maintained by The YMCA Gisborne Inc. It covers client information, employee records, financial records, health and safety data, and other business-related documentation.

3. Data Retention Periods

Records shall be retained for the following periods unless otherwise required by law or contractual obligations:

Type of DataRetention PeriodLegal Basis
Client Personal InformationRetained only as long as necessary for service provision, then securely deletedPrivacy Act 2020 (IPP 9)
Financial & Tax RecordsMinimum 7 yearsTax Administration Act 1994
Employee Records (Contracts, Leave, Wage Records)Minimum 6 years after employment endsEmployment Relations Act 2000
Health & Safety RecordsMinimum 5 yearsHealth and Safety at Work Act 2015
Incident Reports (Serious Harm)Minimum 10 yearsWorkSafe NZ Requirements
Health & Medical RecordsMinimum 10 years after last contactHealth Information Privacy Code 2020
Legal & Contractual DocumentsMinimum 6 years after contract expirationLimitation Act 2010

4. Data Review Process

Data will be reviewed at least annually to identify records that are eligible for disposal. A Data Retention Officer (DRO), designated by senior management, will oversee the review process to ensure compliance.

5. Secure Disposal Methods

Once data has exceeded its retention period, it must be securely disposed of as follows:

  • Paper records: Shredded or securely incinerated.
  • Electronic records: Permanently deleted using data wiping software to prevent recovery.
  • Backups: Regularly purged according to the IT data retention schedule.

All disposals must be documented in a Data Destruction Log, recording the type of data, date of disposal, and method used.

6. Data Security & Access Control

To protect sensitive information, the YMCA Gisborne Inc. implements:

  • Role based access controls (RBAC) to limit access to authorised personnel only.
  • Encryption for stored and transmitted electronic data.
  • Secure physical storage for paper records with restricted access.

7. Data Breach & Compliance Monitoring

  • Any unauthorised access or data breach must be reported immediately to the Privacy Officer.
  • The Privacy Officer will ensure compliance with the Privacy Act 2020, including mandatory notification of serious breaches to the Office of the Privacy Commissioner and affected individuals.

8. Policy Review & Updates

This policy will be reviewed annually to ensure ongoing compliance with legal requirements and best practices. Updates will be approved by senior management.

Reviewed: 12 March 2025  |  Next review date: 12 March 2027  |  Approved by: Lara Meyer (Interim CEO)