Legal

Data Retention Policy

Effective from 15 March 2021

This Data Retention Policy ("the Policy") applies to all employees, contractors and consultants of Autop Pty Ltd and associates (the Company).

This policy will commence from 15 March 2021 and replaces all or any other Data Retention Policies (whether written or not).

Scope

The Company collects, holds, processes, and shares personal and proprietary data, a valuable asset that needs to be suitably protected and deleted when the purpose for which it was collected has been fulfilled.

This policy sets out the procedures to be followed by all employees, contractors and consultants that access and process data for Autop, to ensure a consistent approach for the management and retention of data.

This is in line with the Company's Policies:

  • Systems Access & Confidentiality Policy
  • Privacy Policy
  • Data Breach Procedure Policy
  • and the Privacy Act 1988 (Cth), including the Notifiable Data Breaches Scheme.

Determining data type

Personal Data

For information to be personal data, it must be either about an identifiable individual or about an individual who is reasonably identifiable.

Some information may be context dependent, for example: a date of birth may not seem to be Personal Data on its own, without a name. However, this date of birth would make the individual 're-identifiable' in some instances.

Personal data is collected by the Company from its clients, in relation to their personnel who use the Company's services.

Proprietary Data

The term proprietary data is used to describe data that is owned by an individual or organisation, which is deemed important enough that gives it a competitive advantage. This data is protected by copyright laws and/or contractual obligations.

Proprietary data is collected by the Company from its clients and third-party suppliers in order to supply the Company's clients with the Services.

Scope of use of personal and proprietary data

Personal and proprietary data is only permitted to be used in order to provide the Company's services to clients and for no other reason.

It is the responsibility of the client relationship manager to determine for the client or third-party data:

  • Acceptable use of data when performing the services;
  • Notice to third party suppliers of changes to content required (for example when a client has terminated a contract with Autop);
  • Time frames for the data deletion or deidentification to be performed; and
  • Personal and proprietary data supply and ownership organisations.

Personal or Proprietary Data is not to be exported or copied from Company systems unless it is part of your duties in a process approved by the Company. If you are unsure if you are authorised to export data, you should confirm with your line manager.

De-identification or deletion of data

Unless otherwise agreed in writing by the Client or third-party supplier:

  1. Personal data of a user is to be de-identified within thirty (30) days of the User's account has been disabled by the client on the Company's mobile application or website;
  2. Personal data of a user is to be deleted or deidentified upon request by an individual asserting their rights under our Privacy Policy and The Privacy Act 1988;
  3. Proprietary data and personal data relating to a relevant client account is to be deleted within 30 days of the client's termination of services with the Company.

Responsibilities

It is the responsibility of all employees, contractors and consultants to:

  • Notify your line manager if you receive a request from an individual to have their personal data deleted or deidentified.
  • Notify your line manager if you identify data that should be deleted or de-identified.
  • Delete any personal information that you receive in your company email (including shared email addresses).
  • Delete or deidentify any copies or backups you create of data containing personal or proprietary data as soon as the task that required it is complete.
  • Notify third-party data suppliers if a client is no longer using the Company's services in order to cease transfer of relevant proprietary data going forward.