Contents

 

  1. INTRODUCTION.. 2
  2. PURPOSE. 2
  3. SCOPE OF THE POLICY. 2
  4. ROLES AND RESPONSIBILITIES. 2
  5. PRINCIPLES OF RETENTION AND DISPOSAL. 4
  6. SECURE DATA STORAGE. 5
  7. BACKUP AND DISASTER RECOVERY. 5
  8. DATA RETENTION SCHEDULE. 5
  9. SECURE DATA DISPOSAL. 6
  10. DATA DISPOSAL PROCEDURES. 6
  11. ARCHIVING OF PERSONAL DATA.. 6
  12. PERIODIC AUDITs 7
  13. MONITORING, REVIEW and ENFORCEMENT. 8

APPENDIX 1: DATA RETENTION AND DISPOSAL SCHEDULE. 9

APPENDIX 2: DATA DISPOSAL PROCEDURE. 13

APPENDIIX 3: DEFINITIONS. 14

 

1.          INTRODUCTION

 

2.          PURPOSE

3.          SCOPE OF THE POLICY

 Compliance with this Policy is mandatory. Any breach shall be treated as misconduct and addressed in accordance with NAS’s disciplinary procedures.

 4.          ROLES AND RESPONSIBILITIES

 

5.          PRINCIPLES OF RETENTION AND DISPOSAL

 

6.          SECURE DATA STORAGE

7.          BACKUP AND DISASTER RECOVERY

 

8.          DATA RETENTION SCHEDULE

 

9.           SECURE DATA DISPOSAL

 

10.         DATA DISPOSAL PROCEDURES

11.        ARCHIVING OF PERSONAL DATA

12.        PERIODIC AUDITS

 

13.        MONITORING, REVIEW & ENFORCEMENT

changes in the law or regulatory requirements, significant organisational, technological, or operational changes; or recommendations arising from audits, compliance assessments, or incidents.

 

 

APPENDIX 1: DATA RETENTION AND DISPOSAL SCHEDULE

Data Subjects Data Collected Retention Period Justification  Disposal Measures
Job Applicants

 

 

 

·       Applicants’ personal information (e.g.,Name, ID, address, contact details )

·       Application documents (e.g., CV, cover Letter)

·       Employment history and references

·       Academic and professional documents

·       Background checks

·       Pre-employment health checks

·       Family Medical history

 

3 years from the date of application

 

 

 

 

 

o   Recruitment record keeping

o   Verification of information

o   Future job opportunities

o   Legal or complaint handling

o   Compliance and audit purposes

o   Fit for work checks

o   Secure deletion such as overwriting and anonymisation

o   Degaussing, physical destruction

o   Shredding, incineration or pulping.

Employees §  Contact details: Telephone numbers, Personal email and Postal address.

§  Recruitment data: Work history, Academic certificates, Interview notes, CVs, Cover letters, Information contained in the interview score sheets, Police clearance certificates, References from former employers, Psychometric tests results.

§  Onboarding data: Contract or letters of offer, Statutory documents such as NSSF, SHIF, KRA PIN, Bank details, Passport photos.

§  Employee Records: Employee personal data forms, Consent to use personal data form, Staff registers, Payroll and Employee benefits records, Transfer and promotion records, Salary review records, Performance management records, Disciplinary records, Leave records, Training records, Health records, Payroll and employee benefits records, Employee signatures, Communication with employees in form of emails, phone calls, letters.

§  Health Data: Family medical history, medical checks, laboratory tests, Medical insurance information, On-site clinic visits information including name, statutory medical records; WIBA records, DOSH records.

Internship records: Intern personal data sheets and internship evaluation forms.

§  Duration of employment at The Organization and 5 years thereafter for legal purposes

§  For photographs and videos: For the duration of the consent.

§  For cookies: refer to Cookie Policy.

§  CCTV records: as per CCTV Policy.

 

o   Administration of contract

o   Identification and verification

o   Legal Compliance

o   Health and Safety Compliance

o   Legitimate interests

o   Business requirements

o   Secure deletion such as overwriting, anonymization, degaussing, physical destruction

o   Shredding, incineration or pulping.

o   Or any other method as may be determined by The Organization from time to time.

Individual Clients Clients’ personal (e.g., name, address, contact)

·       Invoices and receipts

·       Payment records

·       Compliance and regulatory documentation

·       Correspondence and communication records

3 years after a service/transaction o   Business record keeping  and accountability

o   Legal and regulatory compliance

o   Audit and verification

o   Dispute resolution

o   Historical reference

o   Secure deletion such as overwriting and anonymisation

o   Degaussing, physical destruction

o   Shredding, incineration or pulping.

Third-party Service Providers

 

·       Third-party Service Providers Agreements

Financial Records

·       Invoices and receipts

·       Payment records

·       Bank details

·       Tax and audit documentation

·       Financial statements

 

o   Termination date + 10 years

 

o   Legal claims

o   Dispute resolution

o   Auditing

o   Regulatory and tax compliance

o   Financial reporting

o   Audit and verification

o   Legal and dispute resolution

o   Record keeping and accountability

o   Secure deletion such as overwriting and anonymisation

o   Degaussing, physical destruction

o   Shredding, incineration or pulping.

 

 

 

 

Outsourced Employees ·       Employee contracts

·       Employee personnel files (e.g., performance reviews, disciplinary actions)

·       Payroll records

·       Employee health and safety records

·       Pension and benefits records

·       Employee training records

·       Employee leave records (sick leave, maternity leave)

o   Termination date + 10 years o   Legal protection,

o   Managing employment disputes

o   Compliance with tax laws

o   Compliance with labor laws.

Visitors ·       Name and staff/visitor ID

·       Access card number

·       Airport pass number

·       CCTV footage and access logs

·       Date and time of entry/exit

o   1 year from date of record creation (CCTV footage: 30–90 days unless required for investigation) o   Security monitoring and incident investigation

o   Access verification and audit trail

o   Regulatory and safety compliance

o   Automatic deletion or overwriting of access logs after retention period

o   Secure erasure of digital records

o   Shredding of physical access records or logs

Airline Representatives ·       ID Number

·       Staff Number

·       Airport Pass Number

·       CCTV Records

o   Termination date + 10 years

o   CCTV records: as per CCTV Policy.

 

o   Access control and security verification

o   Operational coordination

o   Safety and incident investigation

o   Legal and regulatory compliance

o   Secure deletion such as overwriting and anonymisation

o   Degaussing, physical destruction

o   Shredding, incineration or pulping.

Shareholder/Board of Directors ·       Board meeting minutes and resolutions

·       Directors’ contracts and service agreements

·       Director remuneration and benefits records

·       Conflict of interest declarations

·       Directors’ personal information (e.g., ID, address, tax information)

·       Financial and investment information

o   Termination date + 10 years

 

 

o   Corporate governance,

o   Legal compliance

o   Audits

o   Historical records.

o   N/A
Marketing Models ·       Proof of consent for marketing purposes and audits.

·       Contact details (e.g., name, email, phone number)

·       Opt-in/opt-out requests

 

o   2 years after withdrawal of consent o   Proof of consent for marketing purposes and audits.

o   Marketing audit trail

o   Secure deletion such as overwriting and anonymisation

o   Degaussing, physical destruction

o   Shredding, incineration or pulping.

Suppliers ·       Contact details: phone number, email address, identification details: name, ID/Passport, KRA PIN, contract details

·       Third-party agreements (e.g., medical service providers)

·       Payment details: supplier statements, bank account details,

·       CCTV records

·       Complaints/requests

o   Termination date + 10 years

o   For photographs and videos: for the duration of the consent

o   CCTV records: as per CCTV Policy.

o   Legal claims, dispute resolution,

o   Regulatory requirements.

o   Secure deletion such as overwriting and anonymisation

o   Degaussing, physical destruction

o   Shredding, incineration or pulping.

 

Office Visitors ·       contact details: phone number,

·       identification details: name, ID, Car registration number,

·       CCTV records

·       Complaints/requests

o   1 year

o   CCTV records: as per CCTV Policy.

o   Security and incident investigation

o   Data protection compliance

o   Emergency management

o   Secure deletion such as overwriting and anonymisation

o   Degaussing, physical destruction

o   Shredding, incineration or pulping

Website Visitors ·       Name, Contact details i.e., phone number/email address, Online identifiers such as cookies and related tags, IP addresses o   1 year o   Legitimate Interest o   As per the Terms and Conditions of the Website Privacy

 

 

APPENDIX 2: DATA DISPOSAL PROCEDURE

 

Type of Data Format Approved Disposal Method Responsible Department / Officer Verification / Documentation
Personal Data Files Physical (paper) Shredding or pulping under supervision HR Officer Certificate or disposal log signed by supervisor
Employee Records Physical / Electronic Shredding (physical), secure deletion (electronic) HR Officer Disposal log retained for 2 years
Financial Documents Physical Shredding or incineration Finance Certificate of destruction
Client Records Electronic Secure erasure or overwriting; verified deletion from backups IT Department Disposal report reviewed by DPO
Emails and Communications Electronic Permanent deletion from servers and devices IT Department Audit log confirmation
Media and Storage Devices Hardware / Drives Degaussing, secure wiping, or physical destruction IT Department Destruction certificate / witness record
Third-Party Disposals Any As per contract; certified by vendor DPO / Procurement Certificate of destruction retained

 

 

 

APPENDIX 3: DEFINITIONS

Data all data that we hold or have control over and therefore to which this Policy applies. This includes physical data such as hard copy documents, contracts, notebooks, letters and invoices. It also includes electronic data such as emails, electronic documents, audio and video recordings and CCTV recordings. It applies to both personal data and non-personal data. In this Policy we refer to this information and these records collectively as “data”.
Data Protection Officer the person within the organization who is responsible for advising on and monitoring compliance with data protection laws.
Data Retention Policy this Policy, which explains our requirements to retain data and to dispose of data and provides guidance on appropriate data handling and disposal
Disposable information disposable information consists of data that may be discarded or deleted at the discretion of the user once it has served its temporary useful purpose and/or data that may be safely destroyed because it is not a formal or official record as defined by this Policy and the Record Retention Schedule.
Non-personal data data which does not identify living individuals, either because it is not about living individuals (for example financial records) or because it has been fully anonymized.
Personal data any information identifying a living individual or information relating to a living individual that we can identify (directly or indirectly) from that data alone or in combination with other identifiers we possess or can reasonably access. This includes special categories of personal data such as property details and pseudonymized personal data but excludes anonymous data or data that has had the identity of an individual permanently removed. Personal data can be factual (for example, a name, email address, location or date of birth) or an opinion about that person’s actions or behaviour
Record Retention Schedule: the schedule attached to this Policy which sets out retention periods for our formal or official records.
Storage limitation principle data protection laws require us to retain personal data for no longer than is necessary for the purposes for which it is processed. This is referred to as the principle of storage limitation