Contents
APPENDIX 1: DATA RETENTION AND DISPOSAL SCHEDULE. 9
APPENDIX 2: DATA DISPOSAL PROCEDURE. 13
Compliance with this Policy is mandatory. Any breach shall be treated as misconduct and addressed in accordance with NAS’s disciplinary procedures.
changes in the law or regulatory requirements, significant organisational, technological, or operational changes; or recommendations arising from audits, compliance assessments, or incidents.
| Data Subjects | Data Collected | Retention Period | Justification | Disposal Measures | |
| Job Applicants
|
· Applicants’ personal information (e.g.,Name, ID, address, contact details )
· Application documents (e.g., CV, cover Letter) · Employment history and references · Academic and professional documents · Background checks · Pre-employment health checks · Family Medical history
|
3 years from the date of application
|
o Recruitment record keeping
o Verification of information o Future job opportunities o Legal or complaint handling o Compliance and audit purposes o Fit for work checks |
o Secure deletion such as overwriting and anonymisation
o Degaussing, physical destruction o Shredding, incineration or pulping. |
|
| Employees | § Contact details: Telephone numbers, Personal email and Postal address.
§ Recruitment data: Work history, Academic certificates, Interview notes, CVs, Cover letters, Information contained in the interview score sheets, Police clearance certificates, References from former employers, Psychometric tests results. § Onboarding data: Contract or letters of offer, Statutory documents such as NSSF, SHIF, KRA PIN, Bank details, Passport photos. § Employee Records: Employee personal data forms, Consent to use personal data form, Staff registers, Payroll and Employee benefits records, Transfer and promotion records, Salary review records, Performance management records, Disciplinary records, Leave records, Training records, Health records, Payroll and employee benefits records, Employee signatures, Communication with employees in form of emails, phone calls, letters. § Health Data: Family medical history, medical checks, laboratory tests, Medical insurance information, On-site clinic visits information including name, statutory medical records; WIBA records, DOSH records. Internship records: Intern personal data sheets and internship evaluation forms. |
§ Duration of employment at The Organization and 5 years thereafter for legal purposes
§ For photographs and videos: For the duration of the consent. § For cookies: refer to Cookie Policy. § CCTV records: as per CCTV Policy.
|
o Administration of contract
o Identification and verification o Legal Compliance o Health and Safety Compliance o Legitimate interests o Business requirements |
o Secure deletion such as overwriting, anonymization, degaussing, physical destruction
o Shredding, incineration or pulping. o Or any other method as may be determined by The Organization from time to time. |
|
| Individual Clients | Clients’ personal (e.g., name, address, contact)
· Invoices and receipts · Payment records · Compliance and regulatory documentation · Correspondence and communication records |
3 years after a service/transaction | o Business record keeping and accountability
o Legal and regulatory compliance o Audit and verification o Dispute resolution o Historical reference |
o Secure deletion such as overwriting and anonymisation
o Degaussing, physical destruction o Shredding, incineration or pulping. |
|
| Third-party Service Providers
|
· Third-party Service Providers Agreements
Financial Records · Invoices and receipts · Payment records · Bank details · Tax and audit documentation · Financial statements
|
o Termination date + 10 years
|
o Legal claims
o Dispute resolution o Auditing o Regulatory and tax compliance o Financial reporting o Audit and verification o Legal and dispute resolution o Record keeping and accountability |
o Secure deletion such as overwriting and anonymisation
o Degaussing, physical destruction o Shredding, incineration or pulping.
|
|
| Outsourced Employees | · Employee contracts
· Employee personnel files (e.g., performance reviews, disciplinary actions) · Payroll records · Employee health and safety records · Pension and benefits records · Employee training records · Employee leave records (sick leave, maternity leave) |
o Termination date + 10 years | o Legal protection,
o Managing employment disputes o Compliance with tax laws o Compliance with labor laws. |
||
| Visitors | · Name and staff/visitor ID
· Access card number · Airport pass number · CCTV footage and access logs · Date and time of entry/exit |
o 1 year from date of record creation (CCTV footage: 30–90 days unless required for investigation) | o Security monitoring and incident investigation
o Access verification and audit trail o Regulatory and safety compliance |
o Automatic deletion or overwriting of access logs after retention period
o Secure erasure of digital records o Shredding of physical access records or logs |
|
| Airline Representatives | · ID Number
· Staff Number · Airport Pass Number · CCTV Records |
o Termination date + 10 years
o CCTV records: as per CCTV Policy.
|
o Access control and security verification
o Operational coordination o Safety and incident investigation o Legal and regulatory compliance |
o Secure deletion such as overwriting and anonymisation
o Degaussing, physical destruction o Shredding, incineration or pulping. |
|
| Shareholder/Board of Directors | · Board meeting minutes and resolutions
· Directors’ contracts and service agreements · Director remuneration and benefits records · Conflict of interest declarations · Directors’ personal information (e.g., ID, address, tax information) · Financial and investment information |
|
o Corporate governance,
o Legal compliance o Audits o Historical records. |
o N/A | |
| Marketing Models | · Proof of consent for marketing purposes and audits.
· Contact details (e.g., name, email, phone number) · Opt-in/opt-out requests
|
o 2 years after withdrawal of consent | o Proof of consent for marketing purposes and audits.
o Marketing audit trail |
o Secure deletion such as overwriting and anonymisation
o Degaussing, physical destruction o Shredding, incineration or pulping. |
|
| Suppliers | · Contact details: phone number, email address, identification details: name, ID/Passport, KRA PIN, contract details
· Third-party agreements (e.g., medical service providers) · Payment details: supplier statements, bank account details, · CCTV records · Complaints/requests |
o Termination date + 10 years
o For photographs and videos: for the duration of the consent o CCTV records: as per CCTV Policy. |
o Legal claims, dispute resolution,
o Regulatory requirements. |
o Secure deletion such as overwriting and anonymisation
o Degaussing, physical destruction o Shredding, incineration or pulping.
|
|
| Office Visitors | · contact details: phone number,
· identification details: name, ID, Car registration number, · CCTV records · Complaints/requests |
o 1 year
o CCTV records: as per CCTV Policy. |
o Security and incident investigation
o Data protection compliance o Emergency management |
o Secure deletion such as overwriting and anonymisation
o Degaussing, physical destruction o Shredding, incineration or pulping |
|
| Website Visitors | · Name, Contact details i.e., phone number/email address, Online identifiers such as cookies and related tags, IP addresses | o 1 year | o Legitimate Interest | o As per the Terms and Conditions of the Website Privacy |
| Type of Data | Format | Approved Disposal Method | Responsible Department / Officer | Verification / Documentation |
| Personal Data Files | Physical (paper) | Shredding or pulping under supervision | HR Officer | Certificate or disposal log signed by supervisor |
| Employee Records | Physical / Electronic | Shredding (physical), secure deletion (electronic) | HR Officer | Disposal log retained for 2 years |
| Financial Documents | Physical | Shredding or incineration | Finance | Certificate of destruction |
| Client Records | Electronic | Secure erasure or overwriting; verified deletion from backups | IT Department | Disposal report reviewed by DPO |
| Emails and Communications | Electronic | Permanent deletion from servers and devices | IT Department | Audit log confirmation |
| Media and Storage Devices | Hardware / Drives | Degaussing, secure wiping, or physical destruction | IT Department | Destruction certificate / witness record |
| Third-Party Disposals | Any | As per contract; certified by vendor | DPO / Procurement | Certificate of destruction retained |
| Data | all data that we hold or have control over and therefore to which this Policy applies. This includes physical data such as hard copy documents, contracts, notebooks, letters and invoices. It also includes electronic data such as emails, electronic documents, audio and video recordings and CCTV recordings. It applies to both personal data and non-personal data. In this Policy we refer to this information and these records collectively as “data”. |
| Data Protection Officer | the person within the organization who is responsible for advising on and monitoring compliance with data protection laws. |
| Data Retention Policy | this Policy, which explains our requirements to retain data and to dispose of data and provides guidance on appropriate data handling and disposal |
| Disposable information | disposable information consists of data that may be discarded or deleted at the discretion of the user once it has served its temporary useful purpose and/or data that may be safely destroyed because it is not a formal or official record as defined by this Policy and the Record Retention Schedule. |
| Non-personal data | data which does not identify living individuals, either because it is not about living individuals (for example financial records) or because it has been fully anonymized. |
| Personal data | any information identifying a living individual or information relating to a living individual that we can identify (directly or indirectly) from that data alone or in combination with other identifiers we possess or can reasonably access. This includes special categories of personal data such as property details and pseudonymized personal data but excludes anonymous data or data that has had the identity of an individual permanently removed. Personal data can be factual (for example, a name, email address, location or date of birth) or an opinion about that person’s actions or behaviour |
| Record Retention Schedule: | the schedule attached to this Policy which sets out retention periods for our formal or official records. |
| Storage limitation principle | data protection laws require us to retain personal data for no longer than is necessary for the purposes for which it is processed. This is referred to as the principle of storage limitation |