HLD Group
Data retention & disposal policy
Retention schedules and secure destruction of information.
Last updated: 24 July 2026
Version 1.0 · Review cycle: 365 days · View all frameworks
1. Purpose
This policy defines how long HLD Group retains information and how it is disposed of at the end of its lifecycle. Retaining data only as long as necessary reduces risk, cost, and regulatory exposure, while ensuring we meet legal, contractual, and operational obligations to keep records for defined periods.
2. Scope
This policy applies to all information held by HLD Group in any form, across all systems and storage, including backups and archives, and to customer data subject to any stricter contractual retention requirement.
3. Retention principles
- Storage limitation — personal data is kept no longer than necessary for the purposes for which it was collected
- Purpose alignment — retention periods are set by legal, regulatory, contractual, and legitimate business needs
- Defensible disposal — data is disposed of securely and consistently when its retention period ends
- Legal hold overrides disposal — data subject to litigation, investigation, or regulatory hold is preserved until released
4. Indicative retention periods
The following are indicative and are superseded by any specific legal, regulatory, or contractual requirement applicable to the data.
- Financial and tax records: 7 years (Australia and US requirements as applicable)
- Employment and personnel records: per applicable employment law, generally 7 years after end of employment
- Customer contracts and related records: term plus the applicable limitation period
- Security and audit logs: at least 12 months, and longer where required — see the Logging and Monitoring Policy
- Whistleblower and investigation records: at least 7 years from closure
- Marketing and consent records: for the duration of the relationship plus any period required to evidence consent
- Personal data of prospects and inactive users: reviewed and minimised on a defined cycle
5. Disposal and destruction
At the end of its retention period, information is securely disposed of using methods appropriate to its classification and medium, under the Asset Management Policy. Disposal of Confidential and Restricted data is recorded with evidence retained. Disposal is suspended for any data under legal hold.
6. Backups and archives
Retention rules apply to backups and archives as well as primary systems. Where technical constraints prevent selective deletion from immutable backups, data is removed on the natural expiry of the backup cycle, and this is documented so that deletion commitments to individuals and customers are honoured accurately.
7. Framework alignment
- Privacy Act 1988 (Cth), Australian Privacy Principle 11.2 (destruction or de-identification of personal information no longer needed)
- GDPR Article 5(1)(e) (storage limitation) and Article 17 (right to erasure)
- ISO/IEC 27001:2022 Annex A control 8.10 (information deletion)
- SOC 2 Trust Services Criteria confidentiality category (C1.2)
8. Roles, exceptions, and review
Data owners set and apply retention periods with legal and compliance input. Exceptions require documented approval with justification and an expiry date. This policy is reviewed at least annually and on any material change to legal retention requirements.
Related frameworks
For contractual attestations or audit packs, contact [email protected].