HLD Group
Records management policy
Managing controlled records and evidence.
Last updated: 24 July 2026
Version 1.0 · Review cycle: 365 days · View all frameworks
1. Purpose
This policy establishes how HLD Group creates, maintains, protects, and disposes of records so that they remain authentic, reliable, complete, and usable for as long as they are required. Sound records management supports accountability, legal defensibility, regulatory compliance, and effective operations.
2. Scope
This policy applies to all records created or received by HLD Group in the course of business, in any format, including documents, data, email, and system records, and works together with the Data Retention Policy.
3. Definitions
- Record — information created, received, and maintained as evidence of an activity or obligation
- Record lifecycle — creation, use, maintenance, retention, and disposition
- Authenticity — assurance that a record is what it purports to be
- Integrity — assurance that a record is complete and unaltered
- Legal hold — a directive to preserve records relevant to actual or anticipated legal or regulatory matters
4. Record management principles
- Records are captured reliably and stored in managed systems
- Records remain authentic, complete, and tamper-evident throughout their life
- Records are retrievable within reasonable timeframes to meet business and legal needs
- Records are retained and disposed of under the Data Retention Policy
- Access to records is controlled according to their classification
5. Legal hold and preservation
When litigation, investigation, or a regulatory matter is reasonably anticipated, a legal hold is issued and normal disposal is suspended for the affected records until the hold is lifted. Personnel must comply with legal holds and must not alter or destroy records subject to them. Failure to preserve records under hold can result in serious legal consequences for HLD Group and the individuals involved.
6. Vital records
Records essential to the continuity of the business — including contracts, corporate records, intellectual property, and key financial records — are identified and given additional protection, including resilient storage consistent with the Business Continuity and Backup and Recovery Policies.
7. Framework alignment
- ISO 15489-1:2016 (records management)
- ISO/IEC 27001:2022 Annex A controls 5.33 (protection of records) and 8.10 (information deletion)
- SOX and financial recordkeeping requirements for applicable records
- SOC 2 Trust Services Criteria CC2.1 and the confidentiality category
8. Roles, exceptions, and review
Records owners are accountable for their records; legal and compliance administer holds. Exceptions require documented approval. This policy is reviewed at least annually.
Related frameworks
For contractual attestations or audit packs, contact [email protected].