SBS Portal Access Hub
Data Retention and Disposal Policy
How SBS reviews, protects, anonymises and securely disposes of portal information.
Version 1.0
1. Purpose and scope
This policy explains how Shard Business Services (SBS) retains, reviews, anonymises and securely disposes of information held in the SBS Portal. It applies to portal accounts, client organisations, service and audit records, uploaded evidence, activity records, security logs, technical logs and protected backups.
SBS applies the UK GDPR storage-limitation and data-minimisation principles. Information must not be retained indefinitely merely because it may be useful. Retention must support a documented service, legal, contractual, security or accountability purpose.
2. Responsibilities
- SBS administrators are responsible for reviewing due records, recording decisions and applying legal holds.
- Service owners must identify records required for an unresolved engagement, complaint, investigation, claim or regulatory obligation.
- Client organisations must upload only evidence needed for the relevant service and notify SBS where evidence must be preserved or removed.
- Only authorised administrators may approve anonymisation or permanent deletion.
3. Standard retention schedule
| Record category | Standard period | Action |
|---|---|---|
| Uploaded evidence and working files | 12 months from upload | Administrator review and permanent deletion unless held |
| Inactive user profile and contact information | Review after 12 months; normally anonymise after 24 months | Remove name, email, username and credentials while retaining a neutral identifier for historical attribution |
| Contracts and service records | Six years after contract or service end | Review and delete or anonymise where no continuing justification applies |
| Completed audit reports and necessary audit trail | Six years after completion or contract end | Review; retain only the report and accountability information still required |
| Authentication, security and administrator activity logs | Up to 12 months unless needed for an incident | Delete or anonymise after review |
| Application and technical logs | Up to 12 months | Delete after operational need ends |
| Protected backups | Normally up to three months | Expire through controlled backup rotation |
These are standard review points, not permission to retain every record for the full period. Information may be deleted earlier where the purpose has ended.
4. Account and organisation closure
When a user leaves, the account is deactivated rather than deleted immediately. Sessions, trusted devices, passwords and MFA credentials are revoked. When an organisation leaves, it is archived and its operational access is removed. Restoring an organisation does not automatically restore former users. Returning users require individual approval, a new password and fresh MFA enrolment.
5. Legal holds and exceptions
Deletion and anonymisation must be paused where information is reasonably required for an unresolved complaint, dispute, legal claim, investigation, safeguarding matter, information-rights request, audit, regulatory enquiry or other legal obligation. The administrator must record the reason for the hold. Holds must be reviewed and removed promptly when the reason ends.
6. Review and disposal procedure
- Review the due record and confirm the applicable category, date and purpose.
- Check for an organisation or record-level legal hold and consult the relevant service owner where needed.
- Confirm that no active service, complaint, request, investigation or claim requires retention.
- Approve deletion or anonymisation in the Data Retention console.
- Confirm the action completed and review any failure message before retrying.
- Retain the minimal disposal log showing the category, record identifier, action, administrator and date—not a copy of the deleted content.
7. Secure disposal and backups
Approved portal files are removed from authorised storage and their source records are marked deleted. User anonymisation replaces direct identifiers and permanently invalidates credentials. Information already contained in protected backups is not restored to normal use and expires through backup rotation. If a backup is restored for disaster recovery, completed retention actions must be reapplied where necessary.
8. Individual rights and client instructions
A retention period does not override applicable rights to erasure, restriction, objection or correction. Requests must be assessed individually. Where SBS acts as a processor for uploaded client evidence, SBS will normally refer the request to, or act on documented instructions from, the relevant client controller.
9. Governance and review
SBS will review this policy at least annually and when services, legal requirements, contracts or portal functionality materially change. Changes to standard periods must be documented, approved and reflected in the privacy notice, contracts or processing terms where appropriate.
10. Contact
Questions, preservation requests or concerns about disposal should be sent to [email protected] or the usual SBS contact.

