Shard Business ServicesShard Business ServicesReturn to sign in

SBS Portal Access Hub

Data Retention and Disposal Policy

How SBS reviews, protects, anonymises and securely disposes of portal information.

Version 1.0

1. Purpose and scope

This policy explains how Shard Business Services (SBS) retains, reviews, anonymises and securely disposes of information held in the SBS Portal. It applies to portal accounts, client organisations, service and audit records, uploaded evidence, activity records, security logs, technical logs and protected backups.

SBS applies the UK GDPR storage-limitation and data-minimisation principles. Information must not be retained indefinitely merely because it may be useful. Retention must support a documented service, legal, contractual, security or accountability purpose.

2. Responsibilities

  • SBS administrators are responsible for reviewing due records, recording decisions and applying legal holds.
  • Service owners must identify records required for an unresolved engagement, complaint, investigation, claim or regulatory obligation.
  • Client organisations must upload only evidence needed for the relevant service and notify SBS where evidence must be preserved or removed.
  • Only authorised administrators may approve anonymisation or permanent deletion.

3. Standard retention schedule

Record categoryStandard periodAction
Uploaded evidence and working files12 months from uploadAdministrator review and permanent deletion unless held
Inactive user profile and contact informationReview after 12 months; normally anonymise after 24 monthsRemove name, email, username and credentials while retaining a neutral identifier for historical attribution
Contracts and service recordsSix years after contract or service endReview and delete or anonymise where no continuing justification applies
Completed audit reports and necessary audit trailSix years after completion or contract endReview; retain only the report and accountability information still required
Authentication, security and administrator activity logsUp to 12 months unless needed for an incidentDelete or anonymise after review
Application and technical logsUp to 12 monthsDelete after operational need ends
Protected backupsNormally up to three monthsExpire through controlled backup rotation

These are standard review points, not permission to retain every record for the full period. Information may be deleted earlier where the purpose has ended.

4. Account and organisation closure

When a user leaves, the account is deactivated rather than deleted immediately. Sessions, trusted devices, passwords and MFA credentials are revoked. When an organisation leaves, it is archived and its operational access is removed. Restoring an organisation does not automatically restore former users. Returning users require individual approval, a new password and fresh MFA enrolment.

5. Legal holds and exceptions

Deletion and anonymisation must be paused where information is reasonably required for an unresolved complaint, dispute, legal claim, investigation, safeguarding matter, information-rights request, audit, regulatory enquiry or other legal obligation. The administrator must record the reason for the hold. Holds must be reviewed and removed promptly when the reason ends.

6. Review and disposal procedure

  1. Review the due record and confirm the applicable category, date and purpose.
  2. Check for an organisation or record-level legal hold and consult the relevant service owner where needed.
  3. Confirm that no active service, complaint, request, investigation or claim requires retention.
  4. Approve deletion or anonymisation in the Data Retention console.
  5. Confirm the action completed and review any failure message before retrying.
  6. Retain the minimal disposal log showing the category, record identifier, action, administrator and date—not a copy of the deleted content.

7. Secure disposal and backups

Approved portal files are removed from authorised storage and their source records are marked deleted. User anonymisation replaces direct identifiers and permanently invalidates credentials. Information already contained in protected backups is not restored to normal use and expires through backup rotation. If a backup is restored for disaster recovery, completed retention actions must be reapplied where necessary.

8. Individual rights and client instructions

A retention period does not override applicable rights to erasure, restriction, objection or correction. Requests must be assessed individually. Where SBS acts as a processor for uploaded client evidence, SBS will normally refer the request to, or act on documented instructions from, the relevant client controller.

9. Governance and review

SBS will review this policy at least annually and when services, legal requirements, contracts or portal functionality materially change. Changes to standard periods must be documented, approved and reflected in the privacy notice, contracts or processing terms where appropriate.

10. Contact

Questions, preservation requests or concerns about disposal should be sent to [email protected] or the usual SBS contact.

Legal documents

Acceptable UsePrivacy & Cookie NoticeData Retention and Disposal
Acceptable UsePrivacy & CookiesData Retention
© 2026 Shard Business Services · SBS Portal Access Hub