DATA GOVERNANCE
Data retention and disposal
How MedTalk manages the retention and secure disposal of information throughout its lifecycle.
Purpose
This policy defines how MedTalk manages the retention and secure disposal of information throughout its lifecycle, so that information is retained only for as long as necessary, protected in accordance with its sensitivity, and disposed of securely when no longer required.
- Support compliance with legal, regulatory and contractual obligations
- Reduce the risk of data breaches and unnecessary data exposure
- Enable audits, investigations and legal processes
- Ensure secure and verifiable disposal of information
Scope
Personnel
- Employees
- Contractors and consultants
- Third-party service providers
- Vendors handling MedTalk data
Information assets
- Personal and healthcare-related data
- Customer and partner data
- Corporate and operational information
- Emails and collaboration data
- System logs and audit records
- Backups and archived data
Technology environments
- Cloud and SaaS platforms
- Corporate systems and networks
- Endpoints and mobile devices
- Backup and archival systems
- Third-party hosted environments
Governance and accountability
Executive leadership is responsible for ensuring appropriate governance is in place for managing information lifecycle risks, with retention practices reviewed periodically through risk and compliance governance forums.
- Chief Information Security Officer: owns this policy, oversees secure data handling and disposal practices, and monitors compliance with retention requirements.
- Data owners: classify information appropriately and define retention requirements based on business needs.
- Legal and privacy functions: interpret legal and regulatory requirements and manage legal holds and investigations.
This policy aligns with the Australian Privacy Act 1988, the Notifiable Data Breaches (NDB) Scheme, and ISO/IEC 27001 Information Security Management. Where MedTalk operates across jurisdictions, additional regulatory requirements may apply.
Data retention principles
- Minimum necessary retention: information is retained only as long as required to meet business, legal or regulatory obligations
- Risk-based retention: decisions consider data sensitivity, business value, legal and regulatory requirements, and the risk of unauthorised access or exposure
- Consistency and standardisation: retention requirements are applied consistently across systems and data types, supported by standardised schedules and automation where possible
- Security throughout lifecycle: information is protected through appropriate controls during storage, archival and disposal
- Auditability: retention and disposal activities are documented to support audit and compliance requirements
Retention, backups and media disposal
Retention requirements are documented in a Data Retention Schedule, which defines minimum retention periods, aligns with legal and contractual obligations, and is reviewed regularly. Where multiple requirements apply, the longest applicable retention period is followed.
- Information hosted in cloud infrastructure is backed up at a frequency commensurate with its business criticality
- Full snapshots of application environments and server configurations are captured at least every 24 hours
- The recoverability of encrypted backup sets is verified through quarterly restoration testing
- Audio recordings captured during service delivery are treated as transient data and are securely and irreversibly destroyed within 24 hours of creation, in practice immediately after transcription via burn-after-read audio destruction
Archival and legal holds
Information no longer actively used but required to be retained may be moved to archival storage, which remains encrypted, access-restricted, and retrievable for legal or business purposes. Backups are not used as a substitute for structured data retention processes.
Where legal or regulatory obligations require preservation of information, an authorised legal hold suspends disposal processes for affected data until the hold is formally released by authorised legal or compliance personnel.
Secure disposal
When information is no longer required and no legal hold applies, it is securely disposed of using approved methods appropriate to its sensitivity: secure deletion of electronic data, cryptographic erasure, or physical destruction of storage media or paper records, designed to prevent reconstruction or recovery of the data.
Disposal activities are logged, auditable, and supported by evidence such as certificates of destruction where required.
Third parties and data subject requests
Third-party providers handling MedTalk data must comply with defined retention and disposal requirements, implement appropriate security controls, and support data return or deletion on request. Third-party compliance is enforced contractually and monitored through vendor management processes.
Requests relating to personal information, including access, correction and deletion requests, are handled in accordance with legal obligations, balanced against retention requirements and any applicable legal holds.
Monitoring, exceptions and review
Compliance with this policy is monitored through periodic audits and reviews, monitoring of retention and deletion processes, and validation of system configurations. Non-compliance is addressed through risk management and remediation processes.
Exceptions must be formally documented with business justification, risk assessment and compensating controls, and approved by the Chief Information Security Officer.
This policy is reviewed at least annually, following significant regulatory or business changes, and after major security or data-related incidents.
Contact
Security & Compliance: support@medtalk.co
Legal / compliance: legal@medtalk.co