Data Retention & Secure Deletion Policy
Outlines campus data retention rules and secure deletion of data.
Policy Information
| Policy Number | Policy Owner |
|---|---|
| 10025.1 | Information Technology Services |
- 1.0 Purpose
- 2.0 Revision History
- 3.0 Units and Persons Affected
- 4.0 Policy
Applicable laws and SUNY policy take precedence governing data retention and secure deletion. If not specified by SUNY or law, data should be kept for as long as required for business purposes plus two years.
Dataset owners determine business need.
Any person who maintains or otherwise possesses sensitive information for a business purpose must properly dispose of such information by taking reasonable measures to protect against unauthorized access to or use of the information in connection with its disposal.
- 5.0 Definitions
- 6.0 Responsibilities
- 7.0 Procedures
- 8.0 Forms
- 9.0 Appendix
- 10.0 Distribution and Training
For additional information about this policy, please contact the policy owner listed above.