The purpose of this Data Retention Policy is to outline the principles and guidelines for retaining and disposing of data at MField MEA. This policy ensures that data is retained for the necessary period to comply with legal, regulatory, and business requirements while ensuring that data is securely deleted when no longer needed.
This policy applies to all employees, contractors, and third-party service providers of MField MEA who handle, manage, or have access to company data, including electronic and physical records.
Data is classified into the following categories for retention purposes:
Data will be securely deleted or disposed of after the retention period has expired, using the following methods:
Where applicable, backed-up data sets will be encrypted based on the data classification policy. MField MEA uses AES256-bit encryption for data backups.
To ensure that deleted data cannot be recovered:
MField MEA will comply with all applicable legal and regulatory requirements concerning data retention and disposal. The policy will be reviewed and updated as necessary to reflect changes in legal requirements.
This Data Retention Policy will be reviewed annually to ensure it remains relevant and effective in light of any changes to legal requirements, business needs, or technological advancements.
Any exceptions to this policy must be approved by the Data Protection Officer and documented accordingly.