Data Retention Policy

Beccles Choral Society Data Retention Policy (May 2026)

Introduction

This policy sets out how the Society will approach data retention and establishes processes to ensure we do not hold data for longer than is necessary. It forms part of the Society’s Data Protection Policy. 

Roles and responsibilities

The Society is the Data Controller and will determine what data is collected, retained and how it is used. The Committee is responsible for the secure and fair retention and use of data by the Society. Any questions relating to data retention or use of data should be directed to the Committee.

Regular Data Review

A regular review of all data will take place to establish if the Society still has good reason to keep and use the data held at the time of the review. As a general rule a data review should be held every two years.    

Data to be reviewed

  • The Society stores data on digital documents (e.g. spreadsheets) stored on personal devices held by committee members.
  • Physical data stored at the homes of committee members

Who the review will be conducted by

The review will be conducted by the members of the Committee, to be decided on at the time of the review.

How data will be deleted

  • Physical data will be destroyed safely and securely, including shredding.
  • All reasonable and practical efforts will be made to remove data stored digitally.
    • Priority will be given to any instances where data is stored in active lists (e.g. where it could be used) and to sensitive data.
    • Where deleting the data would mean deleting other data that we have a valid lawful reason to keep (e.g. on old emails) then the data may be retained safely and securely but not used.

Criteria

The following criteria will be used to make a decision about what data to keep and what to delete.

QuestionAction
 YesNo
Is the data stored securely?  No action necessaryUpdate storage protocol in line with Data Protection policy
Does the original reason for having the data still apply?  Continue to useDelete or remove data
Is the data being used for its original intention?  Continue to useEither delete/remove or record lawful basis for use and get consent if necessary
Is there a statutory requirement to keep the data?Keep the data at least until the statutory minimum no longer appliesDelete or remove the data unless we have reason to keep the data under other criteria.
Is the data accurate?Continue to useAsk the subject to confirm/update details
Where appropriate do we have consent to use the data. This consent could be implied by previous use and engagement by the individual  Continue to useGet consent
Can the data be anonymisedAnonymise dataContinue to use

Statutory Requirements

Data stored by the Society may be retained based on statutory requirements for storing data other than data protection regulations. This might include but is not limited to:

  • Gift Aid declarations records
  • Details of payments made and received (e.g. in bank statements and accounting records)
  • Trustee meeting minutes
  • Contracts and agreements with suppliers/customers
  • Insurance details
  • Tax and employment records

Member data

  • When a member leaves the Society and all administrative tasks relating to their membership have been completed, any potentially sensitive data held on them will be deleted – this might include bank details or medical data
  • Unless consent has been given data will be removed from all email mailing lists

Mailing list data

  • If an individual opts out of a mailing list their data will be removed as soon as is practically possible.

POLICY APPROVAL AND REVIEW

This policy will be reviewed annually, or sooner, if legislation, guidance or Beccles Choral Society’s activities change.