IOSHQ Data Retention Policy
The IOSHQ Data Retention Policy explains the principles used to retain, review and dispose of learner, credential, administrative and personal data records according to their purpose and applicable requirements.
Purpose of the IOSHQ Data Retention Policy
IOSHQ maintains records for educational, credential, administrative, operational, security and compliance purposes. This policy establishes a general framework for determining how long information should be retained and when it should be reviewed, archived, anonymized or securely disposed of.
Retention periods may differ according to the type of record, its continuing purpose, contractual requirements, dispute or investigation needs, and applicable legal or regulatory obligations.
How IOSHQ Approaches Data Retention
Records should be retained for a legitimate purpose and for no longer than reasonably necessary, except where continued retention is justified by credential verification, academic records, legal obligations, disputes, security requirements or another legitimate institutional need.
Purpose
Retention should be connected to a defined educational, administrative, credential, operational or compliance purpose.
Duration
The appropriate retention period depends on the record category and the reason the information remains necessary.
Disposition
Records that no longer require retention should be handled using an appropriate deletion, destruction or anonymization process.
Information Covered by Data Retention
The IOSHQ data retention framework may apply to different categories of information depending on the services, systems and institutional processes involved.
Learner & Academic Records
Enrollment, participation, assessment, completion and related academic records may require retention to support educational administration and record integrity.
Credential Records
Credential information may require longer-term retention where necessary to maintain certificate records and support future verification.
Administrative Records
Communications, transactions, enquiries and other administrative records may be retained according to their operational or compliance purpose.
Retention of Certificate and Credential Records
Credential records have a distinct institutional purpose because IOSHQ may need to confirm whether a credential was issued and maintain sufficient information to support credential-record integrity and verification.
The information retained for this purpose should be limited to what is reasonably necessary for the applicable record and verification function.
How Retention Periods Are Determined
IOSHQ does not apply one universal retention period to every type of information. The appropriate period depends on the record’s purpose and the circumstances associated with it.
Operational Need
Information may be retained while it remains necessary to administer a program, service, transaction, account or institutional process.
Applicable Obligations
Retention may be affected by applicable legal, contractual, accreditation, dispute-resolution or recordkeeping requirements.
Record Integrity
Some records may remain necessary to establish historical transactions, academic outcomes, credential status or security events.
When Information May Need to Be Retained Longer
Information that would otherwise be eligible for disposal may need to remain available when it is relevant to an active complaint, appeal, investigation, dispute, security incident, legal matter, audit or other legitimate requirement.
Once the reason for extended retention ends, the information should return to the applicable records-management process.
Protection Throughout the Record Lifecycle
Reasonable safeguards should be applied to retained records according to the nature of the information and the systems in which it is maintained. When information reaches the end of its required retention period, an appropriate disposal method should be used.
Secure Storage
Access to retained information should be appropriately controlled according to its sensitivity and operational purpose.
Archiving
Records that remain necessary but are no longer routinely used may be moved to an appropriate archival state where applicable.
Secure Disposal
Information no longer requiring retention should be deleted, destroyed or anonymized using a method appropriate to the record and storage medium.
Data Retention and Personal Information
Where retained records contain personal information, retention should be considered together with the purposes for which the information is processed and the IOSHQ Privacy Policy.
A request concerning personal information does not necessarily require deletion of every associated record where IOSHQ has a continuing legitimate or applicable recordkeeping requirement.
IOSHQ Data Retention Policy FAQ
There is no single retention period for every record. Retention depends on the type of information, its purpose and any applicable educational, credential, operational, contractual or legal requirements.
Credential records may need longer-term retention so IOSHQ can preserve record integrity and support future verification of credentials issued by the Institute.
Not necessarily. Some learner, assessment, completion, transaction or credential records may remain necessary after program completion for legitimate recordkeeping purposes.
Yes. Relevant records may need to be retained while a complaint, appeal, investigation, dispute, security incident or other legitimate matter remains active.
Questions About IOSHQ Records?
For questions concerning personal information or institutional records, review the applicable IOSHQ policy or contact the Institute.
