New Practical Law Commercial resources: Two brand new data protection and privacy resources to mark Privacy Awareness Week
- Standard Document, Data Retention Policy: also known as a records management policy, this document describes how an organisation expects its employees to manage data from creation through to disposal. A data retention policy serves many important functions including:
- helping an organisation to demonstrate their compliance with their obligations under the Privacy Act 1988 (Cth) (Privacy Act) and the Australian Privacy Principles (APPs) (as well as other relevant legislation);
- communicating employer expectations about secure storage, as well as timely and proper disposal, of data; and
- identifying who is in charge of data management within an organisation and the roles and responsibilities of all employees.
- Standard Document, Data Retention Schedule (Personal information): covers a wide range of records containing personal information that may be held by an organisation and is arranged by typical business functions. A data retention schedule can help organisations holding personal information (including sensitive information) to demonstrate their compliance with the requirements for the retention and proper destruction or de-identification of data containing personal information in accordance with the Privacy Act and the APPs, as well as other relevant Commonwealth, state and territory legislation.
Both resources feature integrated drafting notes designed to ensure these templates can be easily adapted for fast implementation in your organisation.
Subscribers have access to a number of template privacy resources on Practical Law Australia, including a Data breach response plan and Privacy policy, as well as guidance on Performing a privacy impact assessment and a Quick Comparison Chart (GDPR and Australia) to name just a few. Find information about these topics and related content including APRA Prudential Standard CPS 234 Information Security and information about the Commonwealth Security Legislation Amendment (Critical Infrastructure) Bill 2020 and Establishing a digital resilience framework under the Commercial sub-topic Data protection and privacy.