Data retention and lifecycle policy
What personal data First Six holds, how long it is kept, and how it is deleted across the whole lifecycle — active students, leavers, cohort end, and tenant exit. States the current reality including the gaps, the committed position, and what still needs building.
What this policy commits us to
- The institution is the data controller and First Six the processor; retention defaults are fixed contractually in the per-tenant DPA.
- Students can hard-delete their own account, cascading through every live child record.
- Backup copies age out within 30 days — the counsel-approved outer bound, stated identically across the DPA, the privacy policy, and the subprocessor register.
- A retention floor protects mandatory-reporting and duty-of-care trails. The committed position is that a deceased student's records are never auto-purged; the legal-hold flag that would enforce it is not built yet, and no automated purge of student data runs today.
- Open items are documented rather than implied done: institution-initiated erasure tooling, tenant-teardown orchestration, and retention clocks.
Controls mapped to this policy
Mapping controls to the policy is how we check adherence. A green dot marks a control that is operating and traceable to evidence; an amber dot marks one that is documented and scheduled but has not run yet.
- Secure file upload controlsApplications
- Data classification and retention scheduleData
- Student self-service erasureData
- Bounded backup retention (30-day age-out)Data
- Off-site encrypted backupData
- Automated demo and visitor-data purgesData
- Small-cell suppression on analyticsData
- Tenant exit and exportCustomers
Standards mappings
Through its controls, this policy maps to the following standards and frameworks. Each entry states our real relationship with the standard.
ISO/IEC 27001:2022InfoSec complianceSelf-assessed
A full 93-control Annex A Statement of Applicability is maintained and honestly dispositioned, and the ISMS went live on 26 July 2026 with its first completed management review. Not certified: no external audit has occurred, the clause 9.2 internal audit is openly unmet, and the certification trigger (a named tender, funding, or first hire) was formally decided at the first management review.
- A.8.26Application security requirements
- A.5.12Classification of information
- A.8.10Information deletion
- A.8.13Information backup
- A.5.30ICT readiness for business continuity
- A.8.11Data masking
HECVAT (Higher Education Community Vendor Assessment Toolkit)Higher educationSelf-assessed
A full HECVAT answer pack is maintained and kept current for university procurement, deliberately honest about gaps (no SOC 2 or ISO attestation, no independent penetration test, PITR not enabled). It is a vendor self-assessment, not an externally validated response, backed by a full internal HECVAT-aligned self-audit.
- ExitVendor viability and data exit
Australian Privacy Act 1988 (APPs, incl. the NDB scheme)PrivacyApplicable law
The primary legal regime. APP 8 drives the residency objective and every disclosed cross-border flow, APP 11 drives retention and erasure, and the Notifiable Data Breaches scheme's assessment clock is built into the incident runbook with OAIC contacts documented. The privacy policy, terms, and DPA template are counsel-reviewed and approved.
- APP 11.2Destruction and de-identification
- APP 11Security of personal information
GDPR (EU General Data Protection Regulation)PrivacyApplicable law
Applies via international students. The 72-hour breach path is in the incident runbook, Article 28 processor terms sit in the counsel-approved DPA, Article 17 erasure maps to the student's own hard-delete cascade (with the audit-trail carve-out disclosed rather than hidden), and Article 22-equivalent disclosure covers automated crisis detection.
- Art. 17Right to erasure
Request access and we can share the full policy set, assessment reports, and completed questionnaires under NDA — or answer your security questionnaire directly.