Template notice: confirm the final retention periods with the business, client contracts and legal/compliance reviewer before launch.
1. Retention principle
Personal information should not be kept longer than needed for the purpose it was collected, unless retention is required or allowed by law, contract, security, audit or legitimate business purposes.
2. Suggested retention periods
- Learner account records: active contract period plus [insert period].
- Training progress and certificates: [insert period] for company training evidence.
- Admin audit logs: [insert period] for security and accountability.
- Support tickets/messages: [insert period] after closure.
- Temporary imports/export files: delete as soon as they are no longer needed.
3. Secure disposal
- Delete or anonymise records when retention ends.
- Remove old exported reports from shared drives and email attachments where possible.
- Keep backups only for the approved backup cycle.
- Restrict access to archived reports.
4. Client-specific retention
Some companies may need longer or shorter retention based on contract, audit, training policy or internal compliance rules. Record those requirements in the company onboarding file.
Last reviewed: 2026-08-22