Miva Open University, Data Retention Policy

1. Introduction

Miva Open University ("the University") is committed to maintaining the highest standards of data protection and information management in compliance with applicable regulations such as the Nigeria Data Protection Regulation (NDPR), the General Data Protection Regulation (GDPR), and other international standards. In the digital age, data has become a critical asset for academic institutions, underpinning essential operations such as admissions, academic management, research, and financial activities. It is therefore vital for Miva Open University to ensure that data, both personal and institutional, is handled with care, preserved for an appropriate length of time, and securely disposed of when it is no longer needed. This responsibility is not only a matter of compliance but also essential for building trust with students, staff, alumni, and external stakeholders.

The Data Retention Policy outlines the University's approach to managing data throughout its lifecycle, from the point of collection or creation, through active use, to eventual archiving and disposal. By implementing robust data retention practices, the University ensures that its operations remain efficient and that it can respond to legal obligations, such as data access requests, audits, or litigation proceedings, with speed and accuracy.

Moreover, by establishing a clear data retention framework, the University can minimize the risks associated with over-retention, such as data breaches, storage inefficiencies, and the unauthorized access to outdated or irrelevant information. The policy ensures that data is only retained for as long as it is needed for operational, legal, or academic purposes, after which it is disposed of in a secure and irreversible manner.

This policy applies to all University staff, students, contractors, and third-party partners who interact with any form of University data, whether in digital or physical format. Compliance with this policy is mandatory, and failure to adhere to its principles may result in disciplinary action or legal consequences.

2. Purpose

The purpose of this Data Retention Policy is to ensure that Miva Open University manages its data in a manner that is secure, compliant, and efficient. Specifically, the policy aims include:

  1. Compliance with Legal and Regulatory Requirements: The policy ensures that Miva Open University complies with data protection laws, including the Nigeria Data Protection Regulation (NDPR) and the General Data Protection Regulation (GDPR). These regulations require organizations to only retain personal data for as long as it is necessary, and to dispose of it securely once it is no longer required.
  2. Operational Efficiency: By defining clear data retention periods, the policy helps prevent unnecessary data accumulation, which can lead to inefficiencies and confusion over outdated or irrelevant information. Proper data management improves workflow and decision-making across the University by ensuring that only current, accurate, and relevant data is accessible.
  3. Data Security: Retaining unnecessary or outdated data increases the risk of breaches and unauthorized access. This policy reduces those risks by ensuring that unnecessary data is securely deleted or archived, limiting exposure to potential security threats and ensuring sensitive data is handled appropriately throughout its lifecycle.
  4. Support for Legal and Audit Requests: The policy helps the University efficiently respond to legal inquiries, audits, and other regulatory obligations by ensuring that required data is retained for the appropriate length of time and that irrelevant or outdated data is no longer stored, which helps mitigate legal risks.
  5. Preservation of Institutional Memory: Some records, such as academic transcripts, research, and operational history, have long-term or permanent value. The policy ensures that such important data is preserved, maintaining the University's historical and institutional memory.

3. Scope

This policy applies to all forms of data within the University, including but not limited to:

  1. Personal Data: Any information relating to an identified or identifiable individual (data subjects), such as students, staff, alumni, or other stakeholders.
  2. Institutional Data: Non-personal data such as records of academic programs, operational procedures, and research data.
  3. Digital Data: Data stored in electronic formats, such as files, databases, and emails.
  4. Physical Data: Hard copies of documents, files, and printed records.
  5. Sensitive Data: Data subject to additional protections, such as health records, financial data, or disciplinary records.

4. Legal and Regulatory Framework

This Data Retention Policy is grounded in the legal and regulatory frameworks that govern the management and protection of personal data. Miva Open University adheres to the following regulations and standards to ensure lawful and secure handling of data:

  1. Nigeria Data Protection Regulation (NDPR): The NDPR is Nigeria's principal data protection legislation, regulating the collection, processing, storage, and retention of personal data. This policy ensures that Miva Open University complies with the NDPR's stipulations, which mandate that personal data should only be retained for as long as necessary and be securely disposed of when no longer required. The NDPR also requires the University to implement data retention schedules and practices that protect the privacy rights of individuals.
  2. General Data Protection Regulation (GDPR): Although primarily a European regulation, the GDPR's scope extends to institutions like Miva Open University that may handle personal data of individuals within the European Economic Area (EEA). The GDPR emphasizes the principles of data minimization and storage limitation, requiring that personal data be retained only as long as necessary for its intended purpose. This policy aligns with GDPR's stringent requirements on data retention, storage, and disposal, ensuring that the University avoids unnecessary retention of personal data.
  3. Freedom of Information Act (FOIA): The Freedom of Information Act allows individuals to access certain types of information held by public institutions, including universities. This policy ensures that Miva Open University retains records and data for the appropriate time periods required by the FOIA, so they can be made available when required by law.
  4. Records Management and Archiving Standards: The policy is designed to align with industry standards for records management and archiving, including ISO 15489 (Information and Documentation, Records Management) and ISO 27001 (Information Security Management Systems). These standards emphasize the importance of structuring retention schedules, ensuring data accuracy, and implementing secure archiving and destruction protocols.
  5. Contractual Obligations: Miva Open University is subject to various contracts and agreements, which may specify particular retention periods for certain types of data. The policy ensures compliance with these contractual obligations, ensuring that data retention is managed in accordance with both internal and external agreements.
  6. Other Applicable Laws: The University is also subject to other national and international laws, including those related to employment, education, finance, and intellectual property, all of which may have specific requirements regarding data retention.

This policy ensures that Miva Open University complies with all relevant legal obligations, avoiding penalties or breaches of compliance.

5. Roles and Responsibilities

  1. Data Protection Officer (DPO): Oversees compliance with this policy and the University's broader data protection obligations.
  2. Department Heads: Ensure that data retention practices within their respective departments comply with this policy and conduct periodic reviews of stored data.
  3. IT Department: Responsible for the secure storage, backup, and deletion of electronic data in compliance with retention schedules.
  4. Staff and Students: Responsible for ensuring that personal and institutional data they handle is stored and disposed of in accordance with this policy.

6. Data Classification

To ensure the appropriate retention and disposal of data, all University data is classified into categories:

  1. Permanent Records: Records required for the long-term operation of the University, including minutes of meetings, annual reports, and accreditation documents.
  2. Operational Records: Data needed for day-to-day operations, including student records, staff records, and financial documents.
  3. Temporary Records: Data that serves a short-term purpose, such as drafts, meeting notes, and other transitory materials.
  4. Confidential Records: Sensitive information that requires a higher level of security, such as health records, disciplinary files, and examination results.

7. Data Retention Principles

  1. Necessity: Data shall only be retained for as long as it is necessary to fulfil its intended purpose.
  2. Minimization: Only data essential to operational, legal, or academic requirements shall be collected and retained.
  3. Accuracy: Data shall be maintained in an accurate and up-to-date manner throughout its retention period.
  4. Confidentiality: Access to data shall be restricted to authorized personnel, and data shall be stored securely to prevent unauthorized access or breaches.
  5. Accountability: Each department is responsible for ensuring that the data under its control is retained and disposed of in compliance with this policy.

8. Data Retention Periods

The University has established specific retention periods for different categories of data. These periods are based on legal, regulatory, and operational needs.

8.1 Student Records

8.2 Staff Records

8.3 Financial Records

8.4 Research Data

8.5 IT and System Logs

8.6 Recruitment and Candidate Data

For candidates who apply to open roles via the uLesson Group Careers portal, we retain recruitment data only as long as it is needed for the hiring process and the periods below:

8.7 Your Rights as a Candidate

In line with NDPR and GDPR, every candidate has the following self-serve rights, available from the Profile page after signing in:

9. Secure Disposal of Data

When data has reached the end of its retention period, it must be securely disposed of to prevent unauthorized access or data breaches. The following methods are used based on the data's format:

10. Data Archiving

Data that is no longer required for day-to-day operations but has historical or regulatory value will be archived. Archived data shall be stored securely, with access restricted to authorized personnel.

  1. Criteria for Archiving: Data that has a legal requirement, historical significance, or long-term operational value may be archived.
  2. Storage: Archived data will be stored in secure digital or physical formats, and access will be limited based on data sensitivity.

11. Data Breach Management

In the event of a data breach, the University shall promptly investigate and take necessary steps to mitigate any potential damage. If personal data is involved, affected individuals shall be notified as per the NDPR and GDPR requirements.

12. Data Access Requests

Individuals have the right to request access to their personal data under the NDPR and GDPR. The University will respond to access requests within 30 days of receiving a valid request. Requests may include the right to:

13. Training and Awareness

All University staff and students must undergo regular training on data retention, privacy, and security practices to ensure compliance with this policy. The University will provide ongoing resources to maintain awareness of data protection obligations.

14. Monitoring and Compliance

The University will conduct regular audits to ensure compliance with this Data Retention Policy. Department heads are responsible for ensuring that data is handled in accordance with retention schedules. Non-compliance may result in disciplinary action or legal consequences.

15. Review of Policy

This policy shall be reviewed every 2 years or whenever there is a significant change in data protection laws, regulations, or University operations. Updates will be communicated to all relevant stakeholders.

← Back to home