Miva Open University, Data Retention Policy
1. Introduction
Miva Open University ("the University") is committed to maintaining the highest standards of data protection and information management in compliance with applicable regulations such as the Nigeria Data Protection Regulation (NDPR), the General Data Protection Regulation (GDPR), and other international standards. In the digital age, data has become a critical asset for academic institutions, underpinning essential operations such as admissions, academic management, research, and financial activities. It is therefore vital for Miva Open University to ensure that data, both personal and institutional, is handled with care, preserved for an appropriate length of time, and securely disposed of when it is no longer needed. This responsibility is not only a matter of compliance but also essential for building trust with students, staff, alumni, and external stakeholders.
The Data Retention Policy outlines the University's approach to managing data throughout its lifecycle, from the point of collection or creation, through active use, to eventual archiving and disposal. By implementing robust data retention practices, the University ensures that its operations remain efficient and that it can respond to legal obligations, such as data access requests, audits, or litigation proceedings, with speed and accuracy.
Moreover, by establishing a clear data retention framework, the University can minimize the risks associated with over-retention, such as data breaches, storage inefficiencies, and the unauthorized access to outdated or irrelevant information. The policy ensures that data is only retained for as long as it is needed for operational, legal, or academic purposes, after which it is disposed of in a secure and irreversible manner.
This policy applies to all University staff, students, contractors, and third-party partners who interact with any form of University data, whether in digital or physical format. Compliance with this policy is mandatory, and failure to adhere to its principles may result in disciplinary action or legal consequences.
2. Purpose
The purpose of this Data Retention Policy is to ensure that Miva Open University manages its data in a manner that is secure, compliant, and efficient. Specifically, the policy aims include:
- Compliance with Legal and Regulatory Requirements: The policy ensures that Miva Open University complies with data protection laws, including the Nigeria Data Protection Regulation (NDPR) and the General Data Protection Regulation (GDPR). These regulations require organizations to only retain personal data for as long as it is necessary, and to dispose of it securely once it is no longer required.
- Operational Efficiency: By defining clear data retention periods, the policy helps prevent unnecessary data accumulation, which can lead to inefficiencies and confusion over outdated or irrelevant information. Proper data management improves workflow and decision-making across the University by ensuring that only current, accurate, and relevant data is accessible.
- Data Security: Retaining unnecessary or outdated data increases the risk of breaches and unauthorized access. This policy reduces those risks by ensuring that unnecessary data is securely deleted or archived, limiting exposure to potential security threats and ensuring sensitive data is handled appropriately throughout its lifecycle.
- Support for Legal and Audit Requests: The policy helps the University efficiently respond to legal inquiries, audits, and other regulatory obligations by ensuring that required data is retained for the appropriate length of time and that irrelevant or outdated data is no longer stored, which helps mitigate legal risks.
- Preservation of Institutional Memory: Some records, such as academic transcripts, research, and operational history, have long-term or permanent value. The policy ensures that such important data is preserved, maintaining the University's historical and institutional memory.
3. Scope
This policy applies to all forms of data within the University, including but not limited to:
- Personal Data: Any information relating to an identified or identifiable individual (data subjects), such as students, staff, alumni, or other stakeholders.
- Institutional Data: Non-personal data such as records of academic programs, operational procedures, and research data.
- Digital Data: Data stored in electronic formats, such as files, databases, and emails.
- Physical Data: Hard copies of documents, files, and printed records.
- Sensitive Data: Data subject to additional protections, such as health records, financial data, or disciplinary records.
4. Legal and Regulatory Framework
This Data Retention Policy is grounded in the legal and regulatory frameworks that govern the management and protection of personal data. Miva Open University adheres to the following regulations and standards to ensure lawful and secure handling of data:
- Nigeria Data Protection Regulation (NDPR): The NDPR is Nigeria's principal data protection legislation, regulating the collection, processing, storage, and retention of personal data. This policy ensures that Miva Open University complies with the NDPR's stipulations, which mandate that personal data should only be retained for as long as necessary and be securely disposed of when no longer required. The NDPR also requires the University to implement data retention schedules and practices that protect the privacy rights of individuals.
- General Data Protection Regulation (GDPR): Although primarily a European regulation, the GDPR's scope extends to institutions like Miva Open University that may handle personal data of individuals within the European Economic Area (EEA). The GDPR emphasizes the principles of data minimization and storage limitation, requiring that personal data be retained only as long as necessary for its intended purpose. This policy aligns with GDPR's stringent requirements on data retention, storage, and disposal, ensuring that the University avoids unnecessary retention of personal data.
- Freedom of Information Act (FOIA): The Freedom of Information Act allows individuals to access certain types of information held by public institutions, including universities. This policy ensures that Miva Open University retains records and data for the appropriate time periods required by the FOIA, so they can be made available when required by law.
- Records Management and Archiving Standards: The policy is designed to align with industry standards for records management and archiving, including ISO 15489 (Information and Documentation, Records Management) and ISO 27001 (Information Security Management Systems). These standards emphasize the importance of structuring retention schedules, ensuring data accuracy, and implementing secure archiving and destruction protocols.
- Contractual Obligations: Miva Open University is subject to various contracts and agreements, which may specify particular retention periods for certain types of data. The policy ensures compliance with these contractual obligations, ensuring that data retention is managed in accordance with both internal and external agreements.
- Other Applicable Laws: The University is also subject to other national and international laws, including those related to employment, education, finance, and intellectual property, all of which may have specific requirements regarding data retention.
This policy ensures that Miva Open University complies with all relevant legal obligations, avoiding penalties or breaches of compliance.
5. Roles and Responsibilities
- Data Protection Officer (DPO): Oversees compliance with this policy and the University's broader data protection obligations.
- Department Heads: Ensure that data retention practices within their respective departments comply with this policy and conduct periodic reviews of stored data.
- IT Department: Responsible for the secure storage, backup, and deletion of electronic data in compliance with retention schedules.
- Staff and Students: Responsible for ensuring that personal and institutional data they handle is stored and disposed of in accordance with this policy.
6. Data Classification
To ensure the appropriate retention and disposal of data, all University data is classified into categories:
- Permanent Records: Records required for the long-term operation of the University, including minutes of meetings, annual reports, and accreditation documents.
- Operational Records: Data needed for day-to-day operations, including student records, staff records, and financial documents.
- Temporary Records: Data that serves a short-term purpose, such as drafts, meeting notes, and other transitory materials.
- Confidential Records: Sensitive information that requires a higher level of security, such as health records, disciplinary files, and examination results.
7. Data Retention Principles
- Necessity: Data shall only be retained for as long as it is necessary to fulfil its intended purpose.
- Minimization: Only data essential to operational, legal, or academic requirements shall be collected and retained.
- Accuracy: Data shall be maintained in an accurate and up-to-date manner throughout its retention period.
- Confidentiality: Access to data shall be restricted to authorized personnel, and data shall be stored securely to prevent unauthorized access or breaches.
- Accountability: Each department is responsible for ensuring that the data under its control is retained and disposed of in compliance with this policy.
8. Data Retention Periods
The University has established specific retention periods for different categories of data. These periods are based on legal, regulatory, and operational needs.
8.1 Student Records
- Application and Admission Records: Retained for 7 years after the student's last date of attendance.
- Academic Records (Grades, Transcripts): Retained permanently for all students.
- Examination Scripts: Retained for 7 years after the completion of the exam.
- Disciplinary Records: Retained for 7 years after the resolution of the case.
- Financial Aid and Scholarship Records: Retained for 7 years following the last date of award.
8.2 Staff Records
- Employee Personnel Files: Retained for 7 years after the employee's termination of employment.
- Payroll and Tax Records: Retained for 7 years after the last date of employment.
- Performance Reviews: Retained for 5 years after completion.
8.3 Financial Records
- Accounts Payable/Receivable: Retained for 7 years after the date of transaction.
- Budget Reports: Retained for 5 years after the end of the fiscal year.
- Audit Reports: Retained for 7 years after completion of the audit.
8.4 Research Data
- Research Proposals: Retained for 5 years following the completion or rejection of the proposal.
- Approved Research Data: Retained for 10 years following the completion of the research.
- Ethics Review Records: Retained for 7 years following the approval of the research.
8.5 IT and System Logs
- User Access Logs: Retained for 1 year to comply with cybersecurity policies.
- System Backups: Retained for 1 year following the backup process.
- Email Archives: Retained for 3 years to support institutional records.
- Regulatory Filings: Retained for 7 years after the date of submission.
8.6 Recruitment and Candidate Data
For candidates who apply to open roles via the uLesson Group Careers portal, we retain recruitment data only as long as it is needed for the hiring process and the periods below:
- Rejected or withdrawn applications: Candidate profile, CV, assessment answers, scenario recordings, project submissions, and supporting documents are permanently deleted 6 months after final disposition (the date the application was rejected or withdrawn). Deletion is performed automatically by a nightly purge job and is irreversible.
- Hired candidates: Recruitment records are transferred to the employee personnel file and retained under Section 8.2 above.
- Audit trail: Anonymised action logs (e.g. "candidate purged on YYYY-MM-DD") are retained for compliance but do not contain personal data after purge.
8.7 Your Rights as a Candidate
In line with NDPR and GDPR, every candidate has the following self-serve rights, available from the Profile page after signing in:
- Right to access (data portability): Download a complete JSON export of your profile, applications, assessments, scenario responses, project submissions, and decisions using the "Download my data" button.
- Right to rectification: Edit your profile details from the Profile page at any time.
- Right to withdraw an application: Use the "Withdraw" action on any active application in your dashboard. The application is marked terminal immediately and enters the 6-month retention window described above.
- Right to erasure: Use "Delete my account" on the Profile page to permanently remove your profile, every application, and all associated files (CVs, recordings, submissions) from our systems. This action is immediate and cannot be undone. If you prefer, our People & Culture team can fulfil the request on your behalf — contact careers@ulesson.com.
9. Secure Disposal of Data
When data has reached the end of its retention period, it must be securely disposed of to prevent unauthorized access or data breaches. The following methods are used based on the data's format:
- Physical Records: Shredding or incineration of hard copy documents.
- Digital Data: Use of secure deletion tools to permanently remove data from storage systems and ensure it is irrecoverable.
- Backup Data: Deletion of old backups that no longer serve a purpose, using secure destruction methods.
10. Data Archiving
Data that is no longer required for day-to-day operations but has historical or regulatory value will be archived. Archived data shall be stored securely, with access restricted to authorized personnel.
- Criteria for Archiving: Data that has a legal requirement, historical significance, or long-term operational value may be archived.
- Storage: Archived data will be stored in secure digital or physical formats, and access will be limited based on data sensitivity.
11. Data Breach Management
In the event of a data breach, the University shall promptly investigate and take necessary steps to mitigate any potential damage. If personal data is involved, affected individuals shall be notified as per the NDPR and GDPR requirements.
- Reporting a Breach: All staff and students must report suspected data breaches to the Data Protection Officer immediately.
- Remediation Measures: The University will follow its incident response plan to address breaches and prevent future occurrences.
12. Data Access Requests
Individuals have the right to request access to their personal data under the NDPR and GDPR. The University will respond to access requests within 30 days of receiving a valid request. Requests may include the right to:
- Access personal data.
- Request the correction of inaccurate data.
- Request the deletion of data under certain circumstances, including when:
- The data is no longer necessary for the purpose it was collected.
- Consent has been withdrawn, with no other legal basis for processing.
13. Training and Awareness
All University staff and students must undergo regular training on data retention, privacy, and security practices to ensure compliance with this policy. The University will provide ongoing resources to maintain awareness of data protection obligations.
14. Monitoring and Compliance
The University will conduct regular audits to ensure compliance with this Data Retention Policy. Department heads are responsible for ensuring that data is handled in accordance with retention schedules. Non-compliance may result in disciplinary action or legal consequences.
15. Review of Policy
This policy shall be reviewed every 2 years or whenever there is a significant change in data protection laws, regulations, or University operations. Updates will be communicated to all relevant stakeholders.