Table of Contents
- 1. Purpose
- 2. Scope
- 3. Policy Statement
- 4. Roles and Responsibilities
- 5. Policy Requirements
- 6. Implementation Guidance
- 7. Monitoring, Evidence, and Compliance
- 8. Exceptions
- 9. Review and Maintenance
- 10. Related Standards
1. Purpose
Ligala Tech Pte Data Retention and Secure Disposal Policy establishes the minimum requirements for retaining, archiving, placing legal holds on, and securely disposing of personal data and business records across the organization. Ligala Tech Pte operates in Singapore and handles information that may include client matter details, employee records, vendor records, product logs, support tickets, communications, and system-generated data. Because the company is small and uses cloud-based tools and applications, clear retention and deletion rules are essential to avoid inconsistent handling, unnecessary storage growth, and avoidable exposure during security incidents.
This policy supports compliance with the Singapore Personal Data Protection Act by ensuring personal data is not kept longer than necessary for legal or business purposes. It also supports ISO 27001 requirements for lifecycle management, information classification, and controlled disposal of assets and records. By defining how long information is kept and how it is deleted, archived, or preserved under legal hold, Ligala Tech Pte can better protect client and employee data while maintaining the records needed for business, audit, tax, employment, and legal obligations.
This policy is intended to create predictable and repeatable retention practices. It helps the company manage records consistently across cloud storage, email, collaboration tools, source code repositories, support platforms, and endpoint devices. It also strengthens incident response by reducing the volume of information that must be assessed during a breach or account compromise, and it reduces the risk of retaining outdated or unnecessary records that no longer serve a legitimate purpose.
2. Scope
This policy applies to all Ligala Tech Pte personnel, including employees, directors, contractors, interns, temporary workers, and any third parties who process information on behalf of the company. It covers all business records and all personal data processed, stored, transmitted, or backed up by Ligala Tech Pte regardless of format or media. This includes electronic records, cloud-hosted documents, emails, chat messages, tickets, records exported from applications, scanned documents, printed records, and portable media.
The policy applies to all environments where company information is stored or processed, including software-as-a-service platforms, cloud drives, collaboration tools, customer relationship systems, accounting systems, human resources tools, device storage, backups, archives, and test or development environments. It also applies to records created by company-owned tools such as security logs, application telemetry, access logs, and business analytics outputs when those records contain personal data or business-sensitive information.
This policy covers records associated with clients, prospects, employees, job candidates, vendors, partners, and operational activities. It includes information generated in the ordinary course of running a legal technology business, such as contract documents, invoices, payroll records, support communications, implementation notes, and incident records. Where a contractual, statutory, regulatory, or legal obligation requires a longer retention period than this policy would otherwise allow, the longer requirement governs.
3. Policy Statement
Ligala Tech Pte shall retain information only for as long as it is required to fulfill a documented business purpose, satisfy legal or regulatory obligations, support contractual commitments, or preserve evidence under a legal hold. Personal data shall not be retained indefinitely and shall be securely deleted or anonymized once its retention purpose expires, unless a documented exception applies. Retention periods must be set in a way that reflects the company’s size, system architecture, and operating model, while still meeting the obligations expected of a Singapore-based legal technology provider.
Information shall be classified, stored, and disposed of according to its sensitivity and purpose. Records that are no longer active but must be preserved shall be archived in a controlled manner with restricted access, integrity protections, and clear retrieval procedures. Records subject to legal hold shall be preserved intact and exempted from routine deletion until the hold is lifted by the authorized approver. Secure disposal shall be used to prevent unauthorized recovery, reuse, or disclosure of information that has reached the end of its retention life.
All business units and system owners are responsible for ensuring that retention and disposal practices are embedded into daily operations. This includes configuring application settings, automating deletion where feasible, retaining only necessary backups, and ensuring that employees understand when records may be kept, archived, or deleted. Ligala Tech Pte expects retention decisions to be documented, reviewable, and consistently applied across all platforms and processes.
4. Roles and Responsibilities
- Managing Director: approves this policy, resolves high-risk exceptions, and ensures the organization has resources to implement retention and disposal controls.
- Data Protection Officer: owns privacy alignment with Singapore PDPA, maintains retention principles for personal data, reviews legal hold decisions, and advises on deletion or anonymization requirements.
- Head of Operations: owns operational execution of retention schedules, archive management, and disposal workflows across business systems.
- IT Administrator or System Owner: configures technical retention rules, backup lifecycle settings, deletion automation, access controls, and secure disposal methods for systems under their control.
- Legal Counsel or External Legal Advisor: identifies litigation, investigation, or regulatory hold requirements, confirms hold scope, and authorizes release of holds.
- Human Resources Lead: manages retention and disposal of employee and candidate records in accordance with employment, payroll, and recruitment obligations.
- Finance Lead or Bookkeeper: manages retention for invoices, receipts, tax, and accounting records in line with statutory and audit requirements.
- All Employees and Contractors: follow retention instructions, store records in approved systems, avoid informal retention of unnecessary copies, and report records that may require legal hold.
5. Policy Requirements
- Ligala Tech Pte shall maintain a documented retention schedule for all major record categories; ownership: Data Protection Officer and Head of Operations; frequency: reviewed at least annually and upon material business or legal change; evidence: approved retention schedule with version history.
- Personal data shall be retained only for the minimum period needed for the stated purpose or legal obligation; ownership: record owner and Data Protection Officer; frequency: continuously, with purpose review at record creation and during scheduled retention reviews; evidence: system record retention settings, privacy notices, and disposal logs.
- A legal hold shall suspend routine deletion for relevant records immediately upon notice; ownership: Legal Counsel or external legal advisor with execution by system owners; frequency: event-driven upon trigger and reviewed monthly while active; evidence: written hold notice, scope list, acknowledgement records, and hold register.
- Archived records shall be stored separately from active records with restricted access and integrity protection; ownership: Head of Operations and IT Administrator; frequency: at archive creation and reviewed quarterly; evidence: archive location list, access control records, and integrity checks.
- Secure disposal shall be used for electronic records through deletion, overwrite, cryptographic erasure, or vendor-certified destruction methods appropriate to the medium; ownership: IT Administrator or system owner; frequency: upon retention expiry or approved disposal event; evidence: deletion reports, vendor certificates, or system audit logs.
- Physical records shall be cross-cut shredded, pulped, or otherwise rendered unreadable before disposal; ownership: Operations or office administrator; frequency: upon retention expiry and after approval of disposal batch; evidence: destruction certificate, disposal log, or witnessed destruction record.
- Backups shall follow a defined lifecycle so expired records are not restored indefinitely from backup media; ownership: IT Administrator; frequency: backup retention reviewed quarterly and after major system changes; evidence: backup policy settings, retention configuration export, and restore test records.
- Business-critical records required for tax, employment, contract, or client dispute purposes shall be retained for the applicable statutory or contractual period; ownership: Finance Lead, HR Lead, or record owner depending on category; frequency: at record creation and reviewed annually; evidence: category mapping to legal basis and retention rationale.
- Development, testing, and staging environments shall not contain production personal data unless approved and minimized; ownership: Product and Engineering Lead with IT Administrator; frequency: before each data refresh and reviewed at least quarterly; evidence: refresh approvals, masking logs, and environment configuration.
- Employees shall not store company records solely in personal email accounts, unapproved cloud drives, or personal devices without approved synchronization and retention controls; ownership: all employees, monitored by department leads; frequency: continuously; evidence: acceptable use acknowledgements and spot-check results.
- Retention exceptions shall require written approval, a defined business justification, an expiry date, and a documented review cycle; ownership: Managing Director and Data Protection Officer for privacy-related exceptions; frequency: at request and reviewed before expiry; evidence: exception register and approval record.
- Disposal activities shall be logged with date, record category, method, approver, and responsible party; ownership: Operations and IT Administrator; frequency: each disposal batch; evidence: disposal register and supporting certificates or system logs.
- Staff handling records shall complete retention and disposal awareness training; ownership: Human Resources and Data Protection Officer; frequency: at onboarding and at least annually; evidence: training attendance records and acknowledgement forms.
6. Implementation Guidance
Ligala Tech Pte should implement this policy by first creating a master inventory of record types and where they reside. Because the organization is small, a practical first step is to map key systems such as email, shared drives, HR tools, accounting software, ticketing tools, source control, and cloud backups. Each record category should be assigned an owner, a retention period, a business purpose, and a disposal method. This inventory should then be converted into a simple retention schedule that is easy to apply and update.
The company should configure native retention controls where possible rather than relying only on manual reminders. Examples include automatic deletion rules for recruitment records after the recruitment period ends, archive folders with restricted permissions for closed matters, and backup retention windows that align with the longest legitimate recovery need. For personal data in active systems, the company should prefer deletion or anonymization over indefinite storage. Where records must be preserved for operations, the company should limit access to only those who need the information to perform their role.
Legal hold handling should be operationalized through a standardized notice and tracking process. When a hold is issued, the affected systems, users, and record classes should be identified in writing, and routine deletion must be paused for those records. Once the matter ends and release is approved, the company should resume normal disposal processes promptly. For secure disposal, Ligala Tech Pte should define approved methods for each record medium, use certified vendors where internal destruction is not practical, and retain destruction evidence in a central register. Periodic spot checks should confirm that employee workflows follow the policy in practice.
7. Monitoring, Evidence, and Compliance
Ligala Tech Pte shall monitor compliance through periodic checks of retention settings, disposal logs, archive access, and legal hold registers. The Data Protection Officer and Head of Operations should jointly review a sample of records each quarter to confirm that disposal occurs on schedule and that archived records remain protected. The IT Administrator should verify that system-level retention rules, backup expiration, and deletion automation are functioning as configured. Findings should be documented and tracked to closure.
Evidence of compliance shall be maintained in a form suitable for audit and internal review. Acceptable evidence includes the retention schedule, policy acknowledgements, legal hold notices, exception approvals, destruction certificates, system audit logs, backup configuration exports, access reviews, and training records. For cloud services, screenshots or exported admin reports may be used where direct logs are not available. For physical disposal, vendor certificates or witnessed destruction logs should identify the date, quantity, record type, and disposal method.
Compliance metrics should focus on practical control effectiveness. Examples include the percentage of record categories mapped to retention periods, the number of overdue disposal items, the number of active legal holds, the percentage of systems with configured retention controls, and the completion rate of annual training. Escalation is required if records are retained beyond approved periods without a valid exception, if legal holds are not implemented in time, if destruction evidence is missing, or if a system cannot support the required retention or deletion control. High-risk findings shall be reported to the Managing Director promptly.
8. Exceptions
Exceptions to this policy are permitted only when there is a documented business, legal, technical, or contractual reason that makes full compliance temporarily impractical. An exception must identify the specific requirement being waived, the reason, the records affected, the compensating controls, and the expiry date. Privacy-related exceptions require review by the Data Protection Officer, and operational exceptions require review by the Head of Operations or IT Administrator as relevant. High-risk exceptions must be approved by the Managing Director.
All exceptions shall be recorded in an exception register maintained by the Head of Operations or Data Protection Officer. Each exception record must include the request date, approver, implementation date, expiry date, and review outcome. Exceptions must not be open-ended. They should be granted only for the shortest period necessary, and they must be reassessed before expiry. If an exception is no longer justified, the affected records shall return to standard retention and disposal rules immediately.
9. Review and Maintenance
This policy shall be reviewed at least annually and sooner if there are significant changes in law, regulatory guidance, client obligations, company structure, or information systems. The Data Protection Officer and Head of Operations are responsible for initiating the review, collecting feedback from record owners, and recommending updates. The review should consider whether retention periods remain appropriate, whether disposal methods are still secure, and whether the organization has introduced new platforms or workflows that require additional controls.
Policy maintenance must include version control, approval records, and communication of changes to affected personnel. When the policy is updated, Ligala Tech Pte should refresh the retention schedule, training content, legal hold procedures, and disposal instructions as needed. Changes should be communicated to employees and contractors in a timely manner, and acknowledgment should be obtained when changes materially affect user behavior. Any open exceptions and active legal holds should also be checked against the revised policy to determine whether additional action is required.
10. Related Standards
Singapore PDPA is the primary privacy framework supporting this policy. Its retention limitation principle requires organizations to cease retaining personal data once it is no longer necessary for legal or business purposes. This policy operationalizes that requirement by defining retention periods, controlling archival storage, and requiring secure disposal of personal data after the relevant purpose ends. The policy also supports accountability by documenting decisions, approvals, and evidence that retention is justified.
ISO 27001 is the information security management standard that informs the control design in this policy. Its emphasis on information lifecycle management, asset handling, access control, and secure disposal is reflected in the requirements for record inventories, retention schedules, legal holds, archive protection, and destruction evidence. For a small legal technology company, adopting these practices demonstrates disciplined control over information assets and reduces operational risk across cloud and business systems.
This policy also aligns with broader good practice in records management, privacy governance, and secure information handling. It provides a practical bridge between legal requirements, client expectations, and day-to-day operations. By combining PDPA retention principles with ISO 27001 lifecycle discipline, Ligala Tech Pte can manage information in a way that is compliant, defensible, and efficient.
Comments
0 comments
Please sign in to leave a comment.