Policy Classification: Public
Document Type: Data Retention and Secure Disposal Policy
Applicability: Candidates, Data Subjects, Clients, Employees, Contractors, Authorized Users, Service Providers, Verification Partners, and Business Partners
Policy Owner: Data Privacy, Protection, and Security Office
Approving Authority: Circa Logica Group Management
Version: 3.2
Effective Date: 1 March 2022
Last Review Date: 6 January 2026
PART I
GENERAL RETENTION FRAMEWORK
1. POLICY STATEMENT
Talentprobe Due Diligence (“Talentprobe”), operated by Circa Logica Group (“CLG” or the “Group”), recognizes that responsible data protection requires not only the secure collection, use, and storage of information, but also appropriate decisions concerning how long information should be retained and how it should be disposed of when no longer required.
Background screening and due diligence activities may generate or require personal information, sensitive personal information, candidate documents, consent and authorization records, verification evidence, screening reports, correspondence, audit records, dispute records, client records, security logs, contractual records, financial records, and other information.
Talentprobe shall not retain personal data indefinitely merely because it may become useful at an unspecified future time.
Personal data shall be retained only for as long as reasonably necessary to fulfill the purpose for which it was collected or subsequently lawfully processed, or for such longer period as may be justified by applicable legal, regulatory, contractual, security, audit, dispute-resolution, evidentiary, or legitimate business requirements.
When information is no longer required and no lawful or legitimate basis exists for continued retention, Talentprobe shall take reasonable and appropriate measures to securely delete, destroy, anonymize, de-identify, or otherwise dispose of the information in a manner designed to prevent unauthorized recovery, access, reconstruction, or further processing.
Talentprobe shall apply a lifecycle approach to information management covering creation, collection, active use, storage, archival, preservation, backup, retrieval, retention, and final disposal.
2. PURPOSE
This Policy establishes Talentprobe’s framework for:
a. determining appropriate retention periods;
b. managing personal and confidential information throughout its lifecycle;
c. distinguishing active, archived, backup, and disposal-stage information;
d. establishing record-specific retention requirements;
e. preventing unnecessary or indefinite retention;
f. preserving records subject to legal, regulatory, contractual, or evidentiary requirements;
g. implementing legal holds;
h. securely disposing of electronic information;
i. securely destroying physical records;
j. managing data contained in backups;
k. managing information held by authorized third parties;
l. documenting appropriate disposal activities;
m. responding to data subject requests concerning deletion or erasure;
n. managing anonymized and de-identified information;
o. protecting information during migration or system retirement; and
p. maintaining accountability for retention and disposal decisions.
3. SCOPE
This Policy applies to information created, received, collected, generated, maintained, stored, archived, backed up, or otherwise processed by Talentprobe in connection with its operations.
This includes information maintained:
a. in Talentprobe systems;
b. in Circa Logica Group systems supporting Talentprobe;
c. in cloud environments;
d. in authorized third-party systems;
e. on approved endpoint devices;
f. in databases;
g. in email or communications systems;
h. in backup environments;
i. in physical files;
j. in archives;
k. in screening platforms;
l. in verification records;
m. in client account systems; and
n. through other authorized storage or processing arrangements.
4. INFORMATION COVERED
This Policy may apply to:
a. candidate personal information;
b. sensitive personal information;
c. identity documentation;
d. candidate-submitted documents;
e. consent and authorization records;
f. employment verification records;
g. education verification records;
h. professional credential verification records;
i. reference information;
j. court and public record information;
k. sanctions and compliance information;
l. screening reports;
m. verification evidence;
n. case notes;
o. correspondence;
p. dispute and correction records;
q. client information;
r. user account information;
s. contracts;
t. invoices and financial records;
u. security and access logs;
v. audit records;
w. quality assurance records;
x. incident and breach records;
y. employee and contractor records; and
z. other information maintained in connection with Talentprobe operations.
PART II
RETENTION PRINCIPLES
5. NECESSITY
Information shall be retained only where continued retention serves a legitimate and identifiable purpose.
Talentprobe shall periodically consider whether categories of information remain necessary for:
a. service delivery;
b. contractual performance;
c. legal compliance;
d. regulatory compliance;
e. audit;
f. security;
g. quality assurance;
h. dispute resolution;
i. establishment, exercise, or defense of legal claims;
j. fraud prevention;
k. business continuity;
l. legitimate corporate recordkeeping; or
m. another lawful purpose.
6. PURPOSE LIMITATION
Information retained for a particular purpose shall not automatically be used for unrelated purposes merely because it remains technically available.
Continued storage does not create an unrestricted right to reuse information.
7. DATA MINIMIZATION
Talentprobe shall seek to avoid retaining unnecessary copies of personal or confidential information.
Where information is no longer required in identifiable form, Talentprobe may consider deletion, destruction, anonymization, de-identification, aggregation, or another appropriate measure.
8. PROPORTIONALITY
Retention periods shall be proportionate to:
a. the nature of the information;
b. sensitivity of the information;
c. purpose of processing;
d. potential harm associated with unauthorized access;
e. contractual requirements;
f. applicable legal requirements;
g. evidentiary value;
h. likelihood of disputes or claims; and
i. legitimate operational requirements.
9. SECURITY DURING RETENTION
Information that remains within an applicable retention period shall continue to be subject to appropriate privacy, confidentiality, access control, and information security measures.
Archival does not remove the requirement to protect information.
10. ACCOUNTABILITY
Talentprobe shall maintain appropriate governance over retention and disposal activities.
Retention decisions should be capable of reasonable explanation by reference to an identified legal, contractual, regulatory, operational, security, or legitimate business requirement.
PART III
RETENTION CATEGORIES
11. CATEGORY-BASED RETENTION
Talentprobe shall use a category-based approach to data retention rather than applying a single universal retention period to all records.
Different records may require different retention periods because they serve different purposes and carry different legal, operational, evidentiary, and privacy considerations.
12. RETENTION SCHEDULE
Talentprobe shall maintain an internal Data Retention Schedule identifying appropriate retention requirements for relevant categories of information.
The schedule may identify:
a. record category;
b. responsible function;
c. retention trigger;
d. active retention period;
e. archival period where applicable;
f. legal or business justification;
g. disposal method;
h. applicable exceptions; and
i. responsible owner.
The detailed Data Retention Schedule may be maintained as an internal controlled document and does not need to be publicly disclosed in full.
13. RETENTION TRIGGERS
A retention period may begin from an event appropriate to the record concerned.
Examples include:
a. date of collection;
b. date of report completion;
c. date of case closure;
d. date of last candidate interaction;
e. date of contract termination;
f. date of client relationship termination;
g. date of dispute resolution;
h. date of incident closure;
i. date of employee separation;
j. date of financial transaction;
k. date of regulatory filing; or
l. another documented event.
PART IV
CANDIDATE AND SCREENING RECORDS
14. CANDIDATE PROFILE INFORMATION
Candidate profile information shall be retained only for as long as necessary for authorized screening, account administration, dispute resolution, applicable legal requirements, or another legitimate purpose.
Information that is no longer necessary should be removed, anonymized, or otherwise appropriately disposed of according to the applicable retention schedule.
15. IDENTITY DOCUMENTATION
Copies or images of identification documents may contain sensitive information and shall be subject to appropriate retention controls.
Talentprobe shall avoid retaining identity documentation longer than reasonably necessary for:
a. identity verification;
b. completion of authorized screening;
c. quality assurance;
d. dispute resolution;
e. fraud prevention;
f. legal compliance; or
g. another documented lawful requirement.
Where continued retention of the entire identification document is unnecessary, Talentprobe may retain only information reasonably necessary to evidence that identity verification was completed, where appropriate.
16. CONSENT AND AUTHORIZATION RECORDS
Records demonstrating candidate consent, authorization, acknowledgment, or other lawful authority for screening may be retained for an appropriate period following completion of the screening.
Such records may have continuing evidentiary importance because they demonstrate the basis upon which Talentprobe was authorized to perform particular checks.
Consent records may therefore be retained separately from other candidate documents and may be subject to a different retention period.
17. CANDIDATE-SUBMITTED DOCUMENTS
Documents submitted by candidates may include:
a. identification;
b. curriculum vitae or résumé;
c. employment certificates;
d. diplomas;
e. transcripts;
f. academic records;
g. professional licenses;
h. certifications;
i. reference information;
j. government documents; and
k. other supporting material.
Such documents shall be retained according to their necessity for the relevant screening, quality assurance, dispute handling, contractual obligations, and applicable legal requirements.
18. VERIFICATION EVIDENCE
Talentprobe may retain reasonable evidence demonstrating how a screening result was verified.
Evidence may include:
a. verification responses;
b. correspondence;
c. source confirmations;
d. authorized screenshots or extracts;
e. official records;
f. researcher notes;
g. source documentation;
h. system records; and
i. other information supporting the reported finding.
Verification evidence may be retained for an appropriate period to support quality assurance, client inquiries, candidate disputes, audits, and legal claims.
19. FINAL SCREENING REPORTS
Final screening reports may be retained for an appropriate period following case completion.
Retention may support:
a. client access;
b. report reissuance;
c. audit;
d. candidate disputes;
e. quality assurance;
f. regulatory compliance;
g. legal claims;
h. contractual requirements; and
i. other legitimate purposes.
Final reports shall not be retained indefinitely solely because storage is technically available.
20. DRAFT AND WORKING RECORDS
Temporary working records, duplicate files, intermediate reports, and other non-essential working materials should not automatically be retained for the same period as final records.
Where such records have no continuing business, evidentiary, legal, or compliance purpose, they should be securely disposed of according to applicable procedures.
21. INCOMPLETE OR CANCELLED CASES
Information relating to incomplete, abandoned, or cancelled screening cases shall be subject to an appropriate retention period based upon:
a. the stage at which processing stopped;
b. information already collected;
c. contractual requirements;
d. billing or administrative requirements;
e. potential disputes;
f. applicable privacy obligations; and
g. other legitimate considerations.
Cancellation of a case does not necessarily require immediate deletion of every record associated with that case.
PART V
DISPUTES, CORRECTIONS, AND QUALITY RECORDS
22. DISPUTE RECORDS
Records relating to candidate disputes may be retained for an appropriate period following resolution.
Such records may include:
a. original disputed finding;
b. candidate correspondence;
c. supporting documents;
d. reinvestigation records;
e. source communications;
f. determination;
g. amended reports; and
h. client communications.
These records may have legitimate evidentiary, quality, legal, and compliance value.
23. CORRECTION RECORDS
Where a screening report has been corrected, Talentprobe may retain appropriate records of:
a. the original information;
b. the identified error;
c. the investigation;
d. the corrected information;
e. reason for correction;
f. persons notified;
g. amended report; and
h. corrective action.
Retention of appropriate correction history supports auditability and prevents inaccurate information from inadvertently being reintroduced.
24. QUALITY ASSURANCE RECORDS
Quality review records may be retained for purposes including:
a. demonstrating compliance with verification standards;
b. identifying recurring errors;
c. monitoring performance;
d. training;
e. audit;
f. corrective action; and
g. continuous improvement.
Where quality records contain personal information, such information shall remain subject to applicable privacy and security requirements.
PART VI
CLIENT AND BUSINESS RECORDS
25. CLIENT ACCOUNT INFORMATION
Client information may be retained for the duration of the commercial relationship and for an appropriate period thereafter.
This may include:
a. account information;
b. authorized users;
c. service configuration;
d. contact information;
e. transaction history;
f. screening instructions;
g. account correspondence; and
h. administrative records.
Post-termination retention may be necessary for legal, contractual, accounting, dispute, audit, or legitimate business purposes.
26. CONTRACTS AND DATA PROCESSING AGREEMENTS
Contracts, Data Processing Agreements, confidentiality agreements, service agreements, amendments, and related legal documents may be retained for the duration of the agreement and for an appropriate period thereafter.
Such records may be required to demonstrate:
a. contractual rights;
b. processing authority;
c. agreed security requirements;
d. confidentiality obligations;
e. client instructions;
f. commercial terms; and
g. rights or obligations surviving termination.
27. FINANCIAL AND BILLING RECORDS
Invoices, payment records, tax documentation, transaction records, accounting records, and related information shall be retained according to applicable financial, tax, audit, and legal requirements.
Deletion of a client account does not necessarily require deletion of financial records that Talentprobe or Circa Logica Group is legally required to retain.
28. BUSINESS COMMUNICATIONS
Business communications may be retained where they document:
a. contractual instructions;
b. screening authorizations;
c. disputes;
d. material client decisions;
e. legal matters;
f. compliance matters;
g. service changes; or
h. other legitimate business activities.
Routine communications without continuing business value may be subject to shorter retention periods.
PART VII
SECURITY, ACCESS, AND SYSTEM RECORDS
29. SECURITY LOGS
Security logs may be retained for a period appropriate to support:
a. security monitoring;
b. investigation;
c. fraud prevention;
d. incident response;
e. forensic analysis;
f. audit;
g. regulatory compliance; and
h. legal claims.
30. ACCESS LOGS
Records of access to Talentprobe systems may be retained to support accountability, security, privacy, and audit requirements.
Such records may include authentication events, account activity, administrative actions, and other relevant access information.
31. SECURITY INCIDENT RECORDS
Records concerning information security incidents and personal data breaches may be retained for an appropriate period following closure.
Such records may include:
a. incident reports;
b. investigation records;
c. forensic evidence;
d. breach assessments;
e. notifications;
f. regulator communications;
g. corrective actions;
h. post-incident reviews; and
i. other relevant evidence.
32. AUDIT TRAILS
Audit trails shall be retained for periods appropriate to their security, accountability, quality, legal, and compliance purposes.
PART VIII
EMPLOYEE, CONTRACTOR, AND PROVIDER RECORDS
33. PERSONNEL RECORDS
Talentprobe and Circa Logica Group may retain employee and contractor information in accordance with applicable employment, tax, social security, corporate, privacy, and other legal requirements.
Personnel records may be subject to retention periods different from candidate screening records.
34. CONFIDENTIALITY RECORDS
Confidentiality agreements, security acknowledgments, privacy undertakings, and similar records may be retained beyond termination where necessary to establish continuing obligations.
35. VENDOR AND SERVICE PROVIDER RECORDS
Records relating to vendors, subprocessors, verification partners, and service providers may be retained for:
a. contract administration;
b. due diligence;
c. security review;
d. audit;
e. regulatory compliance;
f. disputes;
g. legal claims; and
h. vendor performance management.
PART IX
ACTIVE, ARCHIVED, AND BACKUP DATA
36. ACTIVE DATA
Active data is information maintained in systems or environments used for current business operations.
Access to active information shall be restricted according to legitimate business need.
37. ARCHIVED DATA
Information may be moved from active systems into an archive where:
a. frequent operational access is no longer necessary;
b. continued retention remains justified; and
c. deletion is not yet appropriate.
Archived information shall remain protected and shall not become unrestricted merely because it is no longer actively used.
38. ARCHIVAL ACCESS
Access to archived information should be more limited where appropriate.
Archived information may be retrieved for:
a. legal requirements;
b. disputes;
c. audits;
d. investigations;
e. regulatory requests;
f. client requirements;
g. data subject requests; or
h. other legitimate purposes.
39. BACKUP DATA
Talentprobe may maintain backups for disaster recovery, business continuity, system restoration, security, and operational resilience.
Backups may contain information that has subsequently been removed from active production systems.
40. BACKUP RETENTION
Backup information shall be retained according to established backup cycles appropriate to Talentprobe’s business continuity and recovery requirements.
Backup retention does not constitute authorization to use expired information for unrelated operational purposes.
41. DELETION FROM BACKUPS
Immediate deletion of an individual record from every backup may not always be technically feasible without compromising the integrity of the backup environment.
Where information has been appropriately deleted from active systems but remains temporarily within a backup:
a. the information shall remain protected;
b. access shall be restricted;
c. the information shall not ordinarily be restored for active use except as necessary for legitimate recovery;
d. applicable backup cycles shall eventually overwrite or expire the information; and
e. if a backup is restored, reasonable measures shall be taken to ensure that previously deleted information is not improperly returned to active processing.
42. DISASTER RECOVERY COPIES
Disaster recovery copies shall be used for continuity and recovery purposes and shall remain subject to appropriate access, security, and retention controls.
PART X
LEGAL HOLDS AND PRESERVATION
43. LEGAL HOLD
Talentprobe may suspend ordinary deletion or disposal of information where preservation is reasonably necessary in connection with:
a. actual or anticipated litigation;
b. legal claims;
c. regulatory investigation;
d. government inquiry;
e. candidate dispute;
f. client dispute;
g. internal investigation;
h. security incident;
i. audit;
j. law enforcement request; or
k. another lawful preservation requirement.
44. EFFECT OF LEGAL HOLD
Information subject to a valid legal hold shall not be destroyed merely because its normal retention period has expired.
The legal hold shall supersede ordinary disposal until the hold is appropriately released.
45. SCOPE OF HOLD
A legal hold should be limited to information reasonably relevant to the matter requiring preservation.
Talentprobe shall avoid unnecessarily preserving unrelated information where it can reasonably distinguish relevant from unrelated records.
46. RELEASE OF HOLD
When the legal or preservation requirement ends, affected records shall return to their normal retention lifecycle.
If the applicable retention period has already expired, the records may proceed to secure disposal unless another lawful basis for retention exists.
PART XI
DATA SUBJECT REQUESTS FOR DELETION
47. RIGHT TO REQUEST ERASURE OR BLOCKING
Data subjects may have the right under applicable law to request erasure, deletion, blocking, or restriction of personal information.
Talentprobe shall evaluate such requests in accordance with its Data Privacy and Protection Policy and applicable law.
48. DELETION IS NOT ABSOLUTE
A request for deletion does not automatically require Talentprobe to delete every record relating to the requester.
Talentprobe may retain information where continued retention is permitted or required for:
a. legal compliance;
b. contractual obligations;
c. establishment, exercise, or defense of legal claims;
d. dispute resolution;
e. regulatory requirements;
f. fraud prevention;
g. security;
h. legitimate business purposes recognized by applicable law; or
i. another lawful basis.
49. PARTIAL DELETION
Where only part of a record requires deletion, Talentprobe may delete, redact, restrict, anonymize, or otherwise appropriately address the affected information while retaining information that remains lawfully required.
50. PROCESSOR RELATIONSHIPS
Where Talentprobe processes personal data solely on behalf of a client, a deletion request may require coordination with or instructions from the relevant client acting as Personal Information Controller.
Talentprobe shall provide appropriate assistance in accordance with applicable law and contractual requirements.
PART XII
ANONYMIZATION AND DE-IDENTIFICATION
51. ANONYMIZED INFORMATION
Where information has been irreversibly anonymized so that an individual can no longer reasonably be identified, the information may cease to constitute personal data under applicable law.
Talentprobe may retain properly anonymized information for legitimate purposes including:
a. statistical analysis;
b. service improvement;
c. quality measurement;
d. operational analysis;
e. research;
f. benchmarking; and
g. trend analysis.
52. ANONYMIZATION STANDARD
Removal of a name alone does not necessarily constitute anonymization.
Talentprobe shall consider whether remaining information could reasonably permit re-identification when determining whether information has been sufficiently anonymized.
53. PSEUDONYMIZED INFORMATION
Pseudonymized information that can be re-associated with an individual through additional information shall continue to be treated as personal data and remain subject to appropriate protection and retention requirements.
54. AGGREGATED DATA
Talentprobe may retain statistical or aggregated information that does not reasonably identify individual data subjects.
Aggregated information may be used for quality, operational, research, benchmarking, or business intelligence purposes.
PART XIII
SECURE DISPOSAL
55. DISPOSAL PRINCIPLE
Information that has reached the end of its applicable retention period and is not subject to a valid preservation requirement shall be securely disposed of.
Disposal methods shall be appropriate to:
a. the sensitivity of the information;
b. the storage medium;
c. the risk of unauthorized recovery;
d. available technology; and
e. applicable legal or contractual requirements.
56. ELECTRONIC RECORD DELETION
Electronic information may be disposed of through methods including:
a. secure deletion;
b. cryptographic erasure;
c. secure overwrite;
d. destruction of encryption keys where appropriate;
e. account or database deletion;
f. storage media sanitization;
g. physical destruction of media; or
h. another appropriate method.
The specific method shall depend upon the technology and risk involved.
57. PHYSICAL RECORD DESTRUCTION
Physical documents containing personal, sensitive, confidential, or restricted information shall not ordinarily be discarded through unsecured general waste.
Appropriate destruction methods may include:
a. cross-cut shredding;
b. pulping;
c. secure destruction services;
d. controlled incineration where lawful and appropriate; or
e. another method reasonably designed to prevent reconstruction.
58. STORAGE MEDIA
Before storage media is reused, transferred, returned, sold, or disposed of, Talentprobe shall take reasonable measures to ensure that confidential or personal information has been appropriately removed or rendered inaccessible.
59. DEVICES
Devices containing Talentprobe information shall be subject to appropriate data removal, sanitization, or destruction before disposal or unauthorized reuse.
60. CLOUD DATA
Deletion of information stored in cloud environments shall be performed through available secure deletion mechanisms and according to applicable provider capabilities, contractual arrangements, and retention requirements.
61. THIRD-PARTY DESTRUCTION SERVICES
Where a third party is engaged to destroy records or media, Talentprobe shall take reasonable measures to use an appropriate provider and maintain suitable confidentiality and security arrangements.
Where warranted, evidence or certification of destruction may be obtained.
PART XIV
DISPOSAL DOCUMENTATION
62. DISPOSAL RECORDS
Talentprobe may maintain records demonstrating disposal of relevant categories of information.
A disposal record may include:
a. category of records destroyed;
b. applicable date range;
c. date of disposal;
d. disposal method;
e. responsible person or provider;
f. authorization; and
g. confirmation of completion.
Disposal records should not unnecessarily reproduce the personal information that has been destroyed.
63. CERTIFICATES OF DESTRUCTION
Where a third-party provider performs secure destruction, Talentprobe may obtain a certificate of destruction or comparable evidence where appropriate.
64. MASS DISPOSAL
Large-scale disposal of sensitive information may require additional approval, verification, or documentation according to risk.
PART XV
THIRD-PARTY RETENTION AND DELETION
65. PROCESSORS AND SERVICE PROVIDERS
Third parties processing Talentprobe information shall be expected to retain information only as necessary for authorized purposes and in accordance with applicable contractual and legal requirements.
66. CONTRACT TERMINATION
Where a service provider relationship ends, Talentprobe shall consider whether personal or confidential information should be:
a. returned;
b. transferred;
c. deleted;
d. destroyed;
e. anonymized; or
f. retained for a justified period.
The appropriate action shall depend upon applicable law, contractual terms, technical limitations, and legitimate preservation requirements.
67. SUBPROCESSORS
Where Talentprobe acts as a processor on behalf of a client, retention and deletion requirements applicable to authorized subprocessors may also be governed by the relevant Data Processing Agreement.
68. THIRD-PARTY CONFIRMATION
Where appropriate and proportionate to risk, Talentprobe may require a provider to confirm deletion or return of information following termination or completion of services.
PART XVI
SYSTEM MIGRATION AND DECOMMISSIONING
69. SYSTEM MIGRATION
When information is migrated from one system, infrastructure provider, platform, or storage environment to another, Talentprobe shall take reasonable measures to protect the information throughout the migration.
70. MIGRATION VALIDATION
Where appropriate, Talentprobe shall verify that information required in the new environment has been successfully transferred before legacy copies are disposed of.
71. LEGACY SYSTEMS
Legacy systems containing retained information shall remain subject to appropriate security controls for as long as they continue to hold Talentprobe information.
72. SYSTEM DECOMMISSIONING
When a system is retired, Talentprobe shall determine whether information contained within the system should be:
a. migrated;
b. archived;
c. retained under legal hold;
d. anonymized;
e. securely deleted; or
f. otherwise appropriately disposed of.
73. DUPLICATE DATA FOLLOWING MIGRATION
Temporary duplicate information created as part of a migration should be removed when no longer required, subject to appropriate validation, retention, and preservation requirements.
PART XVII
EMAIL, COMMUNICATIONS, AND LOCAL COPIES
74. EMAIL RETENTION
Email communications may contain personal or confidential information and shall be subject to appropriate retention requirements.
Emails documenting material business, legal, verification, privacy, security, contractual, or dispute matters may require longer retention than routine communications.
75. LOCAL DOWNLOADS
Personnel shall avoid unnecessarily retaining local copies of candidate reports, identity documents, verification evidence, or other sensitive information where centralized authorized systems are available.
76. TEMPORARY FILES
Temporary downloads, exports, working copies, and locally generated files containing personal or confidential information should be deleted when no longer required for the authorized purpose.
77. PRINTED COPIES
Printed copies of personal or confidential information should be minimized.
Where printing is necessary, documents shall be appropriately protected and securely destroyed when no longer required.
PART XVIII
RETENTION GOVERNANCE
78. DATA OWNERSHIP
Relevant business functions may be designated as owners or custodians of particular categories of information.
Data owners may be responsible for:
a. identifying business requirements;
b. supporting retention decisions;
c. identifying applicable legal requirements;
d. authorizing disposal;
e. identifying legal holds; and
f. supporting periodic review.
79. DATA PRIVACY, PROTECTION, AND SECURITY OFFICE
The Data Privacy, Protection, and Security Office shall provide appropriate oversight of retention and disposal practices involving personal data.
Responsibilities may include:
a. reviewing retention requirements;
b. supporting data subject requests;
c. advising on privacy requirements;
d. coordinating legal holds;
e. reviewing disposal practices;
f. supporting audits; and
g. maintaining relevant policies and schedules.
80. TECHNOLOGY FUNCTION
Appropriate technology personnel may be responsible for implementing technical retention, backup, archival, deletion, and system decommissioning controls.
81. LEGAL AND COMPLIANCE REVIEW
Legal, regulatory, contractual, and compliance requirements may affect applicable retention periods.
Talentprobe may obtain legal or compliance guidance where the appropriate retention period is uncertain or where competing obligations exist.
PART XIX
RETENTION EXCEPTIONS
82. REGULATORY REQUIREMENTS
Where a regulator or applicable law requires information to be retained for a specified period, the mandatory period shall apply.
83. CONTRACTUAL REQUIREMENTS
Where Talentprobe has accepted a lawful contractual retention requirement, the relevant records may be retained according to the contract.
Contractual requirements shall not be interpreted as authorizing retention prohibited by applicable law.
84. ACTIVE DISPUTES
Information relevant to an unresolved candidate or client dispute may be retained until the dispute has been appropriately resolved and for such further period as may be justified for legal or evidentiary purposes.
85. SECURITY INCIDENTS
Information relevant to an active or historical security incident may be retained where necessary for investigation, regulatory compliance, remediation, legal claims, audit, or security improvement.
86. FRAUD AND MISUSE
Information reasonably necessary to prevent, investigate, or respond to suspected fraud, identity misuse, unauthorized access, or abuse may be retained where supported by an appropriate legal basis.
PART XX
PERIODIC REVIEW AND DATA HYGIENE
87. PERIODIC RETENTION REVIEW
Talentprobe shall periodically review relevant categories of information to identify records that have exceeded their applicable retention period.
88. DATA HYGIENE
Talentprobe shall seek to reduce unnecessary accumulation of information through measures such as:
a. scheduled deletion;
b. archival controls;
c. duplicate removal;
d. account closure procedures;
e. temporary file cleanup;
f. secure disposal campaigns;
g. system configuration; and
h. periodic review.
89. EXCESSIVE RETENTION
Where Talentprobe identifies information that has been retained beyond its appropriate period without sufficient justification, the information shall be reviewed and appropriately disposed of unless a valid reason for continued retention exists.
90. SUSPENSION OF AUTOMATED DELETION
Automated deletion may be suspended where necessary to preserve information subject to:
a. legal hold;
b. security investigation;
c. regulatory inquiry;
d. dispute;
e. system recovery;
f. audit; or
g. another authorized exception.
PART XXI
PRIVACY AND SECURITY DURING DISPOSAL
91. CONFIDENTIALITY THROUGH FINAL DISPOSAL
Information shall remain confidential until secure disposal is complete.
Information does not cease to require protection merely because it has been marked for deletion or destruction.
92. DISPOSAL ACCESS
Access to records awaiting disposal shall remain restricted to authorized personnel.
93. TRANSPORT FOR DESTRUCTION
Where physical records or storage media must be transported for destruction, reasonable measures shall be taken to prevent unauthorized access, loss, or disclosure during transport.
94. DISPOSAL INCIDENTS
Loss, unauthorized disclosure, or compromise of information during disposal shall be treated as a potential information security incident and handled in accordance with the Information Security and Data Breach Management Policy.
PART XXII
SPECIAL CONSIDERATIONS FOR BACKGROUND SCREENING
95. RETENTION DOES NOT CHANGE A FINDING
The continued retention of a background screening report does not mean that the information remains current indefinitely.
A screening report reflects information available and verified at the time the relevant screening was performed.
96. HISTORICAL REPORTS
Where a historical report is accessed or reissued, Talentprobe may indicate that the report reflects a previous screening date and should not necessarily be interpreted as representing the individual’s current circumstances.
A new screening may be required where current information is necessary.
97. SUPERSEDED REPORTS
Where a report has been materially corrected or amended, Talentprobe shall seek to ensure that the current version is identifiable.
Superseded reports may be retained where necessary for audit, dispute, quality, legal, or evidentiary purposes but should be appropriately identified or restricted to reduce the risk of unintended reliance.
98. REUSE OF SCREENING INFORMATION
The existence of a historical screening report does not automatically authorize its reuse for a new purpose, new client, or new employment decision.
Any reuse shall be subject to applicable privacy requirements, contractual arrangements, consent or authorization requirements, relevance, currency, and other lawful considerations.
99. CLIENT COPIES
Once a screening report has been lawfully delivered to a client, the client is responsible for its own retention, security, use, and disposal obligations as an independent recipient or Personal Information Controller, as applicable.
Talentprobe’s deletion of its own copy does not automatically delete copies independently maintained by the client.
100. CANDIDATE ACCESS
Where a candidate is lawfully entitled to access screening information, the fact that a record is approaching the end of its retention period shall not be used to intentionally frustrate a valid request.
Where a valid request has been received, disposal may be temporarily suspended where appropriate to allow the request to be addressed.
PART XXIII
RETENTION SCHEDULE GOVERNANCE
101. ESTABLISHING RETENTION PERIODS
Retention periods shall be established after consideration of relevant factors, including:
a. purpose of processing;
b. applicable Philippine law;
c. contractual obligations;
d. applicable foreign law where relevant;
e. limitation periods for legal claims;
f. regulatory requirements;
g. industry practices;
h. sensitivity of information;
i. security risks;
j. likelihood of disputes;
k. audit requirements; and
l. operational necessity.
102. REVIEW OF RETENTION PERIODS
Retention periods shall not be treated as permanent merely because they have historically been used.
Talentprobe may shorten or extend a retention period where supported by changes in law, risk, contractual obligations, technology, operational requirements, or legitimate business need.
103. APPROVAL OF RETENTION SCHEDULE
The Data Retention Schedule shall be approved through appropriate Talentprobe or Circa Logica Group governance.
Material changes affecting sensitive personal information or significant categories of records should receive appropriate privacy, legal, compliance, security, or management review.
104. RETENTION PERIOD AS MAXIMUM, NOT DEFAULT REQUIREMENT
Unless otherwise required by law, a stated retention period should generally be treated as the maximum routine period for retaining the relevant information.
Information may be disposed of earlier where:
a. the purpose has been fulfilled;
b. no legal or contractual requirement requires continued retention;
c. no legal hold applies;
d. no unresolved dispute requires preservation; and
e. earlier disposal is appropriate.
PART XXIV
COMPLIANCE AND AUDIT
105. COMPLIANCE MONITORING
Talentprobe may periodically review compliance with this Policy and the applicable Data Retention Schedule.
106. RETENTION AUDITS
Retention reviews or audits may assess:
a. records retained beyond schedule;
b. incomplete disposal;
c. excessive duplication;
d. inappropriate local storage;
e. backup practices;
f. legal hold compliance;
g. vendor deletion practices;
h. disposal documentation; and
i. other relevant matters.
107. CORRECTIVE ACTION
Where non-compliance is identified, Talentprobe may implement corrective measures including:
a. deletion;
b. secure destruction;
c. process changes;
d. system configuration changes;
e. training;
f. revised retention periods;
g. vendor remediation; or
h. other appropriate measures.
108. POLICY VIOLATIONS
Intentional unauthorized retention, destruction, concealment, extraction, or improper disposal of Talentprobe information may result in disciplinary, contractual, legal, or other appropriate action.
PART XXV
RELATIONSHIP WITH OTHER POLICIES
109. DATA PRIVACY AND PROTECTION POLICY
This Policy supplements the Talentprobe Data Privacy and Protection Policy.
Where personal data is retained, all applicable privacy principles continue to apply.
110. INFORMATION SECURITY AND DATA BREACH MANAGEMENT POLICY
Information retained under this Policy shall be protected in accordance with the Information Security and Data Breach Management Policy.
Any suspected compromise during storage, archival, migration, or disposal shall be assessed under the incident management framework.
111. BACKGROUND SCREENING QUALITY AND ACCURACY POLICY
Verification evidence, quality records, correction records, and screening reports retained under this Policy shall be managed consistently with the Background Screening Quality and Accuracy Policy.
112. CANDIDATE RIGHTS, DISPUTE AND RESOLUTION POLICY
Candidate requests concerning deletion, correction, access, restriction, or disputed screening information shall also be governed by the Candidate Rights, Dispute and Resolution Policy, where applicable.
113. DATA PROCESSING AGREEMENTS
Where Talentprobe acts as a Personal Information Processor, applicable client instructions and Data Processing Agreements may establish specific retention, return, or deletion requirements.
Such requirements shall be followed to the extent they are lawful and contractually applicable.
PART XXVI
POLICY ADMINISTRATION
114. POLICY REVIEW
This Policy shall be reviewed periodically and may be updated in response to:
a. changes in applicable law;
b. National Privacy Commission requirements;
c. changes in Talentprobe services;
d. changes in information systems;
e. new categories of information;
f. security developments;
g. contractual requirements;
h. audit findings;
i. privacy impact assessments;
j. operational changes;
k. regulatory developments; or
l. recognized data protection practices.
115. POLICY AVAILABILITY
This Policy is classified as a public policy and may be:
a. published on Talentprobe’s official website;
b. provided to candidates;
c. provided to clients;
d. submitted during vendor accreditation;
e. provided during procurement or due diligence;
f. shared with auditors or compliance reviewers; and
g. otherwise provided to legitimate stakeholders.
Talentprobe’s detailed internal Data Retention Schedule, system configurations, disposal workflows, backup architecture, legal hold procedures, and other sensitive internal information may remain confidential.
116. POLICY INTERPRETATION
This Policy establishes Talentprobe’s general retention and secure disposal framework.
It does not require destruction of information where continued retention is required or permitted by applicable law, regulatory obligation, valid contract, legal hold, legitimate legal claim, or another lawful basis.
Where a mandatory legal requirement conflicts with this Policy, the applicable legal requirement shall prevail.
PART XXVII
CONTACT INFORMATION
117. PRIVACY AND RETENTION INQUIRIES
Questions concerning data retention, deletion, secure disposal, privacy rights, or this Policy may be directed to:
Data Privacy, Protection, and Security Office
Talentprobe Due Diligence / Circa Logica Group
Email: privacy@circalogicagroup.com
Data subjects seeking deletion, correction, access, or another privacy right should provide sufficient information to enable Talentprobe to identify the relevant records and verify the requester’s identity.
PART XXVIII
TALENTPROBE DATA LIFECYCLE COMMITMENT
118. OUR COMMITMENT
Talentprobe recognizes that responsible information management does not end when a background screening report is completed.
Information remains a responsibility for as long as it remains in Talentprobe’s custody or control.
Talentprobe therefore commits to maintaining reasonable and appropriate practices designed to:
collect information only for legitimate and authorized purposes;
retain information only while a legitimate need or lawful basis exists;
apply retention periods according to the nature and purpose of different records;
protect active and archived information against unauthorized access;
maintain appropriate controls over backup information;
preserve information when required for legitimate legal, regulatory, contractual, security, audit, or dispute purposes;
avoid indefinite retention merely because storage remains technically available;
respond appropriately to valid deletion and erasure requests;
remove unnecessary duplicate and temporary information;
anonymize or de-identify information where appropriate;
securely delete electronic records when no longer required;
securely destroy physical records and storage media;
manage third-party retention and deletion responsibilities;
maintain appropriate evidence of material disposal activities; and
periodically review retention practices as law, technology, risk, and business requirements evolve.
The responsible handling of personal information includes knowing not only how to protect information, but also when there is no longer a legitimate reason to keep it.
