Retention Management

Expand All

Helpful Videos for You

Need help? Check out videos for quick assistance!

The Retention Management feature is designed to help organisations streamline their data privacy retention processes while avoiding duplicate data entries. This feature, accessible under Data Privacy and Protection (DP&P) in the left navigation, allows users to manage retention policies efficiently and integrates data from Records of Processing Activities (RoPA) and Data Protection Impact Assessments (DPIA) to centralise retention requirements.

Effective retention management is essential for organisations to meet regulatory obligations, protect sensitive data, and ensure that information is managed responsibly throughout its lifecycle. Retention management helps organisations define and enforce policies for storing, archiving, and securely disposing of data in alignment with legal, compliance, IT, and operational requirements. By centralising retention policies, organisations can minimise the risk of retaining outdated or unnecessary data, reducing exposure to data breaches and improving data governance.

Retention management also supports data minimisation principles, ensuring that personal data is retained only as long as necessary. By clearly defining retention periods and regularly reviewing them, organisations can improve operational efficiency, enhance data security, and reduce storage costs. As data protection regulations increasingly mandate strict retention policies, effective retention management is a critical component of an organisation’s data protection and privacy strategy.

Access to Retention Management is included as part of 9ine’s Privacy Platform licence. For further information contact [email protected]. 

Accessing retention management

Upon purchasing 9ine’s Privacy Platform and its associated features, users can be granted access to Retention Management. Your organisation’s 9ine Platform administrator(s) have the option to allocate permission via  User Management available in the header.

Granting access to this feature does not automatically provide access to all retention management items. However, it allows users to log a new retention management item. Users must be added as the owner, members, or notified users to gain edit access. Owners and members of any risks, issues, lessons or tasks are also granted edit access if associated with a retention management item. 

A retention management items permissions include:

  • Owner
  • Member(s)
  • Notified user 
  • Attachment reviewer

There can only be a single owner of a retention management item but there are no limits to the number of members or notified users. Each attachment can also have one reviewer. Owners can edit and delete their items, while all other roles have edit rights but cannot delete. When more than two members or notified users are added, the additional user details are combined into a single pill, which can be clicked to view further details. These pills are alphabetically ordered.

Retention management items can be deleted by the owner. If the item is linked with a record of processing activity and/or a DPIA, the record of processing area owner, record of processing activity owner, and DPIA owner also have delete permissions. 

Warning:

 If a retention management item is linked to a record of processing activity and/or DPIA, the area owners and members are granted access. Similarly, the record of processing activity and/or DPIA owner, member, reviewer, approver, attachment reviewers, notified users, and DPIA screening reviewer gain access. 

 

Tip:

When creating or associating a retention management item with a record of processing activity or DPIA, the owners and members from the linked item are automatically copied to the retention management item. While you can change the owner of the retention management item, the original owner from the associated item must remain as a member. Additionally, you have the flexibility to add other members outside of those originally copied from the record of processing activity or DPIA.

 
 
 

Adding and removing notified users

Mention User (@)

To add a notified user, use the mention function in either the description field ...

To add a notified user, use the mention function in either the description field on the Details tab or the notes field on the Notes tab. 

  • To begin, click the @ symbol on your keyboard and type the first name of the user you wish to mention. 
  • A user can be mentioned at the start, in the middle, or at the end of the entered text. 
  • To remove a user as a notified user, simply delete their name from the relevant note. 
  • Mentioning a user sends an in-Platform notification and an email unless the user has disabled email notifications. 
  • The email notification sends a complete copy of the text entered by the user in the 9ine Platform, to the user’s registered email address.

Step 1:

Step 2:

 
 

Understanding how to create a retention management item

There are three ways to create a retention management item:

  • By clicking New in the Retention Management log.
  • By clicking Add Retention on the Processing Overview step of a record of processing activity form.
  • By clicking Add Retention on the Processing Description step of a DPIA form.

When clicking either of the options, you will then be presented with a popup which displays a mandatory field Title. 

When adding a retention item from a record of processing activity or DPIA, the Association, RoPA / DPIA, Owner, and Member(s) fields are pre-populated with the relevant information. 

Tip:

  • You can associate a retention management item with additional records of processing activities and/or DPIAs by searching by reference number or title in the RoPA / DPIA field. When linking to multiple forms, each form’s permissions are applied to the retention management item, but permissions are not shared across forms. For example, if retention management item 1 is linked to DPIA 2 and DPIA 3, users with access to DPIA 2 and DPIA 3 gain access to retention management item 1. However, users of DPIA 2 will not have access to DPIA 3 and vice versa.
  • You also have the option from the record of processing and DPIA forms to use the dropdown available next to the Add Retention button to quickly associate the form with a retention management item.
 
 
 

Creating a new retention management item or editing an existing one

When creating a new retention management item or editing an existing one, you will be directed to a standardised popup accessible from the retention management log, the record of processing activity form, or the DPIA form. The first tab allows you to capture and view key details associated with the retention, including the title, number, what is the retention period for the personal data being processed, owner, members, notified users, frequency, retention type,  retention exception, method of destruction, retention method, and status. If you wish to add an infinite retention a checkbox is provided, which automatically disables the Retention Period field. You can enter the retention period using the format Years (y), Months (m) and Days (d), for example: 1y 2m 6d.

Additionally, you have the option to specify a Next review date to ensure timely review of the retention policy.

Calendar Field

When selecting a date, you can manually type in the specified format or click on 

When selecting a date, you can manually type in the specified format or click on the date in the header to quickly navigate through months or years. The clear button allows you to easily remove any entered date. 

When the date entered in either of the date field lapses, a warning message is displayed. Similarly, lapsed dates are shown in red on the moduleName log.

Tip:

To access retention data linked to a record of processing activity or DPIA form, go to the retention management log or view the details in the retention management popup within each form. Note that this retention information is not directly visible in the records of processing or DPIA logs.

 
 
 

Utilising the notes and attachments features

Notes Tab

The 

The Notes tab allows you to maintain a single repository of information. You can add multiple notes at once using the Add Another function, but these notes are not saved until you click the primary Save button at the bottom of the popup. 

When adding a new note, a record of the user's details, date, and time of entry are added, and the most recent notes will automatically appear at the top of the list. If an individual note is edited, the time and date of the note are updated, and the note reordered.

Additional formatting functionality is provided on the notes tab. If entering large volumes of data, click the Full Screen option.

Warning:

  • For security purposes, the 9ine Platform will log users out of their active sessions after 45 minutes of inactivity, with a reminder triggered at 30 minutes of inactivity. 
  • If you are in full screen mode, the reminder may not appear unless you have browser-based notifications enabled. 
  • Typing in the field is not considered activity; activity is only registered when clicking Cancel or Save.
 

Attachments

The 

The Attachments tab allows you to upload files or images using your native file explorer. 

  • Maximum file size: 10MB
  • A maximum of five files can be uploaded at a time
  • Supported file types: jpg, jpeg, tif, tiff, png, odg, otg, txt, rtf, doc, docx, pages, odt, ott, odm, pdf, xml, xmlx, numbers, ods, ots, ppt, pptx, key, keynote, odp, otp, xls, xlsx, tsv, csv, pst, eml, emlx, ost, oft, msg
  • The file name cannot contain special characters: /?<>|"\ #+&'~

 

Each attachment uploaded can be assigned a reviewer, allocated a review date, and further information can be included. This process ensures that attachments added remain current and do not become obsolete. When an attachment is added and a reviewer is assigned, the reviewer is automatically granted access to the moduleName, enabling them to review the attachment.

 
 

Understanding how to use the retention management log

When creating a new retention management item, or editing an existing one, the details entered are added to the log. Each item is automatically assigned a unique reference number (starting with REM) that cannot be edited.To view only the retention items you are responsible for, use the My Retention toggle located in the top right-hand corner of the log. This will filter and display items where you are the owner, member, or notified user.

Sorting, View and Filter for log

Default sorting is applied to the “No.” column, which can be altered by clicking 

Default sorting is applied to the No. column, which can be altered by clicking on the title of any other column. Clicking a column header once sorts the log by the selected column, and clicking it a second time reverses the order. 

To remove individual columns, click View and deselect the columns you do not want to display, whilst retaining a minimum of one column. After selecting your preferred columns, click Apply. You also have the option to Save View.

You can also change the sequence order of the columns by dragging and dropping them into your preferred order. Any changes are automatically saved and retained on the next login. 

Info:

  • The changes applied to the sequence order of the log and in the View popup are user and log specific and only applied to your profile.
  • The sequence order in the View popup does not update to reflect the order created through dragging and dropping.
  • The log opens using your most recently saved filter and column view. If you have not saved any preferences, the organisation default view is applied, this is why the log can appear differently per user account.
 

To focus on specific items, you can use the Filter or Search functions. When a filter is active, an orange icon appears next to the filter icon for easy recognition. 

  • To quickly clear any filters, click the Clear Filters button in the popup. 
  • You can also apply a temporary filter without clicking Save Filter.
  • To revert back to your saved filter, click Reset.
  • Similarly, you can select data points and click Apply without saving your filter options.
 
 

Downloading the retention management log

Download Governance Log Items

To download the data shown on the respective log, click the Download button located in the top right-hand corner. You can customise the download report to include or exclude data by using the search bar, filter, view options, or My moduleName functions. Upon clicking the Download button, an export will be saved to your local file explorer. The format of the exported moduleName is XLS.

 
 

Understanding the quick actions for a retention management item

The retention management log provides a range of quick-access functions within the menu options, including:

  • Create Task
    This allows your to directly create a task associated with the retention.
  • Create Risk
    This allows your to directly create a risk associated with the retention.
  • Create Issue
    This allows your to directly create an issue associated with the retention.
  • Create Lesson
    This allows your to directly create a lesson associated with the retention.
  • Add Note
    Opens the retention popup directly on the Notes tab.
  • Add Attachment(s)
    Opens the retention popup directly on the Attachments tab.
  • Add Member(s)
    Opens a members popup to quickly grant users access to the retention management item.
  • Duplicate
    Duplicates the retention item and all associated risks, issues, lessons, and tasks labelling them with the prefix Copy of. The duplicated items do not include notes, attachments, logged time and logged cost data.
  • Archive
    Marks the retention management item and all its associated risks, issues, lessons, and tasks as closed, removing all items from their respective logs.
  • Delete
    Marks the retention management item and all its associated risks, issues, lessons, and tasks as deleted, effectively removing them from the 9ine Platform.