Data Retention Schedule
How to use this schedule
- The period starts from the trigger shown, not necessarily the date the record was created.
- At expiry, securely delete or irreversibly anonymise the record unless an exception applies.
- Do not keep a record merely because it might be useful one day.
- Where several categories apply, use the longest justified period.
- Record material departures, extensions and disposal decisions.
Retention schedule
| Record category | Examples and purpose | Normal retention | Disposal or review action | Owner |
|---|---|---|---|---|
| Incomplete registration and onboarding | Unverified account, abandoned application, unfinished onboarding | 12 months after last activity; verification/reset secrets expire much sooner | Delete account data unless needed for fraud prevention or a live enquiry | Secretary / system administrator |
| Active account and profile | Login, email, contact details, parent/child links, current role and preferences | While active; review after 24 months with no membership or login | Contact where appropriate, then delete or anonymise unnecessary account data | Secretary |
| Membership and subscription history | Member identity, class, season, status, renewal, amount due | Six years after membership or the relevant financial year ends | Delete or anonymise; retain only non-identifying totals where useful | Secretary / Treasurer |
| Emergency, health and accessibility details | Emergency contact, allergy, condition, adjustment or support need | Current season/activity plus one year | Delete unless incorporated into an accident, insurance or safeguarding record | Secretary / team manager / Safeguarding Officer |
| Payment and accounting records | Membership/event payment, refund, invoice, Stripe reference, bank reconciliation | Six years after the end of the financial year concerned; longer if an HMRC enquiry or legal hold applies | Secure deletion; retain anonymised financial reporting if required | Treasurer |
| 100 Club administration | Supporter, number assignment, entry, draw, prize and winner-delivery records | Current assignment while active; financial, draw and prize records for six years after the relevant financial year | Remove obsolete contact details; retain auditable draw outcome with the minimum identity needed | Treasurer / authorised administrator |
| Match availability and team management | Availability response, team eligibility, selection and captain/coach notes | Two years after the relevant season | Delete person-level operational records unless part of a dispute or disciplinary matter | Cricket committee / captains |
| Junior open-age consent and eligibility | Written parental consent, date of birth, readiness, emergency/medical information, protective-equipment requirements and County Talent Pathway approval where exceptionally required | While the player is registered and normally six years after the final relevant season; follow the longer incident, safeguarding, insurance or claims period where one applies | Restrict access, retain signed evidence and securely delete when the period expires | Club Safeguarding Officer / cricket committee |
| Playing results and statistics | Fixtures, scorecards, results, appearances and performance statistics | Indefinite historical sporting record where justified; players' first and last names may remain on historic scorecards | Remove private contact/account data; retain public sporting facts, names needed for scorecard integrity and provenance | Cricket committee |
| Play-Cricket linking | Player ID, link claim, verification and administrator decision | While linked; decision/audit evidence for six years after unlinking | Remove obsolete identifiers and pending claims | Secretary / cricket administrator |
| Policies, acknowledgements and consents | Policy version, hash, acceptance, photography choice and withdrawal history | Six years after membership ends or the acknowledgement/choice is superseded or withdrawn | Delete person-level record after period; retain policy versions as governance records | Secretary |
| Policy and governance documents | Published versions, approvals, minutes, constitutional decisions | Permanent for constitution, formal minutes and final policy versions | Archive final versions; remove unnecessary working drafts after two years | Secretary |
| Events, bookings and volunteering | RSVP, attendance, volunteer allocation, event contact information | Two years after the event; related payment records six years | Delete operational contact data and retain anonymised attendance totals if useful | Event organiser / Secretary |
| Equity, diversity and inclusion monitoring | Ethnicity, disability, gender or other equality information actually collected for cricket participation or regulatory monitoring | Identifiable data while needed for the relevant programme or reporting cycle, normally no more than two years; anonymised statistics may be retained longer | Anonymise at the earliest practical point and restrict identifiable special-category data | Secretary / authorised EDI lead |
| Photographs and video | Club website, news, social media, promotion and historical archive | For the stated purpose and reviewed annually; selected historical material may be archived longer following a documented assessment | Remove when permission is withdrawn where consent is the basis, unless another lawful reason applies | Communications lead / Secretary |
| Communication preferences | Email, in-app and push choices; consent or preference history | Current preference while the relationship continues; history for six years | Keep the minimum suppression record as long as needed to honour an opt-out | Secretary / system administrator |
| Notifications and delivery records | Message, recipient, in-app state, email/push attempt and delivery outcome | Two years after sending; financial, policy, safeguarding or formal administration evidence may follow the related category | Delete message/recipient data and retain anonymous service statistics if useful | Secretary / communications lead |
| Mobile push devices | Encrypted push token, platform, device state and last use | While registered and active; remove after sign-out, account deletion or 90 days after the device is disabled | Erase token and device identifiers | System administrator |
| Authentication tokens and security secrets | Access/refresh token hashes, email verification, password reset, recovery code hashes | Access token: about 15 minutes; mobile refresh session: up to 30 days; verification/reset link: until used or expiry; revoked-token metadata: 90 days | Revoke, expire and securely delete; never retain raw passwords or raw reusable tokens | System administrator |
| API, website and diagnostic logs | IP address, endpoint, status, duration, error and rate-limit data | 90 days; extend relevant extracts to 12 months for a security investigation | Automated deletion or anonymisation | System administrator |
| Administrative audit trail | Role changes, approvals, policy activity, account actions and notification administration | Six years after the recorded action | Delete or anonymise after checking there is no live dispute, claim or investigation | Secretary / system administrator |
| Account-deletion requests | Request source, verification, status, processor, completion and retention/deletion notes | Six years after completion or cancellation; public verification link expires after one hour | Delete expired secret; later anonymise the request while retaining sufficient compliance evidence | Secretary / authorised account manager |
| Enquiries and routine correspondence | General member or public query and response | Two years after closure | Delete unless linked to another record category | Relevant officer |
| General complaints and disputes | Formal complaint not governed by cricket conduct rules, investigation, evidence, outcome and appeal | Six years after final closure | Restricted review and secure deletion unless legal hold or safeguarding rule applies | Secretary / Chair |
| ECB conduct, anti-discrimination and disciplinary matters | Match-official report, witness statement, social-media evidence, alleged breach, panel papers, decision, sanction and appeal under applicable cricket regulations | Until the matter and any sanction conclude, then review after two years. Retain for up to six years, or longer, where regulation, safeguarding, continuing risk, integrity of the sport or legal claims justify it. Relevant sanction/case information may exceptionally require indefinite retention while a continuing risk exists | Limit access and disclosures; at each review delete, anonymise or document the continuing justification | Secretary / disciplinary officer / Chair |
| Accidents and health-and-safety incidents | Accident report, witness details, action and insurer correspondence | Adults: at least three years after the incident; children: at least three years after the child's 18th birthday; longer if an insurer or legal hold requires | Secure deletion after checking limitation, insurance and reporting requirements | Secretary / Health and Safety lead |
| Safeguarding concerns and case files | Concern, referral, chronology, decisions and communications | Case-specific under current ECB/NSPCC guidance; as a Club default, child-related files are reviewed for retention until the subject's 25th birthday and adult-only files for six years after closure, with longer retention where advised | Club Safeguarding Officer review only; normally disclose within cricket only to the County Safeguarding Officer, ECB/Cricket Regulator safeguarding team or others with a clear need to know. Never dispose during an investigation, referral, allegation process or legal hold | Club Safeguarding Officer |
| DBS certificate information | Certificate or disclosed contents used for a suitability decision | No longer than necessary and normally no more than six months after the decision or resolution of a dispute/audit need | Securely destroy certificate/copy; retain only permitted check metadata and decision record | Club Safeguarding Officer |
| Volunteer, coach and office-holder records | Role, training, qualification, appointment and service history | Six years after the role ends; final minutes may be permanent | Delete contact and operational details; retain minimum governance history | Secretary / Safeguarding Officer |
| Data-rights requests and breaches | Access/erasure request, identity check, response, breach assessment and notification | Six years after closure | Delete request evidence after confirming no complaint, claim or regulatory action remains | Secretary / privacy lead |
| Routine system backups | Disaster-recovery copies containing database or website information | Provider or Club rolling backup cycle | Deleted live records age out when backups are overwritten; backups are access-restricted and not restored solely to recover deleted personal data | System administrator |
Exceptions and legal holds
Suspend normal disposal only where the record is relevant to an active safeguarding matter, complaint, insurance claim, tax enquiry, litigation, police/regulatory request or other documented legal need. The responsible officer must record the reason, scope, access restrictions and next review date. When the hold ends, the normal period resumes or the record is disposed of promptly.
Account deletion
Account deletion removes access credentials, sessions, device push tokens, roles, notification preferences and account-to-member links, and anonymises the login record. The processor must review the other categories above and record what is deleted, anonymised or retained and the reason. A deletion request does not override a continuing legal, safeguarding, accounting or claims-related retention need.
Disposal and review controls
- Review this schedule annually and after a material system or legal change.
- Run at least an annual review of expired paper and electronic records.
- Use secure deletion, confidential shredding or irreversible anonymisation as appropriate.
- Restrict safeguarding, health, DBS, payment and security records to authorised roles.
- Keep a brief disposal log for higher-risk or bulk record destruction.
- Review service-provider retention and backup terms annually.
Guidance used
- ICO storage-limitation guidance
- HMRC record-retention guidance
- DBS certificate-information handling guidance
- NSPCC child-protection record guidance
- ECB Recreational Game Privacy Notice
- ECB junior open-age cricket consent guidance
Questions about this schedule should be sent to info@westbrettoncc.com. See also the Member Privacy Notice.