Skip to main content

Support

Configure data retention and privacy settings

Set the inactive member retention period, understand fixed legal retention periods, and run a scan before applying data cleanup.

The Privacy & Compliance settings page lets you set how long inactive member data is kept, review fixed legal retention periods, monitor consent status, and manage PI export requests. Go to Settings in the sidebar, then select Privacy & Compliance.

Set the inactive member retention period

Inactive Member Retention controls how long member data is kept after a member's last recorded activity before it is flagged for de-identification.

  1. In the Data Retention Policy card, find the Inactive Member Retention dropdown.
  2. Choose a period from the list: options range from 6 months to 120 months (10 years). The default is 24 months.
  3. Select Save next to the dropdown.

A success toast confirms the new retention period.

Understand fixed legal retention periods

Some retention periods are set by law and cannot be changed:

| Data type | Minimum retention | Note | |---|---|---| | Financial records | 7 years | ATO requirement (s262A ITAA 1936) | | Audit logs | 7 years | Compliance requirement | | Health screening data (sensitive information) | 7 years or longer | Retention varies by state; records for minors are kept longer | | Consent records | 7 years | Required as legal defence evidence |

These periods are shown as read-only in the interface.

Scan for records past the retention period

Before applying retention cleanup, scan first to preview what will be affected.

  1. In the Retention actions section, select Scan retention.
  2. The scan runs and returns a count of documents and inactive member records that are past the configured retention period.
  3. Review the result — a toast shows either the count of flagged records or confirmation that nothing is past the period.

Scanning does not change any data.

Apply retention cleanup

Once you have reviewed the scan result and are satisfied with the scope, apply the retention policy.

  1. In the Retention actions section, select Apply retention.
  2. A confirmation toast reports the number of documents deleted and members de-identified.

Applied retention is irreversible. Ensure you have reviewed the scan result and are operating on the correct environment before applying.

What is de-identified vs deleted

When retention is applied to inactive member records:

  • Member profile data is de-identified (name, contact details, and personal identifiers are removed or anonymised).
  • Attached documents past their own retention period are deleted.
  • Financial records, audit logs, consent records, and health data are kept for their full legal retention period regardless of the member's inactive status.

Review consent status

The Consent Overview section on the same page shows a breakdown of how many members have given, withdrawn, or not yet been asked for each consent type: Marketing (Email), Marketing (SMS), Photo / Media Use, Health Data Collection, and Data Processing.

PI export requests

When a member requests a copy of their personal information, the request appears in the PI Export Requests section. You can monitor export job status and download completed exports from this page.

Related