An official document regulating the collection, storage, and maintenance of students' personal and academic data. It defines security standards, access permissions, and cloud backup mechanisms to protect information and prevent digital breaches.
Data Type | Retention Period | Action Upon Expiry |
|---|---|---|
Active Student Data | Throughout the registration period | Review upon registration expiry |
Graduated Student Data | 7 years | Secure deletion or archiving |
Login Records | 1 year | Secure deletion or archiving |
Audio/Video Recordings | 1 year | Archiving |
Level | Party | Scope of Authority |
|---|---|---|
Level One | Senior Management | Full access to all data |
Level Two | Administration and Teachers | Data of their registered students only (grades, attendance, assignments) |
Level Three | Administration and Students | Their personal data and academic performance only |
Level Four | Administration and Parents | Their children's data only via the parent account on the learning platform |
Backup Type | Frequency | Responsible Party |
|---|---|---|
Daily Automatic Backup | Daily | IT Admin |
Weekly Full Backup | Every Saturday | IT Admin |
Monthly Archive Copy | First of every month | Senior Management + IT |
Phase | Action | Timeline |
|---|---|---|
Detection and Containment | Isolate affected system and prevent breach spread | Immediately upon detection |
Assessment | Determine scope and nature of affected data | Within 6 hours |
Internal Notification | Notify senior management and IT administrator | Within 12 hours |
Notify Affected Parties | Inform relevant parents and students | Within 48 hours |
Documentation and Review | Submit official report and root cause analysis | Within 7 days |