Data Retention and Footprints
Introduction
The Global Data API prioritizes data privacy and protection. This section details our policies regarding the retention, storage, and access of the data communicated through our API.
Important Note: No Personally Identifiable Information (PII) sent to Global Data as part of an API request is stored or retained unless it's explicitly necessary for processing the request.
Data Retention Policy
What We Retain:
- Query Data: This encompasses the data necessary to process the requested query. For instance, a "Person Search" might involve PII like names, addresses, and phone numbers.
- Return Data: Data sent back in response to a query, which might also contain PII.
- Local Data: Details from the local web browser or software agent making the request. Examples include browser versions, operating systems, and screen resolutions.
- Network Data: Captured from internet connections to our API services, primarily the IP address of the requester.
While we retain various data types, PII within Query Data is never stored or retained.
How We Store Data:
- Local and Network Data: Stored in server logs and our service audit database.
- Query Data: Stripped of any PII and then stored in the service audit database.
- Return Data: Contains PII already known to Global Data and stored in our service audit database.
Security Measures:
- All data, both in transit and at rest, is encrypted using industry-standard methodologies.
- Access to stored data adheres strictly to the Global Data IT policy, following the principle of least privilege.
Why We Store Data:
Data storage primarily caters to:
- Historic Review: Enables users to revisit their past API queries or searches.
- Audit Purposes: For refining service performance or addressing service hitches.
- Regulatory Compliance: Meeting requirements like the Australian Privacy Act and Australian Privacy Principles.
- Specific Processing: Particularly when data is added for future access purposes, e.g., in datawashes.
Data Retention Duration
The period for which data is retained varies:
- Query Data: Retained indefinitely from the capture time, stripped of any PII.
- Return Data: Retained indefinitely post initial capture.
- Network and Local Data: Kept indefinitely if they're devoid of PII.
Data Erasure
Once the retention period is fulfilled, data is systematically purged and obliterated, aligning with industry best practices and the Global Data's Data Lifecycle policy.
Access Footprint Policy
It's crucial to highlight that Global Data is not a credit bureau or assessment entity. Therefore, we don't create access footprints or access records on a data record that's discernible to end-users or record proprietors, beyond the scope described in this documentation.