Skip to main content
GGHRA
Legal & Governance

Data Retention Policy

How long the Global Gambling Harm Reduction Alliance retains personal information, and how it is destroyed, under the Australian Privacy Principles and GDPR storage-limitation principle.

Last updated: 2 August 2026

1. Purpose and Scope

This policy defines how long the Global Gambling Harm Reduction Alliance (GGHRA) retains personal information and the secure destruction of that information once the purpose for which it was collected has been fulfilled. It implements the storage-limitation principle under GDPR Article 5(1)(e) and Australian Privacy Principle 11.

2. Retention Principles

  • Personal information is retained only for as long as necessary to fulfil the purpose of collection or as required by law.
  • When information is no longer required, it is destroyed or permanently de-identified in a secure manner.
  • Retention periods are reviewed at least annually.

3. Retention Schedule

The following retention periods apply to the categories of personal information GGHRA holds:

  • Account profile (name, email, country, city): retained for the life of the membership, plus 30 days after account closure to allow for recovery, then deleted.
  • Date of birth (age verification): used solely to verify the member is 18 years or older at registration. Retained for the life of the membership and deleted within 30 days of account closure.
  • Research submissions and metadata: retained for the life of the platform unless the submitter requests deletion, in which case the record is removed within 30 days. Linked files are removed from storage at the same time.
  • Community posts, comments, and reactions: retained for the life of the membership or until the author requests deletion, then removed within 30 days.
  • Published articles: retained indefinitely unless the author requests withdrawal, at which point the article is unpublished and deleted within 30 days.
  • Financial transparency transactions: retained for 7 years to meet Australian record-keeping and tax obligations, then deleted.
  • Membership payment records: retained for 7 years for tax and accounting compliance, then deleted.
  • Meeting metadata and join links: retained for 12 months after the meeting, then deleted.
  • Audit and security logs: retained for 12 months, then deleted.
  • Data-subject request records: retained for 3 years after resolution for accountability, then deleted.
  • Analytics events: retained for 24 months, then aggregated or deleted.

4. Secure Destruction

Destruction is performed by removing records from the production database and purging associated files from storage and backups. Where a subprocessor holds the data, GGHRA requests confirmation of deletion in accordance with the processor agreement.

5. Member Rights

Members may request access to, correction of, or deletion of their personal information at any time through the data-subject request form on their profile. GGHRA responds within 30 days, in line with GDPR Articles 12-15 and APPs 12 and 13. Where deletion would conflict with a legal retention obligation (for example financial records), GGHRA restricts processing instead and deletes the information once the obligation ends.

6. Legal Hold

Where information is subject to a legal hold or ongoing investigation, the standard retention period is suspended until the hold is lifted, after which the standard schedule resumes.

7. Review

This policy is reviewed at least annually by the Privacy Lead and updated as data categories or legal obligations change.

We use cookies to measure how the platform is used and improve it.

Essential cookies are always on. Analytics cookies are only enabled with your consent. See our Privacy Policy.