Online Services Data Retention Policy
Policy
QPHI is a data controller and is registered under Qatar Foundation. QPHI retains only that data that is necessary to effectively conduct its services, fulfill its mission and comply with applicable laws and regulations. Reasons for data retention include:
Data within QPHI is classified into the following categories:
- Participant Data: Information that can identify an individual.
- Operational Data: Data necessary for business operations.
- Financial Data: Information related to financial transactions and records.
- Communication Data: Emails, mobile logs, and other forms of communication.
- Legal and Compliance Data: Records required to meet regulatory and legal obligations.
- Providing an ongoing service (e.g., Publication, ongoing updates to an individual, accessing individual reports (upon consent) online, and requests for QPHI online services for researcher and interested individuals)
QPHI seeks to avoid duplication in data storage whenever possible, though there may be instances in which for programmatic or other business reasons it is necessary for data to be held in more than one place.
This policy applies to all data in QPHI’s possession, including duplicate copies of data. Retention Requirements QPHI has set the following guidelines for retaining all personal data as defined in the Institute’s data privacy policy.
- QPHI participants data will be retained as long as necessary to provide the service requested/initiated through the QPHI participants portal and mobile application.
- All sensitive data will be encrypted at rest and in transit.
- Access to data will be restricted to authorized personnel only. Participants who requested to delete their data to QPHI recruitment department, their records will be deleted accordingly.
- Participants who consented to receive their medical reports online, their reports will be available for 15 calendar days to be accessed through the portal and mobile app.
- Outbound and Inbound calls targeting participants recruitments are recorded for quality check purposes and retained for 120 Days.
- Researchers who registered through research portal and their account is active they will be retained for life time unless it was in-active for 2 years then they will be deleted.
- Approved Data Extract requests submitted by researchers will remain available through the portal for 15 calendar days and then will be inaccessible.
Data Destruction
- Data destruction ensures that QPHI manages the data it controls and processes it in an efficient and responsible manner. When the retention period for the data as outlined above expires, QPHI will actively destroy the data covered by this policy. Any exceptions to this data retention policy must be approved by QPHI’s Director in consultation with Information Security Manager.
- Upon participant request to withdraw from the studies, the data used for research is destroyed by QPHI and participant data will be deleted from the PRMS application.