Data and system records

About University systems and data

The University uses multiple systems to manage data and digital documents, which are considered University records, and must be managed appropriately.

Some systems are locally managed using University storage and infrastructure, while many are implemented using vendor products and services, such as Software as a Service (SaaS) applications.

Records management requirements for systems

The University’s Records Management Policy (MPF1106) outlines procedural principles for University records. According to the policy, a system must be assessed for compliance with records standards before it is implemented, or before records are migrated to or from the system.

This includes working with third-party vendors to ensure their products, once implemented for University use, are meeting records management requirements.

If the system:

  • will collect or use personal information, then you must complete a Privacy Impact Assessment (PIA) for the system
  • will not collect personal information, then you can share your documented disposal approach with Records & Information and seek guidance, as needed by submitting us a ServiceNow request.

Important: Any third-party service provider managing records on behalf of the University must adhere to the University's records management policy and requirements.

Who is responsible for ensuring systems are meeting requirements?

The Business Owner of the system is responsible, eg Faculty or Chancellery work area that implemented and uses the system. They may receive assistance from IT and vendors, as needed to ensure requirements are implemented and operational.

Senior delegates, level 4 or higher (4-1) in Schedule B, University Delegations are responsible for approving records management processes in systems and accepting any risks identified, such as over-retention or over-collection.

How do I ensure my system meets requirements?

The following steps outline the key actions which should be undertaken when implementing systems.

  • It is important to ensure appropriate access and control of records is maintained within systems.

    Refer to KBA Role-based access and seek advice from Privacy team, as needed by submitting an email to: privacy-officer@unimelb.edu.au.

    Refer to Cybersecurity risk management for guidance.

    Note: If you submit a PIA for your system project, representatives from Privacy and Cybersecurity will get in contact with you to complete reviews and provide guidance.

  • Understanding the retention and disposal requirements may influence how data should be arranged and stored within the system. Therefore, it is important to establish the retention and disposal requirements early on in your system project.

    Using the University Records Retention and Disposal Authority (RDA), determine how long the University is legally obligated to retain the records held in the system. If there are multiple categories of records, multiple RDA classes and retention periods may apply.

    If the records are:

    • classed as Temporary value in the RDA, they must be destroyed as soon as reasonably practicable after the minimum required retention period stipulated in the RDA
    • classed as Permanent value in the RDA, they must be able to be extracted in a usable and understandable format, along with available metadata, so that they can be transferred to the University of Melbourne Archives in future, for ongoing preservation and access
    • a copy derived from a different source, then they can be disposed from the system any time under the principles of Normal Administrative Practice, once no longer needed to support University business.

    Note: Depending on system capabilities, if multiple temporary RDA classes apply, it may be acceptable to round up to the longest period, to make disposal more practical to implement.

    If the system is being used to deliver a commercial service, then the records and data held in the system will likely not be covered by the RDA. Retain these for as long as necessary for the University to deliver the commercial service.

  • Once the retention and disposal requirements are known, determine how these can be implemented within the system. Refer to Destruction of temporary records and Transfer of permanent records for guidance.

    Ideally the system will support some automated disposal workflows. If not, manual approaches may need to be implemented to identify and delete records once they become time expired, eg annual or quarterly purging process.

    Work with vendors and technical specialists, as needed. This may include adding clauses within agreements to ensure the vendor will support records disposal approaches.

    Important: At the minimum, the vendor should provide data back to the University, then securely delete all University data held within their systems upon cessation of business with the University.

  • Document within a plan or procedure how the disposal approach will be undertaken in the system.

    Ensure the documented disposal approach is approved by the Business Owner of the system. For temporary records, this will act as a Proof of Destruction to support lawful destruction of University records.

    Note: If the scope of the system or records changes, then you should update the disposal approach and corresponding plan or procedure accordingly.

Records about University business systems

As well as data and records held within systems, you will likely create records about University business systems. Such as when a system is evaluated, implemented or updated at the University.

These records should also be retained in accordance with the University Records RDA. See common examples below.

ExampleRDA class
Records about evaluating a potential systemThese records are covered by RDA class 15.5.3 TECHNOLOGY & APPLICATIONS | System Development & Management: Evaluation and feasibility
Records about a system that is fully implementedThese records are covered by RDA class 15.5.1 TECHNOLOGY & APPLICATIONS | System Development & Management: Production
Master control records for key University systemsThese records include system configuration manuals and schemas, and are covered by RDA class 15.5.1 TECHNOLOGY & APPLICATIONS | Master control records
Records about maintaining and updating systemsThese records are covered by RDA class 15.4.1 TECHNOLOGY & APPLICATIONS | Maintenance: Updates and Maintenance
System logsThese records are covered by 15.4.3 TECHNOLOGY & APPLICATIONS | Maintenance: System logs

Decommissioning business systems

When decommissioning systems, data must be evaluated to determine retention and disposal obligations and whether it has continuing use for business.

  • Data that is still needed for business use should be extracted in a usable format or migrated to a new system
  • Data that is no longer needed for business use should be assessed, to determine the retention and disposal requirements. If the data contains sensitive or personal information, then it will need to be stored appropriately.

Further information

If you require further information or advice, please submit a ServiceNow request.