Zammit Corporate Limited
Effective Date: 5/12/2025
Version: 1.0
This Data Retention & Disposal Policy establishes the rules by which Zammit Corporate Limited (“the Company”) retains, stores, archives, and disposes of personal data.
The policy ensures compliance with:
The objective is to ensure personal data is kept no longer than necessary and is securely disposed of when no longer required.
This policy applies to all personal data processed by Zammit Corporate Limited, in all formats:
It applies to all employees, contractors, consultants, and third-party processors acting on behalf of the Company.
In line with Article 5 of GDPR, the Company adheres to the following:
The Company follows these general rules unless specific laws require otherwise:
Below are the recommended retention timelines based on Maltese legal obligations and corporate advisory sector standards.
A full retention table can be provided on request.
5.1 Client Records
|
Document Type |
Retention Period |
Legal Basis |
|
Client onboarding forms / KYC (if applicable) |
5 years after end of relationship |
AMLD requirements (if applicable to services) |
|
Contracts, proposals, advisory reports |
10 years |
Maltese commercial & tax laws |
|
Client correspondence & email |
5 years from last interaction |
Legitimate interest + limitation periods |
|
Project documentation |
10 years |
Professional service obligations |
5.2 Accounting & Finance
|
Document Type |
Retention Period |
Legal Basis |
|
Invoices, receipts, ledgers |
10 years |
VAT Act & Income Tax Management Act |
|
Payroll and salary records |
10 years |
Employment law + tax laws |
|
Bank statements and reconciliations |
10 years |
Commercial Code obligations |
5.3 Human Resources (HR)
|
Document Type |
Retention Period |
Legal Basis |
|
Employee personnel files |
5 years after termination |
Employment rules |
|
Contracts of employment |
10 years |
Contract limitation rules |
|
Attendance records |
2 years |
Employment law guidance |
|
Recruitment records (CVs, applications) |
1 year from decision |
Legitimate interest & discrimination defence |
|
Training records |
5 years |
Professional recordkeeping |
5.4 IT, Systems & Security
|
Document Type |
Retention Period |
Notes |
|
Access logs & system logs |
6–12 months |
Security monitoring |
|
Backup files |
Up to 12 months unless critical data |
Rolling backup cycles |
|
Email accounts (ex-employees) |
Max 6 months after termination |
Data minimisation |
Zammit Corporate Limited does not use CCTV or biometric systems, so there are no retention obligations for these categories.
5.5 Marketing & Communications
|
Document Type |
Retention Period |
Legal Basis |
|
Mailing lists (with consent) |
Until consent withdrawn |
GDPR Article 7 |
|
Contact form submissions |
2 years |
Legitimate interest |
5.6 Corporate Governance
|
Document Type |
Retention Period |
|
Board meeting minutes |
Permanently |
|
Shareholder resolutions |
Permanently |
|
Compliance documentation |
10 years |
The Company shall ensure:
When retention periods expire, personal data must be securely disposed of using one of the following methods:
Digital Data
Paper Documents
The method chosen must ensure data cannot be reconstructed.
Deletion must be paused if:
During this period, no related data may be altered or deleted.
Data Protection Officer
Employees
Third-Party Processors
This policy shall be reviewed at least annually or when: