PHIG Policy Framework v1.2 · Policy 36 · Adopted 1 September 2026 · References: ASF Policy 31; 2 CFR 200.334–338 (record retention and access); EU MGA Art. 20 (five years, three years for low-value grants); GDPR storage limitation; Georgian accounting law
1. Purpose and scope
To create, keep, protect and dispose of records so that PHIG can demonstrate what it did, meet legal and donor retention periods, and respect data minimisation. Applies to the Board, the Director, staff, consultants, volunteers, experts, partners and suppliers of PHIG and all platforms of its network.
2. Policy
- Records are kept of every decision, transaction, contract, grant, assessment, publication and incident, in a structured filing system (cloud, access-controlled, backed up).
- Retention: accounting and tax records 6 years; grant records 5 years after the final payment (EU) or 3 years after the final report (US), or longer if an audit or litigation is open; personnel records employment plus 10 years; Board minutes and statutes permanently; research raw data 10 years; verdict and assessment files 10 years; website and publication archives permanently; logs 90 days; recruitment of unsuccessful candidates 6 months.
- Donors, auditors, OLAF, EPPO, the European Court of Auditors, US agencies and inspectors general have access to records as the grant provides.
- Records containing personal data follow the Data Protection Policy; disposal is secure and logged.
- Original signed documents are scanned; electronic records are authoritative where the law allows.
3. Procedures
- Retention schedule maintained by the Director; annual disposal review.
Responsibilities
Director; accountant; all record owners.
Review
Every two years and when donor rules change.
Part of the PHIG Policy Framework. Breaches and concerns may be reported under the Whistleblowing Procedure to info@accreditation.ge (subject “Confidential — integrity”).