Proctored Web Test Platform Assessment with clarity and integrity.

Data Retention Policy

This page describes how long ClearGrade data is retained and the principle used to set retention periods, aligned with GDPR storage-limitation requirements.

Legal context

Retention schedules should be interpreted in line with the Zambia Data Protection Act, 2021, GDPR where applicable, and relevant institutional obligations in the United States. Where rules conflict, the stricter or specifically applicable rule should be followed.

Retention principle

Data is kept only as long as necessary for assessment operations, academic integrity review, and legal or institutional obligations. When no longer required, it should be deleted or anonymised according to institution policy.

Typical retention periods

Deletion and restriction

Deletion requests are handled by the lecturer or institution controlling the course data. Records tied to statutory educational obligations may be restricted from deletion until those obligations expire.

Backup and disaster recovery

Retention can be extended temporarily in encrypted backups and recovery snapshots. These copies are used only for restoration and are rotated out according to backup policy.

Controller responsibility

Each institution or lecturer acting as controller should define exact retention periods in local policy and communicate them to candidates before exams begin.

Contact for retention or deletion requests

Retention-period, deletion, and restriction requests should be raised through your lecturer or institution data-protection contact:

Last updated: 23 August 2026

This policy is a framework, not legal advice. Confirm final retention schedules with institutional legal/compliance teams.