Employee Data Retention/GDPR Settings

Daniel Galea St John
Daniel Galea St John
  • Updated

Overview

In Malta, GDPR compliance is anchored by the Data Protection Act (Cap. 586) and overseen by the Data Protection Officer (DPO). The Employee Data Retention/GDPR tab on Talexio will allow your company's DPO to manage such retention periods on Talexio.

Permissions

To allow the DPO to have access to manage the Employee Data Retention/GDPR settings, they will need the Manage Data Retention/GDPR Settings permission set on Global. If this is not set on Global, the DPO will not be able to upload the Data Retention Policy.

Employee Data Retention/GDPR Settings

The Data Retention/GDPR settings tab is found in the Settings section: 

To set your company's DPO, you will first need to create a profile for them. If the DPO is not employed with your company, they do not need to have a position. In such a case, all you need to do is add their Name, Surname, Work Email address, and Access level (permissions).

After being invited to access Talexio, the DPO will have access to the Data Retention/GDPR page:

  • Once the DPO is added to Talexio, you will need to set them as such from the Data Protection/GDPR page: 
  • The DPO will be able to upload the company's Data Retention Policy. This policy will be available for all employees. They will be able to see this in their Notifications pod in their dashboard:


     
  • The DPO will be able to set the retention periods applicable. The default periods are Mico (7 days), Short (31 days), Medium (93 days) and Long (365 days), but the DPO may amend these (both the name and the duration), delete them, and add new ones: 


     
  • This is where the DPO will assign retention periods to the different data categories found in Talexio. Data Categories refer to the folders found in the employee Documents tab: 



    Setting a Data Category's retention period to Indefinite means that documents found in such a category do not need to be deleted.

Are documents automatically deleted?

So how does this all work? Let's say you added a retention period of 365 days for Contracts. If an employee was terminated on the 14th of April 2026, the DPO will receive an email 365 days after the termination date informing them that, in line with the retention period set up in the Data Retention/GDPR settings, the employee's contract must be deleted.

The company's Admin must delete the documents themselves if the DPO does not have access to other employees' documents.

 

Share: