Data Retention Policy
Last updated:
This policy explains how long DREWQ retains different categories of data, what triggers deletion, and how operators and individuals can request early deletion. Retention periods are set to balance operational requirements, legal obligations, and the data minimisation principle under the Ghana Data Protection Act 2012 (Act 843).
1. Retention Schedule
The following schedule applies to all data processed through DREWQ:
Citizen records (name, ID, card number, nationality, sex, DOB, expiry)
Retention Period
Duration of operator account, plus 30 days after termination
Deletion Trigger
Operator account closure, or explicit deletion via API or dashboard. Sensitive fields (name, nationality, MRZ, photo) are stored AES-256-GCM encrypted.
Facial photo data (DG2 image from card chip)
Retention Period
Same as the associated citizen record
Deletion Trigger
Citizen record deletion. The photo is removed together with the record. It is stored encrypted at rest and is never retained in plaintext.
MRZ data (machine-readable zone lines)
Retention Period
Same as the associated citizen record
Deletion Trigger
Citizen record deletion
Scan logs (timestamp, station ID, scan outcome)
Retention Period
Minimum 12 months from the date of the scan
Deletion Trigger
After 12 months, or operator account closure (whichever is later)
Operator account data (name, email, organisation)
Retention Period
Duration of account, plus 60 days after termination
Deletion Trigger
Operator-initiated account deletion, or administrative termination
API access logs (endpoint, timestamp, response code)
Retention Period
12 months from the date of the request
Deletion Trigger
Rolling 12-month window; older logs are automatically purged
BAC key material (card number, DOB, expiry used for chip authentication)
Retention Period
Not retained. Session-only.
Deletion Trigger
Discarded immediately after the card-reading session ends
2. Why We Retain Data
Each retention period reflects a specific operational or legal purpose:
- Citizen records are retained to avoid re-scanning the same card on repeat visits and to provide operators with a searchable identity record for their service interactions
- Scan logs are retained for audit, accountability, and fraud investigation purposes. The 12-month period aligns with standard audit trail requirements in Ghanaian financial regulations.
- API access logs are retained to support security investigations and to detect anomalous usage patterns
- Operator account data is retained for a short period after termination to support billing reconciliation and dispute resolution
3. Operator-Initiated Deletion
Operators can delete citizen records at any time through the operator dashboard or via the API. Deletion is permanent and irreversible. The associated facial photo and MRZ data are removed together with the record.
Operators are responsible for deciding when to delete citizen records consistent with their stated purpose for the scan and their obligations under the Ghana Data Protection Act 2012. We recommend operators establish their own internal retention policies and use the API to automate deletion when records are no longer needed.
Scan logs associated with a deleted citizen record are anonymised (citizen fields are nulled) rather than deleted outright, so that the audit trail of scan activity remains intact for the minimum 12-month period.
4. Data Subject Deletion Requests
Individuals whose data has been processed have the right to request erasure under the Ghana Data Protection Act 2012. Because operators are the data controllers for the scans they perform, erasure requests should in the first instance be directed to the operator organisation that performed the scan.
If the operator cannot be identified or is unresponsive, individuals may contact us directly. We will:
- Verify the identity of the person making the request
- Locate the relevant citizen record using the personal ID number
- Delete the record and associated photo data within 30 days of a verified request
- Confirm deletion in writing to the requestor
Note that anonymised scan log entries may be retained even after citizen record deletion, as they do not identify the individual once anonymised.
5. Account Termination
When an operator account is terminated (whether by the operator or by us for policy violations):
- API keys associated with the account are revoked immediately
- Citizen records are scheduled for deletion within 30 days of account closure
- Scan logs are retained for the remainder of their 12-month window from the date of each scan, then deleted
- Operator account data is retained for 60 days for billing and dispute purposes, then permanently deleted
Operators may request an export of their citizen records before account closure by contacting support. Exports are provided in JSON format and are available for 7 days after generation.
6. Legal Holds
We may retain data beyond the standard retention periods where we are subject to a legal obligation to do so, including:
- Court orders or preservation demands from law enforcement or regulatory bodies
- Ongoing investigations into suspected fraud, identity theft, or abuse of DREWQ
- Active litigation or formal disputes in which the data is relevant evidence
We will notify affected operators of any legal hold unless prohibited from doing so by law or court order.
Request deletion or data export
Operators can manage records directly in the dashboard. For account closure, data exports, or individual deletion requests, use our contact form. We respond within 30 days.
Also read our Privacy Policy and Security Policy.