ZeroCarbon Enterprise Logo
DATA MANAGEMENT SPECIFICATION | COMPANIES ACT 2013 · SEBI BRSR CORE

DATA RETENTION POLICY

statutory archival & destruction schedule

Statutory schedule and cryptographic standards for storage lifecycles, immutable audit archival, and secure data disposal across enterprise carbon accounting estates.

Effective DateSeptember 29, 2026
Legal RefZC-LEG-RET-2026-V3
Audit Window8 - 10 Years Mandate
Destruction StandardNIST SP 800-88
01/Legal Mandates

1. Statutory Objectives & Legal Mandates

ZeroCarbon manages, archives, and securely disposes of enterprise sustainability records in accordance with global statutory obligations. Corporate carbon accounting records serve as statutory financial and ESG disclosures subject to regulatory audit by Big-4 assurance partners, SEBI, the European Commission, and the Ministry of Corporate Affairs (MCA).

This policy coordinates compliance across:

  • Section 128 of the Companies Act, 2013 (India): Requiring books of account and vouchers to be preserved in good order for a minimum of 8 financial years.
  • Section 44AA of the Income Tax Act, 1961: Mandatory maintenance of financial books and utility bills for 7 to 8 assessment years.
  • SEBI BRSR Core Guidelines: Mandatory 8-year preservation of reasonable assurance verification documents.
  • European Union CSRD / ESRS E1: Prescribed 10-year archival for corporate sustainability reports.
02/Classification Matrix

2. Corporate Data Classification Matrix

Information processed by ZeroCarbon is classified into four operational tiers:

Tier A: Primary Evidence Vouchers

Raw utility invoices, meter exports, fuel receipts, logistics manifests, and third-party lab assay certificates uploaded by the client.

Tier B: Calculated Emissions Ledgers

Deterministic Scope 1, 2, and 3 calculations, mapped emission factor coefficients, and unit conversion traces.

Tier C: Cryptographic Lineage Seals

SHA-256 merkle roots, immutable timestamps, audit log chains, and public ledger anchor proofs.

Tier D: Ephemeral Session & System Logs

API access logs, HTTP request telemetry, worker queue jobs, and client debug traces.

03/Schedules

3. Statutory Retention Schedules

Record CategoryRetention DurationTrigger EventStatutory Basis
Emissions Invoices & Utility Bills8 Financial YearsEnd of relevant Financial YearCompanies Act, 2013 (Sec 128)
BRSR Core Assurance Packages8 Financial YearsDate of statutory filingSEBI Listing Regulations (LODR)
CSRD / European ESRS Archives10 Calendar YearsDate of CSRD declarationEU Directive 2022/2464
Cryptographic SHA-256 Ledger SealsIndefinite (Permanent)Chain commitmentVerifiable provenance standard
API Access & Security Logs365 Days (1 Year)Log creationCERT-In Direction No. 20(3)/2022
04/Archival Standards

4. Immutable Archival & SHA-256 Anchoring

ZeroCarbon utilizes Write-Once-Read-Many (WORM) storage tiers for finalized reporting periods. Once an emissions inventory is signed off for external assurance:

  • Data tables and source files transition to Object Lock compliance mode in AWS S3 (ap-south-1).
  • No administrative user, customer employee, or ZeroCarbon engineer can overwrite or delete records during the retention lock.
  • Every record maintains an explicit cryptographic SHA-256 hash linked to previous historical entries.
05/Cryptographic Shredding

5. Secure Cryptographic Shredding Protocols

Upon expiration of the mandatory retention window or upon formal, verified customer request following contract termination (where statutory retention permits):

  • Data is purged using cryptographic erasure in compliance with NIST SP 800-88 Rev. 1 Guidelines for Media Sanitization.
  • The specific Customer Data Encryption Key (DEK) managed within AWS KMS is permanently destroyed, rendering all ciphertexts irrecoverable.
  • A formal Certificate of Cryptographic Sanitization is generated and delivered to Customer's designated compliance officer.
06/Portability

6. Customer Data Export & Portability

Customer may at any time export complete emissions ledgers, raw source attachments, and verification audit packages via our automated Data Export API or the dashboard in industry-standard JSON, CSV, and XBRL formats. ZeroCarbon does not engage in proprietary data locking.

07/Governance

7. Annual Compliance Audit & Review

ZeroCarbon Records Management Directorate

This policy is reviewed annually in Q3 to incorporate updates from SEBI, MCA, and global climate reporting bodies.

Compliance Inquiries: compliance@zerocarbon.org.in