Data & Document Retention Policy
Last updated: July 1, 2026
This policy describes the course and student records the provider maintains, how long they are retained, and how they are secured and disposed of, in accordance with the NMLS Approved Course Data and Document Retention Policy.
Records Retained
The following records are created and maintained for every course offering.
- •Student registration and enrollment records, including NMLS ID and contact information.
- •Rules of Conduct (ROCS) acknowledgements and identity-verification records.
- •Course syllabus and course content as delivered.
- •Student time-tracking within the learning management system for the primary SAFE Act topical areas (federal law, ethics, non-traditional mortgage lending).
- •Attendance rosters, sign-in/sign-out records, and login/logout records.
- •Gradebook entries, coursework submissions, assessment results, and course completion status.
- •Course completion certificates issued to students.
- •End-of-course survey responses and the resulting improvement actions.
- •Instructor qualification, approval, and evaluation records.
Retention Period
- •All course and student records listed above are retained for a minimum of five (5) years from the last date the course is taught or administered.
- •Records may be retained longer where required by state law or regulatory request.
- •Course data and documents are produced to the State Regulatory Registry (SRR) or a state regulator within fourteen (14) calendar days of a written request.
- •The provider allows NMLS to audit course data as needed to confirm courses are administered correctly and student participation is tracked.
- •Records are stored electronically with encryption at rest and in transit, access controls, and audit logging, with backups maintained to protect against loss.
Security & Access
- •Access to student records is limited to authorized personnel on a need-to-know basis.
- •The provider does not sell student data. Data is handled in accordance with the Privacy Policy.
- •Any suspected data incident is investigated and handled under the provider’s incident-response process.
Disposal
- •After the retention period expires and no legal hold applies, records are securely and permanently destroyed.
- •Electronic records are cryptographically erased or wiped; any physical media is destroyed beyond recovery.