

DFS Data Governance Policy

30 May 2024, Scott Turnbull
DFS Data Governance Policy
Introduction
At Data Friendly Space (DFS), our mission is to provide digital tools and actionable data that empower social impact organizations to drive positive change effectively. Born out of the Nepal earthquake of 2015, we deeply understand the critical role that timely, reliable, and ethically managed data plays in preparing for and responding to humanitarian needs. As such, we must mirror the same professionalism and strong principles of the humanitarian community in our ethical and secure approach to data governance.
Our commitment to ethical and inclusive practices is at the core of our work. We recognize that the trust placed in us by our partners and the individuals they serve is paramount. To maintain this trust, we must ensure that our data governance practices are transparent, secure, and aligned with the principles of humanitarian service.
This Data Governance Policy reflects our dedication to upholding the highest standards of privacy, security, and ethical data use. It outlines our approach to data management, ensuring that we collect, process, store, and use data responsibly and in compliance with relevant regulations and recognized best practices. By adhering to these principles, we aim to foster trust, protect the privacy rights of individuals, and maintain the integrity of the data we handle.
Our data governance practices are guided by the core values that underpin our work as a nonprofit organization dedicated to driving positive social impact. These include:
- Respect for the dignity and rights of individuals: Recognizing the human context and lived experiences behind the data we collect and analyze.
- Impartiality and non-discrimination: Ensuring that our technologies and analyses benefit all members of society equitably.
- Accountability and transparency: Maintaining open communication with stakeholders and being forthright about our data practices.
- Data minimization and privacy-first approach: Only gathering and retaining data necessary for our objectives and respecting individuals’ right to privacy.
- Security and confidentiality: Implementing robust safeguards to protect the information entrusted to us.
By embedding these principles into our data governance framework, we strive to create a safe and trustworthy environment for data sharing and collaboration.
Policy
The purpose of this Data Governance Policy is to establish a framework for the effective management, security, privacy, and ethical use of data and AI within Data Friendly Space. Inspired by and in compliance with IASC Operational Guidance on Data Responsibility in Humanitarian Action, this policy aims to ensure that our organization maintains the highest standards of data governance while serving international NGOs that provide humanitarian relief services.
Scope
This policy applies to all DFS employees, contractors, partners, and third-party service providers who collect, process, store, or use personal data on behalf of Data Friendly Space. Additionally, this policy governs all data handling services provided by Data Friendly Space to partners, unless otherwise specified in writing.
Data Protection Officer (DPO)
A Data Protection Officer (DPO) shall oversee data protection strategy and implementation, ensuring compliance with recognized best practices and alignment with humanitarian principles. The DPO shall report directly to the highest level of management and shall be provided with the necessary resources to carry out their tasks effectively.
Data Security
- Data Classification: All data shall be classified based on its sensitivity, criticality, and relevance to humanitarian purposes. Classifications include Public, Internal, Restricted, and Classified. See Appendix A: Data Classifications for more information.
- Access Control: Access to personal data shall be granted on a need-to-know basis, considering the data classification and the individual’s role in humanitarian service delivery. Multi-factor authentication shall be implemented for all critical systems.
- Encryption: All sensitive personal data shall be encrypted at rest and in transit using industry-standard encryption algorithms.
- Monitoring and Auditing: Regular monitoring and auditing of personal data access and usage shall be conducted to detect and prevent unauthorized activities.
- Incident Response: A well-defined incident response plan tailored to the unique challenges of humanitarian settings shall be maintained to handle personal data breaches or security incidents effectively.
Data Privacy
- Data Collection: Personal data shall be collected only for specified, explicit, and legitimate purposes that align with DFS’s mission. The collection of personal data shall be limited to what is necessary and conducted respectfully.
- Data Processing: Personal data shall be processed lawfully, fairly, and transparently, considering the specific needs and vulnerabilities of individuals in humanitarian settings.
- Data Retention: Personal data shall be retained only as long as necessary to fulfill the intended purpose. A data retention schedule shall be maintained and reviewed regularly.
- Data Subject Rights: Data subjects shall have rights in alignment with recognized best practices, including access, rectification, erasure, restriction, portability, and objection. DFS shall facilitate the exercise of these rights.
- Consent Management: Valid consent shall be obtained from data subjects for data processing where possible. Mechanisms shall be implemented to manage and document consent, including withdrawal.
Data Protection Impact Assessment (DPIA)
DPIAs shall be conducted when processing activities are likely to result in high risk to the rights and freedoms of individuals. They shall be conducted prior to processing and reviewed regularly, considering the evolving nature of humanitarian crises.
Data Transfers
Personal data shall only be stored or transferred to countries that provide an adequate level of data protection. When transferring data to countries without an adequacy decision, appropriate safeguards such as Standard Contractual Clauses (SCCs) or Binding Corporate Rules (BCRs) shall be implemented.
Data Breach Notification
In the event of a personal data breach, the supervisory authority shall be notified within 72 hours unless the breach is unlikely to result in a risk to individuals’ rights and freedoms. Affected data subjects shall be notified without undue delay when the breach is likely to result in high risk.
Privacy by Design and Default
Privacy by design and default principles shall be integrated into the development of new systems and processes involving personal data. Data protection measures shall be incorporated into system design, ensuring only necessary personal data is processed.
Third-Party Management
- Due Diligence: Prior to engaging with third-party partners, a thorough due diligence process shall assess their data governance practices.
- Contractual Obligations: Contracts with third parties shall include provisions for data security, privacy, and ethical use.
- Data Processor Management: A written contract shall outline the processing subject matter, duration, nature, purpose, and obligations.
- Monitoring and Auditing: Regular monitoring and auditing of third-party partners shall ensure compliance with contractual obligations and this policy.
Ethical Use of Data and AI
- Fairness and Non-discrimination: Data and AI systems shall be designed and used to promote fairness and non-discrimination, with regular audits to mitigate biases.
- Neutrality: Data and AI systems shall avoid promoting any political, ideological, or commercial interests, focusing on objective analysis.
- Transparency and Explainability: AI system use shall be transparent, and decisions explainable. Clear information about AI system purpose, function, and limitations shall be provided.
- Accountability and Governance: Clear roles and responsibilities for ethical data and AI use shall be assigned. An ethics committee shall oversee ethical principles’ implementation.
- Continuous Improvement: Regular reviews and assessments shall identify improvement areas in data and AI ethics, incorporating stakeholder feedback and staying updated on best practices.
Training and Awareness
- Employee Training: All DFS employees shall receive regular training on data governance, security, privacy, ethical data use, and humanitarian context application.
- Awareness Programs: Programs shall promote a culture of responsible data governance and ethical data use throughout the organization.
Policy Review and Update
This policy shall be reviewed and updated annually or as needed to address evolving data governance requirements, industry best practices, and humanitarian data management needs.
By implementing this Data Governance Policy, Data Friendly Space demonstrates its commitment to responsible data management, ethical data use, and the protection of individual rights and freedoms, leveraging data and technology to support humanitarian relief efforts and drive positive social change.
Appendix A: Data Classifications
These data classifications provide a framework for determining the appropriate level of security and protection required for different types of data handled by the organization.
Public Data
- Definition: Data that is freely available to the public and can be accessed, used, and shared without restrictions.
- Examples: Press releases, annual reports, public website content.
- Security Measures: No specific security measures required.
Internal Data
- Definition: Data intended for use within the organization and its authorized partners.
- Examples: Internal policies, procedures, employee directories, non-sensitive project data.
- Security Measures: Access limited to authorized personnel, basic security controls.
Restricted Data
- Definition: Data that is highly sensitive and requires the highest level of protection due to its potential to cause significant harm if compromised.
- Examples: Sensitive personal data (health data, biometric data), data related to vulnerable populations.
- Security Measures: Strict access controls, strong encryption, regular security audits, specialized staff training, enhanced monitoring, and incident response procedures.
Classified Data
- Definition: Data classified by government agencies or international organizations due to its potential impact on national security, international relations, or individual safety.
- Examples: Data related to conflict zones, data shared by government agencies or military organizations.
- Security Measures: Compliance with relevant regulations, specialized security protocols, restricted access, secure communication channels, regular security assessments.
Appendix B: Roles and Responsibilities
DFS Staff, vendors, and appropriate partners shall be aware of their roles and responsibilities when engaging with data or designing data systems.
Data Protection Officer (DPO)
- Oversee data protection strategy and implementation.
- Ensure compliance with recognized best practices and humanitarian principles.
- Report directly to the highest level of management.
- Provide necessary resources for effective task execution.
Data Security
- Classify data based on sensitivity and relevance.
- Implement access controls and encryption.
- Conduct regular monitoring and auditing.
- Maintain and execute incident response plans.
Data Privacy
- Ensure lawful, fair, and transparent data processing.
- Manage data collection and retention schedules.
- Handle consent management and documentation.
Ethical Use of Data and AI
- Advise on the implementation of fairness, non-discrimination, bias, and neutrality in data and AI systems.
- Ensure transparency and explainability of AI systems.
- Conduct regular audits to identify and mitigate biases.
- Stay updated on best practices and continuous improvement in ethical data and AI use.
Third-Party Management
- Conduct due diligence on third-party data governance practices.
- Draft and enforce contractual obligations for data security, privacy, and ethical use.
- Monitor and audit third-party compliance regularly.
Training and Awareness
- Develop and deliver regular training sessions for DFS employees.
- Promote responsible data governance and ethical data use awareness.
- Create and update training materials and programs.
Policy Review
- Review and update the data governance policy annually or as needed.
- Ensure the policy remains relevant and effective.
- Incorporate industry best practices and feedback from stakeholders.
By adhering to these roles and responsibilities, DFS ensures a robust and comprehensive approach to data governance, fostering a culture of accountability, transparency, and ethical data management.