Published using Google Docs
DFS Data Governance Policy.docx
Updated automatically every 5 minutes

 

Text

Description automatically generated

DFS Data Governance Policy

30 May 2024, Scott Turnbull


DFS Data Governance Policy

Introduction

At Data Friendly Space (DFS), our mission is to provide digital tools and actionable data that empower social impact organizations to drive positive change effectively. Born out of the Nepal earthquake of 2015, we deeply understand the critical role that timely, reliable, and ethically managed data plays in preparing for and responding to humanitarian needs. As such, we must mirror the same professionalism and strong principles of the humanitarian community in our ethical and secure approach to data governance.

Our commitment to ethical and inclusive practices is at the core of our work. We recognize that the trust placed in us by our partners and the individuals they serve is paramount. To maintain this trust, we must ensure that our data governance practices are transparent, secure, and aligned with the principles of humanitarian service.

This Data Governance Policy reflects our dedication to upholding the highest standards of privacy, security, and ethical data use. It outlines our approach to data management, ensuring that we collect, process, store, and use data responsibly and in compliance with relevant regulations and recognized best practices. By adhering to these principles, we aim to foster trust, protect the privacy rights of individuals, and maintain the integrity of the data we handle.

Our data governance practices are guided by the core values that underpin our work as a nonprofit organization dedicated to driving positive social impact. These include:

By embedding these principles into our data governance framework, we strive to create a safe and trustworthy environment for data sharing and collaboration.

Policy

The purpose of this Data Governance Policy is to establish a framework for the effective management, security, privacy, and ethical use of data and AI within Data Friendly Space. Inspired by and in compliance with IASC Operational Guidance on Data Responsibility in Humanitarian Action, this policy aims to ensure that our organization maintains the highest standards of data governance while serving international NGOs that provide humanitarian relief services.

Scope

This policy applies to all DFS employees, contractors, partners, and third-party service providers who collect, process, store, or use personal data on behalf of Data Friendly Space. Additionally, this policy governs all data handling services provided by Data Friendly Space to partners, unless otherwise specified in writing.

Data Protection Officer (DPO)

A Data Protection Officer (DPO) shall oversee data protection strategy and implementation, ensuring compliance with recognized best practices and alignment with humanitarian principles. The DPO shall report directly to the highest level of management and shall be provided with the necessary resources to carry out their tasks effectively.

Data Security

Data Privacy

Data Protection Impact Assessment (DPIA)

DPIAs shall be conducted when processing activities are likely to result in high risk to the rights and freedoms of individuals. They shall be conducted prior to processing and reviewed regularly, considering the evolving nature of humanitarian crises.

Data Transfers

Personal data shall only be stored or transferred to countries that provide an adequate level of data protection. When transferring data to countries without an adequacy decision, appropriate safeguards such as Standard Contractual Clauses (SCCs) or Binding Corporate Rules (BCRs) shall be implemented.

Data Breach Notification

In the event of a personal data breach, the supervisory authority shall be notified within 72 hours unless the breach is unlikely to result in a risk to individuals’ rights and freedoms. Affected data subjects shall be notified without undue delay when the breach is likely to result in high risk.

Privacy by Design and Default

Privacy by design and default principles shall be integrated into the development of new systems and processes involving personal data. Data protection measures shall be incorporated into system design, ensuring only necessary personal data is processed.

Third-Party Management

Ethical Use of Data and AI

Training and Awareness

Policy Review and Update

This policy shall be reviewed and updated annually or as needed to address evolving data governance requirements, industry best practices, and humanitarian data management needs.

By implementing this Data Governance Policy, Data Friendly Space demonstrates its commitment to responsible data management, ethical data use, and the protection of individual rights and freedoms, leveraging data and technology to support humanitarian relief efforts and drive positive social change.


Appendix A: Data Classifications

These data classifications provide a framework for determining the appropriate level of security and protection required for different types of data handled by the organization.

Public Data

Internal Data

Restricted Data

Classified Data


Appendix B: Roles and Responsibilities

DFS Staff, vendors, and appropriate partners shall be aware of their roles and responsibilities when engaging with data or designing data systems.  

Data Protection Officer (DPO)

Data Security

Data Privacy

Ethical Use of Data and AI

Third-Party Management

Training and Awareness

Policy Review

By adhering to these roles and responsibilities, DFS ensures a robust and comprehensive approach to data governance, fostering a culture of accountability, transparency, and ethical data management.

V2024.05.30