Draft policy 08
Information Security & Records Retention Policy
The Foundation should protect administrative, financial, project, partner and beneficiary-related records throughout collection, use, storage, access, retention and disposal.
Least-privilege accessAdministrative systems and private records should be available only to authorised people who require access for an approved function.
Strong account securityAdministrator accounts should use unique credentials, secure recovery methods and available multi-factor authentication once enabled and verified.
Sensitive informationIdentity documents, health information, exact private addresses and safeguarding case details should be collected only when genuinely necessary and kept out of public project fields.
Private evidence storageReceipts, invoices and project evidence should use restricted storage rather than public website folders or public repositories.
Device and session securityAdministrators should use trusted devices, keep systems updated, avoid shared sessions and sign out when access is no longer required.
Retention by purposeRecords should be retained according to legal, financial, safeguarding, audit and operational requirements rather than kept indefinitely without reason.
Secure disposalWhen lawful retention is no longer required, records should be securely deleted, destroyed or de-identified as appropriate.
BackupsGovernance data should have reliable backups or exports, stored separately and protected from unauthorised access.
Incident responseSuspected account compromise, data loss or unauthorised disclosure should be contained, documented, assessed and escalated promptly.
Public reporting boundaryTransparency reports should publish only information appropriate for public release and should never automatically expose private evidence files.
Pre-launch status
Controls before scale.
Retention periods and mandatory breach-response obligations should be aligned with the final legal structure, jurisdictions and actual information handled before formal adoption.
Material incidents, suspected wrongdoing or legal obligations should be escalated to appropriate qualified or external support rather than handled informally where that would be inadequate.