Privacy Policy
A proposed framework for collecting, using, storing and sharing personal information in a way that protects dignity and limits unnecessary exposure.
Collect less. Protect more.
The foundation should collect only personal information that is reasonably necessary for a defined humanitarian, governance, communication or compliance purpose.
Minimum privacy controls.
Proof of delivery should not expose people.
Public project reporting should favour aggregated numbers, financial summaries, redacted evidence and non-identifying descriptions. Private verification records may be retained where genuinely necessary, but should not automatically be published.
Extra care should be taken where disclosure could expose a person to stigma, retaliation, exploitation, family conflict, security risk or other foreseeable harm.
People should be able to raise privacy concerns.
The foundation should maintain a practical process for people to ask what information is held about them, request correction of inaccurate information, or raise a concern about how information has been handled, subject to lawful and operational limitations.
Contact details and formal response timeframes should be inserted into this policy before it is adopted for active operations.