Draft pre-launch policy — subject to formal adoption and applicable legal requirements.October 2026
HHSKRCHumanitarian Foundation
Draft policy 04

Privacy Policy

A proposed framework for collecting, using, storing and sharing personal information in a way that protects dignity and limits unnecessary exposure.

Status: DraftVersion: 1.0Review before formal adoption
Purpose

Collect less. Protect more.

The foundation should collect only personal information that is reasonably necessary for a defined humanitarian, governance, communication or compliance purpose.

Privacy by design: public transparency does not require publication of beneficiary names, exact addresses, identity documents, health details or other sensitive information.
Core rules

Minimum privacy controls.

Purpose limitationBefore collecting information, identify why it is needed and avoid collecting data merely because it may be useful later.
Data minimisationUse the least amount of personal information reasonably required to assess eligibility, deliver assistance, maintain records or respond to a legitimate enquiry.
Sensitive informationHealth, identity, family, financial and other sensitive information should receive heightened protection and restricted access.
Access controlPersonal information should be accessible only to people who need it for an authorised function, with stronger controls for higher-risk information.
Secure storageRecords should be stored using reasonable technical and organisational safeguards appropriate to their sensitivity and operational context.
SharingPersonal information should not be shared with partners, suppliers or other parties unless there is a legitimate operational reason and appropriate safeguards.
RetentionInformation should not be kept indefinitely. Retention periods should reflect legal, financial, safeguarding and accountability needs.
Deletion and disposalWhen information is no longer required, it should be securely deleted, destroyed or de-identified where appropriate.
Photos and storiesImages and personal stories should be published conservatively and only with an appropriate basis and meaningful consent where required.
IncidentsSuspected loss, unauthorised disclosure or misuse of personal information should be recorded, contained and escalated promptly.
Beneficiary privacy

Proof of delivery should not expose people.

Public project reporting should favour aggregated numbers, financial summaries, redacted evidence and non-identifying descriptions. Private verification records may be retained where genuinely necessary, but should not automatically be published.

Extra care should be taken where disclosure could expose a person to stigma, retaliation, exploitation, family conflict, security risk or other foreseeable harm.

Requests & corrections

People should be able to raise privacy concerns.

The foundation should maintain a practical process for people to ask what information is held about them, request correction of inaccurate information, or raise a concern about how information has been handled, subject to lawful and operational limitations.

Contact details and formal response timeframes should be inserted into this policy before it is adopted for active operations.