AFRDA
Data Protection and Privacy Policy
Responsible use of personal information
African Resilience & Development Agency (AFRDA) respects the privacy of community members, programme participants, website visitors, applicants, staff, volunteers, interns, partners, suppliers, donors and other stakeholders. We use personal information responsibly, for clear purposes and with safeguards proportionate to the sensitivity of the information.
Scope
This policy applies to personal information handled by AFRDA in paper, digital, photographic, audio, video, email, website, cloud, mobile-device, database and other forms. It covers information AFRDA handles directly and information processed for AFRDA by an authorised partner, consultant or service provider.
Information we may collect
- Contact and identity information: names, contact details, organisation, role, location, identity or eligibility documents where necessary.
- Programme and community information: participation records, survey or interview responses, community diagnostic information, livelihood or environmental information and feedback.
- Images and stories: photographs, video, audio, interviews, case stories and consent records.
- Application and engagement information: job, volunteer, internship, consultancy, partnership and supplier information.
- Financial and transaction information: supplier details, payment information, donation or grant records and related compliance information.
- Sensitive information: safeguarding concerns, complaints, health or disability information, demographic information and other sensitive data only when necessary and appropriately protected.
- Website and communication information: messages submitted through forms, email correspondence and limited technical information generated by website or communication services.
Our privacy principles
- Lawfulness, fairness and transparency. We use personal information for legitimate and explained purposes and in accordance with applicable law.
- Purpose limitation. We do not use information for an incompatible purpose without a proper basis and, where required, further notice or consent.
- Data minimisation. We collect only information reasonably needed for the relevant activity.
- Accuracy. We take reasonable steps to keep information accurate and correct material errors.
- Storage limitation. We keep personal information only as long as needed for programme, safeguarding, legal, donor, audit, employment or accountability purposes.
- Security and confidentiality. We use proportionate organisational and technical safeguards and limit access to people with a genuine need.
- Privacy by design. We consider privacy before collecting field data, creating forms or databases, sharing reports, publishing stories or engaging service providers.
- Respect for communities. We do not collect information merely because it may be useful later, and we avoid data uses that could stigmatise or endanger individuals or groups.
Why we use personal information
Depending on the activity and applicable law, AFRDA may use personal information with consent, to perform an agreement, to meet a legal or donor requirement, to protect vital interests, for a legitimate organisational or public/community interest, or for safeguarding and accountability purposes.
- Plan, deliver, monitor and improve programmes and community engagement.
- Communicate with participants, partners, donors, applicants, suppliers and other stakeholders.
- Manage recruitment, volunteering, internships, consultancy and supplier relationships.
- Respond to safeguarding concerns, complaints, security incidents and legal obligations.
- Prepare donor, governance, audit, financial and programme reports, using aggregated or anonymised information where individual identification is not needed.
- Publish authorised stories, images and learning materials with appropriate consent and safeguarding review.
- Maintain the security, administration and effectiveness of AFRDA’s website and information systems.
Community data, research, photographs and stories
- We explain the purpose of data collection in language that participants can reasonably understand.
- Participation in surveys, interviews, photographs and stories is voluntary unless information is required for a clearly explained and legitimate programme process.
- We avoid unnecessary intrusive questions and use anonymised or aggregated data when individual identification is not required.
- We review reports and communications for privacy, safeguarding, stigma, political, social and economic risks before sharing.
- We do not sell personal information or share it for unrelated marketing or political purposes.
Sharing information
AFRDA may share information with authorised staff, service providers, implementing partners, donors, auditors, advisers, safeguarding specialists or competent authorities where there is a legitimate purpose and appropriate protection. We share only what is reasonably necessary.
- Service providers and partners that handle personal information are expected to use it only for authorised purposes and protect it appropriately.
- Donor and public reports should use aggregated or anonymised information unless identification is necessary and lawfully justified.
- International transfers, where relevant, are assessed for legal, confidentiality and security risks.
- We may disclose information where required by law or where necessary to protect a person from serious harm, while limiting disclosure as far as reasonably possible.
Retention and secure disposal
Retention periods depend on the type of information and the reasons it must be kept. AFRDA considers legal, donor, audit, safeguarding, employment, financial, programme and accountability requirements. When information is no longer needed, it is securely destroyed, anonymised or deleted where reasonably possible.
Your privacy rights
Subject to applicable law and legitimate limitations, a person may ask AFRDA to:
- Confirm whether AFRDA holds personal information about them and explain how it is used.
- Provide access to relevant personal information.
- Correct inaccurate or incomplete information.
- Delete information that AFRDA no longer has a valid reason to keep.
- Restrict or object to certain uses of information.
- Withdraw consent for future use where consent is the basis for processing.
- Complain about how information has been handled.
AFRDA may need to verify identity before responding. A request may be limited where disclosure would endanger another person, reveal confidential information, compromise an investigation, conflict with a legal or donor retention duty, or otherwise be lawfully restricted.
Data security incidents
A lost document or device, unauthorised disclosure, compromised account, unsafe publication or other suspected data breach should be reported promptly. AFRDA will seek to contain the incident, assess risk, protect affected persons, document decisions and make notifications required by law, donor obligations or the seriousness of the risk.
Children and vulnerable participants
Information relating to children and vulnerable participants receives additional safeguards. AFRDA seeks appropriate permission, limits collection to what is necessary, avoids harmful publication and considers the best interests, safety and dignity of the person when deciding how information is used or shared.
Website services and external links
The AFRDA website may use third-party hosting, email, analytics, form, social media or communication services. Those services may process limited technical or contact information under their own terms. AFRDA shall publish a separate cookie notice where non-essential cookies or analytics are used. External websites linked from AFRDA’s website are responsible for their own privacy practices.
Contacting AFRDA about privacy
AFRDA aims to acknowledge privacy requests within five working days and to respond substantively within a reasonable period, normally within 30 calendar days, subject to identity verification, complexity and applicable law.
Updates to this policy
This policy may be updated when AFRDA’s activities, systems, legal obligations or data practices change.