Policy Area: Policies & Guidelines | Date of Issue: June 15, 2024 |
Subject: Privacy and Data Protection Policy | Revision Date: July 18, 2025 |
The Mandate Development Centre (TMDC) Privacy and Data Protection Policy
Purpose: To outline TMDC’s commitment to protecting personal and organizational data, ensuring compliance with privacy laws, and safeguarding the trust of stakeholders.
Scope: This policy applies to all TMDC stakeholders, including staff, volunteers, board members, donors, and service recipients. It governs the collection, storage, usage, and sharing of personal and sensitive data.
Key Principles
- Transparency:
- TMDC provides clear information about how personal data is collected, used, and shared.
- Consent is obtained where legally required before data collection.
- Accountability: TMDC appoints a Data Protection Officer (DPO) responsible for implementing and monitoring compliance with privacy laws and policies.
- Data Minimization: Only data necessary for operational and legal purposes is collected.
- Security: Robust technical and organizational measures are implemented to prevent unauthorized access, loss, or disclosure of data.
- Rights of Data Subjects: Individuals have the right to access, correct, or delete their data and the right to lodge a complaint with relevant authorities.
Collection of Data
- Personal data is collected through forms, surveys, registrations, and online interactions.
- Sensitive data (e.g., health information) is only collected with explicit consent and used for authorized purposes.
Use of Data
- Data is used strictly for TMDC’s operational activities, including communication, program management, fundraising, and reporting.
- Personal data will not be shared with third parties without prior consent unless legally mandated.
Data Retention and Disposal
- Data is retained only for as long as necessary to fulfill the purpose for which it was collected or as required by law.
- Secure methods (e.g., shredding, data wiping) are used to dispose of outdated or unnecessary data.
Security Measures
- Physical Security: Secure storage facilities for hard copies of data.
- Digital Security: Password-protected systems, firewalls, and encrypted databases.
- Access Control: Role-based access limits data handling to authorized personnel only.
Data Breach Protocol
- Any data breach is reported immediately to the Data Protection Officer.
- Affected individuals and relevant authorities are notified within 72 hours, as required by law.
Training and Awareness
- Regular training is provided to staff and volunteers on data protection responsibilities and practices.
Compliance
- TMDC complies with all applicable privacy laws, including GDPR, PIPEDA, and other jurisdiction-specific regulations.
- Regular audits ensure compliance and identify areas for improvement.
Contact Information
- Questions or concerns regarding this policy or privacy practices can be directed to the Data Protection Officer at tmdcmoncton@gmail.com