PHIG Policy Framework v1.2 · Policy 05 · Adopted 1 September 2026 · References: Regulation (EU) 2016/679 (GDPR); Law of Georgia on Personal Data Protection (2023); EU Model Grant Agreement Art. 15 (Data protection); Convention 108+
1. Purpose and scope
PHIG processes personal data of staff, experts, authors, reviewers, learners, submitters, donors, partners, website users and participants in research and training. This policy sets out how PHIG complies with the Law of Georgia on Personal Data Protection and, where it processes data of persons in the European Union or acts for EU-funded projects, with the General Data Protection Regulation (GDPR). It applies to all sites and platforms of the network and to all persons acting for PHIG.
2. Principles
Lawfulness, fairness and transparency · purpose limitation · data minimisation · accuracy · storage limitation · integrity and confidentiality · accountability.
3. Roles
- Controller: PHIG, 3 Betlemi Rise, Tbilisi.
- Data protection contact point: info@accreditation.ge; a Data Protection Officer is designated where the law or a grant requires one.
- Processors: hosting providers, e-mail and API services, payment and accounting providers, learning-management and survey tools — each bound by a data processing agreement.
4. What PHIG processes and why
| Category | Data | Legal basis | Retention |
|---|---|---|---|
| Website users | IP address, device, pages visited (server logs); cookie consent | Legitimate interest (security, operation); consent for non-essential cookies | Logs 90 days |
| Submitters (Sheni Labs, journal, forms) | Name, e-mail, organisation, submitted content and documents | Performance of the request; legitimate interest in the integrity of the process | Duration of the matter + 5 years |
| Experts, reviewers, committee members | Contact details, CV, declaration of interests, consent to be named | Contract / legitimate interest; consent for publication | Engagement + 5 years |
| Learners (GMJ Academy) | Account, progress, certificates | Contract (terms of use) | Account lifetime + 3 years; certificate records 10 years |
| Donors and clients | Identity, payment and invoicing data | Contract; legal obligation (accounting) | As required by tax and accounting law (6 years) |
| Research and training participants | As defined in each protocol | Consent; public interest / research, with safeguards | As stated in the protocol; raw data 10 years for integrity |
| Staff and applicants | Employment and recruitment data | Contract; legal obligation | Employment + statutory periods; unsuccessful applications 6 months |
5. Rights
Every data subject may ask for access, rectification, erasure, restriction, portability, and may object to processing based on legitimate interest and withdraw consent at any time, by writing to the contact point. Requests are answered within one month. Complaints may be made to the Personal Data Protection Service of Georgia or, for persons in the EU, to their national supervisory authority.
6. Security
Access on a need-to-know basis with individual accounts; encryption in transit; two-factor authentication for administrators; regular backups stored off the production server; prompt security updates; records of processing activities maintained; data protection impact assessments for high-risk processing (health data of participants, large-scale monitoring); breach register and notification to the supervisory authority within 72 hours and to data subjects where the risk is high.
7. Transfers
Data are hosted in Georgia and the European Union. Transfers to processors outside the EU/EEA or Georgia rely on adequacy decisions or standard contractual clauses.
8. Children and vulnerable persons
Services are not directed at children under 16; where a project involves minors or vulnerable adults, the Safeguarding Policy applies and consent is obtained from the person with parental responsibility or a legal representative.
9. EU-funded projects
Each project has a data management plan and, where personal data are processed, a data protection section in its ethics self-assessment; processing follows the grant agreement and the GDPR regardless of where the data subjects are.
10. Review
Reviewed annually and after any breach.
Part of the PHIG Policy Framework. Breaches and concerns may be reported under the Whistleblowing Procedure to info@accreditation.ge (subject “Confidential — integrity”).