Policy 05 — Data Protection and Privacy Policy

← All 75 policies · Full framework PDF · Forms · Print this policy · Governing text: English · Reviewed 6 October 2026

PHIG Policy Framework v1.2 · Policy 05 · Adopted 1 September 2026 · References: Regulation (EU) 2016/679 (GDPR); Law of Georgia on Personal Data Protection (2023); EU Model Grant Agreement Art. 15 (Data protection); Convention 108+

1. Purpose and scope

PHIG processes personal data of staff, experts, authors, reviewers, learners, submitters, donors, partners, website users and participants in research and training. This policy sets out how PHIG complies with the Law of Georgia on Personal Data Protection and, where it processes data of persons in the European Union or acts for EU-funded projects, with the General Data Protection Regulation (GDPR). It applies to all sites and platforms of the network and to all persons acting for PHIG.

2. Principles

Lawfulness, fairness and transparency · purpose limitation · data minimisation · accuracy · storage limitation · integrity and confidentiality · accountability.

3. Roles

  • Controller: PHIG, 3 Betlemi Rise, Tbilisi.
  • Data protection contact point: info@accreditation.ge; a Data Protection Officer is designated where the law or a grant requires one.
  • Processors: hosting providers, e-mail and API services, payment and accounting providers, learning-management and survey tools — each bound by a data processing agreement.

4. What PHIG processes and why

Category Data Legal basis Retention
Website users IP address, device, pages visited (server logs); cookie consent Legitimate interest (security, operation); consent for non-essential cookies Logs 90 days
Submitters (Sheni Labs, journal, forms) Name, e-mail, organisation, submitted content and documents Performance of the request; legitimate interest in the integrity of the process Duration of the matter + 5 years
Experts, reviewers, committee members Contact details, CV, declaration of interests, consent to be named Contract / legitimate interest; consent for publication Engagement + 5 years
Learners (GMJ Academy) Account, progress, certificates Contract (terms of use) Account lifetime + 3 years; certificate records 10 years
Donors and clients Identity, payment and invoicing data Contract; legal obligation (accounting) As required by tax and accounting law (6 years)
Research and training participants As defined in each protocol Consent; public interest / research, with safeguards As stated in the protocol; raw data 10 years for integrity
Staff and applicants Employment and recruitment data Contract; legal obligation Employment + statutory periods; unsuccessful applications 6 months

5. Rights

Every data subject may ask for access, rectification, erasure, restriction, portability, and may object to processing based on legitimate interest and withdraw consent at any time, by writing to the contact point. Requests are answered within one month. Complaints may be made to the Personal Data Protection Service of Georgia or, for persons in the EU, to their national supervisory authority.

6. Security

Access on a need-to-know basis with individual accounts; encryption in transit; two-factor authentication for administrators; regular backups stored off the production server; prompt security updates; records of processing activities maintained; data protection impact assessments for high-risk processing (health data of participants, large-scale monitoring); breach register and notification to the supervisory authority within 72 hours and to data subjects where the risk is high.

7. Transfers

Data are hosted in Georgia and the European Union. Transfers to processors outside the EU/EEA or Georgia rely on adequacy decisions or standard contractual clauses.

8. Children and vulnerable persons

Services are not directed at children under 16; where a project involves minors or vulnerable adults, the Safeguarding Policy applies and consent is obtained from the person with parental responsibility or a legal representative.

9. EU-funded projects

Each project has a data management plan and, where personal data are processed, a data protection section in its ethics self-assessment; processing follows the grant agreement and the GDPR regardless of where the data subjects are.

10. Review

Reviewed annually and after any breach.


Part of the PHIG Policy Framework. Breaches and concerns may be reported under the Whistleblowing Procedure to info@accreditation.ge (subject “Confidential — integrity”).

Operated by the Public Health Institute of Georgia (PHIG) · non-profit, ID 404407815 · 3 Betlemi Rise, Tbilisi 0105, Georgia · info@accreditation.ge · Policy Framework · Legal notice · Privacy · Accessibility · Part of the PHIG network