Part of the PHIG policy framework. Download the full manual (PDF). To raise a concern: admin@accreditation.ge.
PHIG collects only the personal data it needs, protects it, and uses it only for the purpose people were told about. Owner: Data Protection Officer (Tamar Talakvadze).
Framework: the Law of Georgia on Personal Data Protection (in force since 1 March 2024), supervised by the Personal Data Protection Service of Georgia; the EU General Data Protection Regulation where PHIG processes data of people in the EU or for EU-funded projects; and donor data requirements.
Principles
- Lawful and transparent: a legal basis and a clear privacy notice for every collection.
- Purpose-limited: used only for the stated purpose.
- Minimal: only the data needed.
- Accurate and kept up to date.
- Time-limited: deleted or anonymised when no longer needed.
- Secure: protected against loss, misuse and unauthorised access.
- Accountable: PHIG can show how it complies.
Special-category data
Health, genetic, biometric data and data on ethnicity, religion, sexual life, criminal record or migration status need explicit consent or another specific legal basis, a data protection impact assessment before large-scale processing, and pseudonymisation wherever possible. Research data follow Policy 18.
Retention
| Data | Kept for |
|---|---|
| Personnel files | Duration of employment + 5 years |
| Financial and grant records | 6 years after project end, or longer if a donor requires |
| Research data (identifiable) | Only as long as the approved protocol states; then anonymised |
| Incident and safeguarding files | 7 years after closure |
| Website contact forms and newsletters | Until consent is withdrawn, reviewed every 2 years |
Security measures
- Encrypted devices and two-factor authentication on all PHIG accounts.
- Access on a need-to-know basis; access removed on the day a person leaves.
- No personal data on personal email or unapproved cloud services.
- Contracts with processors (hosting, survey tools, payroll) include data protection clauses.
Rights of individuals
People may ask to access, correct, delete or restrict use of their data, or object to processing. Requests go to the Data Protection Officer and are answered within the legal deadline.
Data breaches
Any suspected breach is reported to the Data Protection Officer immediately. The Officer assesses risk, notifies the Personal Data Protection Service and affected people where the law requires, and notifies donors under Policy 15.