Policy 71 — Confidentiality and Information Classification

← All 75 policies · Full framework PDF · Forms · Print this policy · Governing text: English · Reviewed 6 October 2026

PHIG Policy Framework v1.2 · Policy 71 · Adopted 1 September 2026 · References: ISO/IEC 27001 Annex A information classification (reference); GDPR; EU MGA Art. 13 (confidentiality); 2 CFR 200.303(e); Policies 05, 36, 37

1. Purpose and scope

To define what information PHIG holds in confidence, how it is classified, handled and shared, and the obligations of everyone who has access to it. Applies to the Board, the Director, staff, consultants, volunteers, experts, partners and suppliers of PHIG and all platforms of its network.

2. Policy

  1. Classification: Public (published or publishable); Internal (not for publication but low harm if disclosed); Confidential (would harm a person, partner, client or PHIG if disclosed: unpublished verdicts, assessment files, manuscripts under review, personal data, financial details, security plans); Restricted (safeguarding and integrity cases, credentials, legal matters).
  2. Confidential and Restricted information is stored in access-controlled systems, shared on a need-to-know basis, encrypted when sent outside PHIG, never on personal accounts or unsecured messaging, and never discussed in public.
  3. Everyone signs a confidentiality undertaking on engagement that survives the end of the engagement; reviewers and committee members are bound in respect of what they review.
  4. Information received from donors, partners and clients in confidence is used only for the purpose given and protected as Confidential unless agreed otherwise.
  5. Confidentiality never prevents reporting of wrongdoing under the Whistleblowing Procedure or cooperation with lawful investigations and audits.
  6. Breaches are handled under the Incident Reporting and Data Protection policies.

3. Procedures

  1. Classification markings in document templates; confidentiality undertaking on file.

Responsibilities

Director; every person.

Review

Every two years and when donor rules change.


Part of the PHIG Policy Framework. Breaches and concerns may be reported under the Whistleblowing Procedure to info@accreditation.ge (subject “Confidential — integrity”).

Operated by the Public Health Institute of Georgia (PHIG) · non-profit, ID 404407815 · 3 Betlemi Rise, Tbilisi 0105, Georgia · info@accreditation.ge · Policy Framework · Legal notice · Privacy · Accessibility · Part of the PHIG network