NRC Data Protection Policy
NRC Data Protection Policy
1 Introduction 3
2 Definitions 4
3 Principles 6
3.1 Obtain information fairly and lawfully 7
3.2 Purpose limitation 8
3.3 Data minimisation 8
3.4 Information quality 8
3.5 Storage limitation 8
3.6 Information security 9
3.7 NRC’s Responsibility towards Data Protection Law 9
4 The rights of the Data Subjects 10
5 When NRC is Processing data on behalf of others 11
6 When publishing pictures of individual persons 11
7 Questions related to NRC`s data protection policy? 12
2
1 Introduction
NRC helps people fleeing from conflict and disasters in countries worldwide. To provide
adequate assistance, NRC must collect information, including Personal Data. NRC
processes Personal Data to fulfil obligations towards beneficiaries, employees, public
authorities, donors, partners and other stakeholders.
The NRC Data Protection policy establishes the organisation’s standard on how to protect
the privacy of the individuals whose data is processed in line with applicable legislation and
humanitarian principles such as the following:
NRC Mission statement: NRC works to protect the rights of displaced and vulnerable
persons during crisis.
Sphere protection principle: Avoid exposing people to further harm as a result of your
actions.
Legal framework
NRC staff, partners or suppliers processing Personal Data on behalf of NRC must do this in
accordance with the EU General Data Protection Regulation 2016/679 - GDPR (NRC is a
Norwegian based organisation, subjected to GDPR) and data protection legislation that is
relevant in the country in which the processing (as defined below) of Personal Data takes
place. This applies both to Personal Data stored on electronic format and in a paper
archive. When GDPR, local legislation or donor requirements conflicts, NRC shall always
comply with whichever offers the highest level of privacy protection.
Other legislation, such as tax and employment and labour laws might also be relevant for
how and what type of Personal Data regarding employees NRC may process.
Policies
The NRC Code of Conduct set out how NRC staff act and handle sensitive and confidential
information. The privacy of all persons whose data is being processed by NRC shall be
safeguarded in accordance to this policy. This policy, together with principles and guidelines
presented in this document, is part of NRC’s internal control on processing of Personal
Data.
3
2 Definitions
The following definitions describe key terminology related to Data Protection and will be
used in all documents related to this subject.
Personal Data
Personal Data shall mean any information relating to an identified or identifiable natural
person ('Data Subject'). An identifiable person is one who can be identified, directly or
indirectly, in particular by reference to an identification number, location data, online
identifier or to one or more factors specific to their physical, physiological, genetic, mental,
economic, cultural or social identity, such as but not limited to, name, address, phone
number, e-mail, photo, IP address, title etc.
It is important to be aware that in complex emergencies and conflict situations any type of
Personal Data may be regarded as “sensitive”, even though it does not fall under the
definition of special categories in Personal Data legislation. This is due to context and what
(harm) that information could bring to people in case it should fall in the wrong hands.
Processing
Processing of Personal Data (“Processing”) means any operation, or set of operations,
performed upon Personal Data, whether or not by automatic means, such as collection,
recording, organization, storage, adaptation or alteration, retrieval, consultation, use,
printing, publishing, disclosure by transmission, dissemination or otherwise making
available, alignment or combination, blocking, erasure or destruction.
Data Subject
The individual person whose Personal Data is being processed.
Data controller
Data controller (“Controller”) shall mean the natural or legal person, public authority,
agency or any other body which alone, or jointly with others, determines the purposes and
means of the processing of Personal Data.
4
Data processor
Data processor (“Processor”) shall mean a natural or legal person, public authority, agency
or any other body which processes Personal Data on behalf of the data controller, including
partners, outsourcing companies, cloud storage providers, software providers (e.g. Unit4,
Telecomputing, WebCruiter, Microsoft etc.).
Consent
Consent of the Data Subject means any freely given, specific, informed and unambiguous
indication of the Data Subject's wishes by which he or she, by a statement or by a clear
affirmative action, signifies agreement to the processing of Personal Data relating to him or
her. As far as possible, NRC wants the consent to be in writing.
NRC will use declarations of Consent in various contexts in which Personal Data are
processed.
Data breach
Data breach (“Data Breach”) means a breach of security leading to the accidental or
unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Personal
Data transmitted, stored or otherwise processed.
5
3 Principles
To comply with Personal Data protection regulations, NRC shall ensure that Personal Data
must be:
• Collected for specified, explicit and legitimate purposes and not further processed
in a way incompatible with those purposes;
• Processed lawfully, fairly and in a transparent manner;
• Adequate, relevant and not excessive in relation to the purposes for which they are
collected and/or further processed;
• Accurate and, where necessary, kept up to date. Every reasonable step must be
taken to ensure that data which are inaccurate or incomplete, having regard to the
purposes for which they were collected or for which they are further processed, are
erased or rectified;
• Kept in a form which permits identification of Data Subjects for no longer than is
necessary for the purposes for which the data were collected or for which they are
further processed.
• Protected against unauthorised access, loss and destruction
• Made available to allow Data Subjects’ right to access their Personal Data;
NRC shall ensure that Personal Data may be processed only if:
6
3.1 Obtain information fairly and lawfully
All Personal Data processed by, or on behalf of, NRC shall be collected and used fairly. The
processing of Personal Data by NRC should be within the reasonable expectation of the
Data Subjects and not have unjust adverse effects on his or her rights.
The processing must have a lawful basis from one of the following conditions:
2. Contractual necessity
NRC may process Personal Data when necessary in order to prepare for or enter into a
contract with a Data Subject.
3. Legitimate interest
NRC may process Personal Data to fulfil a legitimate interest such as (but not limited to);
manage user accounts, distribution lists, security incidents, recruitment, communication
with partners, donors, suppliers and vendors.
NRC will document the legitimate interest and ensure that Personal Data is only processed
based on legitimate interest if it does not override the fundamental rights and freedoms of
the individual.
4. Consent
In absence of legal justifications, contractual relationship or legitimate interest, NRC shall
ask for consent when processing Personal Data. The consent must be given
freely/voluntarily and in an informed manner, which means that prior to collecting Personal
Data, the Data Subject (or the guardian of the Data Subject in case of a minor) must be
informed about their rights1.
The consent must be displayed by an explicit action by the Data Subject preferably by
signature or use of tick boxes for electronic data collection tools. Oral consent is not
recommended as NRC must be able to provide proof of having obtained informed consent if
requested by the Norwegian Data Protection Authority. If it is impossible to get verifiable
consent from the Data Subject, due to emergencies or conflict situations, the NRC
representative must document how oral consent was obtained from the Data Subject. All
verifiable consent (or the NRC representative’s documentation) must always be filed for
future reference.
.........................................................................................................................................................
1 see section 4 The rights of the Data Subject
7
3.2 Purpose limitation
Personal Data processed by or on behalf of NRC can only be used for informed/agreed
specific and predetermined purposes. The Personal Data can only be processed in a way
that is compatible with those purposes.
NRC shall make sure that any need for special categories of data2 is justified and limited to
the bare necessity.
Be aware that in some countries where NRC operates, processing special categories of
(sensitive) Personal Data might require to register with the national Data Protection
Commissioner (before data collection starts).
Personal Data shall be deleted (or in the case of paper documents destroyed via burning or
shredding):
.........................................................................................................................................................
2 see chapter 2 Definitions
8
3.6 Information security
NRC shall ensure safe storage of personal data. Personal data processed by, or on behalf
of NRC, shall be kept safe from unauthorized access, loss and unintended disclosure,
changes or deletion. Security measures shall be proportionate to the above mentioned
risks and the sensitivity of the data. This is particularly important where the processing
involves transmission of data over a network or transported outside NRC premises (both
paper documents and information residing on electronic equipment).
Where processing is carried out on NRC’s behalf, NRC must choose a Processor providing
sufficient guarantees in respect of the technical security measures and organizational
measures governing the processing to be carried out, and must ensure compliance with
those measures.
.........................................................................................................................................................
3 see the NRC Start-up Handbook
9
• at all times keep updated log on Data Breaches (loss or unintentional disclosure of
Personal Data) and corrective actions. Report all Data Breaches to the DPO
immediately after being aware of the situation;
• ensure signed data processer agreements with partners and/or suppliers that
impose the same requirements on the data processors as resting upon NRC.
• The purpose of the data collection. Why you need to collect personal data;
• The lawful basis of the processing. If it is consent, inform about the right to withdraw
consent at any time;
• If the Personal Data was obtained from a third party, who or what was is the source;
• Who will have access to the Personal Data and if it will be shared with a third party.
10
5 When NRC is Processing data on behalf of others
Whenever NRC is engaged as an implementing partner and processes data on behalf of
others, we act as a data processor and shall ensure that there is a signed data processor
agreement4 with the data controller that specifies the requirements of the data controller.
In such case, NRC will ensure that every NRC staff involved in the collaboration are familiar
with the terms. If a Partner data protection policy is in conflict with the NRC data protection
policy, NRC shall always comply with the most privacy-friendly regulation.
Example: collecting beneficiary registration data on behalf of UNHCR.
Still in doubt? Ask for informed consent or refrain from publishing the image.
.........................................................................................................................................................
4 See the Data Processor Agreement Template
5 see also the NRC Global Communication Policy
11
7 Questions related to NRC`s data protection policy?
If you have any questions or issues related to NRC`s data protection policy, please don`t
hesitate to contact:
Norwegian Refugee Council – NRC
Email: [email protected]
Telephone number: +47 23 10 98 00 (Switchboard)
12