Data Protection Policy
Data Protection Policy
This policy refers to the Cranbrook Food Bank’s commitment to treat information of employees, clients, volunteers, donors, and other interested parties with the utmost care and confidentiality, while ensuring we gather, store and handle data fairly, transparently and with respect towards individual rights. In addition, this policy establishes a standard for how confidential or personal data must be collected, handled and stored to protect against potential data breaches.
Responsibilities
The Cranbrook Food Bank has responsibility for ensuring data is collected, stored and handled appropriately. Each group or individual that handles data must ensure that it is handled and processed in line with this policy.
Cranbrook Food Bank will provide support to all employees and volunteers to help them understand their responsibilities when handling data. Anyone who is unsure about any aspect of data protection or storage should request assistance.
- Board of Directors
The Board of Directors is ultimately responsible for ensuring that Cranbrook Food Bank meets its legal obligations regarding data privacy.
- Cranbrook Food Bank Employees and Volunteers
Ensure sensitive data is kept secure by taking precautions and following these guidelines:
- Utilizing strong passwords which are not shared
- Not disclosing sensitive data to unauthorized parties internal or external to Cranbrook Food Bank
Data Classification
All information retained by the Cranbrook Food Bank should be classified to ensure appropriate information security measures are taken to protect the information. The sensitive nature of the information should determine the level of protection required.
All information, data and documents must be processed and stored in strict accordance with the classification level assigned to the item. Data can be classified under 3 categories.
- Confidential/Restricted: This is the highest level of sensitivity, and this info is carefully controlled. Access is only given to individuals who need the data to do their work. This would include client information, employee and volunteer personal information and any donor information.
- Internal: This data level is specifically for all the information that is used internally. It correlates to the medium sensitivity level. This would include employee and volunteer policies and directives.
- Public: Similar to low sensitivity data, this classification level is used for information that can be viewed, accessed and used by anyone. This includes organizational policies, organizational public financial records, general organizational information.
Data Storage
Any personal information entrusted to Cranbrook Food Bank will be protected with a combination of technological and procedural security controls to prevent the details being accessed by non-authorized personnel, modified or in any other way shared with unauthorized persons.
- Physical Copies
Any data stored on paper should be stored in a secure location where unauthorized individuals cannot see or access it. The guidelines below apply to all physical copies of data.
- When not in use should be kept in a locked drawer or cabinet
- Should not be left where unauthorized individuals could see them
- Should be shredded and disposed of securely when no longer required for business or retention purposes
- Electronic Data
Electronic data must be protected from unauthorized access, accidental deletion and hacking attempts. The guidelines below apply to all electronic data.
- Should be protected by strong passwords that are changed regularly and never shared
- Only stored on Cranbrook Food Bank’s OneDrive, or other cloud services.
- Data should be backed up frequently
- Shall be protected with approved security software and a firewall
- No data shall be saved on an individual’s (employee or volunteer) laptop or on external media such as an external hard drive unless expressly authorized by the Executive Director
Data Use and Exchange
If sensitive information is being shared during a phone call, the individual sharing is responsible for ensuring that all participants take reasonable precautions to prevent the information from being overheard.
When working with personal or sensitive data, employees and volunteers must ensure their computer is locked when unattended.
Any voice mails should be retrieved and deleted in a timely manner and dealt with as appropriate relative to the sensitive nature of the message.
Data Disposal
All data must be disposed of when it is no longer necessary for business purposes or exceeds the data retention requirements.
Physical documents should be shredded and disposed of in a secure manner.
Individual files should be deleted from the system, and the user should ensure residual copies are also cleared from the recycle bin application if deleted on a computer.
All physical drives or removable media holding sensitive data must be returned to Executive Director.