EDITIONEN·FR·ქართ

Accréditation Sans Frontières

International Accreditation of Healthcare Facilities

ASF Institutional Policy Manual · Aligned with PHIG, September 2026

Part of the ASF policy framework, aligned with the equivalent PHIG policy. To raise a concern: see the ASF Complaints and Reporting Channel.

ASF collects only the personal data it needs, protects it, and uses it only for the purpose people were told about. Owner: Standards & Accreditation Committee.

Framework: the French Data Protection Act (Loi Informatique et Libertés), supervised by the Commission Nationale de l’Informatique et des Libertés (CNIL); the EU General Data Protection Regulation where ASF processes data of people in the EU or for EU-funded projects; and donor data requirements.

Principles

  1. Lawful and transparent: a legal basis and a clear privacy notice for every collection.
  2. Purpose-limited: used only for the stated purpose.
  3. Minimal: only the data needed.
  4. Accurate and kept up to date.
  5. Time-limited: deleted or anonymised when no longer needed.
  6. Secure: protected against loss, misuse and unauthorised access.
  7. Accountable: ASF can show how it complies.

Special-category data

Health, genetic, biometric data and data on ethnicity, religion, sexual life, criminal record or migration status need explicit consent or another specific legal basis, a data protection impact assessment before large-scale processing, and pseudonymisation wherever possible. Research data follow Policy 18.

Retention

Data Kept for
Personnel files Duration of employment + 5 years
Financial and grant records 6 years after project end, or longer if a donor requires
Research data (identifiable) Only as long as the approved protocol states; then anonymised
Incident and safeguarding files 7 years after closure
Website contact forms and newsletters Until consent is withdrawn, reviewed every 2 years

Security measures

Rights of individuals

People may ask to access, correct, delete or restrict use of their data, or object to processing. Requests go to the Data Protection Officer and are answered within the legal deadline.

Data breaches

Any suspected breach is reported to the Data Protection Officer immediately. The Officer assesses risk, notifies the Personal Data Protection Service and affected people where the law requires, and notifies donors under Policy 15.

© 2026 Accréditation Sans Frontières · PHIG · Sheni Network