Part of the ASF policy framework, aligned with the equivalent PHIG policy. To raise a concern: see the ASF Complaints and Reporting Channel.
ASF collects only the personal data it needs, protects it, and uses it only for the purpose people were told about. Owner: Standards & Accreditation Committee.
Framework: the French Data Protection Act (Loi Informatique et Libertés), supervised by the Commission Nationale de l’Informatique et des Libertés (CNIL); the EU General Data Protection Regulation where ASF processes data of people in the EU or for EU-funded projects; and donor data requirements.
Principles
- Lawful and transparent: a legal basis and a clear privacy notice for every collection.
- Purpose-limited: used only for the stated purpose.
- Minimal: only the data needed.
- Accurate and kept up to date.
- Time-limited: deleted or anonymised when no longer needed.
- Secure: protected against loss, misuse and unauthorised access.
- Accountable: ASF can show how it complies.
Special-category data
Health, genetic, biometric data and data on ethnicity, religion, sexual life, criminal record or migration status need explicit consent or another specific legal basis, a data protection impact assessment before large-scale processing, and pseudonymisation wherever possible. Research data follow Policy 18.
Retention
| Data | Kept for |
|---|---|
| Personnel files | Duration of employment + 5 years |
| Financial and grant records | 6 years after project end, or longer if a donor requires |
| Research data (identifiable) | Only as long as the approved protocol states; then anonymised |
| Incident and safeguarding files | 7 years after closure |
| Website contact forms and newsletters | Until consent is withdrawn, reviewed every 2 years |
Security measures
- Encrypted devices and two-factor authentication on all ASF accounts.
- Access on a need-to-know basis; access removed on the day a person leaves.
- No personal data on personal email or unapproved cloud services.
- Contracts with processors (hosting, survey tools, payroll) include data protection clauses.
Rights of individuals
People may ask to access, correct, delete or restrict use of their data, or object to processing. Requests go to the Data Protection Officer and are answered within the legal deadline.
Data breaches
Any suspected breach is reported to the Data Protection Officer immediately. The Officer assesses risk, notifies the Personal Data Protection Service and affected people where the law requires, and notifies donors under Policy 15.