EDITIONEN·FR·ქართ

Accréditation Sans Frontières

International Accreditation of Healthcare Facilities

ASF Governance & Policy Manual · ASF-POL-18

Data Protection, IT and Cybersecurity

Part of the ASF Governance & Policy Manual. Adapted from the PHIG Institutional Policy Manual (consolidated edition, September 2026), scoped to ASF’s structure and accreditation-specific risks.

ASF systems are protected by access control, encryption and backups, and used only for ASF work. As a French association, ASF processes personal data — facility assessment records, Coordinator/Monitor credentials, donor and partner data — under the EU General Data Protection Regulation (GDPR) and the French Data Protection Act (Loi Informatique et Libertés), under the supervision of the CNIL (Commission Nationale de l’Informatique et des Libertés), in addition to any data protection law applicable where a facility or donor is based. This policy governs facility assessment data, Coordinator/Monitor credential records, and standards-development material at every stage — including while a facility’s name is withheld pending a certification decision, consistent with ASF’s stated duty of confidentiality toward facilities undergoing assessment. Owner: ASF Secretariat (Data Protection function), reporting to the International Standards Council.

  • Accounts: individual accounts only; strong passwords and two-factor authentication on email, the website, the training platform, and any system holding facility assessment data.
  • Facility assessment data: a facility’s evidence file, Monitor findings, and any disputed criterion are accessible only to that facility’s assigned Coordinator, Monitor, and the ASF Secretariat — never published or shared beyond what the facility itself has consented to disclose, until a certification decision is final and the facility’s own publication preference is confirmed. A facility is told plainly, before assessment begins, exactly what the final accreditation outcome (scope, dates, validity) will be published once the award is made, per the Public Accreditation Register in ASF-POL-22 — so nothing about what becomes public is a surprise.
  • Devices: encrypted, screen-locked and kept updated; a lost or stolen device reported within 24 hours.
  • Backups: standards documents, the Public Standards Register, and active facility assessment records backed up at least weekly to a separate location; restore tested every six months.
  • Access review: granted on a need-to-know basis, reviewed every six months, and removed the day a Council member, Coordinator, or Monitor’s term ends or rotates off a facility.
  • Websites and platforms: administrator credentials held by named individuals only; security updates applied promptly; incidents logged and investigated under the same Appeals and Conflict of Interest framework published on Standards Development.
  • Data subject rights (GDPR): any individual whose personal data ASF holds — a Coordinator, a Monitor, a facility contact — may request access, correction, or erasure, subject to ASF’s record-retention obligations under Records Management and Retention (ASF-POL-40); requests are handled within the one-month statutory window.
  • Acceptable use: no illegal content, no unlicensed software, and no personal or commercial use of ASF systems unrelated to accreditation activity.

Review, audit and training

This policy, and the information management arrangements it describes, are reviewed annually with progress reported to the International Standards Council, consistent with ASF-POL-46. Access logs and security settings across ASF’s systems are audited annually to identify risks and required corrective action, reported to the Council alongside the Risk Register (ASF-POL-17). Every Secretariat staff member, Coordinator, and Monitor is trained — at induction (ASF-POL-51) and through the annual refresher (ASF-MON-STD-v1, Standard G10) — on password security, data handling, and recognising a potential breach. Information is organised so that the people who need it for a live assessment (the assigned Coordinator and Monitor) can access it without delay, while remaining restricted from anyone without that need.

© 2026 Accréditation Sans Frontières · PHIG · Sheni Network