Legal
Connected Impact Advisory (CIA) is an independent monitoring, evaluation, and learning (MEL) consultancy. In the course of delivering evaluation design, program strategy, capacity building, and community engagement services, CIA collects, manages, and analyses data on behalf of client organisations, research participants, and program beneficiaries.
This policy establishes the principles, roles, and procedures that govern how CIA handles data responsibly across the full data lifecycle, from collection and storage through to use, sharing, and disposal.
This policy applies to:
Requirements of any funding body or government agency under whose grant or contract CIA operates.
As a private sector consultancy, CIA is primarily bound by the federal Privacy Act 1988 (Cth) and APPs. State and territory legislation becomes relevant where CIA is engaged by a state or territory government agency, or where CIA handles personal health information in the private sector. CIA monitors legislative developments including anticipated federal Privacy Act reform during 2026.
| Term | Definition |
|---|---|
| Personal information | Information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether true or not. |
| Sensitive information | A subset of personal information including health, racial or ethnic origin, political opinion, religious belief, sexual orientation, and financial counselling data. |
| De-identified data | Data from which all personal identifiers have been removed such that re-identification is not reasonably practicable. |
| Data subject | Any individual whose personal information is collected or processed by CIA in connection with an evaluation, program, survey, or community engagement activity. |
| Data controller | The entity responsible for determining the purposes and means of processing personal data — in most CIA projects, this is the client organisation. |
| Data processor | An entity that processes data on behalf of the controller — CIA frequently acts as data processor in client-commissioned evaluations. |
| Consent | Freely given, specific, informed, and unambiguous agreement by a data subject to the collection and use of their personal information for a stated purpose. |
Data collection and use must serve the people it concerns. CIA centres the needs, rights, and dignity of data subjects above operational convenience. Where there is tension between data utility and participant welfare, participant welfare takes precedence.
Data is collected only for clearly defined evaluation, learning, or program improvement purposes. Data collected for one purpose will not be repurposed for unrelated activities without explicit consent from the data subject or written agreement with the client organisation.
CIA collects only the data necessary to answer the evaluation questions or fulfil the agreed scope of work. Collection instruments are designed with minimisation in mind.
CIA takes reasonable steps to ensure that data is accurate, complete, and up to date at the point of use. Findings presented to clients or published externally are based on verified, accurately recorded data.
Personal and sensitive data is retained only for as long as necessary to fulfil the stated purpose. Retention periods are specified at the point of project planning and in applicable Service Agreements.
CIA implements appropriate technical and organisational measures to protect data against loss, unauthorised access, modification, or disclosure. Security standards are proportionate to the sensitivity of the data held.
CIA is transparent with data subjects and client organisations about what data is collected, why, how it is used, and who can access it. The Data Governance Lead is accountable for maintaining this policy and responding to data-related concerns.
| Role | Responsibility |
|---|---|
| Data Governance Lead | Owns this policy; reviews annually; responds to data incidents; authorises third-party data sharing. |
| Contracted Evaluators / Subcontractors | Comply with this policy and the relevant CIA Service Agreement; complete privacy induction prior to project commencement. |
| Clients / Partner Organisations | Provide accurate data under agreed data sharing arrangements; notify CIA of any changes to consent status. |
| Classification | Description | Examples |
|---|---|---|
| Sensitive Personal | Data that could cause harm if disclosed; highest protection required. | Health information, financial counselling records, domestic violence disclosures |
| Personal | Identifiable information about individuals that does not meet the sensitive threshold. | Names, contact details, employment status, program participation records |
| Confidential Organisational | Client, partner, or operational data not intended for public release. | Evaluation findings in draft, contract terms, unpublished program data |
| Internal | CIA operational information with limited sensitivity. | Project schedules, internal process documents |
| Public | Information approved for public release. | Published evaluation reports, CIA website content, Her Algorithm toolkit materials |
CIA obtains informed consent prior to collecting personal or sensitive information from individual data subjects. Consent processes are written wherever practicable, plain-language and jargon-free, specific to the purposes for which data will be used, and adapted for the literacy, language, and accessibility needs of participants.
Where CIA works with data collected by client organisations, CIA confirms with the client that original collection met consent requirements sufficient for the intended evaluation use. CIA will not process secondary data where consent status is uncertain without first seeking legal or ethical advice.
CIA does not collect biometric data, location tracking data, or sensitive financial account information in the course of evaluation work. Where engagement with highly vulnerable populations is required, CIA applies additional safeguards and consults AES ethical guidelines before instrument finalisation.
CIA stores data using platforms that meet Australian privacy standards. Two-factor authentication is enabled on all primary platforms. Approved platforms include Google Workspace, Netlify, Beehiiv, and survey platforms including KoBoToolbox, SurveyCTO, and Google Forms.
Data is not stored in unencrypted email attachments for extended periods, personal social media platforms, shared public drives without access controls, or AI tool chat interfaces where data persistence is not under CIA's control.
Access to personal and sensitive data is restricted to personnel with a demonstrable need to access it for the purposes of the project. Subcontractors are granted access only to the data required for their specific scope of work.
CIA uses AI-assisted tools (including Claude by Anthropic) to support tasks such as drafting reports, synthesising data, coding qualitative data, and developing evaluation instruments. No identifiable personal data or sensitive client data is inputted into AI tools without explicit consent. Sensitive personal information is not entered into AI tools under any circumstances. All AI-generated outputs are reviewed and validated before delivery. AI is used as a drafting and analysis aid; all professional judgements remain human-led.
CIA does not share personal or confidential data with third parties except where the data subject has provided explicit consent, the sharing is required under a client contract, CIA is required to disclose by law, or the sharing is with a subcontractor operating under a CIA Service Agreement.
De-identified and aggregated data may be used by CIA for sector-level learning and knowledge dissemination, internal capability development, and program evaluation reporting where individual identification is not possible.
Some CIA platforms store or process data outside Australia, including Beehiiv and Anthropic (Claude), which operate servers in the United States. Where cross-border transfers occur, CIA reviews provider privacy policies, uses data processing agreements where available, and limits the personal data shared with these platforms to what is strictly necessary.
| Data Type | Retention Period |
|---|---|
| Client contracts and MOUs | 7 years post-engagement |
| Personally identifiable evaluation data | 7 years post-project conclusion |
| Financial records and invoices | 7 years (ATO requirements) |
| Survey and interview recordings | Until transcribed and verified, then deleted |
| Her Algorithm / She Thinks survey and session data | Duration of program evaluation period; then de-identified or deleted |
| Newsletter subscriber data (Beehiiv) | Until unsubscribe request or account closure |
| Tally intake form submissions | 12 months post-submission or until project scoping concluded |
| Correspondence (project-related) | 7 years post-project |
A data breach occurs when personal information held by CIA is lost, accessed without authorisation, disclosed without consent, or altered or destroyed without CIA's knowledge. Under the Notifiable Data Breaches (NDB) scheme, CIA will contain the breach as quickly as practicable, assess notification obligations within 30 days, notify the OAIC and affected individuals where the serious harm threshold is met, and notify the client organisation immediately upon becoming aware of any breach involving their data.
Data subjects have the right to request access to personal information CIA holds about them, request correction of inaccurate information, request deletion subject to legal retention obligations, withdraw consent at any time, and make a complaint. Requests should be directed to hello@connectedimpactadvisory.com. CIA will respond within 30 days.
If unsatisfied with CIA's response, data subjects may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
This policy is reviewed annually or following a significant change in CIA's scope of operations, a confirmed data breach or near-miss incident, a legislative or regulatory change, or the introduction of a new data platform or AI tool.
| Role | Name | Date |
|---|---|---|
| Data Governance Lead / Founder | Belinda Hendrickson | June 2026 |