Legal

Data Governance Policy

Version
1.2
Effective Date
June 2026
Review Date
June 2027
Status
Active
Policy Owner
Belinda Hendrickson, Founder
ABN
62 854 990 387

1. Purpose and Scope

Connected Impact Advisory (CIA) is an independent monitoring, evaluation, and learning (MEL) consultancy. In the course of delivering evaluation design, program strategy, capacity building, and community engagement services, CIA collects, manages, and analyses data on behalf of client organisations, research participants, and program beneficiaries.

This policy establishes the principles, roles, and procedures that govern how CIA handles data responsibly across the full data lifecycle, from collection and storage through to use, sharing, and disposal.

This policy applies to:

2. Legislative and Framework Alignment

2.1 Privacy and Data Law

2.2 Evaluation and Research Standards

2.3 Sector-Specific Obligations

Requirements of any funding body or government agency under whose grant or contract CIA operates.

2.4 State and Territory Legislation

As a private sector consultancy, CIA is primarily bound by the federal Privacy Act 1988 (Cth) and APPs. State and territory legislation becomes relevant where CIA is engaged by a state or territory government agency, or where CIA handles personal health information in the private sector. CIA monitors legislative developments including anticipated federal Privacy Act reform during 2026.

3. Key Definitions

TermDefinition
Personal informationInformation or an opinion about an identified individual, or an individual who is reasonably identifiable, whether true or not.
Sensitive informationA subset of personal information including health, racial or ethnic origin, political opinion, religious belief, sexual orientation, and financial counselling data.
De-identified dataData from which all personal identifiers have been removed such that re-identification is not reasonably practicable.
Data subjectAny individual whose personal information is collected or processed by CIA in connection with an evaluation, program, survey, or community engagement activity.
Data controllerThe entity responsible for determining the purposes and means of processing personal data — in most CIA projects, this is the client organisation.
Data processorAn entity that processes data on behalf of the controller — CIA frequently acts as data processor in client-commissioned evaluations.
ConsentFreely given, specific, informed, and unambiguous agreement by a data subject to the collection and use of their personal information for a stated purpose.

4. Data Governance Principles

4.1 Person-Centred Practice

Data collection and use must serve the people it concerns. CIA centres the needs, rights, and dignity of data subjects above operational convenience. Where there is tension between data utility and participant welfare, participant welfare takes precedence.

4.2 Purpose Limitation

Data is collected only for clearly defined evaluation, learning, or program improvement purposes. Data collected for one purpose will not be repurposed for unrelated activities without explicit consent from the data subject or written agreement with the client organisation.

4.3 Data Minimisation

CIA collects only the data necessary to answer the evaluation questions or fulfil the agreed scope of work. Collection instruments are designed with minimisation in mind.

4.4 Accuracy and Integrity

CIA takes reasonable steps to ensure that data is accurate, complete, and up to date at the point of use. Findings presented to clients or published externally are based on verified, accurately recorded data.

4.5 Storage Limitation

Personal and sensitive data is retained only for as long as necessary to fulfil the stated purpose. Retention periods are specified at the point of project planning and in applicable Service Agreements.

4.6 Security

CIA implements appropriate technical and organisational measures to protect data against loss, unauthorised access, modification, or disclosure. Security standards are proportionate to the sensitivity of the data held.

4.7 Transparency and Accountability

CIA is transparent with data subjects and client organisations about what data is collected, why, how it is used, and who can access it. The Data Governance Lead is accountable for maintaining this policy and responding to data-related concerns.

5. Roles and Responsibilities

RoleResponsibility
Data Governance LeadOwns this policy; reviews annually; responds to data incidents; authorises third-party data sharing.
Contracted Evaluators / SubcontractorsComply with this policy and the relevant CIA Service Agreement; complete privacy induction prior to project commencement.
Clients / Partner OrganisationsProvide accurate data under agreed data sharing arrangements; notify CIA of any changes to consent status.

6. Data Classification

ClassificationDescriptionExamples
Sensitive PersonalData that could cause harm if disclosed; highest protection required.Health information, financial counselling records, domestic violence disclosures
PersonalIdentifiable information about individuals that does not meet the sensitive threshold.Names, contact details, employment status, program participation records
Confidential OrganisationalClient, partner, or operational data not intended for public release.Evaluation findings in draft, contract terms, unpublished program data
InternalCIA operational information with limited sensitivity.Project schedules, internal process documents
PublicInformation approved for public release.Published evaluation reports, CIA website content, Her Algorithm toolkit materials

7. Data Collection and Consent

7.1 Informed Consent

CIA obtains informed consent prior to collecting personal or sensitive information from individual data subjects. Consent processes are written wherever practicable, plain-language and jargon-free, specific to the purposes for which data will be used, and adapted for the literacy, language, and accessibility needs of participants.

7.2 Secondary Data

Where CIA works with data collected by client organisations, CIA confirms with the client that original collection met consent requirements sufficient for the intended evaluation use. CIA will not process secondary data where consent status is uncertain without first seeking legal or ethical advice.

7.3 Limits on Collection

CIA does not collect biometric data, location tracking data, or sensitive financial account information in the course of evaluation work. Where engagement with highly vulnerable populations is required, CIA applies additional safeguards and consults AES ethical guidelines before instrument finalisation.

8. Data Storage and Security

8.1 Approved Storage Platforms

CIA stores data using platforms that meet Australian privacy standards. Two-factor authentication is enabled on all primary platforms. Approved platforms include Google Workspace, Netlify, Beehiiv, and survey platforms including KoBoToolbox, SurveyCTO, and Google Forms.

Data is not stored in unencrypted email attachments for extended periods, personal social media platforms, shared public drives without access controls, or AI tool chat interfaces where data persistence is not under CIA's control.

8.2 Access Controls

Access to personal and sensitive data is restricted to personnel with a demonstrable need to access it for the purposes of the project. Subcontractors are granted access only to the data required for their specific scope of work.

8.3 AI-Assisted Tools

AI Transparency Statement

CIA uses AI-assisted tools (including Claude by Anthropic) to support tasks such as drafting reports, synthesising data, coding qualitative data, and developing evaluation instruments. No identifiable personal data or sensitive client data is inputted into AI tools without explicit consent. Sensitive personal information is not entered into AI tools under any circumstances. All AI-generated outputs are reviewed and validated before delivery. AI is used as a drafting and analysis aid; all professional judgements remain human-led.

9. Data Sharing and Third Parties

CIA does not share personal or confidential data with third parties except where the data subject has provided explicit consent, the sharing is required under a client contract, CIA is required to disclose by law, or the sharing is with a subcontractor operating under a CIA Service Agreement.

9.1 De-Identified and Aggregated Data

De-identified and aggregated data may be used by CIA for sector-level learning and knowledge dissemination, internal capability development, and program evaluation reporting where individual identification is not possible.

9.2 Cross-Border Data Transfers

Some CIA platforms store or process data outside Australia, including Beehiiv and Anthropic (Claude), which operate servers in the United States. Where cross-border transfers occur, CIA reviews provider privacy policies, uses data processing agreements where available, and limits the personal data shared with these platforms to what is strictly necessary.

10. Data Retention and Disposal

Data TypeRetention Period
Client contracts and MOUs7 years post-engagement
Personally identifiable evaluation data7 years post-project conclusion
Financial records and invoices7 years (ATO requirements)
Survey and interview recordingsUntil transcribed and verified, then deleted
Her Algorithm / She Thinks survey and session dataDuration of program evaluation period; then de-identified or deleted
Newsletter subscriber data (Beehiiv)Until unsubscribe request or account closure
Tally intake form submissions12 months post-submission or until project scoping concluded
Correspondence (project-related)7 years post-project

11. Data Breach Response

A data breach occurs when personal information held by CIA is lost, accessed without authorisation, disclosed without consent, or altered or destroyed without CIA's knowledge. Under the Notifiable Data Breaches (NDB) scheme, CIA will contain the breach as quickly as practicable, assess notification obligations within 30 days, notify the OAIC and affected individuals where the serious harm threshold is met, and notify the client organisation immediately upon becoming aware of any breach involving their data.

12. Individual Rights and Requests

Data subjects have the right to request access to personal information CIA holds about them, request correction of inaccurate information, request deletion subject to legal retention obligations, withdraw consent at any time, and make a complaint. Requests should be directed to hello@connectedimpactadvisory.com. CIA will respond within 30 days.

If unsatisfied with CIA's response, data subjects may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.

13. Policy Review and Maintenance

This policy is reviewed annually or following a significant change in CIA's scope of operations, a confirmed data breach or near-miss incident, a legislative or regulatory change, or the introduction of a new data platform or AI tool.

14. Policy Approval

RoleNameDate
Data Governance Lead / FounderBelinda HendricksonJune 2026