Confidentiality Policy

Sensitivity
Public
Status
Approved
Person Responsible
IT / Operations Administrator
Category
Staff and Volunteers

Auckland Challenge Confidentiality Policy (2020)

Auckland Challenge is committed to maintaining the safety of its stakeholders, which includes the safekeeping of their information.

Interpretation

All references to files are to be assumed as referencing files containing confidential information only. Confidential information is defined as information that is not publicly available, information classed as need-to-know, or information that has been requested not to be shared.

Online Record Book (ORB)

Auckland Challenge makes use of the ‘Online Record Book’ provided by the International Award; Auckland Challenge is not responsible for the security of the back-end services. To maintain the security of ORB data, staff shall ensure they have logged out of the ORB when their device is unattended, and shall not permit third parties access to their ORB account.

Physical Information Technology

Auckland Challenge makes use of information technology to carry out day-to-day operations. To ensure the safety of data stored on this technology, staff shall: ensure all devices are password or PIN protected in compliance with the NIST password standard; ensure devices are not left unattended in a public place; ensure devices are digitally locked when unattended; and ensure all devices are securely encrypted. Auckland Challenge accepts that devices may be used for personal use, in which case the device is to be used only by authorised parties and only under supervision.

Online Services and Digital Files

Auckland Challenge makes use of online services and is not responsible for the security of the back-end services. All access to online services is expected to be password protected. Auckland Challenge accepts that internet browsers may record passwords; other, unencrypted methods of recording passwords (e.g. writing them down) are not accepted. All digital files not stored in a protected area (e.g. cloud / password-protected device) shall be individually password protected according to the NIST standard.

Email

Auckland Challenge uses email as a primary method of communication. All access to email services is expected to be password protected. Emails from stakeholders are not to be forwarded to or shared with third parties without consent from all involved parties. All files sent within emails that contain personal information are to be password protected.

Printed Information

It is accepted that Auckland Challenge staff will print documents and information. Printed documents containing confidential information are to be used only for the purpose they are intended, securely destroyed when no longer needed, prefixed with a coversheet hiding the information and marking it as confidential, and stored securely so as not to be easily read.

Information Relating to Persons Involved with Auckland Challenge Events

When running events, Auckland Challenge must print information about parties involved with the event in accordance with the health and safety policy. For safety reasons this information must be easily accessible throughout the event. Printed information is to be prefixed with a coversheet marking it as confidential and hiding the information, and the document is to be destroyed at the completion of the event.

Handling of Confidential Information

Auckland Challenge retains large collections of confidential information. This information is not to be shared with any third party outside Auckland Challenge staff without consent from all involved parties, is stored on a need-to-know basis, and is to be deleted and destroyed when no longer required.

Given Information

Auckland Challenge is regularly given information from third-party organisations to aid those parties. This information is to be stored securely according to the Physical IT and Email sections as appropriate, then destroyed or returned to that party.

Cessation and Distribution of Information

When information is no longer required it must be destroyed: a physical document must be shredded or burned, and a digital file must be deleted and cleared from all recycle bins.

Requested Destruction and Disclosure

If Auckland Challenge receives a request from a stakeholder for the destruction of their data, the data must be destroyed as soon as the request has been verified as authentic. If Auckland Challenge is requested to disclose information to a stakeholder: the information may only be disclosed to the stakeholder it relates to upon verification of their identity, or to the guardian of a stakeholder under 18 once the relationship has been confirmed.

Disclosure of Data

Auckland Challenge staff are not to disclose any information to any third party without the consent of the relevant stakeholder.

Document Control

Version Author Reviewed By Approved By Approval Date Effective Date Change Summary Approval Documents
2020 Auckland Challenge —

Review History

No reviews recorded yet.