Phoenix Resource Association

Data Protection Policy

Swiss nFADP-aligned | GDPR-compatible  ·  Version 1 — March 2026
Versionv1 — March 2026
StatusApproved by PRA Board — March 2026
Policy Owner / Data ControllerDavid Mercer, Founder & Chair
Legal FrameworkSwiss nFADP (in force 1 September 2023); EU GDPR 2016/679 (applied for EU data subjects); Botswana Data Protection Act 2024 (in force 14 January 2025); Namibia (best practice applied pending enactment of the Data Protection Bill)
Data Protection OfficerBoard Chair (interim — to be reviewed when headcount exceeds 5 FTE)
Review DueMarch 2027

1. Purpose & Scope

PRA collects and processes personal data in the course of its governance, programme delivery, fundraising and partner engagement activities. This policy sets out how PRA handles that data lawfully, fairly and transparently in line with the Swiss Federal Act on Data Protection (nFADP), and in a manner compatible with the EU General Data Protection Regulation (GDPR) for any data subjects in EU member states.

This policy applies to: all personal data processed by PRA, regardless of format (digital or paper); all staff, NEDs, volunteers, interns and contractors who handle personal data on PRA's behalf; all processing activities carried out in Geneva, in Botswana, in Namibia, or by any PRA-authorised processor.

2. Data We Hold and Why

Category of dataPurpose
NED & staff contact details, CVs, referencesGovernance, employment, appointment records
Partner and donor contact detailsRelationship management, fundraising, reporting
Programme participant details (trainees, interns)Enrolment, training records, impact reporting
Financial data (invoices, expense claims)Accounting, audit compliance
Correspondence and meeting recordsGovernance, legal record-keeping
Website / communications analyticsUnderstanding audience reach

3. Data Protection Principles

PRA processes personal data in accordance with the following principles:

4. Individual Rights

Data subjects have the following rights under nFADP and, where applicable, GDPR. Requests should be directed to the Data Protection Officer (Board Chair) and will be responded to within 30 days.

Right of accessIndividuals may request a copy of the personal data PRA holds about them.
Right to rectificationIndividuals may request correction of inaccurate or incomplete data.
Right to erasureIndividuals may request deletion of their data where there is no legal basis for retention.
Right to restrict processingIndividuals may request that PRA limits how it uses their data in certain circumstances.
Right to data portabilityWhere processing is based on consent or contract, individuals may request their data in a portable format.
Right to objectIndividuals may object to processing based on legitimate interests; PRA will cease unless it can demonstrate compelling grounds.
Right to withdraw consentWhere processing is based on consent, individuals may withdraw it at any time without detriment.

5. Data Sharing & Third Parties

PRA does not sell personal data. PRA may share data with:

International transfers. PRA's headquarters is in Geneva (Switzerland), which is recognised by the EU as providing adequate data protection. Where data is transferred to Botswana or Namibia for programme purposes, PRA applies appropriate contractual safeguards (standard contractual clauses where required) and limits transfers to what is operationally necessary.

6. Retention Periods

CategoryRetention period
Staff / NED employment recordsDuration of engagement + 7 years
Programme participant recordsDuration of programme + 5 years
Financial records10 years (Swiss CO requirement)
Donor and partner correspondence7 years from last engagement
Board minutes and resolutionsPermanently (governance record)
Unsuccessful grant applications2 years
Website analytics13 months (rolling)
CCTV footage (if installed at campus)31 days unless relevant to an incident

Data due for deletion is securely destroyed: digital data is permanently deleted and confirmed; paper records are shredded.

7. Security Measures

8. Data Breaches

A data breach is any accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. If a breach is suspected or discovered:

9. Monitoring & Review

Contact

To exercise your data rights or raise a data protection concern, contact:

David Mercer, Founder & Chair
Phoenix Resource Association, Geneva
+41 (0)22 539 46 97
david@phoenixresource.org