Data Management Policy
The classification, ownership, access, retention, and disposal rules for Bread Breakers data.
Purpose and Scope
This policy applies to all Bread Breakers stakeholders and all personal, financial, operational, and public data assets.
Ownership and Responsibility
- Bread Breakers is accountable for classifying, protecting, and retaining its data.
- The Chair acts as Data Protection Officer and data custodian unless responsibility is formally delegated.
- Volunteers may access data only for authorised duties and must protect its confidentiality.
Classification
- Public: approved website content and de-identified ledger information.
- Internal: ordinary operating records without beneficiary-sensitive detail.
- Restricted: beneficiary, referrer, donor, payment, receipt, delivery, and authentication information.
Access and Disposal
Access follows least privilege and is reviewed when roles change. Restricted data must not be copied to unmanaged personal systems. Disposal must be secure and recorded where required.
