Use
“Purpose Limitation” (or only use for the reason that you told people)
The NHRI should be clear internally and in what they tell HDRs on why they are collecting personal
information and what they intend to do with it. NHRIs should avoid purpose or use creep, where
personal information is gradually used for purposes beyond the initial one without proper consent.
If some new opportunities arise to use the personal information, seek consent. The GDPR makes
exception for ‘compatible’ uses where you don’t need consent. This is usually statistical reporting,
archiving and certain research uses where there are no privacy implications. Where safeguards are
implemented such as de-identifying the information, this makes it more likely to be a use where you
don’t need consent.
Putting it into practice
An HRD had given you names and addresses of farmers in need of food
aid in their locality. You are later approached by a university to partner on a
research project about how to respond to floods in the same area. Before you
use the farmer details for that research project, you should get consent. You
may not be aware of all the facts or the implications for the farmers of this new
use of their information. The HRD may also not be in a position to know what
the implications are for everyone concerned so you generally shouldn’t rely
on reported consent from an intermediary.
Internal sharing and access
A risk to personal information can be that the data saved in the organisation’s electronic files (whether
saved locally or in cloud storage like Microsoft Sharepoint) is able to be accessed easily by anyone
within the NHRI – even people who may not have a genuine need to access it.
There are measures that can be taken to mitigate the risk of over-sharing internally.
Role-Specific Permissions: Set up permissions based on the roles and responsibilities of staff. For
example, only a small subset of staff may need access to HRD data. All other staff should not be given
access to the HRD folder. When a specific project or task is completed, ensure that any additional
access granted to various staff members for that specific project is revoked to avoid unnecessary
exposure.
For larger organisations, permissions can be made easier if files are classified by sensitivity – for
example common classifications would be public, internal, confidential, highly confidential. This would
allow permissions to be allocated by classification level.
Data Protection Guidelines for NHRIs Toolkit
12