| Version | v1 — March 2026 |
|---|---|
| Status | Approved by PRA Board — March 2026 |
| Policy Owner / Data Controller | David Mercer, Founder & Chair |
| Legal Framework | Swiss nFADP (in force 1 September 2023); EU GDPR 2016/679 (applied for EU data subjects); Botswana Data Protection Act 2024 (in force 14 January 2025); Namibia (best practice applied pending enactment of the Data Protection Bill) |
| Data Protection Officer | Board Chair (interim — to be reviewed when headcount exceeds 5 FTE) |
| Review Due | March 2027 |
PRA collects and processes personal data in the course of its governance, programme delivery, fundraising and partner engagement activities. This policy sets out how PRA handles that data lawfully, fairly and transparently in line with the Swiss Federal Act on Data Protection (nFADP), and in a manner compatible with the EU General Data Protection Regulation (GDPR) for any data subjects in EU member states.
This policy applies to: all personal data processed by PRA, regardless of format (digital or paper); all staff, NEDs, volunteers, interns and contractors who handle personal data on PRA's behalf; all processing activities carried out in Geneva, in Botswana, in Namibia, or by any PRA-authorised processor.
| Category of data | Purpose |
|---|---|
| NED & staff contact details, CVs, references | Governance, employment, appointment records |
| Partner and donor contact details | Relationship management, fundraising, reporting |
| Programme participant details (trainees, interns) | Enrolment, training records, impact reporting |
| Financial data (invoices, expense claims) | Accounting, audit compliance |
| Correspondence and meeting records | Governance, legal record-keeping |
| Website / communications analytics | Understanding audience reach |
PRA processes personal data in accordance with the following principles:
Data subjects have the following rights under nFADP and, where applicable, GDPR. Requests should be directed to the Data Protection Officer (Board Chair) and will be responded to within 30 days.
| Right of access | Individuals may request a copy of the personal data PRA holds about them. |
| Right to rectification | Individuals may request correction of inaccurate or incomplete data. |
| Right to erasure | Individuals may request deletion of their data where there is no legal basis for retention. |
| Right to restrict processing | Individuals may request that PRA limits how it uses their data in certain circumstances. |
| Right to data portability | Where processing is based on consent or contract, individuals may request their data in a portable format. |
| Right to object | Individuals may object to processing based on legitimate interests; PRA will cease unless it can demonstrate compelling grounds. |
| Right to withdraw consent | Where processing is based on consent, individuals may withdraw it at any time without detriment. |
PRA does not sell personal data. PRA may share data with:
| Category | Retention period |
|---|---|
| Staff / NED employment records | Duration of engagement + 7 years |
| Programme participant records | Duration of programme + 5 years |
| Financial records | 10 years (Swiss CO requirement) |
| Donor and partner correspondence | 7 years from last engagement |
| Board minutes and resolutions | Permanently (governance record) |
| Unsuccessful grant applications | 2 years |
| Website analytics | 13 months (rolling) |
| CCTV footage (if installed at campus) | 31 days unless relevant to an incident |
Data due for deletion is securely destroyed: digital data is permanently deleted and confirmed; paper records are shredded.
A data breach is any accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. If a breach is suspected or discovered:
To exercise your data rights or raise a data protection concern, contact:
David Mercer, Founder & Chair
Phoenix Resource Association, Geneva
+41 (0)22 539 46 97
david@phoenixresource.org