Privacy Policy

1. Purpose

This Information Security and Privacy Policy establishes principles and practices to safeguard sensitive information handled by the Board of Directors of Alliance for Community Media — West Region (“the Organization”). Although the Organization has no employees and owns no physical property, it may handle confidential, personal, or proprietary information that requires protection.

2. Scope

This policy applies to all members of the Board of Directors (“Board Members”) and any volunteers or third parties who may be granted access to Organization information.

3. Guiding Principles

The Organization is committed to:

  • Protecting the confidentiality, integrity, and availability of its information
  • Respecting the privacy of individuals whose information may be collected or shared
  • Minimizing the collection and retention of personal information
  • Using reasonable safeguards appropriate to the Organization’s size and activities

4. Types of Information

The Organization may handle:

  • Confidential Board Information: meeting materials, strategic plans, internal communications
  • Personal Information: names, contact details, or other identifying information of donors, partners, or stakeholders 
  • Financial Information: budgets, banking details, or donation records

5. Data Collection and Use

  • Only collect information necessary for legitimate organizational purposes
  • Use information solely for purposes consistent with the Organization’s mission
  • Do not sell, rent, or share personal information except as required by law or with consent

6. Data Storage, Transmission and Retention

Board Members are responsible for safeguarding information:

  • Use password-protected devices and accounts
  • Enable multi-factor authentication where available
  • Store documents in secure, reputable cloud services or encrypted storage
  • Avoid accessing sensitive information over unsecured public networks
  • Do not store sensitive information on shared or public computers
  • Share sensitive information only with authorized individuals
  • Use secure transmission methods (e.g., encrypted email, password-protected files)
  • Verify recipient identity prior to sharing personal or confidential information
  • Retain information only as long as necessary for legal or operational purposes
  • Periodically review and delete outdated or unnecessary records
  • Protect against unauthorized access while disposing of data (e.g., secure deletion or shredding)

7. Incident Response

In the event of a suspected data breach or unauthorized disclosure:

  • Notify the Board President (or designated officer) promptly
  • Take reasonable steps to contain and assess the issue
  • Determine whether notification to affected individuals or authorities is required
  • If applicable, notify affected individuals without unreasonable delay, including the nature of the breach and recommended protective steps
  • Document the incident and actions taken

8. Third-Party Services

When using third-party tools (e.g., email platforms, cloud storage):

  • Select reputable providers with appropriate security practices
  • Limit data shared with third parties to what is necessary
  • Review privacy settings and terms of service where feasible

9. Policy Review and Updates

This policy shall be reviewed yearly by the Board and updated as needed to reflect changes in technology, legal requirements, or organizational practices. 

10. Acknowledgment

Board Members agree to adhere to this policy and to exercise reasonable care in protecting the Organization’s information.