Data Protection Policy
DATA PROTECTION POLICY
Global NGO Alliance (GNA)
Effective Date: 06 July 2026
Last Updated: 03 August 2026
- Introduction
Welcome to Global NGO Alliance (GNA).
Global NGO Alliance recognizes that the protection of personal, organizational, and digital information is fundamental to maintaining public trust, transparency, accountability, and responsible governance.
This Data Protection Policy establishes the principles, standards, responsibilities, and safeguards adopted by Global NGO Alliance for the collection, processing, storage, protection, sharing, retention, and disposal of personal and organizational information collected through its official websites, membership platforms, NGO registration systems, CSR collaboration portals, award programmes, training platforms, digital verification systems, mobile applications, and all other official digital services.
The objective of this Policy is to ensure that information entrusted to Global NGO Alliance is handled lawfully, fairly, securely, transparently, and responsibly while supporting our mission of strengthening NGOs, charitable institutions, CSR organizations, educational institutions, volunteers, and development professionals worldwide.
This Policy should be read together with our Privacy Policy, Terms & Conditions, Cookie Policy, Disclaimer Policy, Refund Policy, and Copyright Policy.
By accessing or using any Global NGO Alliance platform, users acknowledge that they have read, understood, and accepted this Data Protection Policy.
- Scope of this Data Protection Policy
This Policy applies to every visitor, registered member, NGO, charitable trust, society, Section 8 company, CSR organization, educational institution, donor, volunteer, award applicant, researcher, consultant, contractor, vendor, employee, partner organization, and every other individual or legal entity using any service provided by Global NGO Alliance.
This Policy applies to information processed through:
- Official Websites
- Membership Portal
- NGO Registration Portal
- CSR Collaboration Platform
- Global NGO Directory
- Award Portal
- Digital GNA-ID System
- QR Code Verification Portal
- Learning Management System
- Resource Centre
- Help Centre
- Online Support Services
- Volunteer Management Platform
- Conference & Event Registration Systems
- Digital Certificate Verification
- Mobile Applications (where applicable)
- Future Digital Services introduced by Global NGO Alliance
This Policy applies irrespective of whether information is collected electronically, digitally, manually, or through other authorized means.
- Purpose of Data Protection
Global NGO Alliance is committed to protecting information in order to:
- Maintain User Trust.
- Protect Privacy.
- Ensure Secure Digital Operations.
- Prevent Unauthorized Access.
- Strengthen Cyber Security.
- Support Responsible Governance.
- Maintain Information Integrity.
- Comply with Applicable Laws.
- Improve Service Quality.
- Protect Organizational Reputation.
- Promote Ethical Information Management.
- Support International Collaboration.
The protection of information remains an essential component of our digital governance framework.
- Data Protection Principles
Global NGO Alliance processes information in accordance with the following core principles:
- Lawfulness
- Fairness
- Transparency
- Purpose Limitation
- Data Minimization
- Accuracy
- Integrity
- Confidentiality
- Accountability
- Security
- Responsible Processing
- Continuous Improvement
Every department, programme, employee, consultant, volunteer, technology partner, and authorized representative is expected to follow these principles while handling information.
- Categories of Information Protected
Global NGO Alliance protects a broad range of information, including but not limited to:
- Personal Information
- NGO Registration Information
- Membership Information
- CSR Organization Information
- Award Applications
- Volunteer Records
- Donor Information
- Event Registration Data
- Training Records
- Learning Progress
- Digital Certificates
- Digital GNA-ID Records
- QR Verification Records
- Financial Transaction Information
- Communication Records
- Uploaded Documents
- Research Materials
- Administrative Records
- Organizational Reports
- Digital Assets
- Website Usage Information
Appropriate safeguards are applied according to the nature and sensitivity of the information being processed.
- Data Classification
For effective protection, information processed by Global NGO Alliance may be classified into different categories based on its sensitivity and operational importance.
These classifications may include:
- Public Information
- Internal Information
- Confidential Information
- Restricted Information
- Highly Sensitive Information
Different levels of administrative, technical, and organizational protection may apply depending upon the classification assigned to specific information.
- Collection of Information
Global NGO Alliance collects information only for legitimate organizational purposes directly related to its services, programmes, digital platforms, legal obligations, operational requirements, and mission objectives.
Information may be collected through:
- Registration Forms
- Membership Applications
- NGO Registration Forms
- Award Applications
- Event Registration
- Volunteer Registration
- Online Forms
- Contact Forms
- Help Centre Requests
- Digital Verification Systems
- Email Communication
- Website Interaction
- Training Platforms
- Surveys
- Feedback Forms
- Customer Support
Only information reasonably necessary for the intended purpose shall be collected.
- Lawful Processing of Information
Global NGO Alliance processes information only where there is an appropriate legal or operational basis for doing so.
Information may be processed for purposes including:
- Membership Administration.
- NGO Verification.
- CSR Collaboration.
- Award Management.
- Event Administration.
- Volunteer Coordination.
- Certificate Generation.
- Digital Identity Verification.
- Legal Compliance.
- Financial Administration.
- Security Monitoring.
- Fraud Prevention.
- Customer Support.
- Website Administration.
- Research and Statistical Analysis.
- Organizational Development.
Information shall not be processed for purposes incompatible with the original purpose of collection unless otherwise permitted by applicable law.
- Data Accuracy
Global NGO Alliance strives to maintain information that is accurate, complete, relevant, and up to date.
Users are responsible for ensuring that the information they submit remains accurate and promptly notifying Global NGO Alliance of significant changes where applicable.
Reasonable efforts may be made to correct inaccurate information upon verification.
Maintaining accurate information helps improve service quality, operational efficiency, legal compliance, and user experience.
- Data Minimization
Global NGO Alliance follows the principle of collecting only the information reasonably necessary for legitimate organizational purposes.
We seek to avoid collecting excessive, irrelevant, or unnecessary personal information.
Where possible, information shall be limited to that required for:
- Registration
- Verification
- Communication
- Programme Administration
- Certificate Generation
- Membership Management
- Award Evaluation
- Event Coordination
- Security
- Legal Compliance
Data minimization reduces privacy risks while improving information security and responsible governance.
- Data Storage
Global NGO Alliance stores personal, organizational, operational, and digital information using secure systems designed to protect confidentiality, integrity, and availability.
Information may be stored on secure servers, cloud infrastructure, encrypted databases, authorized storage systems, backup repositories, and other approved technology platforms used for organizational operations.
Reasonable administrative, technical, and organizational safeguards are implemented to reduce the risk of unauthorized access, accidental disclosure, unauthorized modification, data loss, or destruction.
Only authorized personnel are permitted to access stored information based on operational responsibilities and legitimate organizational requirements.
- Data Encryption
Global NGO Alliance recognizes encryption as one of the essential safeguards for protecting sensitive information.
Appropriate encryption technologies may be implemented to protect information during storage, transmission, authentication, digital verification, payment processing support, secure communications, and user access.
Encryption may be applied to:
- Personal Information
- Membership Records
- NGO Registration Data
- Award Applications
- Digital Certificates
- Authentication Credentials
- Login Sessions
- QR Verification Data
- Financial Records
- Administrative Information
- Communication Records
Encryption standards may be periodically reviewed and upgraded to reflect technological developments and evolving security requirements.
- Access Control
Access to information maintained by Global NGO Alliance is governed by the principle of least privilege, meaning users receive only the level of access reasonably necessary to perform their authorized responsibilities.
Access rights may be assigned according to:
- Job Responsibilities
- Department
- Organizational Role
- Security Classification
- Operational Requirements
- Legal Obligations
Access permissions are reviewed periodically and may be modified, restricted, suspended, or revoked whenever necessary to maintain security and compliance.
Unauthorized attempts to access restricted information are strictly prohibited.
- Authentication and Authorization
Global NGO Alliance implements authentication and authorization controls to verify the identity of users before granting access to protected systems.
Security measures may include:
- Secure Login Credentials
- Strong Password Requirements
- Multi-Factor Authentication (where implemented)
- Session Management
- Role-Based Permissions
- Account Verification
- Password Reset Procedures
- Secure Authentication Tokens
Users remain responsible for maintaining the confidentiality of their login credentials and immediately reporting any suspected unauthorized account activity.
- Data Sharing
Global NGO Alliance does not sell, lease, or commercially trade personal information.
Information may be shared only where necessary for legitimate organizational purposes, legal obligations, or user-authorized services.
Information sharing may occur with:
- Authorized Service Providers
- Technology Vendors
- Payment Service Providers
- Government Authorities where legally required
- Law Enforcement Agencies where required by law
- Auditors
- Legal Advisors
- Professional Consultants
- Partner Organizations where appropriate authorization exists
Information sharing is conducted only to the extent reasonably necessary for the intended purpose.
- Third-Party Data Processors
Global NGO Alliance may engage carefully selected third-party service providers to support website hosting, cloud infrastructure, payment processing, analytics, customer support, email communications, security monitoring, learning platforms, and other operational services.
Where third-party processors handle information on behalf of Global NGO Alliance, reasonable efforts are made to ensure that such providers maintain appropriate confidentiality, security, and data protection standards.
Third-party processors are expected to process information only for authorized purposes and in accordance with applicable contractual obligations and legal requirements.
- International Data Transfers
As Global NGO Alliance collaborates with organizations, institutions, volunteers, researchers, and development professionals internationally, information may occasionally be processed or accessed from different jurisdictions.
Where cross-border data transfers occur, Global NGO Alliance endeavors to implement appropriate safeguards to protect information and comply with applicable legal requirements.
International transfers are undertaken only where reasonably necessary for organizational operations, digital services, or international collaboration.
- Data Retention
Global NGO Alliance retains information only for as long as reasonably necessary to fulfill the purposes for which it was collected or as required by applicable law.
Retention periods may depend upon:
- Membership Status
- NGO Registration Requirements
- Award Administration
- Financial Reporting
- Legal Compliance
- Tax Requirements
- Audit Obligations
- Certificate Verification
- Historical Organizational Records
- Operational Requirements
When information is no longer required, it may be securely deleted, anonymized, archived, or otherwise disposed of in accordance with applicable policies and legal obligations.
- Backup and Disaster Recovery
To support business continuity and protect organizational information, Global NGO Alliance may maintain secure backup systems and disaster recovery procedures.
Backup measures may include:
- Automated Backups
- Encrypted Backups
- Offsite Storage
- Cloud Backup Services
- Disaster Recovery Planning
- Business Continuity Planning
- System Restoration Procedures
Backup systems are intended to reduce the impact of accidental data loss, technical failures, cybersecurity incidents, or unforeseen operational disruptions.
- Cyber Security Measures
Global NGO Alliance continuously works to strengthen the security of its digital platforms through appropriate technical and organizational safeguards.
Security measures may include:
- Secure HTTPS Communication
- SSL/TLS Encryption
- Firewall Protection
- Malware Detection
- Intrusion Detection Systems
- Security Monitoring
- Vulnerability Assessments
- Software Updates
- Patch Management
- Secure Server Configuration
- Access Logging
- Password Protection
- Role-Based Security Controls
Security practices are reviewed periodically to address emerging cyber threats and technological developments.
- Data Breach Response
Global NGO Alliance maintains procedures for responding to suspected or confirmed information security incidents.
Where a potential data breach is identified, reasonable steps may include:
- Incident Identification
- Initial Risk Assessment
- Containment Measures
- Technical Investigation
- Internal Reporting
- Corrective Actions
- Security Improvements
- User Notification where legally required
- Regulatory Notification where applicable
- Documentation of the Incident
Each incident is reviewed individually to determine the appropriate response based on the nature, scope, and potential impact of the event.
- Security Monitoring
Global NGO Alliance may monitor its digital infrastructure to maintain security, system integrity, operational stability, and compliance.
Monitoring activities may include:
- Login Monitoring
- Access Logs
- System Performance Monitoring
- Security Event Monitoring
- Network Activity Monitoring
- Fraud Detection
- Malware Monitoring
- Authentication Monitoring
- Error Logging
- System Auditing
Monitoring is conducted solely for legitimate organizational purposes including security, fraud prevention, operational management, and legal compliance.
- Confidentiality Obligations
Employees, consultants, volunteers, contractors, technology providers, and other authorized persons who have access to protected information are expected to maintain appropriate confidentiality.
Such individuals may be required to comply with confidentiality obligations, organizational policies, contractual commitments, and applicable legal requirements relating to the handling of sensitive information.
Unauthorized disclosure or misuse of confidential information may result in disciplinary action, termination of access, contractual remedies, or other appropriate legal action.
- Rights of Data Subjects
Global NGO Alliance recognizes that individuals whose personal information is processed may have certain rights under applicable laws.
Subject to legal, regulatory, contractual, and operational requirements, users may request access to, correction of, updating of, restriction of, or deletion of certain personal information maintained by Global NGO Alliance.
The exercise of these rights may require reasonable identity verification to protect information against unauthorized disclosure.
Global NGO Alliance shall review such requests in accordance with applicable laws and organizational procedures.
- Right to Access Information
Users may request confirmation regarding whether Global NGO Alliance processes their personal information.
Where legally permitted, users may request access to certain categories of information relating to:
- Membership Records
- NGO Registration Information
- Digital GNA-ID
- Award Applications
- Training Records
- Event Registrations
- Volunteer Information
- Communication History
- Certificates
- Account Information
Access requests shall be reviewed after appropriate identity verification and may be subject to reasonable legal or administrative limitations.
- Right to Correction
Global NGO Alliance strives to maintain accurate and up-to-date information.
Users who believe that their personal information is inaccurate, incomplete, or outdated may request correction or updating of such information.
Reasonable supporting documentation may be requested where necessary to verify the requested correction.
Approved corrections shall be reflected within organizational records as appropriate.
- Right to Deletion
Users may request deletion of personal information where deletion is legally permissible and operationally appropriate.
However, Global NGO Alliance may retain certain information where required for:
- Legal Compliance
- Financial Reporting
- Tax Obligations
- Audit Requirements
- Certificate Verification
- Fraud Prevention
- Security Investigations
- Historical Organizational Records
- Dispute Resolution
- Contractual Obligations
Where complete deletion is not legally or operationally possible, information may instead be restricted, archived, anonymized, or retained in accordance with applicable legal requirements.
- Withdrawal of Consent
Where information processing is based upon user consent, users may withdraw such consent at any time by contacting Global NGO Alliance through the official communication channels.
Withdrawal of consent shall not affect the lawfulness of processing conducted before the withdrawal became effective.
Certain services may no longer be available following withdrawal of consent where such processing is necessary for service delivery.
- Data Portability
Where applicable and legally required, users may request that certain personal information be provided in a commonly used electronic format.
Such requests shall be evaluated after identity verification and subject to applicable legal, technical, security, and operational considerations.
Global NGO Alliance reserves the right to refuse requests that could adversely affect the rights of other individuals or compromise organizational security.
- Compliance and Accountability
Global NGO Alliance is committed to maintaining a culture of accountability regarding the protection of information.
Reasonable administrative procedures, operational controls, internal reviews, staff awareness programmes, technology safeguards, and organizational governance practices are maintained to support compliance with this Policy.
Employees, consultants, volunteers, contractors, vendors, and authorized representatives handling protected information are expected to comply with applicable confidentiality obligations, organizational policies, and legal requirements.
- Policy Updates
Global NGO Alliance reserves the right to amend, revise, replace, or update this Data Protection Policy whenever necessary to reflect:
- Legal Developments
- Regulatory Requirements
- Technological Advancements
- Cyber Security Improvements
- Operational Changes
- Organizational Growth
- New Digital Services
- Industry Best Practices
- User Feedback
Updated versions shall become effective upon publication on the official Global NGO Alliance websites unless otherwise specified.
Users are encouraged to periodically review this Policy to remain informed of any updates.
Continued use of Global NGO Alliance platforms after publication of revisions constitutes acceptance of the updated Policy to the extent permitted by applicable law.
- Governing Law
This Data Protection Policy shall be interpreted and governed in accordance with the applicable laws of the Republic of India.
Nothing contained in this Policy shall restrict any mandatory legal rights available under applicable privacy, consumer protection, information technology, or other relevant legislation.
Users located outside India remain responsible for complying with the data protection laws applicable within their own jurisdiction.
- Contact Information
Questions, requests, complaints, or concerns relating to this Data Protection Policy may be submitted through the official communication channels available on the Global NGO Alliance websites.
Official Websites
- https://globalngoalliance.com/
- https://globalngoalliance.in/
- https://globalngoalliance.org/
- https://globalngoalliance.online/
Users are encouraged to submit requests through the official Contact Us, Help Centre, or Support Ticket sections available on the websites.
- Severability
If any provision of this Data Protection Policy is determined to be invalid, unlawful, or unenforceable by a court of competent jurisdiction or authorized regulatory authority, such provision shall be considered severable from the remaining provisions.
The remaining provisions shall continue in full force and effect to the maximum extent permitted by applicable law.
- Entire Policy
This Data Protection Policy should be read together with the following official Global NGO Alliance policies:
- Privacy Policy
- Terms & Conditions
- Cookie Policy
- Disclaimer Policy
- Refund Policy
- Copyright Policy
- Membership Policy (where applicable)
- NGO Membership Policy (where applicable)
- Award Policy (where applicable)
Together, these policies establish the legal, administrative, and operational framework governing the collection, protection, processing, and responsible management of information across all Global NGO Alliance digital platforms and services.
- Official Data Protection Declaration
Global NGO Alliance is committed to protecting the confidentiality, integrity, and availability of information entrusted to the organization.
We believe that responsible information management is essential for maintaining public confidence, strengthening institutional governance, supporting international collaboration, and promoting sustainable social development.
Accordingly, Global NGO Alliance continually reviews and improves its information protection practices through appropriate administrative, organizational, and technical safeguards while encouraging transparency, accountability, ethical leadership, and responsible digital governance.
- Official Data Protection Statement
Global NGO Alliance is committed to protecting personal, organizational, and digital information through responsible governance, secure technology, transparent practices, and continuous improvement. We process information only for legitimate organizational purposes, implement appropriate safeguards to protect confidentiality and integrity, and strive to maintain compliance with applicable legal requirements. By using our official platforms, users acknowledge this Data Protection Policy and support our shared commitment to privacy, security, accountability, and responsible information management.
- Data Protection Policy Tagline
“Protecting Information. Preserving Trust. Empowering Collaboration.”
Privacy • Security • Accountability • Responsible Governance