Data Minimization and Privacy Principles
Collect only information that is necessary to assess and resolve the incident. Personal data should be limited to what is required for investigation, with justification for any additional data requests.
Access and Disclosure Controls
Implement role-based access controls and ensure that information is only shared with individuals who have a legitimate need. External disclosures, if any, should follow legal requirements and governance-approved procedures.
Confidentiality of Parties
Maintain confidentiality for reporters, witnesses, and subjects. Consider anonymized summaries when presenting to non-technical audiences within governance meetings, while preserving factual accuracy.
Retention and Destruction
Define retention periods for investigation records and establish secure destruction processes when data is no longer required, in alignment with policy and legal obligations.
Governance in Practice
Privacy safeguards are embedded in all stages of incident handling, from intake to remediation, to uphold trust and regulatory compliance within the Diversity & Harassment program.