The Network Program is moving towards formalizing our data, security, and privacy standards to make strides towards more protection for people we interact with within and outside of the Network. Code for America is in the process of hiring a Privacy Manager who will help support this effort.
Items We Hope to Address
- How CfA uses Brigade and volunteer data
- How Brigades use Brigade and volunteer data
- Network program privacy & security best practices and templates
- Brigade account and data retention
- Volunteer data usage
- What are the limits to “solo experimentation” when a volunteer has access to program data?
- How do we define sensitive data, or data that gains increased sensitivity in aggregate?
- Where does open data become program data?
Note: This is not an exhaustive list
Policy on Brigade Accounts for Tools
One of the major items we’ll explicitly address in the Brigade MOU is how long the Network Team will retain Brigade accounts for tools/services we provide. Note that there will be exceptions, such as:
-
The Brigade has temporarily paused its activities but plans to resume within six months or is actively recruiting for leadership
-
The Brigade member has requested a 1-month extension to transition off a Brigade project or CfA account (e.g., the Brigade member has several accounts tied to their CfA email and needs to change the email addresses on said accounts, the Brigade member needs to transfer a Heroku project to a partner organization, etc.)
-
The Brigade project supported by an in-kind is still active and in use by its audience, and there is a plan for Network volunteers to maintain the project through the Projects Branch.
Account Type | Retention Period / When to Delete |
---|---|
Donorbox | A Brigade will be removed from Donorbox at least six months after the expiration of their last Brigade MOU or by request when the Brigade has formally expressed discontinuation of the group. |
Expensify Accounts | Expensify accounts are to be deleted when the associated Brigade has not been active for a full Brigade MOU cycle (since the last signed MOU). Expensify accounts are to be deleted immediately when the Expensify account user has received a ban from the Network or by request. |
Google Accounts | Google accounts are to be deleted when an account hasn’t been signed on for 12 months (1 year) and the associated Brigade has not been active for a full Brigade MOU cycle (since the last signed MOU). Google accounts are to be deleted immediately when the Google account user has received a ban from the Network or by request. |
Meetup | Meetup pages for Brigades are to be deleted when the associated Brigade has not been active for a full Brigade MOU cycle (since the last signed MOU) or the Brigade has formally expressed discontinuation of the group. The page is set to be deleted one year after the Brigade has formally expressed discontinuation. Deletion of the page will be canceled if there is interest (communicated to the Network team) to reboot the Brigade with new or past leadership. |
Namecheap | Namecheap domain subscriptions are to be canceled when the associated Brigade has not been active for a full Brigade MOU cycle (since the last signed MOU). Domains are to be canceled immediately by request when the Brigade has formally expressed discontinuation of the group. |
Other In-kinds (e.g. Heroku, Mapbox, Twilio) | Other in-kind support is to be discontinued when the associated Brigade has not been active for a full Brigade MOU cycle (since the last signed MOU). Access will be revoked immediately by request when the Brigade has confirmed that the in-kind resource is no longer needed, or when the Brigade has formally expressed discontinuation of the group. |
Prompts for Discussion
Share your thoughts in the comments section below.
-
What else do you hope can be addressed or clarified?
-
What are your thoughts about the retention policy on Brigade accounts for tools outlined in the table above?