top of page
DGB Privacy & Stewardship Policy
Applies to: All employees, contractors, and third-party partners of DGB Global.
1. Introduction
DGB Global is committed to the ethical, secure, and lawful management of personal, confidential, and client information. This Privacy & Data Stewardship Policy outlines how we collect, use, store, protect, and dispose of data across our operations in compliance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
This policy applies to all employees, contractors, and third-party partners of DGB Global, and governs data stewardship across the full lifecycle of our consultancy services, from client commencement through to campaign or program completion and data destruction.
For technical and system-level security measures, refer to the DGB Cyber Security Policy.
2. Definitions
Personal Information: Information or opinion that identifies an individual (e.g. name, contact details, health or employment records).
Confidential Information: Any non-public information provided by a client or generated during a campaign or program that holds commercial, reputational, or legal sensitivity.
Eligible Data Breach: As defined in Part IIIC of the Privacy Act—unauthorised access, disclosure, or loss likely to cause serious harm.
3. Data Collection and Use
DGB Global collects personal and confidential information to:
-
Deliver fundraising consultancy services including comprehensive and capital campaigns, and major donor & bequest programs
-
Communicate with clients, donors and stakeholders
-
Manage internal operations and staffing
-
Meet legal and contractual obligations.
We collect data directly via emails, meetings, digital platforms, surveys, and through documents shared by clients. We may also receive data from publicly available sources or third parties.
DGB Global only collects or manages donor personal data for current clients and only with their express permission.
4. Data Access and Confidentiality
-
Access to client and personal data is restricted to authorised DGB staff involved in delivery of consultant services.
-
All team members are required to maintain strict confidentiality and comply with access protocols.
-
DGB does not disclose, duplicate, or retain confidential client information beyond the campaign term without written consent.
Third-party subcontractors are required to comply with equivalent data and privacy obligations.
5. Storage and Security
DGB Global stores data using secure, encrypted cloud-based infrastructure (Google Workspace) and local systems protected by two-factor authentication and industry-standard safeguards.
Information is classified by sensitivity (Red, Green, Black) and subject to clearance-based access controls. For technical details, see the DGB Cyber Security Policy.
6. Data Retention and Destruction
We retain:
-
Client-facing project documentation for the duration of the client engagement
-
Financial and contractual records for a minimum of 7 years (as required by law)
-
DGB developed methodologies, frameworks, and benchmarking tools (as Background IP).
At the conclusion of a campaign or program, DGB:
-
Transfers agreed data to the client via a secure folder (within a 14 business day access window)
-
Deletes donor data, brand assets, and confidential client IP from our systems
-
Confirms data deletion in writing within 10 business days.
7. Working with Clients
DGB respects and complies with all client contractual requirements relating to privacy, confidentiality, and intellectual property. Specifically:
-
No data is used for training or enhancing AI systems
-
All confidential or personal data remains within Australia (data sovereignty)
-
Any subcontractor used must meet or exceed these same requirements
We will not disclose or transfer client information to any third party without prior written consent.
8. Eligible Data Breach Notification
In accordance with Part IIIC of the Privacy Act:
8.1 Notification of Suspected Breach
DGB will notify the client as soon as practicable—and in any event within 1 business day—if it suspects an eligible data breach involving the client's information.
-
DGB Cyber Security Procedure & Framework
-
DGB Cyber Security Checklist
-
Cyber Security Incident Response Plan.
8.2 Assessment
DGB will undertake a reasonable and expeditious assessment within 2 business days to determine if a breach has occurred. This includes:
-
A description of the incident
-
The types of personal or confidential information involved
-
An evaluation of the risk of serious harm
-
Steps taken to contain or remedy the breach.
8.3 If a Breach is Confirmed
DGB will:
-
Assist the client to notify the Office of the Australian Information Commissioner (OAIC) and affected individuals
-
Cooperate in containment, public messaging, and investigation
-
Not notify any external party without client consent.
8.4 Recordkeeping
DGB will:
-
Maintain records of all incidents, assessments, and notifications
-
Permit client audits to verify compliance.
For technical breach response, see the Cyber Breach Plan in the DGB Cyber Security Policy.
9. Data Stewardship Responsibilities
-
Managing Director: Overall accountability
-
Campaign Lead & Operations Manager: Oversight of project-specific data compliance
-
Cyber Security Officer: Oversight of system-level controls, breach monitoring, and training.
All staff are expected to:
-
Familiarise themselves with this policy
-
Apply access and confidentiality protocols
-
Complete annual data and cyber security training.
10. Policy Governance
-
This policy is reviewed by the DGB SLT annually or as required due to legal, regulatory, or operational changes
-
The policy is maintained in alignment with the DGB Cyber Security Policy and other internal frameworks.
DGB Global
info@dgbgroup.com.au
0485 976 526
www.dgbglobal.com.au
bottom of page