Privacy Policy
1. Introduction
The Massachusetts Immigrant and Refugee Advocacy Coalition (“MIRA”) is committed to protecting the personal and organizational data of its employees, clients, members, donors, volunteers, and other stakeholders. This includes, but is not limited to, donor information such as contact details, donation history, and financial or payment information processed in connection with contributions. This policy sets out MIRA’s approach to ensuring respect for the privacy of all stakeholders and compliance with relevant laws and regulations regarding the safe documentation of personal and organizational information, including §201 CMR17.00.
2. Purpose
This Data Privacy Policy is intended to outline MIRA’s commitment to maintaining any personal data in a lawful, fair, and transparent manner, including protecting donor information to maintain trust through secure and responsible practices. This policy applies to all employees, contractors, and third-party vendors who process personal data on behalf of MIRA.
3. Scope
This policy applies to personal data collected and/or processed by MIRA, including data related to employees, clients, donors, volunteers, and other stakeholders.This includes donor-related data such as contribution records, billing information, and any payment data processed through third-party platforms. It covers data collected, stored, processed, transmitted, and deleted by MIRA, both electronically and on paper.
4. Principles:
MIRA adheres to the following principles of data protection:
- Lawfulness, Fairness, and Transparency: Personal data shall be processed in a lawful, fair, and transparent manner.
- Purpose Limitation: Personal data shall be collected for specific, explicit, and legitimate purposes and not further processed in a manner that is incompatible with those purposes.
- Data Minimization: Personal data shall be adequate, relevant, and limited to what is reasonably expected to be necessary for the purposes for which it is processed.
- Accuracy: Personal data shall be accurate and kept up to date where necessary.
- Storage Limitations: Personal data shall be kept in a form that permits identification of data subjects for no longer than necessary for the purposes for which the data is processed. All personal data shall be disposed of in accordance with MIRA’s data retention policy.
- Integrity and Confidentiality: Personal data shall be processed in a manner that ensures appropriate security, including protection against unauthorized or unlawful processing, accidental loss, destruction, or damage using appropriate technical and organizational measures.
- Accountability: MIRA shall be responsible for, and able to demonstrate, compliance with the above principles.
5. Legal Basis for Processing
MIRA will process personal data based on one or more of the following legal bases:
- The data subject has given consent to the processing of their personal data to support a legal case;
- Processing is necessary for compliance with a legal or contractual obligation;
- Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority; and/or
- Processing is necessary for the purposes of legitimate interests pursued by MIRA except where such interests are overridden by the rights and freedoms of the data subject.
6. Rights of Data Subjects
MIRA recognizes and respects the right of data subjects, including:
- The right to be informed about the collection and use of their personal data;
- The right of access to their personal data;
- The right to rectify any inaccurate or incomplete data;
- The right to erasure, except where it conflicts with legal requirements to retain data; and
- The right to data portability.
Data subjects may exercise their rights by submitting a written request to the Data Protection Officer (DPO).
7. Data Security
MIRA is committed to ensuring the security of personal data through the implementation of appropriate technical and organizational measures, including:
- Encryption of sensitive personal data;
- Access controls and user authentication;
- Regular security audits and risk assessments;
- Employee training and awareness programs; and
- Procedures for reporting and responding to data breaches.
8. Data Breach Response
In the event of a data breach, MIRA will promptly assess the situation and take appropriate steps to mitigate the impact. If the breach is likely to result in a high risk to the rights and freedoms of individuals, MIRA will notify the relevant authorities and affected data subjects within the legally required timeframe.
9. Data Retention and Disposal
MIRA will retain personal data only for as long as necessary to fulfill the purposes for which it was collected and to comply with legal, regulatory, or business requirements in line with MIRA’s Data Retention Policy. Personal data that is no longer required will be securely deleted or destroyed.
10. Third-Party Data Processors
Where MIRA engages third-party vendors to process and maintain personal data, MIRA will ensure that such vendors comply with applicable data protection regulations and implement appropriate safeguards to protect personal data. This includes third-party payment processors used for donations (e.g., online giving platforms), which must adhere to industry standards for secure financial transactions and data protection.
11. Roles and Responsibilities
Data Protection Officer (DPO): The Chief of Staff shall serve as MIRA’s Data Protection Officer and will be responsible for overseeing MIRA’s data protection strategy and ensuring compliance with applicable laws and regulations. The DPO will serve as the point of contact for data subjects and regulatory authorities.
Employees: All employees are responsible for following MIRA’s data protection policy and procedures and for safeguarding personal data in their day-to-day activities. Employees must report any data breaches or suspected breaches to the DPO immediately.
Management: Senior management is responsible for ensuring that data protection is integrated into MIRA’s overall culture and that adequate resources are allocated to implement this policy.
12. Training and Awareness
MIRA will provide regular trainings to ensure that employees understand their responsibilities under this policy and are equipped to handle personal data securely and in compliance with applicable law. This policy will also be incorporated into MIRA’s orientation for new staff to ensure that they understand this policy and their responsibilities under it.
13. Review and Updates
This policy will be reviewed and updated as necessary to reflect changes in data protection laws and regulations, organizational operations, or other relevant factors. The DPO will ensure that the policy remains current and effective
14. Consequences of Non-Compliance
Non-compliance with this policy may result in disciplinary action, including termination of employment or contract, and legal action where appropriate.
Effective Date:
Last Reviewed:
Approved by the Board:
Contact: Sarang Sekhavat, Data Protection Officer, ssekhavat@miracoalition.org.