@media print { .callout-box { border: 1px solid #000; /* Black border for visibility in print */ padding: 15px; /* Padding to create space inside the box */ background-color: #f9f9f9; /* Light background color for contrast */ margin: 20px 0; /* Margin to space out the box from other content */ box-shadow: none; /* Remove any box-shadow */ } } Print Friendly and PDF

Modern local authorities need data to function, and increasingly, this data is digitally shared, handled and stored. To manage this increasing quantity of data, governments have begun to adopt data governance frameworks. Such frameworks describe “how data is handled and for what purpose, its quality and integrity, as well as the privacy and security concerns related to its collection and use.”58 An effective data governance framework will account for local capacities, needs and use of data and will align with your country’s legal framework and national policies. Data governance frameworks can cover a lot of ground but generally include the following categories (sourced from MetroLab Network’s handy guide59):

  • Data classifications: A ranking of how sensitive data is, ranging from most open (job announcements, press releases) to most restricted (data that – if made public – could risk life or property)
  • Privacy and key principles: A consideration of the right to privacy and data protection, national or global standards, and equity
  • Data integrity and cybersecurity: The infrastructure, staff and measures you have in place to ensure data quality, safeguarding and protocols in the event of breaches
  • Data use rights and sharing agreements: A determination of who owns the data, how it is shared internally or within the government, and external sharing policies (such as with vendors or law enforcement)
  • Operationalizing the framework: The procedures, resourcing and organizational structure needed to deliver on the framework, including oversight and community engagement

Does your local authority have such a framework? If not, consider developing a simplified version to guide how data collected during this process will be shared, handled and stored – noting that many of the considerations apply to paper materials as well as digital. The following sections will introduce some standards for privacy and personal data that will be relevant as you prepare to listen to public feedback and gather data.

Privacy and handling personal data

Each country has rules or laws about privacy and data protection, and your team should be fully aware of your obligations in relation to your domestic legal framework before embarking on data collection efforts, especially if you are collecting personal data. Personal data is “any information relating to an identified or identifiable individual.”60 If you are not aware of the rules, you should consult with relevant civil servants or legal departments in the local authority, national ministry or other part of the government administration to understand your responsibilities. Many countries also have a supervisory authority, which can be a single government official, ombudsperson or a body with several members who oversee the application of these rules and may offer guidance.61

In addition to domestic laws on privacy, confidentiality and data protection, your country may be party to international or regional standards or guidelines on collecting, maintaining and sharing data. For example, the European Union’s (EU’s) General Data Protection Regulation (GDPR) applies to EU countries but has become a global standard.62 The Council of Europe’s Convention for the Protection of Individuals with Regard to the Processing of Personal Data (Convention 108+) is another international standard with 55 signatory countries,63 as is the African Union’s Convention on Cybersecurity and Personal Data Protection, ratified by 15 of its 55 member states (and thus in force as of June 2023).64 In the western hemisphere, the Organization of American States (OAS) has also developed its own Principles on Privacy and Protection of Personal Data.65

The Organisation for Economic Co-operation and Development (OECD) offers Guidelines Governing the Protection of Privacy and Transborder Flows of Personal Data,66 which it considers a minimum set of standards and principles, although it recognizes exceptions.

In summary, it is important to understand whether the data collection process will gather personal data. If it does, be sure to understand your obligations under domestic and international frameworks to ensure that you respect residents’ rights. Consider the following questions as you plan (although these are not exhaustive):

  • Are you explaining clearly to residents (and anyone you are collecting data from) what you are using data for?
  • Are there restrictions on the kinds of data the government can collect? Can you get residents’ permission to collect data? Can you get the data you need without collecting personally identifiable information?
  • Does your local authority have rules about how data must be stored and who has access? Are there limits on data sharing, even between agencies or within the local authority’s administration?
  • Are there rules about publishing data?
  • How will your team manage and store data to ensure basic safeguards are in place?

See Annex VI: Data Governance Frameworks for additional resources and an exercise on storing and safeguarding data responses.

SIGNPOST QUESTIONS

How will we collect sufficient data? Who do we need to reach? How will we reach them?

Footnotes

58 Carlos Santiso and Marcelo Facchina, Why Governing Data Is Key for the Future of Cities (OCED Development Matters, 2021), Link.

59 Model Data Governance Policy & Practice Guide: For Cities and Countries (MetroLab Network, 2023), Link.

60 OCED, Recommendation of the Council Concerning Guidelines Governing the Protection of Privacy and Transborder Flows of Personal Data (OECD Legal Instruments, 2013), Link.

61 Data Protection and Privacy Laws: Identification for Development (The World Bank, n.d.), Link.

62 General Data Protection Regulation (GDPR) (Intersoft Consulting, 2016), Link.

63  Convention 108 +  |  Convention for the Protection of Individuals with Regard to the Processing of Personal Data (Council of Europe, 2018), Link.

64 African Union Convention on Cyber Security and Personal Data Protection (African Union, 2014), Link.

65 Jean-Michel Arrighi, Updated Principles on Privacy and Personal Data Protection (OAS Department of International, 2022), Link.

66 OCED, Recommendation of the Council Concerning Guidelines Governing the Protection of Privacy and Transborder Flows of Personal Data (OECD Legal Instruments, 2013), Link