This document sets out MedWHOLE's privacy and data-protection commitments across its website, programmes, outreach activities, health interventions, education activities, volunteering, partnerships, donations and related operations.
1. Introduction
MedWHOLE Alliance for Health and Development (“MedWHOLE”, “we”, “our” or “us”) is committed to protecting the privacy, dignity and personal information of everyone who interacts with our organisation.
Our work involves health, education, nutrition, empowerment, community development, volunteering, partnerships, research, outreach and support programmes. Some of these activities involve children and other potentially vulnerable persons.
We therefore recognise that responsible use of personal information is an important part of the trust placed in MedWHOLE.
This Privacy & Data Protection Policy explains:
- what personal information we collect;
- why we collect it;
- the lawful bases on which we process it;
- how we protect it;
- when we may share it;
- how we handle children’s information;
- how we use photographs and programme stories;
- how long information may be retained; and
- the rights available to individuals whose information we process.
This Policy applies to personal data processed through our website, forms, programmes, outreach activities, offices, events, applications, volunteer activities, donations, surveys, health interventions and other MedWHOLE activities.
2. Who We Are
MedWHOLE Alliance for Health and Development is an organisation advancing health, education, nutrition and empowerment through programmes designed to promote whole-person and sustainable community development.
For personal data for which MedWHOLE determines the purpose and manner of processing, MedWHOLE acts as a Data Controller.
Contact
MedWHOLE Alliance for Health and Development 7 Nissi Drive, Fort Royal Airport Road Abuja, FCT, Nigeria Email: medwholealliance@gmail.com Telephone: +234 818 980 0001
Privacy and data-protection enquiries may be submitted through the contact details above.
3. Applicable Data Protection Framework
MedWHOLE processes personal data in accordance with applicable Nigerian data-protection and privacy requirements, including the Nigeria Data Protection Act 2023, regulations and directives issued by the Nigeria Data Protection Commission, including the General Application and Implementation Directive 2025, and other applicable Nigerian laws.
Where MedWHOLE carries out activities in another country, applicable local privacy and data-protection requirements may also apply.
4. Our Data Protection Principles
When processing personal data, MedWHOLE seeks to ensure that information is:
Lawfully, fairly and transparently processed. We will have an appropriate lawful reason for processing personal information and will explain relevant processing to the individuals concerned.
Collected for specific purposes. Information collected for one purpose will not ordinarily be reused for an unrelated purpose without an appropriate lawful basis.
Limited to what is necessary. We seek to collect only information reasonably required for the programme, service, legal obligation, safeguarding responsibility or other stated purpose.
Accurate and appropriately maintained. Reasonable steps will be taken to correct inaccurate information where necessary.
Retained only for as long as necessary. Personal information will not be retained indefinitely without a legitimate operational, legal, safeguarding, reporting or archival reason.
Protected appropriately. We use administrative, organisational and technical safeguards appropriate to the nature and sensitivity of the information being processed.
Processed accountably. MedWHOLE will maintain appropriate policies, procedures and records to support responsible data-processing practices.
5. Personal Information We May Collect
The information MedWHOLE collects depends on how an individual interacts with us.
Website Visitors
We may collect:
- IP address;
- browser and device information;
- approximate location derived from technical information;
- pages viewed;
- referral information;
- website interaction and analytics information;
- cookie preferences; and
- information voluntarily submitted through website forms.
Programme Participants and Beneficiaries
Depending on the programme, we may collect:
- name;
- age or date of birth;
- sex;
- telephone number;
- email address;
- residential or community information;
- parent or guardian information;
- school or educational information;
- programme attendance;
- needs assessments;
- programme outcomes;
- referral information;
- feedback and survey responses; and
- information required to deliver or evaluate the relevant programme.
Health Programmes
Where necessary for a health intervention, we may process limited health information such as:
- screening information;
- basic medical history relevant to the intervention;
- blood pressure, blood glucose or other screening results;
- referral information;
- treatment or follow-up information where MedWHOLE is responsible for such activities; and
- other health information necessary for the particular intervention.
Health information is treated as sensitive personal data and receives additional protection.
Volunteers
We may collect:
- name;
- contact information;
- skills and qualifications;
- emergency contact information;
- availability;
- professional background;
- training records;
- programme assignments;
- references;
- identification information where necessary;
- safeguarding or background-check information where appropriate; and
- volunteer performance or incident records.
Employment and Applications
We may process:
- CVs;
- application forms;
- qualifications;
- employment history;
- professional references;
- contact information;
- interview records;
- identification documents where required; and
- other information relevant to recruitment.
Donors, Partners and Sponsors
We may process:
- name;
- organisation;
- contact details;
- donation or sponsorship information;
- transaction references;
- communication history;
- partnership documentation; and
- information required for accounting, reporting and regulatory purposes.
MedWHOLE does not require donors to disclose online-banking passwords or similar banking credentials.
6. Sensitive Personal Data
Some information requires greater protection because disclosure or misuse could create significant risk to the person concerned.
Depending on our programmes, this may include:
- health information;
- biometric information where applicable;
- racial or ethnic information;
- religious or similar beliefs;
- information concerning disability;
- and other information classified as sensitive under applicable law.
We will process sensitive personal data only where an appropriate legal condition exists, which may include explicit consent, medical or community welfare purposes carried out under appropriate professional confidentiality, protection of vital interests, legal obligations, or other grounds permitted by applicable law.
Sensitive personal data will not be collected merely because it may be interesting or useful.
7. Why We Process Personal Information
MedWHOLE may process personal data to:
- deliver health, education, nutrition and empowerment programmes;
- register programme participants;
- assess eligibility or needs;
- communicate with participants or their guardians;
- provide referrals and follow-up support;
- manage volunteers;
- manage recruitment;
- coordinate events and outreach activities;
- receive and reconcile donations;
- manage partnerships and sponsorships;
- respond to enquiries;
- conduct monitoring, evaluation and learning;
- measure programme outcomes;
- prepare reports for partners and funders;
- protect participants, staff, volunteers and communities;
- investigate safeguarding concerns;
- prevent fraud or misuse of our services;
- maintain financial and organisational records;
- meet legal and regulatory obligations;
- maintain and secure our website and information systems;
- and communicate organisational news or fundraising information where legally permitted.
Where practical, statistical and impact reporting will use aggregated or de-identified information rather than information identifying individual beneficiaries.
8. Lawful Bases for Processing
Depending on the circumstances, MedWHOLE may rely on one or more lawful bases permitted under applicable law, including:
Consent — where an individual, parent or legal guardian has freely agreed to a specific use of personal data.
Contractual necessity — where processing is necessary to take steps requested by an individual or perform an agreement.
Legal obligation — where MedWHOLE is required to process information by applicable law.
Vital interests — where processing is necessary to protect someone’s life, health, safety or another vital interest and the circumstances justify such processing.
Public interest — where applicable law permits processing in furtherance of an appropriate public or humanitarian interest.
Legitimate interests — where MedWHOLE has a legitimate organisational purpose for processing and that interest is not overridden by the rights and freedoms of the individual.
Different lawful bases may apply to different processing activities.
Consent will not be treated as the only possible lawful basis where applicable law provides another appropriate basis.
9. Children’s Privacy and Data Protection
Our Programmes Serve Children
Some MedWHOLE programmes are intentionally designed for children.
For that reason, MedWHOLE does not adopt a policy stating that it never processes children’s personal information.
Instead, we recognise that children’s information requires a particularly high standard of care.
For the purposes of this Policy, a child is a person under the age recognised as a child under applicable Nigerian law.
Parental or Guardian Consent
Where MedWHOLE relies on consent to process the personal data of a child, we will seek consent from the child’s parent or legal guardian as required by applicable law.
Reasonable steps will be taken to establish that the person giving consent has authority to do so.
Depending on the nature and risk of the processing, verification may include appropriate identification or other reasonable methods of verifying the adult’s identity and relationship to the child.
We will not deliberately design consent mechanisms that allow a child to falsely represent themselves as an adult merely to bypass parental or guardian approval.
Child Assent
Parental or guardian consent does not mean a child’s wishes should be ignored.
Where the child’s age and maturity make it appropriate, MedWHOLE will explain the relevant activity in understandable language and seek the child’s cooperation or assent.
A child should not be unnecessarily pressured into participating in photography, interviews, testimonials or other optional publicity activities.
Education, Medical and Social-Care Activities
Applicable law permits children’s personal information to be processed in certain circumstances without relying on parental consent, including where processing is necessary for:
- protecting the vital interests of the child;
- education, medical or social-care purposes conducted by or under the responsibility of an appropriate professional or service provider owing a duty of confidentiality; or
- other circumstances specifically permitted by law.
Where such a lawful basis applies, MedWHOLE will still apply appropriate safeguards and collect only information necessary for the relevant purpose.
Data Minimisation for Children
MedWHOLE will avoid collecting unnecessary information about children.
In particular, public-facing materials should not ordinarily disclose combinations of information that unnecessarily expose a child, such as:
- full name;
- precise home address;
- personal telephone number;
- detailed health diagnosis;
- school and class information;
- precise routine or regular location;
- family financial circumstances;
- or safeguarding information.
Where identifying information is not necessary, initials, first names, age ranges, pseudonyms, aggregated information or anonymised information should be preferred.
Children’s Health Information
Health information concerning children is treated as sensitive personal data.
Access should be limited to personnel who reasonably require the information for programme delivery, clinical care, referral, safeguarding, reporting or another lawful purpose.
Health results will not ordinarily be published alongside a child’s identity.
Where a child requires referral to another healthcare provider, relevant information may be shared where appropriate consent or another lawful medical or vital-interest basis permits the referral.
Children’s Information and Marketing
MedWHOLE will not use children’s personal information for behavioural advertising.
MedWHOLE will not sell children’s personal information.
Children’s information will not be provided to third parties for their independent commercial marketing purposes.
Contacting Children
Where programme communications involve a child, MedWHOLE should, where appropriate, communicate through or with the knowledge of the child’s parent, legal guardian, school, programme coordinator or another responsible adult.
Any direct communication with children must comply with MedWHOLE’s safeguarding procedures.
Safeguarding
Privacy does not prevent MedWHOLE from taking reasonable action where a child may be at risk of harm.
Where information indicates abuse, exploitation, neglect, a medical emergency, serious safety risk or another safeguarding concern, MedWHOLE may record and disclose necessary information to appropriate safeguarding personnel, healthcare professionals, authorities or other persons where permitted or required by law.
Only information reasonably necessary for the safeguarding purpose should be shared.
Safeguarding records should be stored separately or subject to appropriately restricted access wherever practicable.
10. Photographs, Videos and Children’s Stories
Photographs, videos, audio recordings, case studies and beneficiary stories can themselves constitute personal data.
MedWHOLE recognises that children’s dignity and safety are more important than obtaining promotional material.
Identifiable Images of Children
Where MedWHOLE intends to use an identifiable child’s photograph, video, interview or individual story for publicity, fundraising, social media, website publication, reports or similar communications, appropriate parent or legal-guardian permission should ordinarily be obtained.
Where appropriate, the child should also be informed and asked whether they are comfortable participating.
Separate Media Choice
Consent to publicity should ordinarily be separate from consent required for the child to receive a MedWHOLE service.
A parent or guardian declining optional photography or publicity should not, by itself, cause a child to be excluded from a programme for which they are otherwise eligible.
Dignified Storytelling
MedWHOLE will seek to avoid images or stories that:
- humiliate a child;
- portray a child in a degrading manner;
- unnecessarily expose illness or disability;
- reveal highly sensitive family circumstances;
- suggest helplessness merely to encourage donations;
- identify a child who may face protection or safeguarding risks;
- or disclose information that could reasonably place the child at risk.
Withdrawal of Media Consent
Where media use is based on consent, a parent, guardian or other relevant data subject may request withdrawal of consent for future use.
MedWHOLE will take reasonable steps to stop future controlled use of the material.
Withdrawal may not make it possible to retrieve material already lawfully printed, distributed, archived, published by independent third parties, or incorporated into completed reports before withdrawal.
11. Research, Monitoring, Evaluation and Impact Reporting
MedWHOLE may collect information to understand whether programmes are effective and to improve future interventions.
Where possible, research and impact reporting will use:
- aggregated data;
- anonymised information;
- pseudonymised records; or
- information that does not directly identify individual beneficiaries.
Identifiable personal or sensitive data should not be included in external research or reports unless an appropriate lawful basis and safeguards exist.
Where a partner or funder requires beneficiary-level information, MedWHOLE will assess what information is actually necessary before disclosure.
13. International Data Transfers
Some technology providers or programme partners used by MedWHOLE may process information outside Nigeria.
Where personal data is transferred internationally, MedWHOLE will seek to ensure that the transfer is supported by an appropriate mechanism recognised under applicable Nigerian data-protection law.
This may include an adequate level of protection, appropriate contractual safeguards, a permitted statutory exception or another lawful transfer mechanism.
The sensitivity of the information and risks to affected individuals will be considered before international transfer.
14. Donations and Financial Information
When a person indicates an intention to donate, MedWHOLE may collect information necessary to:
- identify the donor;
- reconcile a donation;
- issue acknowledgements or receipts;
- maintain accounting records;
- comply with financial obligations; and
- communicate about the donation.
Where payments are processed through a bank, payment provider or other financial institution, that institution may separately process information under its own privacy and security obligations.
MedWHOLE does not ask donors to provide online banking passwords, PINs, one-time passwords or similar authentication credentials to MedWHOLE.
16. Data Security
MedWHOLE will apply security measures appropriate to the nature, volume and sensitivity of personal information under its control.
These measures may include, where appropriate:
- access controls;
- role-based permissions;
- strong authentication;
- multi-factor authentication for administrative systems;
- encryption in transit;
- encryption at rest where appropriate and supported;
- secure backups;
- logging and monitoring;
- secure configuration of websites and systems;
- restricted access to sensitive and children’s information;
- confidentiality requirements;
- staff and volunteer training;
- processor and vendor controls;
- secure disposal of records;
- software and security updates;
- and periodic review of security risks.
No organisation can guarantee absolute security. MedWHOLE nevertheless seeks to maintain safeguards proportionate to the risks associated with the personal data it processes.
17. Personal Data Breaches
A personal data breach may include unauthorised access, accidental disclosure, loss, alteration, destruction or other compromise of personal information.
MedWHOLE will maintain procedures for identifying, investigating, containing, documenting and responding to suspected personal-data breaches.
Where a breach is likely to result in a risk to the rights and freedoms of individuals, MedWHOLE will notify the Nigeria Data Protection Commission within the period required by applicable law.
Where a breach is likely to result in a high risk to an affected individual, MedWHOLE will communicate with the affected person as required by law and provide appropriate information concerning steps that may reduce the possible harm.
Personal-data breaches will be documented even where regulatory notification is not legally required.
18. Data Retention
MedWHOLE will retain personal information only for as long as reasonably necessary for the purpose for which it was collected and for applicable legal, accounting, reporting, safeguarding, contractual or regulatory requirements.
Retention periods may differ depending on the information concerned.
For example:
- general enquiries should not be retained indefinitely after the matter has been resolved;
- unsuccessful volunteer or employment applications should be removed after an appropriate recruitment-retention period unless continued retention has been agreed or is otherwise justified;
- programme data may be retained for an appropriate period for programme administration, monitoring, evaluation, reporting and audit purposes;
- financial and donation records may be retained for periods required by applicable accounting, tax or regulatory requirements;
- health information should be retained only as necessary for the relevant health service, follow-up, legal requirement or professional record-keeping obligation;
- child consent and media-permission records may be retained for as long as corresponding material remains in authorised use and for an appropriate period afterwards;
- and safeguarding records may require longer restricted retention where necessary to protect children, establish historical safeguarding decisions or meet legal obligations.
When identifiable information is no longer necessary, it should be securely deleted, destroyed, anonymised or otherwise placed beyond ordinary use, as appropriate.
19. Your Data Protection Rights
Subject to applicable law and relevant exceptions, individuals may have rights including the right to:
- be informed about how their personal data is processed;
- request access to personal information held about them;
- request correction of inaccurate or incomplete information;
- request deletion where applicable;
- request restriction of certain processing;
- object to certain processing;
- withdraw consent where processing relies on consent;
- receive eligible information in a portable format;
- object to or challenge certain solely automated decisions;
- and lodge a complaint with the Nigeria Data Protection Commission.
Parents and legal guardians may exercise appropriate rights concerning children’s information where permitted by law.
Withdrawing consent does not make processing carried out lawfully before withdrawal unlawful.
Requests may be submitted to: medwholealliance@gmail.com
MedWHOLE may request reasonable information to confirm the identity and authority of the person making a request before releasing, changing or deleting personal information.
We will respond within the period required by applicable law, ordinarily within 30 days where applicable.
20. Automated Decision-Making
MedWHOLE does not intend to make significant decisions about beneficiaries solely through automated processing without appropriate safeguards.
If MedWHOLE introduces technology that makes solely automated decisions having significant effects on individuals, affected persons will be provided with information and rights required under applicable law.
21. Third-Party Websites
Our website may contain links to websites operated by third parties.
MedWHOLE is not responsible for the privacy practices of independent third-party websites.
Visitors should review the privacy information provided by those organisations before submitting personal information to them.
22. Staff, Volunteer and Partner Responsibilities
Everyone handling personal information on behalf of MedWHOLE is expected to respect confidentiality and applicable data-protection requirements.
Access to personal information should be based on a genuine need to know.
Staff and volunteers must not:
- download beneficiary databases to personal devices without authorisation;
- share beneficiary information through unauthorised channels;
- publish beneficiary information or photographs without appropriate authority;
- use participant information for personal purposes;
- share passwords or administrative credentials;
- retain unnecessary copies of sensitive records;
- or disclose children’s information outside authorised safeguarding or programme processes.
Relevant personnel should receive periodic data-protection and safeguarding awareness training.
23. Privacy by Design
New MedWHOLE programmes, forms, applications, digital platforms and partnerships should consider privacy before personal data is collected.
Where processing may create a high risk to individuals, particularly processing involving large volumes of children’s information, health information, biometrics, systematic monitoring or new technologies, MedWHOLE should conduct an appropriate Data Protection Impact Assessment before or during implementation as required by law.
24. Changes to This Policy
MedWHOLE may update this Policy as our activities, technologies or legal obligations change.
The current version will be published on our website with its effective date.
Where a change materially affects the way we use information previously collected on the basis of consent, we will obtain any additional consent required by law rather than assuming that continued website use constitutes consent.
25. Questions, Complaints and Privacy Requests
Questions, concerns or requests concerning personal information may be directed to:
Privacy contact
MedWHOLE Alliance for Health and Development · 7 Nissi Drive, Fort Royal Airport Road, Abuja, FCT, Nigeria · medwholealliance@gmail.com · +234 818 980 0001
Individuals who believe their data-protection rights have been infringed also have the right to make a complaint to the Nigeria Data Protection Commission (NDPC) in accordance with applicable law.
Whole People. Lasting Impact. At MedWHOLE, protecting human dignity includes protecting the information entrusted to us.