Skip to content
Voice ofDiplomacyInstitute

GDPR compliance & data protection

The Institute's framework for protecting personal data — its governance policy, published in full. For what this website itself collects, see the privacy notice.

Voice of Diplomacy Institute (VoDI)

GDPR Compliance & Data Protection Policy

Effective Date: 5 September 2026

Last Updated: 5 September 2026

1. Purpose

Voice of Diplomacy Institute (VoDI) is committed to respecting privacy and protecting personal information.

This GDPR Compliance & Data Protection Policy establishes VoDI’s framework for protecting personal data and supporting compliance, where applicable, with the General Data Protection Regulation (EU) 2016/679 (GDPR) and other applicable data-protection laws.

The GDPR establishes principles governing how organisations collect, use, store, secure, and otherwise process personal data.

2. Scope

This Policy applies to VoDI’s processing of personal data in connection with:

  • The VoDI website;
  • Membership;
  • Fellowship programmes;
  • Training and education;
  • Events and conferences;
  • Research and publications;
  • Surveys and consultations;
  • Professional services;
  • Recruitment and applications;
  • Partnerships and institutional relationships; and
  • Other VoDI activities involving personal data.

3. Data Protection Principles

VoDI seeks to follow the following core data-protection principles:

  • Lawfulness, fairness and transparency
  • Purpose limitation
  • Data minimisation
  • Accuracy
  • Storage limitation
  • Integrity and confidentiality
  • Accountability

These are core principles recognised under Article 5 of the GDPR.

4. Personal Data

Personal data may include information that identifies or can reasonably be linked to an individual, such as:

  • Name;
  • Email address;
  • Telephone number;
  • Professional position;
  • Organisation;
  • Educational information;
  • Fellowship or programme application information;
  • Membership information;
  • Event registration information;
  • Communications with VoDI;
  • Online identifiers and technical information; and
  • Other information voluntarily provided to VoDI.

The GDPR can apply to professional contact information where it relates to an identifiable individual.

5. Lawful Basis for Processing

Where GDPR applies, VoDI will process personal data on an appropriate lawful basis.

Depending on the circumstances, this may include:

  • Consent;
  • Performance of a contract;
  • Compliance with a legal obligation;
  • Protection of vital interests;
  • Public-interest grounds where legally applicable; or
  • Legitimate interests, where those interests are not overridden by applicable rights.

6. Transparency

VoDI will seek to explain clearly:

  • What personal data is collected;
  • Why it is collected;
  • How it is used;
  • The legal basis for processing;
  • How long it may be retained;
  • Who may receive it;
  • Whether it may be transferred internationally; and
  • What rights individuals have.

The GDPR requires organisations to provide individuals with clear information about processing and their rights.

7. Data Minimisation

VoDI will seek to collect only personal data that is adequate, relevant, and reasonably necessary for the stated purpose.

VoDI will avoid collecting unnecessary personal information.

8. Accuracy

VoDI will take reasonable steps to maintain accurate and up-to-date personal information.

Where an individual identifies inaccurate information, VoDI will seek to correct or update it within a reasonable period.

9. Data Retention

VoDI will not retain personal data indefinitely without a legitimate reason.

Personal data will generally be retained only for as long as necessary for:

  • The purpose for which it was collected;
  • Programme or membership administration;
  • Legal or regulatory requirements;
  • Legitimate organisational requirements;
  • Research or archival purposes where legally permitted; or
  • Resolution of disputes and enforcement of agreements.

The GDPR recognises storage limitation as a core data-protection principle.

10. Security Measures

VoDI will implement reasonable technical and organisational safeguards appropriate to the nature and risks of the personal data processed.

Measures may include:

  • Access controls;
  • Password protection;
  • Appropriate authentication;
  • Secure data storage;
  • Restricted access on a need-to-know basis;
  • Confidentiality obligations;
  • Backup procedures;
  • Staff awareness and training; and
  • Appropriate security procedures.

The GDPR requires organisations to apply appropriate measures to protect personal data and encourages data protection by design and default.

11. Data Protection by Design and Default

VoDI will seek to consider privacy and data protection when designing:

  • Websites;
  • Online application systems;
  • Membership systems;
  • Fellowship applications;
  • Research projects;
  • Surveys;
  • Registration systems;
  • Digital platforms; and
  • Other systems involving personal information.

Privacy considerations should be incorporated as early as reasonably practicable.

12. Individual Data Protection Rights

Subject to applicable law, individuals may have the right to:

  • Be informed about processing;
  • Access their personal data;
  • Request correction;
  • Request deletion;
  • Request restriction of processing;
  • Object to certain processing;
  • Request data portability;
  • Withdraw consent where processing is based on consent; and
  • Exercise applicable rights concerning automated decision-making and profiling.

These rights are recognised within the GDPR framework.

13. Handling Data Requests

Individuals wishing to exercise their data-protection rights should contact VoDI through its official privacy or data-protection contact.

VoDI will:

  • Receive the request;
  • Verify the request where reasonably necessary;
  • Assess the applicable legal requirements;
  • Locate relevant information;
  • Respond within the applicable legal timeframe; and
  • Maintain appropriate records of the request and response.

15. Third-Party Service Providers

VoDI may use trusted service providers for:

  • Website hosting;
  • Email;
  • Cloud storage;
  • Payment processing;
  • Event registration;
  • Communications;
  • Analytics;
  • IT support; and
  • Other operational functions.

Where applicable, VoDI will seek appropriate contractual and data-protection safeguards when third parties process personal data on its behalf.

16. International Data Transfers

Because VoDI operates and collaborates internationally, personal data may in some circumstances be processed outside the country where it was collected.

Where GDPR transfer requirements apply, VoDI will seek to use an appropriate lawful transfer mechanism and safeguards.

17. Research and Publications

VoDI may conduct research involving interviews, surveys, consultations, questionnaires, and other forms of information collection.

Where personal data is used for research, VoDI will seek to apply appropriate safeguards, including where appropriate:

  • Anonymisation;
  • Pseudonymisation;
  • Aggregation;
  • Restricted access; and
  • Data minimisation.

VoDI will seek to avoid publishing unnecessary personal information.

18. Data Breach Management

VoDI will maintain procedures for identifying, assessing, containing, documenting, and responding to personal-data breaches.

Where GDPR applies and a breach is likely to result in a risk to individuals’ rights and freedoms, VoDI will assess whether notification to the relevant supervisory authority is required.

Where notification is legally required, VoDI will seek to comply with the applicable statutory timeframe.

19. Complaints

Individuals who believe that VoDI has improperly processed their personal data may submit a complaint directly to VoDI.

VoDI will review complaints fairly and take reasonable steps to address legitimate concerns.

Where GDPR applies, individuals may also have the right to lodge a complaint with a competent Data Protection Authority.

20. Data Protection Officer

VoDI will determine whether it is legally required to appoint a formal Data Protection Officer (DPO) based on the nature and scale of its processing activities and applicable law.

Where a DPO is appointed, the DPO’s contact information will be published in the relevant privacy information.

21. Accountability

VoDI recognises accountability as an important element of data protection.

VoDI will seek to maintain appropriate:

  • Policies;
  • Procedures;
  • Records;
  • Training;
  • Security controls;
  • Data-processing documentation;
  • Vendor safeguards; and
  • Review mechanisms.

The GDPR’s accountability principle requires organisations not only to comply with data-protection principles but also to be able to demonstrate compliance.

22. Training and Awareness

Where appropriate, VoDI personnel who handle personal data will receive relevant privacy and data-protection guidance.

Personnel should understand their responsibilities concerning:

  • Confidentiality;
  • Secure handling;
  • Access controls;
  • Data sharing;
  • Data retention; and
  • Reporting suspected breaches.

23. Relationship with VoDI Privacy Policy

This Policy should be read together with the VoDI Privacy Policy.

The Privacy Policy provides website users and other individuals with information about how their personal data is collected and used, while this Compliance Policy establishes VoDI’s internal governance framework for data protection.

24. Policy Review

VoDI will periodically review this Policy to ensure that it remains appropriate for:

  • Changes in applicable law;
  • Changes in VoDI’s operations;
  • New technologies;
  • New programmes;
  • New data-processing activities; and
  • Emerging privacy and security risks.
Exercising your data rights

Write to info@vodinstitute.org or see the full list of ways to reach the Institute on the Contact page.

WhatsApp — message the Institute