Pilot applications openWe’re listening to early-stage support needs.Start an application →
Apply for support

Draft control baseline

Data-protection framework

Ubuntu Gale’s platform design applies data minimisation, purpose limitation, access control, retention and auditable handling to applicant, participant and relationship information.

01

Data inventory and classification

Systems should record data category, purpose, owner, location, sensitivity, authorised roles, processor, retention and deletion method.

02

Access and security

Server-side permission checks, MFA for privileged roles, secure sessions, encrypted transport, signed private-file access, authentication logging and regular access review.

03

Retention and deletion

Proposed defaults include 90 days for abandoned drafts, 24 months for declined applications and contact enquiries, at least 36 months for audit logs, and consent until withdrawal. Final periods require legal approval.

04

Individual requests

A controlled process will verify identity, locate data, apply legal exceptions, export or correct records and record the response deadline and outcome.

05

Incidents

Suspected loss, unauthorised access or disclosure requires containment, evidence preservation, risk assessment, escalation, notification analysis, remediation and documented learning.