Skip to content
    Back to Home

    Data Governance

    Current demo behaviour and the requirements to agree before any safeguarding pilot

    Current status: public demonstrators

    SafeChild, SafeVoice, and SafeSchool are browser-based demonstrators. They do not currently process partner case data, and no production deployment or pilot schedule is confirmed. This page separates behaviour visible in the demos from controls that would need to be specified, implemented, tested, and approved with an operating partner before live data is used.

    1. Current Demo Data Behaviour

    The public SafeApps demos use synthetic sample records. Some workflow state is stored in the visitor's own browser through IndexedDB or local storage so that screens can be explored without a production backend.

    DataUse sample information only. The demos are not reporting channels and must not receive real personal, case, or evidence data.
    Browser storageLocally saved demo state is for demonstration convenience. It is not durable production storage and may be cleared by the visitor or browser.
    Not yet definedProduction hosting, server synchronisation, backups, data residency, deletion routines, and support arrangements have not been selected for a partner implementation.

    2. Ownership and Responsibilities

    Data ownership and legal roles would be agreed for the actual service, rather than assumed from the demo. Before a pilot, Minetrax and the operating partner would document:

    • who acts as data controller, processor, or joint controller for each workflow;
    • the lawful basis, approved purposes, notices, consent or safeguarding authority, and data-subject process;
    • any sub-processors, hosting providers, support access, and cross-border transfers;
    • data ownership, export, return, deletion, legal holds, and exit arrangements; and
    • the contracts and governance documents required before live data is introduced.

    3. Proposed Pilot Security Requirements

    Security controls would be chosen from a documented threat and risk assessment for the agreed pilot. The implementation plan would define and verify:

    • encryption for data in transit and at rest, including key ownership and recovery;
    • authentication, multi-factor authentication where appropriate, session controls, and account recovery;
    • role enforcement, privileged access, secrets management, backups, monitoring, and secure deployment;
    • security testing proportionate to the data and risk, including independent testing if required by the partner or procurement process; and
    • remediation, acceptance, and evidence requirements before any live launch.

    Minetrax does not currently advertise an independent penetration-test report for the public SafeApps demos. Any future report would identify the tested version, scope, date, tester, findings, and remediation status.

    4. Data Minimisation and Safeguarding

    The demos illustrate anonymous intake and do not require a child to create an account to explore the public reporting workflow. This interaction design is not, by itself, an approved safeguarding or privacy model.

    • The operating partner and safeguarding lead would approve every proposed field and whether it is required or optional.
    • Identity, contact, demographic, location, case-note, and evidence handling would be assessed separately.
    • Image, audio, video, biometric, or suspected illegal material would require specialist policy, routing, and safety review before collection.
    • Test and training environments would continue to use synthetic or properly anonymised information.

    5. Retention, Deletion, and Hosting

    No fixed production retention period, automated deletion schedule, or hosting location is promised by the demos. Before a pilot, the partner and Minetrax would document:

    • record categories and purpose-specific retention periods based on current legal, safeguarding, operational, and funder requirements;
    • review, correction, anonymisation, archive, legal-hold, deletion, and evidence-preservation procedures;
    • hosting and backup locations, data residency, cross-border transfer controls, recovery objectives, and provider responsibilities; and
    • how deletion and export would be verified at pilot closure or contract exit.

    6. Access Control and Audit

    Demo role switching illustrates possible workflows. It is not a production security boundary. A pilot would require role and record-level permissions to be agreed, implemented, and tested against real job responsibilities.

    • Named accounts, least-privilege roles, joiner and leaver controls, and privileged-access approval would be defined.
    • Audit events, integrity protections, access, export, monitoring, and retention would be specified and tested.
    • Partner teams would approve who can view, assign, update, export, or delete each class of record.
    • Security and safeguarding reviews would cover misuse, insider risk, unsafe disclosure, and emergency access.

    7. Legal and Regulatory Readiness

    Zambia's Data Protection Act, 2021 provides the national legal framework. The exact obligations depend on the real organisations, people, data, purposes, technology, and locations involved. They would be checked against current law and regulator guidance, with appropriate legal and safeguarding advice, before a pilot.

    This page describes product readiness questions and is not legal advice or a claim of regulatory approval.

    8. Incident Response and Assurance

    Before live data is processed, an implementation would need an approved incident response and escalation plan. Notification duties and timeframes would be based on current law, regulator guidance, contracts, and the actual incident.

    • Roles, contact paths, evidence preservation, containment, recovery, partner escalation, and communications would be rehearsed.
    • Security findings would be tracked to verified remediation before launch or formally accepted by authorised owners.
    • Security concerns about the demos can be reported to info@minetrax.co.zm.
    • Test reports would only be shared after the stated assessment has been completed and its scope can be described accurately.

    Planning a due diligence discussion?

    We can discuss the demo architecture, prepare a proposed control checklist, and run a pilot governance workshop with your technology, legal, safeguarding, and programme teams.

    Contact us: info@minetrax.co.zm