MENA Open Data & Evidence Lab
Data protection & security

Public evidence and confidential client data are different security classes.

The Lab’s public repositories are for material intended to be public. Confidential, personal, restricted or client-provided data must not be committed to public repositories or entered into public website forms.

Data minimization

Collect only the data required to answer the documented research or engagement question. Avoid personal data where aggregate/public evidence is sufficient.

Access control

Confidential project access is limited to people whose role requires it. Access requirements and permitted uses belong in the engagement record or data-handling plan.

Storage separation

Public-source research artifacts may live in public version control. Confidential material is kept outside the public site/repository and is not included in public issue reports, source bundles or examples.

Transfer

Sensitive files should use a project-agreed secure transfer route rather than email attachments or public forms where risk or contractual requirements make those unsuitable.

Retention & deletion

Retention periods are set by research necessity, contractual/legal obligations and reproducibility requirements. Confidential inputs are not retained merely because storage is available.

Incident handling

Suspected unauthorized access, disclosure or integrity failure is triaged promptly, preserved for investigation and communicated to affected counterparties as required by the applicable agreement or law.

Project-specific security plan

For non-public data, the Lab can document classification, approved users, storage location, transfer route, retention period, permitted analysis, publication boundary, deletion/return requirements and incident contact before data is received.

Responsible disclosure

Security issues that could expose restricted information should be reported privately to the monitored contact, not placed in a public issue.

This page describes operating controls and does not claim certifications, audits or legal regimes that have not been formally obtained or established.