Dhamma · Reflection · Statements · Peaceful Communication

Office Of Siridantamahapalaka: LEGAL COMPLIANCE AND SUSTAINABILITY POLICY

Chronological Archive

SECTION VII – LEGAL COMPLIANCE AND SUSTAINABILITY

 


Chapter 27 – Regulatory Compliance


CHAPTER 27 – REGULATORY COMPLIANCE

1. General Provisions

27.1 Purpose of this Chapter
This Chapter establishes HGT’s framework for regulatory compliance, to ensure that:

a) HGT remains duly registered and recognised under applicable law;
b) all activities comply with relevant national laws and, where applicable, international treaties; and
c) failures of compliance are identified, corrected and prevented in future.

27.2 Foundations
This Chapter is guided by:

a) international treaties and norms, including principles from human rights conventions such as CEDAW (elimination of discrimination against women), CRC (rights of the child) and other relevant instruments;
b) Myanmar laws and regulations, including, where applicable, the Penal Code, labour and employment laws, cultural heritage and antiquities laws, environmental and safety laws, and electronic and data laws;
c) UNESCO bioethics and cultural heritage guidance, especially regarding sacred materials, human remains and cultural property; and
d) HGT’s internal governance, safeguarding, financial and heritage policies outlined in earlier Sections.

27.3 Scope
a) This Chapter applies to all HGT bodies, departments, sites and programmes.
b) It covers legal registration, reporting duties, thematic compliance areas and internal handling of non-compliance.


2. Legal Identity, Registration and Founding Documents

27.4 Legal Personality
a) HGT shall maintain a clear legal identity in accordance with applicable Myanmar law (e.g. registration as an association, foundation, religious organisation or other recognised form).
b) The exact legal form and registration details shall be documented and kept accessible in the Legal/Compliance Department.

27.5 Founding and Governing Documents
a) HGT shall adopt and maintain founding and governing documents (e.g. constitution, articles, by-laws) that:

i. define its mission, structure and decision-making bodies;
ii. specify its non-profit, non-distribution and religious/heritage purposes;
iii. set out basic rules on membership, boards and meetings.

b) This Policy Manual shall be consistent with those documents; where contradictions arise, the governing documents and applicable law prevail, and the Manual shall be amended accordingly.

27.6 Registration and Renewal Obligations
a) HGT shall maintain up-to-date registrations with all relevant authorities, including but not limited to:

i. primary registration authority (e.g. associations or religious registration);
ii. tax or revenue authorities;
iii. heritage or antiquities departments, where required.

b) Renewal of registrations, licences or permits (e.g. for certain activities or properties) shall be tracked and completed before expiry.

27.7 Legal/Compliance File
a) The Legal/Compliance Department shall maintain a central compliance file including:

i. registration certificates and renewal documents;
ii. governing documents and amendments;
iii. key licences and permits;
iv. correspondence with regulators on compliance matters.

b) Copies of important documents shall be stored securely and backed up.


3. Compliance Mapping and Responsibilities

27.8 Compliance Mapping
a) HGT shall maintain a Compliance Map identifying key legal and regulatory areas, including at least:

i. registration and corporate/association law;
ii. labour and employment law;
iii. cultural heritage and antiquities law;
iv. financial, tax and anti-money-laundering rules;
v. child protection and safeguarding;
vi. equality and non-discrimination law, including gender-related obligations;
vii. data protection, electronic communications and cybercrime provisions;
viii. health, safety and environmental regulations.

b) For each area, the map shall indicate responsible departments and key obligations.

27.9 Compliance / Legal Officer
a) HGT shall designate a Compliance / Legal Officer (or equivalent) responsible for:

i. monitoring legal and regulatory developments relevant to HGT;
ii. coordinating registration and reporting duties;
iii. advising departments on compliance questions;
iv. supporting risk assessments related to law and regulation.

b) The Officer shall work closely with the Executive Director, Finance, HR & Safeguarding, Relic & Heritage, and Site Management.

27.10 Departmental Responsibilities
a) Each department shares responsibility for compliance in its domain. Examples include:

i. HR & Safeguarding – labour, workplace and safeguarding compliance;
ii. Finance & Administration – financial reporting, tax, audit and anti-corruption;
iii. Relic & Heritage – heritage, cultural property and bioethics;
iv. Operations/Sites – health, safety, environment and local permits;
v. Communications/IT – data protection and communication laws.

b) Departments must cooperate with the Compliance / Legal Officer to ensure obligations are understood and met.


4. Reporting Duties to Authorities, Donors and the Public

27.11 Regulatory Reporting
a) HGT shall file required reports to regulatory authorities in a timely, accurate and complete manner, which may include:

i. annual returns or activity reports to registration authorities;
ii. financial statements and audit reports to relevant ministries;
iii. tax or revenue declarations;
iv. reports required by heritage or cultural authorities;
v. other reports required under specific regulations (e.g. foreign funding, public safety).

b) The Compliance / Legal Officer and Finance Department shall jointly ensure that deadlines are tracked and met.

27.12 Donor and Grantor Reporting
a) Reporting obligations to donors, sponsors and grantors are set out in Chapter 17 and related agreements.
b) HGT shall ensure that donor reports are consistent with internal accounts and legal obligations; no false or misleading reporting is permitted.

27.13 Incident and Mandatory Reporting
a) Where law requires mandatory reporting (e.g. serious crimes, abuse of children, major safety incidents, certain financial irregularities), HGT shall comply, in coordination with Legal/Compliance and relevant authorities.
b) Internal incident reports under Chapters 8, 9, 13, 19 and the Relic & Heritage chapters shall be reviewed to determine whether external reporting is required.

27.14 Public Transparency
a) Within legal and safety limits, HGT may share summary information (e.g. annual reports, major projects, financial highlights) with the public to build trust and accountability.
b) Public information must be truthful and not misleading; sensitive or confidential data shall be protected.


5. Thematic Compliance Areas

27.15 Labour and Employment Compliance
a) HR & Safeguarding shall ensure:

i. employment contracts, working hours, leave and termination comply with Myanmar labour law;
ii. wages and benefits meet or exceed legal minimums;
iii. non-discrimination rules are followed, with consideration of CEDAW and other equality norms;
iv. occupational health and safety standards are addressed.

b) Child labour, forced labour and any illegal employment practices are prohibited.

27.16 Cultural Heritage and Antiquities Compliance
a) Relic & Heritage management shall comply with national laws on antiquities, heritage and export/import, and with UNESCO-related norms described in Sections V and VI.
b) Required permits, notifications or approvals for works, excavations, loans, exhibitions or transfers must be obtained before action is taken.

27.17 Safeguarding, Children and Vulnerable Persons
a) HGT shall align safeguarding practice with CRC principles and national child protection laws.
b) All activities involving children and vulnerable persons must apply safeguarding policies (Chapter 13) and, where required, be reported or registered with relevant authorities.

27.18 Equality and Non-Discrimination
a) Consistent with CEDAW and other human rights standards, HGT shall avoid discrimination on prohibited grounds and shall, where possible, promote gender equality and inclusive participation.
b) Any legal requirements for anti-discrimination policies, complaint mechanisms or reasonable accommodation shall be reflected in HR and safeguarding practice.

27.19 Financial, Tax and AML Compliance
a) The Finance Department shall ensure:

i. adherence to accounting and audit laws;
ii. timely registration and payment of any applicable taxes or fees;
iii. compliance with anti-money-laundering (AML) and countering the financing of terrorism (CFT) rules;
iv. cooperation with lawful audits or investigations.

b) Financial integrity and anti-corruption provisions in Chapters 15–19 are part of regulatory compliance.

27.20 Bioethics, Human Remains and Sacred Materials
a) Where HGT holds or engages with human remains or particularly sensitive sacred materials, it shall consider:

i. relevant national laws;
ii. community norms and religious teachings;
iii. UNESCO and bioethics guidance, especially on respect, dignity and consent.

b) Research, display or transfer involving human remains or analogous materials requires heightened ethical review and compliance with law.

27.21 Health, Safety and Environment
a) Operations and Site Management shall comply with:

i. building, fire and public safety regulations;
ii. health and sanitation requirements;
iii. environmental and waste management regulations.

b) Environmental policies (e.g. energy, water, waste) in sustainability chapters shall support legal compliance and good practice.

27.22 Data Protection and Communications
a) HGT shall comply with applicable laws on data protection, electronic transactions, cybercrime and defamation.
b) Collection, storage and use of personal data must follow Data Protection policies; communications (including online) shall avoid unlawful content.


6. Internal Handling of Non-Compliance

27.23 Detection and Reporting of Non-Compliance
a) Any staff member, volunteer or monastic in an HGT role who becomes aware of potential non-compliance (legal or regulatory breach) must report it promptly to their supervisor, the Compliance / Legal Officer, or through the whistleblowing channel.
b) Non-compliance may include:

i. failures to file required reports;
ii. operation without necessary permits;
iii. repeated breaches of labour, safety or heritage rules;
iv. ignoring lawful instructions of regulators;
v. serious deviations from this Manual that have legal implications.

27.24 Assessment and Investigation
a) Reported issues shall be assessed by the Compliance / Legal Officer, in coordination with relevant departments.
b) Where warranted, a formal investigation shall be initiated, following fair procedures and respecting confidentiality.

27.25 Corrective Actions
Where non-compliance is confirmed, HGT shall:

a) determine the root causes (e.g. lack of awareness, capacity, negligence, intentional misconduct);
b) take steps to correct the situation, which may include:

i. late filing of reports;
ii. seeking regularisation or permissions;
iii. changing procedures or structures;
iv. improved oversight or controls;
v. notifying authorities, where appropriate and required by law.

c) document the corrective action plan and monitor its implementation.

27.26 Internal Sanctions and Disciplinary Measures
a) Where non-compliance results from negligence or misconduct by individuals, HR disciplinary procedures (Chapters 11–14, 19) may apply, up to and including:

i. warnings;
ii. training or reallocation of responsibilities;
iii. suspension or demotion;
iv. termination of employment, volunteer role or appointment.

b) Serious cases involving potential crimes (e.g. corruption, abuse, serious heritage violations) may require referral to state authorities, consistent with legal duties.

27.27 Protection from Retaliation
a) No person shall be subjected to retaliation for reporting potential non-compliance in good faith or cooperating with an investigation.
b) Retaliation itself constitutes a disciplinary offence.


7. Training, Monitoring and Continuous Improvement

27.28 Compliance Training and Awareness
a) HGT shall provide training and awareness-raising on key compliance topics for relevant staff, including:

i. registration and reporting obligations;
ii. labour, safeguarding and equality requirements;
iii. financial, tax and AML rules;
iv. heritage law and permits;
v. data protection and communication rules.

b) Updates on significant legal changes shall be communicated promptly.

27.29 Monitoring and Audits
a) The Compliance / Legal Officer, together with the Audit & Risk Committee, shall monitor compliance performance through:

i. periodic internal reviews;
ii. audits;
iii. risk assessments;
iv. follow-up on regulator feedback.

b) Findings from monitoring and audits shall be used to strengthen policies, procedures and training.

27.30 Engagement with Regulators and Professional Bodies
a) HGT shall maintain constructive relations with regulators, responding promptly to inquiries and participating in dialogue where appropriate.
b) Where useful, HGT may engage with professional or faith-based networks to stay informed about best practices and legal developments.

27.31 Review and Amendment
a) This Chapter and the Compliance Map shall be reviewed periodically, especially when:

i. significant legal or regulatory changes occur;
ii. major compliance incidents arise;
iii. HGT’s size or activities expand significantly.

b) Amendments shall be approved in line with Chapter 3 and communicated to all departments. Updated obligations shall be integrated into training, risk registers and operational procedures.


Chapter 28 – Environmental and Sustainability Policies


CHAPTER 28 – ENVIRONMENTAL AND SUSTAINABILITY POLICIES

1. General Provisions

28.1 Purpose of this Chapter
This Chapter sets out HGT’s policies on environmental protection and sustainability, to ensure that:

a) care for the natural environment is integrated into HGT’s daily practice and long-term planning;
b) heritage sites and activities are managed in a way that reduces harm to ecosystems and climate; and
c) HGT contributes meaningfully to global and national sustainability goals.

28.2 Foundations
This Chapter is guided by:

a) Buddhist principles of ahimsa (non-harm), interdependence and mindful consumption;
b) the Sustainable Development Goals (SDGs), particularly SDG 6 (clean water and sanitation), SDG 7 (affordable and clean energy), SDG 12 (responsible consumption and production), SDG 13 (climate action) and SDG 15 (life on land);
c) relevant Myanmar laws and regulations, including the Environmental Conservation Law, Environmental Impact Assessment (EIA) procedures, and related rules on pollution, waste, land and biodiversity; and
d) HGT’s broader governance, financial and heritage responsibilities.

28.3 Scope
a) This Chapter applies to all HGT sites, activities and projects, including construction, operations, festivals, educational programmes and heritage management.
b) It covers waste and pollution, energy and water use, procurement, construction and event practices, and climate risk assessment for heritage and relic sites.


2. Environmental Principles and Responsibilities

28.4 Principle of Non-Harm and Interdependence
a) HGT recognises that environmental harm—such as pollution, waste and habitat destruction—contradicts the spirit of ahimsa and interdependence.
b) HGT shall strive to minimise environmental harm in its operations and to foster attitudes of care and responsibility among staff, volunteers, monastics, devotees and visitors.

28.5 Preventive and Precautionary Approach
a) HGT shall prioritise prevention of environmental damage rather than only reacting after harm occurs.
b) Where environmental impacts or climate risks are uncertain, HGT shall take a precautionary approach, favoured toward protection.

28.6 Shared Responsibility
a) All departments share responsibility for environmental performance within their areas.
b) The Executive Director shall designate a Sustainability Focal Person or Team to coordinate policy implementation, data collection and awareness-raising.


3. Waste Management and Pollution Prevention

28.7 Waste Hierarchy
a) HGT shall follow a waste hierarchy: reduce → reuse → recycle → safe disposal.
b) Avoidance and reduction of waste shall be prioritised during planning of projects, procurement and events.

28.8 Solid Waste Management
a) All HGT sites shall maintain adequate systems for:

i. provision of bins in appropriate locations;
ii. regular collection and safe storage of waste;
iii. separation of recyclables where feasible; and
iv. appropriate disposal through authorised services.

b) Littering on HGT premises is prohibited. Visitors and staff shall be encouraged to keep sites clean.

28.9 Hazardous and Special Waste
a) Any hazardous materials (e.g. certain chemicals, batteries, electronic waste) shall be handled and disposed of according to law and safe practice.
b) Open burning of waste on HGT premises is prohibited unless specifically authorised by law and safety standards.

28.10 Air, Water and Noise Pollution
a) HGT shall avoid activities that cause excessive smoke, harmful emissions or water contamination, including from cooking, burning, cleaning or construction.
b) Ritual use of candles, lamps and incense shall be managed to limit smoke accumulation and fire risk.
c) Noise levels (e.g. loudspeakers during festivals) shall comply with local regulations and respect the peace of neighbours.

28.11 Chemical Use and Cleaning Products
a) Cleaning and landscaping chemicals shall be used cautiously, preferring low-toxicity and biodegradable options where available.
b) Overuse or careless storage of chemicals that risk spills or contamination is prohibited.


4. Energy and Water Efficiency

28.12 Energy Use and Efficiency
a) HGT shall aim to reduce unnecessary energy consumption by:

i. using energy-efficient lighting and appliances where feasible;
ii. implementing good practices (switching off lights, fans, equipment when not in use);
iii. considering natural lighting and ventilation in design and renovation.

b) Where financially and technically feasible, HGT may explore renewable energy options (e.g. solar systems) for suitable sites.

28.13 Responsible Use of Electricity and Fuel
a) Use of generators, heating/cooling and other high-energy equipment shall consider necessity, efficiency and local environmental impacts.
b) Vehicles used by HGT should be maintained in good condition to reduce fuel consumption and emissions.

28.14 Water Stewardship
a) HGT shall strive to use water carefully, recognising that clean water is a shared and limited resource (SDG 6).
b) Measures may include:

i. prompt repair of leaks;
ii. use of low-flow fixtures where appropriate;
iii. mindful water use in cleaning and gardening;
iv. avoiding pollution of nearby water bodies through runoff or waste.

28.15 Sacred Water Practices
a) Ritual use of water (e.g. sprinkling, washing shrines) shall be organised to avoid unnecessary waste or contamination.
b) Where possible, water used in rituals should be disposed of respectfully in ways that do not harm the environment.


5. Green Procurement, Construction and Events

28.16 Green Procurement Principles
a) Procurement decisions (Chapter 18) should take into account environmental criteria alongside cost and quality, such as:

i. durability and reparability of items;
ii. reduced packaging or recyclable materials;
iii. lower toxicity and environmental footprint;
iv. supplier environmental commitments, where verifiable.

b) Single-use items (e.g. disposable plastics) should be minimised, especially at events.

28.17 Paper and Printing
a) HGT shall reduce paper use through digital communication where feasible, while respecting accessibility needs.
b) When printing is necessary, double-sided printing and use of recycled or certified paper should be considered.

28.18 Construction and Renovation
a) New construction and major renovations shall, as far as possible:

i. comply with environmental and EIA-related laws and requirements;
ii. consider energy-efficient design (orientation, insulation, natural ventilation);
iii. minimise harm to existing trees, habitats and traditional landscape;
iv. use materials that are durable and, where practicable, locally and responsibly sourced.

b) Heritage-sensitive areas must follow additional heritage impact and conservation procedures, in coordination with authorities.

28.19 Event Planning and Festivals
a) Event planning (including festivals, processions and large gatherings) shall incorporate eco-friendly measures, such as:

i. limiting single-use plastics and non-biodegradable decorations;
ii. providing adequate waste and recycling options;
iii. encouraging re-usable utensils where possible;
iv. promoting responsible travel and transport arrangements.

b) Vendors operating during events must adhere to HGT’s waste, pollution and environmental rules as part of their agreements.


6. Climate Risk Assessment and Heritage Sites

28.20 Recognition of Climate Risks
a) HGT acknowledges that climate change (e.g. more intense rainfall, heatwaves, storms, droughts) poses risks to people, relics and heritage sites.
b) These risks shall be considered part of HGT’s overall risk management (Chapter 9).

28.21 Site-Level Climate Risk Assessment
a) For major HGT sites and relic locations, the Relic & Heritage Department, with Site Managers and the Compliance / Risk Officer, shall periodically assess:

i. exposure to flooding, landslides, storms or heat stress;
ii. vulnerability of structures, collections and access routes;
iii. potential impacts on visitors and local communities.

b) Simple climate risk maps or summaries may be developed to guide planning and emergency preparedness.

28.22 Adaptation Measures
Where climate risks are identified, HGT shall consider adaptation measures, such as:

a) improving drainage and water management to reduce flood and erosion;
b) shading and ventilation improvements to mitigate heat impacts on visitors and objects;
c) strengthening or retrofitting vulnerable structures;
d) adjusting festival or event timings to avoid periods of extreme weather;
e) including climate-related scenarios in emergency plans and drills.

28.23 Integration with Conservation Planning
a) Climate risks and adaptation options shall be integrated into conservation strategies for relics and heritage (Chapters 20–22).
b) Long-term planning may consider whether certain relics or collections should be relocated or stored differently to reduce risk, subject to doctrinal and community consultation.


7. Implementation, Training and Monitoring

28.24 Departmental Implementation Plans
a) Each relevant department (e.g. Relic & Heritage, Operations/Sites, Education & Peace, Finance & Procurement) shall identify specific environmental and sustainability actions relevant to its work.
b) These actions may be summarised in an annual sustainability or environmental plan, coordinated by the Sustainability Focal Person/Team.

28.25 Training and Awareness
a) HGT shall provide training and awareness activities on environmental and sustainability topics for staff, volunteers and, where appropriate, monastics and community members.
b) Key themes may include waste reduction, energy and water saving, environmental aspects of heritage care, and climate and disaster risk awareness.

28.26 Educational and Spiritual Integration
a) Environmental themes shall be integrated into educational programmes (Chapter 24), connecting Buddhist teachings with practical sustainability and local environmental issues.
b) Rituals, sermons and public talks may, where appropriate, encourage environmental mindfulness and community action consistent with HGT’s mission.

28.27 Monitoring and Indicators
a) HGT shall seek to monitor simple indicators of environmental performance (e.g. waste volumes, energy or water usage trends, number of green initiatives undertaken).
b) Over time, these indicators may be used to set goals and measure progress.

28.28 Audits and Compliance Checks
a) Environmental practices may be included in internal audits and site inspections, focusing on compliance with this Chapter and relevant laws.
b) Identified problems (e.g. repeated litter issues, uncontrolled burning, unsafe chemical use) shall lead to corrective actions.


8. Review and Continuous Improvement

28.29 Review of Environmental Policies
a) This Chapter shall be reviewed periodically, especially when:

i. environmental or EIA laws and regulations change;
ii. significant climate or environmental incidents affect HGT sites;
iii. new opportunities for improvement or funding for sustainability arise.

b) Proposed changes shall be considered by the Sustainability Focal Person/Team, Compliance / Legal Officer and relevant departments, and approved in line with Chapter 3.

28.30 Continuous Improvement and Learning
a) HGT shall approach environmental management as a continuous learning process, adjusting practices as experience, science and community expectations evolve.
b) Collaboration with other institutions, networks and experts on environmental matters is encouraged where consistent with HGT’s mission and resources.


Chapter 29 – Data Protection and Privacy 


CHAPTER 29 – DATA PROTECTION AND PRIVACY

1. General Provisions

29.1 Purpose of this Chapter
This Chapter sets out HGT’s rules for data protection and privacy, in order to:

a) safeguard personal and sensitive information entrusted to HGT;
b) respect the dignity, safety and rights of individuals whose data HGT holds; and
c) ensure compliance with applicable laws and recognised best practices.

29.2 Foundations
This Chapter is guided by:

a) GDPR-style principles of lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity, confidentiality and accountability;
b) relevant Myanmar laws and regulations, including provisions of the Electronic Transactions Law and any other data, cyber, records or communication laws;
c) Vinaya and Buddhist ethics on confidentiality of confessions, sensitive matters, respect for others and non-harm; and
d) HGT’s safeguarding, HR, heritage and compliance policies.

29.3 Scope
a) This Chapter applies to all personal data processed by HGT in any form (paper, electronic, audio-visual), including data on staff, volunteers, monastics in HGT roles, students, visitors, donors, community members and other stakeholders.
b) It covers data collection, storage, use, sharing, retention and destruction, as well as response to data breaches and requests from individuals.


2. Definitions and Principles

29.4 Personal Data
“Personal data” means any information relating to an identified or identifiable living individual, such as name, contact details, identification numbers, images or other factors specific to their identity.

29.5 Sensitive (Special Category) Data
a) “Sensitive data” includes information about:

i. religious or philosophical beliefs;
ii. health or disability;
iii. children and vulnerable persons;
iv. disciplinary or safeguarding cases;
v. criminal allegations or convictions;
vi. financial hardship and similar sensitive matters.

b) Such data requires heightened protection and limited access.

29.6 Data Controller and Processor
a) For the purposes of this Manual, HGT acts as a Data Controller, deciding why and how personal data is processed.
b) External service providers who process data on behalf of HGT (e.g. cloud services, payroll, survey platforms) act as Data Processors and must be bound by appropriate agreements.

29.7 Core Data Protection Principles
HGT shall:

a) process personal data lawfully, fairly and transparently;
b) collect data for specific, explicit and legitimate purposes, and not process it in ways incompatible with those purposes;
c) limit data collection to what is necessary for the stated purpose;
d) keep data accurate and up to date where needed;
e) retain data no longer than necessary;
f) ensure appropriate security and confidentiality;
g) be accountable, documenting relevant decisions and measures.


3. Data Classification and Inventories

29.8 Data Classification
HGT shall classify data into categories for management purposes, including:

a) Public Data – information intended for public dissemination (e.g. authorised website content, published reports);
b) Internal Data – operational information shared within HGT but not publicly (e.g. internal memos, non-sensitive programme data);
c) Confidential Personal Data – personal data requiring restricted access (e.g. HR records, participant lists);
d) Highly Sensitive Data – sensitive personal and safeguarding data (e.g. health, child protection, disciplinary cases, confessions-like disclosures in pastoral/safeguarding contexts).

29.9 Data Inventories (Records of Processing)
a) Relevant departments shall maintain data inventories describing:

i. types of personal data collected;
ii. purposes of processing;
iii. categories of individuals concerned;
iv. storage locations (physical and digital);
v. access rights and protection measures;
vi. retention periods.

b) These inventories help ensure transparency, risk management and compliance.

29.10 Role of Data Protection / Privacy Focal Person
a) HGT shall designate a Data Protection / Privacy Focal Person (or assign this role to the Compliance / Legal Officer) to:

i. advise on data protection obligations;
ii. monitor implementation of this Chapter;
iii. respond to data subject requests and breaches;
iv. provide or coordinate training.

b) This role does not replace departmental responsibilities for proper data handling.


4. Lawful Basis for Collection and Use

29.11 Lawful Basis
HGT shall process personal data only when a lawful basis exists, such as:

a) consent of the individual (e.g. for photos, recordings, certain communications);
b) necessity for contractual relationships (e.g. employment, volunteer agreements, donor pledges);
c) compliance with legal obligations (e.g. reporting to authorities);
d) protection of vital interests (e.g. emergencies affecting health or safety);
e) performance of HGT’s legitimate mission and activities, balancing HGT’s aims with individuals’ rights (e.g. managing programmes, safeguarding heritage, managing communities).

29.12 Transparency Notices
a) When collecting personal data, HGT shall inform individuals, in clear language, about:

i. who is collecting the data;
ii. purposes of use;
iii. legal basis;
iv. who it may be shared with;
v. how long it will be kept;
vi. how to exercise rights (access, correction, etc.).

b) This may be done through privacy notices, forms, websites or verbal explanations, depending on context.

29.13 Data Minimisation
a) HGT shall only collect data that is relevant and necessary for the stated purposes.
b) Collecting excessive information “just in case” is discouraged, especially for sensitive data.


5. Storage, Access Control and Retention

29.14 Secure Storage
a) Personal data shall be stored securely, using:

i. locked cabinets or rooms for paper files;
ii. password-protected systems and, where appropriate, encryption for digital files;
iii. secure backup procedures to prevent loss.

b) Highly sensitive files (e.g. safeguarding, disciplinary, health) require extra protection and restricted access.

29.15 Access Control
a) Access to personal data shall be granted on a need-to-know basis.
b) Each department shall define which roles may access which data categories and ensure that:

i. user accounts and permissions reflect these rules;
ii. access rights are removed or adjusted when people leave roles or change duties.

29.16 Retention Periods
a) Personal data shall be kept only as long as necessary for the purpose for which it was collected, taking into account legal obligations (e.g. employment, tax, safety, heritage).
b) HGT shall adopt a Retention Schedule for major data types (e.g. HR files, financial records, safeguarding files, research data) specifying typical retention times and review dates.

29.17 Secure Disposal and Anonymisation
a) When data is no longer needed, it shall be securely disposed of or anonymised, for example:

i. shredding or secure destruction of paper records;
ii. secure deletion of electronic files, including from backups where possible;
iii. anonymisation of research data where long-term analysis is desired without identifying individuals.

b) Disposal actions shall respect heritage and archival requirements where certain records must be preserved for historical or legal reasons.


6. Consent for Photos, Recordings, Research and Communications

29.18 Consent Principles
a) When required, consent shall be:

i. freely given (no coercion);
ii. specific and informed (clear about use);
iii. documented (written, recorded or clearly noted).

b) Individuals shall be able to withdraw consent where practical, especially for future uses.

29.19 Photos and Video
a) For public events where photography and filming are expected, HGT shall:

i. inform participants (e.g. signs, announcements);
ii. give options where possible for individuals who do not wish to be prominently featured.

b) For close-up images or identifiable portraits, especially of children or vulnerable persons, explicit consent from the individual or legal guardian is required before publication or promotional use.

29.20 Audio/Video Recordings of Teachings and Events
a) Recordings intended for public sharing shall avoid revealing sensitive personal data (e.g. questions that disclose personal trauma) without consent.
b) Where questions or discussions reveal sensitive information, either obtain explicit consent or edit the recording to protect identities.

29.21 Research Data and Interviews
a) Research involving interviews, surveys or observations shall use consent forms or scripts that explain:

i. purpose and possible risks/benefits;
ii. voluntary nature of participation;
iii. how data will be stored and used;
iv. whether identities will be anonymised;
v. how to withdraw if desired (within reasonable limits).

b) Special care is required for children, vulnerable adults and sensitive topics; parental/guardian consent and additional safeguards may be required.

29.22 Communications (Mailing Lists, Newsletters, SMS, Email)
a) HGT shall obtain consent or an appropriate lawful basis before adding individuals to mailing lists or sending regular communications.
b) Recipients shall have a simple way to unsubscribe or opt out of non-essential communications.


7. Data Sharing and Third Parties

29.23 Internal Sharing
a) Personal data may be shared internally between departments only when necessary for legitimate purposes (e.g. HR working with Finance; Education coordinating with Safeguarding).
b) Internal sharing must respect classification, access controls and confidentiality.

29.24 External Sharing
a) Sharing personal data with external parties (e.g. authorities, partners, service providers) must be based on:

i. a lawful basis (consent, contract, legal obligation, vital interests, legitimate interest); and
ii. appropriate safeguards (e.g. agreements, secure transfer methods).

b) HGT shall not sell personal data to third parties.

29.25 Data Processors (Service Providers)
a) When using external providers to process data on HGT’s behalf (e.g. cloud hosting, email services, survey tools), HGT shall:

i. select providers that offer adequate security and confidentiality;
ii. enter into written agreements specifying data protection obligations;
iii. ensure data is not used by providers for their own unrelated purposes.

29.26 Sharing with Authorities
a) Personal data may be disclosed to authorities when required by law or court order, or when necessary to protect vital interests (e.g. safety, health, serious crime).
b) Such disclosures shall be documented and restricted to the minimum necessary information.

29.27 Cross-Border Transfers
a) If personal data is stored or processed outside Myanmar (e.g. foreign cloud servers), HGT shall consider legal and security implications and apply appropriate safeguards.
b) Individuals shall be informed when their data may be processed in other countries, where feasible.


8. Rights of Individuals (Data Subjects)

29.28 Right to Information
Individuals have the right to know, within reasonable limits:

a) whether HGT holds their personal data;
b) the purposes for which it is used;
c) categories of data and potential recipients.

29.29 Right of Access
a) Individuals may request access to their personal data held by HGT.
b) HGT shall respond within a reasonable timeframe, subject to legal restrictions and protection of others’ privacy or safety.

29.30 Right to Rectification
a) Individuals may request correction of inaccurate or incomplete personal data.
b) HGT shall take reasonable steps to update records promptly, where appropriate.

29.31 Right to Restriction or Objection (Where Applicable)
a) In some cases, individuals may request that processing of their data be limited or object to certain uses (e.g. direct marketing).
b) HGT shall consider such requests in light of legal obligations, mission needs and the rights of others, and shall explain its decision.

29.32 Right to Withdraw Consent
Where processing is based on consent (e.g. use of images in promotion), individuals may withdraw consent for future uses, and HGT shall honour this as far as reasonably possible.


9. Data Breaches and Incident Response

29.33 Definition of Data Breach
A “data breach” includes any incident leading to:

a) unauthorised access to personal data;
b) loss, theft or destruction of personal data;
c) accidental disclosure or exposure of personal data to unauthorised recipients.

29.34 Reporting Suspected Breaches
a) Any staff member, volunteer or monastic in an HGT role who becomes aware of a suspected or actual data breach must report it immediately to their supervisor and the Data Protection / Privacy Focal Person (or Compliance / Legal Officer).
b) Delay increases risk and is discouraged.

29.35 Initial Assessment and Containment
Upon receiving a breach report, the designated officer shall:

a) assess what data is involved, how many individuals are affected, and potential harm;
b) take immediate steps to contain the breach (e.g. revoke access, shut down compromised accounts, recover misplaced files where possible);
c) document key facts and actions taken.

29.36 Notification and Remedies
a) Where a breach is likely to result in significant harm to individuals (e.g. risk of identity theft, serious reputational or safety harm), HGT shall consider:

i. informing affected individuals in clear language;
ii. advising them on steps to protect themselves;
iii. notifying relevant authorities if required by law or good practice.

b) Decisions on notification shall balance transparency with security and legal considerations.

29.37 Post-Incident Review
a) After a breach, HGT shall review:

i. causes and contributing factors;
ii. adequacy of existing controls;
iii. lessons to prevent recurrence.

b) Changes may include technical upgrades, policy adjustments, training or disciplinary action where negligence or misconduct is involved.


10. Training, Awareness and Review

29.38 Training and Awareness
a) Staff, volunteers and monastics in HGT roles who handle personal data shall receive basic training on:

i. this Chapter and related SOPs;
ii. confidentiality obligations and right-speech ethics;
iii. secure handling of paper and digital files;
iv. recognising and reporting data incidents.

b) Specialised training shall be provided to HR, Finance, Safeguarding, IT, Relic & Heritage and Communications staff, as they process more sensitive data.

29.39 Confidentiality Commitments
a) Employment contracts, volunteer agreements and relevant role descriptions shall include confidentiality clauses consistent with this Chapter.
b) Persons entrusted with highly sensitive information (e.g. safeguarding, confessional or pastoral disclosures) bear a heightened duty of discretion, subject to legal reporting obligations.

29.40 Monitoring and Audits
a) Data protection practices may be included in internal audits and compliance reviews (e.g. access control checks, review of consent processes, examination of breach logs).
b) Findings shall inform improvements to systems, training and procedures.

29.41 Review and Amendment
a) This Chapter shall be reviewed periodically, especially when:

i. relevant laws or regulations change;
ii. significant data incidents occur;
iii. new technologies or systems are introduced.

b) Amendments shall be approved in line with Chapter 3 and communicated to all relevant personnel. SOPs, forms and consent templates in the Appendices shall be updated accordingly.