Effective Date: October 1, 2025
The Paediatric Society of Papua New Guinea (PSPNG) is committed to protecting the privacy, confidentiality, and security of all Personal Information (PI) and Sensitive Personal Health Information (PHI) entrusted to us by our members, partners, patients, and the public.
This Policy is formulated based on international best practices (including principles aligned with the draft PNG National Data Governance & Data Protection Policy 2024), recognising the sensitive nature of the data we handle, particularly in the health sector.
1. Scope and Definitions
This Policy applies to all data processing activities undertaken by the PSPNG, whether digital or physical, related to:
Members: Paediatricians, trainees, nurses, and health workers.
Public Health Activities: Data collected through programs like the Paediatric Hospital Reporting (PHR) program and research.
Financial Transactions: Payments for membership fees, donations, or event registrations.
Key Definitions:
Personal Information (PI): Data that can identify an individual (e.g., name, address, email, phone number, employment details).
Sensitive Personal Health Information (PHI): Information relating to the physical or mental health of a data subject, the provision of health services, or medical records, including child morbidity and mortality data.
Data Subject: The individual to whom the PI or PHI relates (e.g., a member or a patient/child receiving care).
Data Controller: PSPNG, which determines the purposes and means of processing personal data.
2. Principles of Data Processing
PSPNG adheres to the following core principles for all data processing:
3. Collection of Personal Information
PSPNG collects data primarily for three categories of operations:
3.1. Membership and Administration Data (PI)
3.2. Public Health and Research Data (PHI)
This category is collected primarily through collaborative programs (e.g., PHR).
What is collected: Highly sensitive information, including anonymised or de-identified data on child morbidities, mortalities, clinical outcomes, and care practices.
How it is handled:
De-identification: All individual identifying markers (names, specific dates of birth, exact addresses) are removed or aggregated at the earliest possible stage before being used for reporting, advocacy, or publications. The goal is to produce evidence-based recommendations rather than identifying individuals.
Consent: Collection and submission of PHI is predicated on strict institutional consent protocols (e.g., from hospitals, clinics, or parents/guardians) that align with the National Department of Health guidelines.
No Direct Patient Identification: The PSPNG’s repository of PHI for national reporting is primarily aggregated data that cannot be used to trace back to a single child/patient.
4. Payment Data Security Standards (BSP Compliance)
PSPNG uses third-party payment gateways for processing membership dues, conference fees, and donations. PSPNG will never store full credit card details on its own servers or in its databases.
To ensure compliance with local best practices, particularly regarding the standards promoted by the Bank of South Pacific (BSP), PSPNG mandates the following security practices when handling financial transactions:
Secure Processing Environment: All payment data is processed using reputable, established, and compliant payment gateways that adhere to global standards (e.g., PCI DSS).
Encryption: All data related to payment (card numbers, CVC codes, expiry dates) transmitted from the user’s browser to the payment processor must be protected using strong encryption (e.g., 128-bit SSL/TLS or higher), aligning with BSP’s stated security minimums for data-in-transit.
Non-Retention of Card Details: PSPNG only retains transaction records (amount, date, payer name, status, and the last four digits of the card number for reference). Full primary account numbers (PAN) are not stored.
Tokenisation: Where recurring payments are required (e.g., annual membership), the payment processor will use secure tokens instead of storing the card details. PSPNG stores only the non-sensitive token.
Audit and Review: PSPNG commits to regularly reviewing the security protocols and certifications of its chosen payment processing partners to ensure continued high standards of protection.
5. Data Security and Safeguards
PSPNG employs physical, technical, and organisational security measures to protect data integrity and confidentiality:
Technical Measures:
Use of Multi-Factor Authentication (MFA) for accessing systems holding PI/PHI.
Access Control: Strict role-based access to PI and PHI, ensuring the principle of least privilege (only staff/volunteers who need the data can access it).
Data stored digitally is encrypted at rest wherever PHI is involved.
Organisational Measures:
All PSPNG staff and volunteers undergo mandatory data privacy and security training.
A designated Data Protection Lead (or equivalent officer) is appointed to oversee compliance.
Physical Measures:
Hard copies of PI/PHI (if any) are stored in locked cabinets or restricted-access areas.
Secure disposal (shredding, certified digital destruction) of records when no longer required.
6. Disclosure and Sharing of Data
PSPNG will only disclose data in the following circumstances:
With Consent: When the Data Subject has given explicit consent for the disclosure (e.g., sharing a member directory with a collaborating medical association).
To Partners for Stated Purposes: To third-party service providers (e.g., conference organizers, email hosts) who assist PSPNG in delivering services, provided they agree to uphold the same high standards of data security and confidentiality under a written contract.
Public Health Reporting (Aggregated Data): PHI may be shared with the National Department of Health (NDOH) or academic partners for the purpose of national planning, policy development, and public health improvement, but only in an aggregated or de-identified format suitable for public reports.
Legal Obligation: Where disclosure is mandatory by law, court order, or governmental requirement in Papua New Guinea.
PSPNG will never sell PI or PHI to third parties for commercial purposes.
7. Data Retention and Disposal
We retain PI and PHI for the period necessary to fulfil the purposes outlined in this Policy, or as required by PNG law and medical best practice.
Data Type
Retention Period Guideline
Membership Data
Retained for the duration of membership plus a maximum of five (5) years after membership ceases for legal/audit purposes.
Financial Transaction Data
Minimum of seven (7) years to comply with financial and audit requirements.
Public Health Data (PHI)
De-identified and aggregated data is retained indefinitely for historical public health tracking and analysis. Source documents containing PI/PHI are disposed of securely once the de-identification and aggregation process is complete and verified.
8. Data Subject Rights (Access and Correction)
Data Subjects have the right to:
Access: Request access to the PI that PSPNG holds about them.
Correction: Request the correction of inaccurate or incomplete PI.
Withdraw Consent: Withdraw consent for processing data where consent was the basis for collection (this does not affect processing based on legitimate interest or legal obligation).
Erasure (Right to be Forgotten): Request the deletion of their PI, subject to any overriding legal or regulatory requirements (e.g., retaining financial records).
All requests must be submitted in writing to the Data Protection Lead (see Section 10). PSPNG will respond to such requests within a reasonable timeframe.
9. Data Breach Protocol
In the event of a security breach involving PI or PHI, PSPNG commits to:
Containment: Immediately take steps to stop the breach and limit further exposure.
Assessment: Investigate the scope, severity, and potential impact of the breach, identifying the data subjects and data types affected.
Notification: If the breach poses a serious risk to the rights and freedoms of the Data Subject, PSPNG will notify affected individuals and relevant regulatory bodies (as mandated by future PNG data law or international partners) without undue delay.
Remediation: Implement necessary changes to systems and procedures to prevent recurrence.
10. Contact Information
For any questions, concerns, or requests regarding this Privacy Policy or the processing of your data, please contact the PSPNG Data Protection Lead:
Paediatric Society of Papua New Guinea
Attention: Data Protection Lead | CEO |Chairperson
Email: [Placeholder Email Address – To be inserted by PSPNG]
Address: [Placeholder Physical Address – To be inserted by PSPNG]