Data Protection and Cybersecurity for NGOs
Description
As African countries increasingly adopt data protection legislation, NGOs handling sensitive beneficiary information face new compliance obligations. This course covers practical data protection principles, basic cybersecurity hygiene, and how to respond to a data incident. Learners will explore the core principles of data protection – consent, data minimisation, purpose limitation, and accountability – and learn how to apply them in their day‑to‑day work. The course also covers common cybersecurity threats (such as phishing and ransomware) and simple, low‑cost measures to prevent them. By the end, learners will be able to apply core data protection principles to beneficiary data, implement basic cybersecurity practices for a small team, draft a simple data protection policy, and respond appropriately to a data breach or incident. This is an essential course for every NGO staff member who handles personal data.
What will you learn
-
Apply core data protection principles – consent, minimisation, purpose limitation, and accountability – to beneficiary data.
-
Implement basic cybersecurity practices for a small team – strong passwords, 2FA, and phishing awareness.
-
Draft a simple data protection policy appropriate for your organisation's size and context.
-
Respond appropriately to a data breach or incident, including notification and mitigation.
-
Identify common cybersecurity threats – phishing, ransomware, and social engineering – and take preventive action.
-
Manage sensitive data categories (health, protection, biometrics) with appropriate safeguards.
-
Build a culture of data protection and cybersecurity awareness within your team.
Requirements
- Digital Tools for NGO Operations (recommended)
- No technical/IT background required
Lessons
- 10 Lessons
- 00:07:15 Hours
About instructor
