Trust & sovereignty
Data Governance Charter.
Sovereignty is handled by architecture, not by promise. This charter sets out how SHENGO holds, protects and accounts for consultation data.
CHARTER v0.9 UNDER REVIEW — TESTING PHASE · JUNE 20261. Purpose and scope
This charter governs all data processed by the SHENGO platform: consultation content, stakeholder registration data, synthesis artefacts and public records. It applies to SHENGO, its infrastructure providers, and any partner with data access.
2. In-country data residency
Personal data of participants is hosted on national infrastructure inside Ethiopia. The AI synthesis layer processes anonymised submission text only; names, emails, phone numbers and institutional affiliations never leave in-country systems without explicit government authorisation. This architecture is designed for compliance with Ethiopia's Personal Data Protection Proclamation (No. 1321/2024).
3. Government data ownership
Each ministry retains full ownership of its consultation data. Data is portable: a ministry may export its complete consultation record — submissions, synthesis artefacts and audit trail — in open formats, at any time, without fee.
4. Four-tier access control
| Tier | Who | Access |
|---|---|---|
| Administrator | SHENGO platform operations | System operation; no access to raw PII, which is segregated on in-country infrastructure |
| Ministry officer | Authorised government staff | Own ministry's consultations, submissions and synthesis |
| Verified stakeholder | Registered experts, civil society, citizens | Own submissions and their verification records |
| Public viewer | Anyone | Published consultation records and outcome mappings |
5. Anonymity and contributor protection
Citizens may submit anonymously. Anonymous submissions are recorded with a one-way token and are never linked back to an identity. Once logged, no submission can be quietly edited or removed from the record.
6. Retention and deletion
| Record class | Retention |
|---|---|
| Active consultation records | Duration of the consultation plus the policy decision cycle |
| Closed consultation records | Retained per the owning ministry's records schedule |
| Public records | Published indefinitely as part of the accountability record |
| Registration PII | Deleted on verified request, subject to legal holds; secure-deletion protocol applies |
7. Independent oversight
An independent oversight board reviews SHENGO's data practices, conducts an annual governance audit, and publishes its findings together with any remediation timeline. The board is being constituted during the testing phase; its composition and terms of reference will be published on this page.
8. Incident response
Suspected data incidents are contained, assessed and notified to affected ministries and, where required, to the competent authority and affected individuals. A public post-incident summary is added to the annual audit record.
9. Changes to this charter
Material changes are versioned, dated and announced on this page before they take effect. The charter cannot be weakened retroactively for data already collected.
Contact
Data governance questions and requests: compliance@shengo.com
General: hello@shengo.com