AWRA OpsHub Search

Who Else Is on That System? Answering the Donor’s Data Clause

The data annex arrives with the grant agreement, and one question in it stops the programme team cold. How to read the donor’s data clause, and how to answer it in a sentence instead of a meeting.

NGOs & Nonprofits Washingtone Aura 8 min read

The grant is agreed. The budget is approved. Then the agreement arrives with an annex on data protection, and somewhere in it is a question nobody on the programme team can answer on their own: where will beneficiary, staff and supplier records be held, and who else has access to the system that holds them?

What the clause is really asking

Donor data clauses are written in many styles, and funders from Europe often draw on European data protection law, but underneath they tend to ask the same five things. Read your annex against this list before you answer any of it.

  • Where the records are held: which system, run by whom, hosted where.
  • Who else is on that system, and what keeps them away from your records.
  • Who on your side can see which records, and whether that access is recorded.
  • What happens at the end of the grant: can you get everything out, and can it then be removed.
  • Whether you can show it, rather than assert it, when the funder’s auditor visits.

Three of those five are about your own controls, and the system only helps you evidence them. Two of them, where and who else, are about the system itself. Those are the two where the hosting arrangement decides how long your answer is.

Three answers, and how each one reads

What you write How a reviewer reads it
“A cloud system shared with other organizations, separated by the software.” Accurate and often acceptable. It usually prompts follow-up questions about how the separation works and what happens if it fails.
“Our own instance of the system. No other organization is on it.” Closes the who-else question in one line. The follow-ups move to your own access controls, where they belong.
“A server in our country office.” Answers where, then raises who patches it, who backs it up, and what happens when the person who set it up leaves.

The best answer to a data clause is the one that does not generate a second meeting.

Why the short answer matters to a programme

A long answer is not wrong. It is slow. Every follow-up round on a data annex is time the grant is signed but the programme is not running, and it lands on people who would rather be in the field. Organizations that receive funding from several donors face the same question several times a year, in several formats, and each one wants it in their own words.

A dedicated instance turns the who-else question into a fact you can state the same way every time: your organization has its own instance, with its own database, its own encryption key and its own backups, and no other organization is on it. That sentence survives being copied into a funder’s template.

What stays your job

Hosting answers where and who else. It does not answer the rest of the annex for you, and no vendor should pretend it does. Consent, retention periods, who on your team can see beneficiary records, and what you share with implementing partners are decisions your organization makes and documents. The system’s part is to make them enforceable and visible: roles that limit who sees what, an audit trail of who changed which record, and an export of your records at the end of the grant.

If you are working out which of those obligations sit with you and which with your provider, controller or processor sets out the split. And because the auditor who reads the data annex usually reads the accounts as well, audit-ready NGOs and tracking donor funds properly are the natural companions to this one.

Before you sign the annex

Can we say in one sentence where our records are held?

What you need

A named system, a named operator, a hosting region.

Where it comes from

Your provider, in writing.

Can we say who else is on that system?

What you need

Either “nobody” or a clear description of the separation.

Where it comes from

The hosting arrangement you choose.

Can we list who on our team sees beneficiary records?

What you need

Roles, not names alone.

Where it comes from

Your own role setup, reviewed each quarter.

Can we hand everything back at grant close?

What you need

A full export in a usable format.

Where it comes from

The system’s export, tested before you need it.

The straight answer

What AWRA OpsHub does today

  • A dedicated instance used by your organization alone, with its own database, encryption key, storage and backups.
  • Roles that limit who sees which records, set by your own administrators.
  • An audit trail of who changed which record, and when.
  • An export of your records when a grant or a relationship ends.

More we can add to your workspace

  • A hosting region of your choosing, for an annex that names one.
  • The AWRA mobile app connected to your dedicated instance, for field staff capturing on phones.
  • A sub-processor list trimmed to your agreement, for example with the AI assistant switched off.

Where we point you to a specialist

  • We will not sign your donor annex or tell you it is satisfied. The agreement is between you and your funder, and your data protection lead or counsel should confirm the answers.

Each of these can be scoped into a dedicated-instance quote.

More we can add

For donor-funded programmes

Where a funder’s terms go further than the standard instance, these are the additions we build.

Region set in the contract

For an annex that requires records to stay in a named country or region.

Field capture on your instance

The mobile app connected to your own address, for teams recording in the field.

A trimmed provider list

Optional services switched off for your instance so the provider list matches your agreement.

How it works: send us the clause, we return a written scope and cost, and once agreed it is built into your instance.

Send us your data annex

The case

Most of a donor data annex is about your own controls, and no hosting arrangement answers it for you. The one question hosting does answer, who else is on the system, is the one that causes the most follow-up. A dedicated instance answers it in a sentence you can reuse for every funder.

One sentence for every funder

Your own AWRA, used by your organization alone. Available to set up now.

See the dedicated instance

Frequently asked questions

What do donor data protection clauses usually ask?

Where records are held, who else is on the system, who on your side can access them, what happens at the end of the grant, and whether you can show all of this to an auditor.

Does a dedicated instance make us compliant with our donor agreement?

No system does that on its own. A dedicated instance answers where your records are and who else is on the system. Consent, retention and access decisions remain your organization’s, and your data protection lead or counsel should confirm the answers.

Can we get our records out when a grant ends?

Yes. Your records can be exported, and the organization’s data can then be removed.

Is a shared system acceptable for donor-funded work?

Often, yes. Many funders accept a shared service with a clear description of how organizations are kept apart. A dedicated instance shortens the answer where a funder asks for more.

Share this article

LinkedIn X WhatsApp

Help Center

Need a quick answer while you read?

Run inventory, procurement, assets, sales, and field work with approved AWRA guidance for setup, migration, integrations, security, pricing, and support.

Search all approved AWRA public help articles.

Open Help Center