The Change Architect logo The Change ArchitectHumanitarian Governance

TCAA professional pathway

AI, data protection, and digital security for NGOs.

A seven-part pathway for protecting people, information, services, and organizational trust through practical governance, safer digital habits, incident decisions, recovery, and tested resilience.

Learning time7 guided hours
Learning checks7 lessons + 7 microchecks
Assessment8 practice + 20 final draft
OutputDigital Resilience Pack
Humanitarian professionals reviewing digital information and organizational safeguards
Digital resilience connects governance, information visibility, daily safeguards, incident decisions, and trusted recovery.

Course modules

Move from governance to trusted recovery.

Orientation
Govern digital risk and critical operations

Connect accountable roles, risk priorities, humanitarian consequences, essential services, and escalation authority.

Part 1
Map processing, assets, and possible harm

Trace purpose, affected people, data, systems, partners, retention, dependencies, and confidentiality, integrity, and availability risks.

Part 2
Select tools and vendors responsibly

Review data use, retention, access, assurance, subprocessors, continuity, rights support, configuration, change, and exit.

Part 3
Control identity, access, devices, and sharing

Apply named accounts, MFA, least privilege, separation of duties, secure collaboration, phishing response, and joiner-mover-leaver controls.

Part 4
Minimize, de-identify, retain, and delete

Build safer document and AI workflows that account for indirect identifiers, generated outputs, logs, temporary copies, and authorized holds.

Part 5
Detect, respond, communicate, and recover

Report quickly, contain without destroying evidence, assess harm, support authorized notification decisions, restore trusted operations, and learn.

Part 6
Defend the Digital Resilience Pack

Test account takeover, exposed-link, and unauthorized-AI-upload scenarios and present a ninety-day improvement decision.

Practical outcomes

Participants should leave with safer habits and reusable controls.

7guided lessons
7decision microchecks
28assessment questions
12working resources

Assessment preview

See the certificate-track task without exposing the private key.

Assessment blueprint

A public outline of the assessment areas, evidence expectations, and certificate boundary. It does not include the admin answer key or scoring decisions.

Assignment brief

A practical data-safety workflow task using fictional or redacted examples only. Real sensitive data must never be submitted in public previews or unsafe tools.

Public starter materials

Twelve practical resources for safer daily work.

The pathway is grounded in the official EU General Data Protection Regulation, EDPB Opinion 28/2024 on AI models, NIST Cybersecurity Framework 2.0, OCHA humanitarian cyber-threat guidance, and the ICRC Handbook on Data Protection in Humanitarian Action. It is professional education, not legal advice, a compliance audit, penetration testing, or security certification.

Protection boundary

This course supports safer practice, not legal certification.

The course supports proportionate governance and safer practice. It cannot determine whether a real breach is legally notifiable, replace incident-response specialists, certify GDPR compliance, or prove technical security. Automated paid certificate release remains inactive until enrollment, payment, private access, reviewed assignment, certificate issue, public verification, correction, revocation, learner support, and admin controls are tested together.

Related learning

Connect data protection with field systems and responsible AI policy.

Responsible AI for NGOs

Build the policy, risk, and approval rules that should sit behind AI-supported work.

Field Data Collection With KoboToolbox

Use practical field-data workflows before moving data into reports, analysis, or learning products.