Privacy Policy for Bullyid App Online Abuse & Non-Consensual Intimate Imagery (NCII) Abuse Help Centre
Last updated: August 2026
1. About this Notice
This Notice applies specifically to the Bullyid App Online Abuse & Non-Consensual Intimate Imagery (NCII) Abuse Help Centre. It should be read together with the general Bullyid App Privacy Notice.
The Help Centre supports adults aged 18 and above affected by the non-consensual sharing, threatened sharing or misuse of intimate images or videos, including sextortion and image-based sexual abuse.
This Notice explains what information we need, how we use it, when we may share it and the choices available to you.
2. Data minimisation: what to send us
Please provide only what is reasonably necessary for us to understand the report and assist with a takedown or support request.
We may ask for:
- your name or chosen identifier;
- contact details so that we can respond;
- confirmation that you are 18 or older;
- the platform/site where the content appears;
- the relevant URL(s);
- usernames or account identifiers involved;
- a short description of what happened;
- screenshots showing the post, account, threat or reporting context; and
- other evidence only where it is genuinely necessary for the requested support.
Where possible, do NOT send us the intimate image/video itself. Re-copying or downloading intimate content can increase risk. A URL and contextual screenshot may be sufficient for platform reporting.
Do not upload or send us sexual images involving a person who is or may be under 18. If the material may involve a child, stop and use the child-protection route described in Section 10 below.
3. Why we use your information
We may use your information to:
- assess whether the request is within the Help Centre’s scope;
- communicate with you and provide non-judgemental support;
- help you prepare or submit a content-reporting/takedown request;
- provide or arrange psychological or legal support where available and requested;
- provide safety, evidence-preservation and account-security guidance;
- protect you or another person where a serious safeguarding risk arises;
- maintain minimal case records for accountability, quality and legal requirements; and
- create de-identified aggregate learning about TFGBV trends where lawful and ethically appropriate.
Identifiable case material will not be used for publicity, fundraising stories, AI training or unrelated research without separate lawful authority and, where required, explicit informed consent.
4. Legal basis and consent
Where we rely on your consent, we will ask for consent for the specific processing or disclosure involved. For example, consent to ask a social media platform to remove content is not automatically the same as consent to report the matter to law enforcement.
Other lawful bases may apply where necessary to comply with legal obligations, protect vital interests, provide a requested service, safeguard a person at serious risk or establish/defend legal rights.
5. Sharing information with platforms and removal partners
If you ask us to assist with takedown, we may share the minimum information required by the relevant platform, hosting provider or trusted removal partner.
We will avoid sending unnecessary identity documents, counselling information or unrelated case details to a platform.
Third-party platforms decide their own enforcement actions. Bullyid App cannot guarantee removal or a response within a fixed time.
6. Police, government and other authorities
Submitting an NCII report to Bullyid App does not automatically create a police report and does not automatically authorise us to forward your entire case file to police, Bareskrim, a ministry or another authority.
We may disclose limited information to an authority where:
- you expressly ask or authorise us to make the referral or disclosure;
- disclosure is required by applicable law or a valid legal process;
- child safeguarding requires action; or
- disclosure is lawful and proportionate to address a serious or imminent risk to a person’s safety.
Where it is safe and lawful to do so, we aim to explain the proposed disclosure before it occurs.
7. Evidence handling
We treat NCII material as highly sensitive.
Our practice is to:
- collect the minimum evidence necessary;
- prefer links, hashes, identifiers or contextual screenshots over duplicate copies of intimate content where possible;
- restrict access to authorised staff/professionals with a case need;
- minimise repeated viewing, downloading or redistribution;
- keep safeguarding records separate or appropriately restricted;
- preserve evidence only where there is a clear case, legal or safety need; and
- securely delete or anonymise material when retention is no longer justified.
8. Withdrawing consent and privacy rights
You may withdraw consent at any time where consent is the legal basis for future processing. Withdrawal does not make earlier lawful processing invalid and may not require deletion of information that must be retained under another lawful basis.
There is no blanket 24-hour limit on making a privacy request.
You may also exercise the rights described in the general Bullyid App Privacy Notice, subject to applicable law and relevant exceptions.
Contact: contact [AT] bullyid.org
9. Retention
NCII case information is retained only for as long as necessary for the support/takedown purpose, safeguarding, professional obligations, legal claims or another lawful requirement.
We do not retain intimate material merely because storage is technically possible. Our internal retention schedule and digital-evidence handling rules apply.
10. If the person in the image is under 18
The adult NCII Help Centre does not accept sexual images of children.
If the image/video involves a person who is under 18, may be under 18, or was under 18 when the material was created:
- do not download, forward or repeatedly view the image;
- do not upload the image to the Bullyid App adult NCII form;
- preserve non-image information such as the URL, username, date/time and a description where safe;
- seek child-protection support; and
- if there is an immediate safety risk in Indonesia, contact Police 110. Violence against women and children may also be reported through SAPA 129 using its official channels.
Bullyid App personnel who become aware of a child-safeguarding concern must follow the Child Protection and Safeguarding Policy.
11. Security incident or privacy complaint
If you believe your NCII report or evidence has been accessed, disclosed or used improperly, message contact [AT] bullyid.org as soon as possible. Safeguarding concerns may also be sent to report [AT] bullyid.org.
12. Contact
NMA Foundation / Bullyid App
Email: contact [AT] bullyid.org
Safeguarding: report [AT] bullyid.org
Phone: +62 821 6118 5455
Anti-Harassment Policy
1. Commitment
NMA Foundation and Bullyid App are committed to a safe, respectful and inclusive environment for staff, volunteers, professional experts, contractors, partners, programme participants, service users and community members.
Harassment, bullying, intimidation, discrimination, sexual harassment, abuse of authority and retaliation are not accepted in our workplace, programmes, digital services, events or communications.
This Policy applies to conduct in person and online, including email, messaging, video calls, social media, collaboration tools, events, travel, training, counselling/support interactions and other work-related contexts.
2. Relationship to safeguarding and PSEA
Conduct involving sexual exploitation, sexual abuse, sexual harassment, a child, a vulnerable person, a person seeking support, or a significant abuse of power may also fall under the PSEA/SEAH Policy and Child Protection and Safeguarding Policy. Those procedures take priority where specialised safeguarding is required.
3. What is harassment
Harassment is unwanted conduct that has the purpose or reasonably foreseeable effect of violating a person’s dignity or creating an intimidating, hostile, degrading, humiliating or offensive environment.
Depending on context, examples may include:
- repeated insults, ridicule, threats or humiliation;
- abusive or intimidating messages;
- discriminatory comments or slurs;
- sexual comments, propositions, jokes or gestures;
- unwanted sexual attention or repeated requests after refusal;
- sharing sexual, degrading or humiliating material;
- unwanted physical contact;
- stalking or intrusive monitoring;
- deliberate outing, doxxing or disclosure of private information;
- exclusion or sabotage used as intimidation or retaliation;
- abuse of seniority, influence, professional status or access to services;
- coordinated online attacks or encouraging others to harass a person; and
- retaliation because a person raised a concern, supported another person or participated in a complaint process.
Reasonable, respectful management, performance feedback, disagreement, safeguarding action or enforcement of organisational rules is not harassment merely because it is unwelcome.
5. Responsibilities
Everyone covered by this Policy must:
- communicate respectfully;
- respect boundaries and consent;
- challenge or report serious misconduct where safe to do so;
- cooperate with reasonable safeguarding and complaint processes;
- protect confidential information; and
- avoid retaliation.
Managers and project leads have additional responsibility to act on concerns, prevent foreseeable harm, model respectful conduct and avoid dismissing complaints as interpersonal conflict without assessment.
6. Reporting
Concerns may be reported through:
- contact [AT] bullyid.org for general complaints or conduct concerns;
- report [AT] bullyid.org for safeguarding, PSEA/SEAH or higher-risk concerns; or
- the approved alternative Board/governance contact where the normal route is inappropriate or presents a conflict.
Reports may be made by the affected person, a witness or another person with a reasonable concern. Anonymous reports may be accepted, although anonymity can limit follow-up.
If there is immediate danger, seek appropriate emergency assistance before using an internal reporting channel.
7. How concerns are handled
The organisation will assess the nature and seriousness of the concern and determine the appropriate process. This may include:
- informal resolution where the affected person wants it and the matter is suitable;
- management action;
- safeguarding/PSEA response;
- mediation only where voluntary and safe;
- HR or disciplinary process;
- independent or specialist investigation; or
- lawful external referral where necessary.
Informal resolution is not appropriate where it would expose a person to danger, pressure them to face an alleged perpetrator, conceal serious misconduct or replace a required safeguarding response.
The organisation will not promise that every concern will be concluded within a fixed number of days. It will manage matters without unreasonable delay and communicate appropriately with affected parties.
8. Fairness, confidentiality, and privacy
Complaints will be handled as confidentially as reasonably possible. Information will be shared only with people who need it for safety, response, investigation, legal or governance purposes.
A person against whom an allegation is made will be treated fairly and given an appropriate opportunity to respond where an investigation or disciplinary process requires it. Protective or interim measures may be taken before a final finding where reasonably necessary; these measures do not by themselves determine wrongdoing.
Sensitive records are handled under the organisation’s privacy, safeguarding and retention controls.
9. Non-retaliation
Retaliation is prohibited. No person may threaten, penalise, isolate, intimidate, disadvantage or harass another person because they raised a concern in good faith, supported a complainant, acted as a witness or participated in a process.
A report that is not substantiated is not automatically false or malicious. Deliberately false or malicious reports may be addressed under applicable rules, but this provision must not be used to discourage good-faith complaints.
10. Outcomes
Where misconduct is substantiated, proportionate outcomes may include an apology or corrective action, training, supervision, access restrictions, reassignment, disciplinary action, termination of employment or contract, termination of partnership, professional-regulatory referral or lawful external referral.
The organisation may also take systemic corrective action where a concern identifies weaknesses in culture, supervision, programme design, digital systems or reporting arrangements.
11. Training and prevention
NMA Foundation will provide information and training proportionate to role and risk. Leaders, managers, safeguarding personnel and service providers should receive additional training on boundaries, power imbalance, digital conduct, confidentiality, PSEA and complaint handling.
12. Review
This Policy will be reviewed at least annually and sooner where incidents, law, donor requirements, organisational structure or programme risks materially change.
Child Protection Policy
1. Purpose and commitment
NMA Foundation and Bullyid App are committed to ensuring that every child, young person and vulnerable adult who interacts with our work is treated with dignity and respect and is protected from abuse, exploitation, harassment, discrimination and avoidable harm.
Safeguarding is everyone’s responsibility. We take a zero-tolerance approach to abuse, exploitation and sexual misconduct while recognising that effective safeguarding requires prevention, safe reporting mechanisms, appropriate responses, survivor-centred support, accountability and continuous learning.
Our approach is guided by the best interests of the child, informed and meaningful participation, privacy, confidentiality, non-discrimination, trauma-informed practice, proportionality, accessibility and the principle of do no harm.
2. Definitions
- Child: Any person under 18 years of age.
- Young person: For programme purposes, generally a person aged 15-24 unless a specific programme uses a different age range. A young person under 18 is also a child for safeguarding purposes.
- Vulnerable adult: An adult who may face heightened risk of abuse, exploitation or difficulty protecting their own interests because of disability, dependency, displacement, economic hardship, trauma, social exclusion, coercion, unequal power or other circumstances.
- Safeguarding: The policies, practices and actions used to prevent and respond to abuse, exploitation, harassment and other avoidable harm arising through our people, programmes, partnerships, data, technology or operations.
- Sexual exploitation and abuse (SEA): Any actual or attempted abuse of a position of vulnerability, differential power or trust for sexual purposes, including profiting socially, financially or politically from another person’s sexual exploitation. Sexual activity with a child is prohibited regardless of any claimed mistake about age or local age of consent, subject only to any narrowly applicable legal exception that the organisation has expressly recognised in policy after legal review.
- Sexual harassment: Unwelcome conduct of a sexual nature that could reasonably be expected or perceived to cause offence, humiliation, intimidation or an unsafe, hostile or offensive environment. It may occur in person or through digital communications.
- Online or technology-facilitated harm: Abuse or exploitation enabled, amplified or distributed through digital technologies, including harassment, stalking, doxxing, grooming, sextortion, non-consensual intimate imagery, sexualised deepfakes, impersonation, threats, hate, coordinated abuse and synthetic or AI-generated sexual content.
- Non-consensual intimate imagery (NCII): Intimate, nude or sexual images or videos created, obtained, shared, threatened to be shared or manipulated without valid consent, including digitally altered or AI-generated material where a real person is depicted or represented.
- Safeguarding concern: Information, an allegation, a disclosure, an observation or a reasonable suspicion that a person may be at risk of or has experienced abuse, exploitation, harassment or other safeguarding harm.
3. Safeguarding principles
3.1 Prevention
We identify and reduce safeguarding risks before activities begin and integrate safeguarding into programme design, recruitment, research, communications, digital services, product design, procurement and partnerships.
3.2 Protection and immediate safety
Any concern about abuse, exploitation, harassment, sexual violence, grooming, coercion or other harm will be taken seriously. Immediate safety and well-being take priority.
3.3 Best interests of the child
In decisions affecting a child, the child’s best interests are a primary consideration. Safety, age, maturity, views, family context, disability, risk of retaliation and access to appropriate support should be considered.
3.4 Participation and agency
Children and young people should be heard on matters affecting them. Participation must remain voluntary, age-appropriate, accessible and safe. No participant is required to disclose personal experiences of violence or trauma in order to take part.
3.5 Non-discrimination and accessibility
Safeguarding protections apply without discrimination. Activities should make reasonable efforts to be accessible to persons with disabilities and people facing language, displacement or other barriers.
3.6 Survivor-centred and trauma-informed practice
People who disclose harm will be listened to without blame, pressure or unnecessary questioning. Their privacy, choices, dignity and safety guide our response insofar as this is compatible with applicable law and safeguarding obligations.
3.7 Data minimisation and privacy
We collect and share only the personal information reasonably necessary for the activity, support or safeguarding purpose. Access to sensitive safeguarding and survivor data is restricted on a need-to-know basis.
3.8 Accountability and transparency
Safeguarding concerns are documented and managed through clear responsibilities, escalation routes and governance oversight while respecting confidentiality.
4. Expected behaviour and safeguarding Code of Conduct
Everyone representing NMA Foundation or Bullyid App must:
- treat children, young people, vulnerable adults, survivors, colleagues and participants with dignity and respect;
- maintain appropriate professional boundaries and avoid relationships that exploit power imbalances;
- avoid language or behaviour that humiliates, sexualises, intimidates, threatens, coerces or discriminates;
- never engage in sexual activity with a child;
- never exploit a participant, beneficiary or person seeking assistance for sexual, financial, professional or personal benefit;
- never exchange money, opportunities, assistance, employment, goods or services for sexual activity;
- never request sexual contact, intimate imagery or sexualised material from a participant or person seeking support except where a narrowly defined professional process requires information and the request is lawful, necessary, proportionate and covered by an approved protocol;
- avoid being alone with a child where this can reasonably be prevented, and use approved communication channels for programme interactions;
- never knowingly request, create, possess, distribute or facilitate child sexual abuse material;
- never use survivor or safeguarding material for humour, gossip, entertainment, demonstration or unauthorised training;
- protect confidential and personal information; and
- report safeguarding concerns promptly through the procedures in this Policy.
A person’s silence, lack of resistance, dependency, previous participation or inability to freely choose does not constitute consent.
5. Working with children, young people and vulnerable adults
Activities involving participants under 18 or adults at heightened risk require an activity-specific safeguarding assessment. Depending on the activity, safeguards may include:
- age-appropriate information about the activity;
- informed permission from a parent or legal guardian and the child’s own informed assent where required or appropriate;
- appropriate supervision and safe venues or digital platforms;
- limits on one-to-one interactions;
- accessible information about complaints and support;
- reasonable accessibility accommodations;
- clear withdrawal options without penalty; and
- a referral or escalation plan for disclosures or immediate safety concerns.
Children and vulnerable adults will never be pressured to participate in research, campaigns, storytelling, interviews, photographs or programme activities. Refusing or withdrawing consent will not affect access to services to which they are otherwise entitled.
A parent or guardian’s consent does not remove the organisation’s obligation to consider the child’s own views, welfare and privacy.
6. Reporting a safeguarding concern
Anyone associated with NMA Foundation or Bullyid App who witnesses, receives a disclosure of, or reasonably suspects abuse, exploitation or other safeguarding harm must report the concern promptly. A person does not need proof before raising a concern. A reasonable safeguarding concern is sufficient.
Reports may include concerns about:
- a child or vulnerable person experiencing harm;
- misconduct by staff, volunteers, consultants, contractors, fellows, experts or partners;
- sexual harassment, exploitation or abuse;
- inappropriate relationships or communications;
- online exploitation, sextortion or image-based abuse;
- misuse of personal data, digital evidence or intimate imagery;
- retaliation against someone reporting a concern; or
- suspected criminal conduct.
Primary reporting route: report [AT] bullyid.org.
If the concern relates to the Safeguarding Focal Point, or the person does not feel safe using that route, the report must be made to the alternative authorised Board/governance contact published by the organisation. Before public release of this version, the current name and secure contact details of that alternative contact must be confirmed.
A safeguarding report may be made without first confronting the person alleged to have caused harm.
7. Responding to concerns and incident management
When a safeguarding concern is received, NMA Foundation or Bullyid App will:
- prioritise immediate safety and urgent protection needs;
- listen without blaming or unnecessarily interrogating the person reporting harm;
- record only information necessary for safeguarding and response;
- share information strictly on a need-to-know basis;
- assess whether specialist legal, psychological, medical, child-protection, digital-security or emergency support is required;
- assess applicable reporting, referral and preservation obligations rather than applying a blanket rule that every concern must automatically be sent to police or government;
- escalate or refer matters where required by law or where a lawful and proportionate step is necessary to protect a person from serious harm;
- manage allegations involving staff or representatives through appropriate disciplinary, PSEA, HR and governance procedures;
- preserve relevant evidence without unnecessary duplication or exposure; and
- take reasonable steps to protect reporters, survivors and witnesses from retaliation.
Safeguarding records will be stored securely and, where appropriate, separately from ordinary programme records. No internal investigation should compromise the safety of the affected person, contaminate digital evidence or interfere with a lawful external investigation.
8. Relevant legal and good-practice framework
This Policy should be read and implemented consistently with applicable Indonesian law and any additional safeguarding requirements of funders, regulators, professional bodies or partners. Relevant frameworks include, as applicable:
- Indonesian child-protection legislation, including Law No. 35 of 2014 amending Law No. 23 of 2002 on Child Protection and subsequent applicable amendments;
- Law No. 12 of 2022 on Sexual Violence Crimes;
- Law No. 27 of 2022 on Personal Data Protection;
- Law No. 1 of 2024, the second amendment to the Electronic Information and Transactions Law;
- Government Regulation No. 17 of 2025 concerning governance of electronic systems in child protection;
- Minister of Communication and Digital Regulation No. 9 of 2026 implementing the child-protection electronic-system framework; and
- other applicable implementing regulations, professional rules, donor safeguards and legally binding obligations.
Where there is uncertainty about a legal reporting obligation, handling of child sexual material, disclosure to authorities, age-assurance requirement or an individual’s immediate safety, the organisation should obtain qualified legal or safeguarding advice promptly.
Anti-Fraud, Anti-Bribery and Anti-Corruption Policies
1. Purpose
NMA Foundation and Bullyid App are committed to using funds, assets, technology, partnerships and organisational authority honestly and for their intended purposes. Fraud, bribery, corruption, kickbacks, theft, embezzlement, falsification and deliberate misuse of organisational resources are prohibited.
This Policy applies to Board/governance members, employees, volunteers, consultants, contractors, professional experts, partners and other people acting for or on behalf of NMA Foundation or Bullyid App.
2. Definitions
- Fraud: Intentional deception, misrepresentation, concealment or abuse of position designed to obtain an unauthorised benefit or cause a loss.
- Bribery: Offering, promising, giving, requesting, receiving or accepting an improper benefit to influence an action, decision or omission.
- Corruption: Abuse of entrusted power or position for private or improper gain.
- Kickback: An improper payment, benefit or return provided in exchange for obtaining or rewarding favourable treatment.
- Conflict of interest: A situation in which personal, family, financial, professional or other interests could improperly influence, or reasonably appear to influence, an organisational decision.
- Facilitation payment: An unofficial payment or benefit intended to speed up or secure a routine action. Such payments are prohibited unless a person reasonably believes payment is necessary to protect life or immediate safety, in which case it must be reported promptly and documented.
3. Prohibited conduct
Covered persons must not:
- steal, misappropriate or misuse organisational, donor, partner or beneficiary assets;
- falsify expenses, timesheets, invoices, procurement documents, programme records, beneficiary records or financial reports;
- create fictitious vendors, beneficiaries, participants or transactions;
- manipulate procurement, recruitment, contracting or grant decisions for improper benefit;
- offer, promise, request or accept a bribe, kickback or secret commission;
- split transactions, circumvent approval thresholds or conceal a conflict of interest;
- use donor-restricted funds for unauthorised purposes;
- make undisclosed related-party transactions;
- use organisational systems or data for unlawful private gain;
- conceal a known fraud or deliberately destroy relevant records; or
- retaliate against a person who reports a concern in good faith.
4. Gifts, hospitality and benefits
Gifts, hospitality or benefits must never be used to influence an official, procurement, funding, referral, recruitment or partnership decision improperly.
Personnel should refuse cash gifts, kickbacks and any gift or hospitality that is excessive, secret, creates an obligation, is offered during a sensitive decision process or could reasonably be perceived as improper.
NMA Foundation should maintain an internal gifts/conflicts process appropriate to its size and risk. Higher-value or sensitive gifts and hospitality should be disclosed and, where required, approved or recorded.
5. Conflicts of interest
Board members, staff and relevant decision-makers must disclose actual, potential or perceived conflicts of interest as soon as they arise.
A conflicted person should not participate in a decision where their impartiality could reasonably be questioned unless the conflict has been formally assessed and an appropriate management arrangement is documented.
Relevant interests may include family relationships, close personal relationships, financial interests, outside employment, board positions, business ownership, gifts or benefits.
6. Financial and procurement controls
NMA Foundation will maintain proportionate financial controls designed to prevent and detect fraud and misuse. Controls should include, as relevant:
- documented budgets and authorisation limits;
- segregation of duties where practicable;
- supporting documentation for expenditure;
- bank and account reconciliations;
- dual or independent approval for higher-risk transactions;
- procurement and vendor due diligence;
- verification of changes to vendor bank details;
- inventory/asset controls;
- restricted access to finance and payment systems;
- donor/grant coding and restricted-fund tracking;
- periodic management review;
- record retention; and
- independent audit or review where required.
No control should depend entirely on one individual where a reasonable separation or review is possible.
7. Partner, vendor and donor due diligence
Before higher-risk partnerships, procurement or sub-grants, NMA Foundation may assess identity, ownership, reputation, conflicts, sanctions/restrictions where relevant, financial controls and ability to comply with applicable anti-fraud and donor requirements.
Contracts should contain proportionate integrity, audit, recordkeeping and termination provisions where the relationship or donor requires them.
8. Reporting concerns
Anyone may report a suspected fraud, bribery, corruption, conflict or misuse of resources through contact [AT] bullyid.org or the organisation’s approved governance/whistleblowing route.
Where the allegation involves the person responsible for receiving the report, it should be escalated to an independent authorised Board/governance contact.
A reporter does not need proof. Reasonable suspicion or information that warrants review is sufficient. Anonymous reports may be accepted.
Urgent action may be taken to protect assets, systems, records or people while preserving fairness and evidence.
9. Response and investigation
The organisation will assess the concern, preserve relevant records and determine whether investigation, specialist financial review, suspension of access, donor notification, insurance notification, disciplinary action or lawful external referral is required.
Investigations should be proportionate, confidential, independent of material conflicts and documented. The organisation will not promise a fixed seven-day or other universal completion period; timing depends on complexity, evidence, external processes and due process.
The subject of an allegation must not destroy, alter or conceal potentially relevant records. Routine deletion may be suspended through a legal/investigative hold where necessary.
10. Outcomes, recovery and reporting
Where wrongdoing is substantiated, the organisation may take proportionate action including disciplinary action, termination, contract remedies, recovery of loss, revised controls, donor notification, audit action or lawful referral to competent authorities.
The organisation will comply with any binding donor, audit, regulatory or legal reporting requirement and will avoid making public accusations before facts are appropriately established.
11. Non-retaliation
Retaliation against a person who raises a concern in good faith, assists an investigation or refuses to participate in improper conduct is prohibited.
Knowingly false or malicious allegations may be addressed under organisational rules, but an unsubstantiated allegation does not by itself establish bad faith.
12. Records and confidentiality
Fraud and corruption records may contain sensitive personal, financial and investigative information. Access should be restricted and retention should follow the organisation’s legal, donor, audit and evidence-preservation requirements.
13. Legal and ethical baseline
This Policy should be implemented consistently with applicable Indonesian law, including relevant anti-corruption, foundation, taxation, financial-recordkeeping, criminal and donor requirements. Relevant anti-corruption legislation includes Law No. 31 of 1999 on Eradication of Corruption Crimes as amended by Law No. 20 of 2001.
Where an issue may involve a criminal offence, public official, donor-reporting duty or material financial loss, obtain appropriate legal, audit or professional advice.
14. Governance and review
Management is responsible for implementing financial controls and escalating material concerns. The Board/governing authority is responsible for oversight of serious fraud/corruption risks and material control failures.
This Policy will be reviewed at least annually and after material incidents, audit findings or significant changes to finance systems or donor obligations.
