Data protection in a resettlement register: obligations nobody assigned
A PAP register is thousands of people's identity, location, income and payment data. Most projects treat it as a spreadsheet.
A PAP register holds, for several thousand people, their names, household composition, exact location, income, land claims, identity documents, photographs, often biometrics, and the amount of money each is about to receive. It is one of the more sensitive datasets any project assembles, and it is routinely emailed as a spreadsheet.
The obligations exist whether or not anyone assigned them
Most jurisdictions in the region now have data protection legislation with the familiar structure: a lawful basis for processing, purpose limitation, data minimisation, accuracy, retention limits, security obligations and breach notification, with a supervisory authority and penalties.
A resettlement register is squarely within it, and the obligations sit with the implementing agency as data controller regardless of who built the system. Confirm the applicable law and any registration requirement early — this is one of the few compliance areas where the timeline is set by someone else's process.[2]
The register is not a project deliverable that happens to contain names. It is thousands of people's personal data that happens to be useful to a project.
Concrete harms, not abstract ones
- Targeted theft. A list of who is being paid what, and when, is an operational document for anyone inclined to rob them.
- Family conflict. Publishing what an individual received can expose them to claims from relatives, and in some settings to violence.
- Opportunistic claims. Detailed asset records circulating locally invite fabricated competing claims.
- Retaliation. Grievance records identifying complainants, if visible to the people complained about, end the mechanism's usefulness immediately.
- Political exposure. In some contexts a list of who lives where, with ethnicity or origin recorded, is dangerous in ways that have nothing to do with the project.
Disclosure versus privacy
Resettlement has a genuine tension here. Public display of the draft register is one of the strongest anti-fraud and inclusion mechanisms available — communities correct omissions and identify ghosts. It also publishes personal data.[3]
The workable resolution is to split what is displayed from what is held. Display names and parcels, which is what allows objection and correction. Do not display amounts, income, household composition or identity numbers. Disclose the individual entitlement privately to the person it concerns. That satisfies both the objection process and the duty not to expose people by publishing what they are about to receive.[4]
Practical minimums
- Role-based access. Enumerators should not see payment data; payment staff should not export identity records; grievance handlers should see complainant details only for their own cases.
- No bulk export to personal devices. The most common breach in this field is a full copy of the register on a consultant's laptop.
- Encryption in transit and at rest, including on field devices, which are lost and stolen routinely.
- Access logging, so that who read what is answerable.
- Explicit consent for photographs and biometrics, recorded, and with a practical alternative for anyone who declines.
- A retention position that survives project closure — the register must be kept long enough to answer a complaint years later, which is a lawful purpose, and that period should be stated rather than indefinite.
What to tell people at enumeration
A short, plain statement, in the local language, given verbally as well as on the form: what is being collected, why, who will see it, how long it will be kept, and how to ask for a correction. It takes a minute and it is the part of a data protection regime that the people concerned actually experience.[1]
It also has a practical benefit. Households that understand why detailed income questions are being asked answer them more accurately, and the baseline the whole monitoring framework depends on gets better.
Sources
- [1]Performance Standard 5: Land Acquisition and Involuntary Resettlement — International Finance Corporation, 2012.
- [2]Good Practice Handbook: Land Acquisition and Involuntary Resettlement — International Finance Corporation, 2023.
- [3]ESF Guidance Note 5: Land Acquisition, Restrictions on Land Use and Involuntary Resettlement — World Bank, 2018.
- [4]Environmental & Social Issues Update — Office of the Compliance Advisor/Ombudsman (CAO), 2023.
Olule Solomon
Lead Consultant, ValueSpace
Olule Solomon is Lead Consultant at ValueSpace, where he works on land acquisition and resettlement systems for donor-financed infrastructure in East Africa. He writes about the practical gap between what the safeguard standards require and what a project can actually evidence at completion audit.
Related reading
- Choosing a data system for a RAP: what to test before you commitSpreadsheets fail resettlement at a predictable point. What a RAP database has to do, and the questions that expose one that cannot.
- Verifying identity when half the register has no IDPaying the right person is a compliance requirement and an exclusion risk. Building an identity standard before payments start.
- Disclosing a RAP: what has to be published, where, and in what languageDisclosure is a dated, evidenced act, not a PDF on a website. What the standards require and what auditors ask to see.
Free entitlement matrix template
15 loss categories, eligibility split by tenure, valuation basis and the PS-5 provision behind every row. CSV, no registration wall.
Get the template →The software behind this
SmartLARMS keeps the record this article describes
PAP register, replacement-cost valuations, entitlements, recorded payments reconciled against disbursement files, and grievances — every change attributed and time-stamped, so a completion audit is evidenced rather than reconstructed. Offline-first in the field.