Research on information security needs in the Gender-Based Violence (GBV) support community
I ) Phase 1: Gather survey data to analyse responses from organisational representatives
II ) Phase 2: Conduct interviews with selected individuals working in the sector and recognised for their expertise in GBV or Tech Facilitated GBV (TFGBV)
This work is made possible thanks to a Digital Futures grant from the Superrr Lab, following the Digital Futures gathering of Fall 2025.

We are grateful for their support to help up lay some ground work to creating information security data tailored to GBV survivors-centered needs.
I ) Phase 1: Findings
We received responses from 7 organisational representatives who deal with a range of less than 10 to more than a 100 GBV cases annually faced by survivors online or on tech-based platforms.
The main overall takeaway from the results is that about 40% of organisations shared that survivors mostly look for additional guidance on improving their online safety.
Detailed findings from our quantitative analysis of results
Although organisations don’t rely heavily on free tools to store and manage survivor data, there are inadequate safety measures on internal and external data sharing or access : Most organisational respondents affirmed that they don’t use free tools to store survivor data or in stakeholder case management. However, more than 70% of them have provision of shared access to data internally, such as through a common login access to the database among colleagues. This significantly raises the risk of data security. Additionally, 80% of respondents shared that they primarily rely on technology from big US companies and there is a lack of clarity on whether or how much access these companies have to the data.
Data deletion provision to manage requests from survivors largely do not exist in organisations: 50% of respondents shared they either did not have any or were not aware of any rules around data retention and deletion in the organisation. Most organisations also mentioned that they usually don’t receive requests related to data deletion from survivors and anyone related to the case. This predominantly signifies a gap in proactively creating a systematic provision of data deletion requisitions from survivors. This also affects creating awareness among survivors that they can raise such data removal or deletion requests and assessing the ease of the process to do so. However, organisations shared they would appreciate more guidance on how to handle such data deletion requests. This indicates there is willingness and interest among these organisations towards enabling data deletion protocols which could have a significant positive impact towards preventing misuse of survivor data.
There is a significant gap in what organisations regard as having clear process and guidance in data security management and implementing them effectively in reality: Majority of the organisations shared they follow the standard practice of implementing security protocols like 2FAs and complex passwords. They also affirmed the presence of organisational policies on data management safety and cybersecurity. Although these organisations regard having a clear process and guidance on keeping sensitive personal data of survivors safe, the lack of conducting risk assessments of tools and processes points to a concerning pattern of deprioritising data security of survivors. Also, technically no cybersecurity risk assessments are conducted before adopting a new tool, which is also a very high risk concern in survivor data management safety. Additionally, there is little knowledge of whether proper testing of new tools is done to check safety features.
While few instances of data breach were reported, there is a lack of preparedness to prevent and manage such occurrences swiftly: The majority of the organisations shared they had not experienced any significant data breach. One respondent mentioned that one of the data breaches they experienced was via facebook but they were able to address the situation because an organisational member was able to commit time on briefing the team regarding what needs to be done. Anecdotes shared show ad hoc incident response, revealing a lack of standard protocols signalling a significant systematic data security gap. And to a large extent organisations themselves are also aware of it. The respondents shared that the biggest fears they have regarding the data they hold are privacy and security concerns of the data falling into the wrong hands and losing the data due to breach.
Developers and tech consultants often do not understand why embedding survivor safety features in system design is the utmost priority: While working with developers and tech consultants, it is quite difficult for some organisations to find experts with a "survivor security-first" mindset. More than 80% view that developers do not usually understand the need to implement special safety measures to protect the tools from abusers. More than 60% shared that they either don’t have an IT team or an internal resource person who can advise on cybersecurity best practice. Also, more than 40% either do not have staff who can explain technical requirements and find that translating their needs to developers remains to be a major gap. This shows a significant lack of organisational capacity to deal with technical requirements. Additionally, 50% respondents shared they are left quite dependent on them for even making small changes to the system even after service delivery is complete. This gap of understanding between technical and operational teams creates a silo in designing effective tools that incorporate appropriate data security measures for survivors.
Funders are interested in the rollout of innovative technologies but it is equally difficult to explain data security and management costs to them: Majority of the respondents shared that there is a significant interest among funders to see new and innovative technologies are being applied to projects. However, 50% shared that it is also very difficult to explain and validate data security and management costs to funders. This creates a conflicting situation where the requirement to introduce advanced tech interventions in managing survivor data is not met with real investments.
II ) Phase 2: Findings
=== Interviews are ongoing. Once concluded we will add a summary of findings here and a general summary of findings collating the two phases of the project. ===