গোপনীয়তা নীতি
১. ভূমিকা ও পরিধি
ডিআইএস (Disability Information System) হলো সমাজসেবা অধিদপ্তর, সমাজকল্যাণ মন্ত্রণালয়, গণপ্রজাতন্ত্রী বাংলাদেশ সরকার কর্তৃক পরিচালিত প্রতিবন্ধী ব্যক্তিদের নিবন্ধন, যাচাই, অনুমোদন ও পরিচয়পত্র ব্যবস্থাপনার সরকারি তথ্যব্যবস্থা। এই গোপনীয়তা নীতি ডিআইএস মোবাইল অ্যাপ্লিকেশনের ক্ষেত্রে প্রযোজ্য এবং ব্যাখ্যা করে — কোন তথ্য সংগ্রহ করা হয়, কেন করা হয়, কার সঙ্গে বিনিময় করা হয়, কতদিন রাখা হয় এবং সংশ্লিষ্ট ব্যক্তির কী কী অধিকার রয়েছে।
এই অ্যাপে সংগৃহীত সকল তথ্য-উপাত্তের মালিক গণপ্রজাতন্ত্রী বাংলাদেশ সরকার এবং হেফাজতকারী কর্তৃপক্ষ সমাজসেবা অধিদপ্তর। অ্যাপটি কোনো ব্যক্তিগত বা বাণিজ্যিক প্রতিষ্ঠানের নয়।
২. আইনগত ভিত্তি
ডিআইএস-এ তথ্য সংগ্রহ, সংরক্ষণ ও ব্যবহার নিম্নলিখিত আইন ও নীতিমালার অধীনে পরিচালিত হয়:
- প্রতিবন্ধী ব্যক্তির অধিকার ও সুরক্ষা আইন, ২০১৩ এবং তদধীন প্রণীত বিধিমালা;
- প্রতিবন্ধী ব্যক্তির তথ্য-উপাত্ত ব্যবহার নীতিমালা, ২০২১ (বাংলাদেশ গেজেট, অতিরিক্ত সংখ্যা, ২ আগস্ট ২০২১) — এই নীতিমালাই ডিআইএস-এর তথ্য সরবরাহ, বিনিময় ও ব্যবহারের একমাত্র অনুমোদিত পদ্ধতি নির্ধারণ করে;
- প্রতিবন্ধী ব্যক্তিদের অধিকার বিষয়ক জাতিসংঘ সনদ (UNCRPD), যা বাংলাদেশ অনুসমর্থন করেছে;
- তথ্য অধিকার আইন, ২০০৯ (ব্যক্তিগত ও সংবেদনশীল তথ্য প্রকাশের সীমাবদ্ধতাসহ);
- সাইবার নিরাপত্তা সংক্রান্ত প্রযোজ্য আইন এবং সরকারি রেকর্ড সংরক্ষণ বিধি।
২০২১ সালের নীতিমালা অনুযায়ী, ডিআইএস-এর তথ্য কেবল নির্ধারিত উদ্দেশ্যে, লিখিত আবেদন ও যথাযথ অনুমোদনের ভিত্তিতে এবং অঙ্গীকারনামা সম্পাদন সাপেক্ষে সরবরাহ করা যায়। এই নীতি সেই বিধিবিধানের সঙ্গে সঙ্গতি রেখে প্রণীত।
৩. কে এই অ্যাপ ব্যবহার করেন
এটি একটি দাপ্তরিক অ্যাপ্লিকেশন। ব্যবহারের জন্য সমাজসেবা অধিদপ্তর কর্তৃক প্রদত্ত অ্যাকাউন্ট প্রয়োজন; সাধারণ নাগরিকের সরাসরি স্ব-নিবন্ধনের সুযোগ এখানে নেই। অনুমোদিত ব্যবহারকারীরা হলেন:
- সমাজসেবা অধিদপ্তরের মাঠপর্যায়ের ও দাপ্তরিক কর্মকর্তা-কর্মচারী;
- প্রতিবন্ধিতা যাচাইয়ের জন্য নিয়োজিত নিবন্ধিত চিকিৎসক (মেডিকেল অফিসার);
- সুপারিশ ও অনুমোদন প্রদানকারী কর্তৃপক্ষ।
প্রতিবন্ধী ব্যক্তি ও তাঁর অভিভাবক এই অ্যাপে সরাসরি অ্যাকাউন্ট খোলেন না; তাঁদের তথ্য সংশ্লিষ্ট কর্মকর্তা তাঁদের (বা আইনানুগ অভিভাবকের) সম্মতিক্রমে নিবন্ধন ফরমে লিপিবদ্ধ করেন। এই নীতি সেই তথ্যভুক্ত ব্যক্তিদের ক্ষেত্রেও সমানভাবে প্রযোজ্য।
৪. আমরা কোন তথ্য সংগ্রহ করি
ক) ব্যবহারকারীর অ্যাকাউন্ট সংক্রান্ত তথ্য
- ব্যবহারকারীর নাম (username), পাসওয়ার্ড এবং ভূমিকা/পদবি (role);
- নাম, ই-মেইল ঠিকানা, মোবাইল নম্বর ও প্রোফাইল ছবি;
- কর্মস্থলের বিভাগ, জেলা, উপজেলা/সিটি কর্পোরেশন ও দপ্তরের পরিচিতি;
- চিকিৎসকের ক্ষেত্রে নিবন্ধন নম্বর এবং মোবাইল নম্বরে প্রেরিত ওটিপি (OTP) যাচাই সংক্রান্ত তথ্য।
খ) প্রতিবন্ধী ব্যক্তির নিবন্ধন তথ্য (সংবেদনশীল তথ্য)
নিবন্ধন ফরমের মাধ্যমে নিম্নলিখিত শ্রেণির তথ্য সংগৃহীত হয়:
- পরিচিতি: বাংলা ও ইংরেজিতে নাম, পিতার নাম, মাতার নাম, স্বামী/স্ত্রীর নাম, অভিভাবকের নাম, তথ্য প্রদানকারীর নাম ও সম্পর্ক;
- জাতীয় পরিচিতি: জাতীয় পরিচয়পত্র (এনআইডি) নম্বর অথবা জন্মনিবন্ধন নম্বর;
- জনমিতিক তথ্য: জন্ম তারিখ ও বয়স, জন্মস্থান, লিঙ্গ, বৈবাহিক অবস্থা, ধর্ম, জাতিসত্তা, জাতীয়তা, রক্তের গ্রুপ;
- ঠিকানা: স্থায়ী ও বর্তমান ঠিকানা (বিভাগ, জেলা, উপজেলা/সিটি কর্পোরেশন, ওয়ার্ড, বাড়ি/গ্রাম);
- যোগাযোগ: অভিভাবকের মোবাইল নম্বর ও ই-মেইল ঠিকানা;
- আর্থ-সামাজিক তথ্য: পরিবারের সদস্যসংখ্যা, শিক্ষাগত যোগ্যতা, পেশা, বার্ষিক আয়, বাসস্থানের মালিকানা, প্রাপ্ত সেবা ও ভাতার তথ্য;
- স্বাস্থ্য ও প্রতিবন্ধিতা সংক্রান্ত তথ্য: প্রতিবন্ধিতার ধরন, কারণ ও মাত্রা, চিকিৎসকের যাচাই-সংক্রান্ত পর্যবেক্ষণ, কার্যক্ষমতা মূল্যায়নের উত্তরসমূহ (দেখা, শোনা, চলাফেরা, কথা বলা, বোঝা, আচরণ ইত্যাদি বিষয়ক), মৃগীরোগ, সহায়ক উপকরণ (শ্রবণযন্ত্র, চশমা প্রভৃতি) ব্যবহারের তথ্য এবং পরিবারে প্রতিবন্ধিতার ইতিহাস;
- সহিংসতা/নির্যাতন সংক্রান্ত বিবরণ, যদি প্রযোজ্য হয়;
- বায়োমেট্রিক ধরনের নথি: ব্যক্তির ছবি ও স্বাক্ষরের চিত্র;
- দাপ্তরিক তথ্য: ফরম নম্বর, যাচাইকারী চিকিৎসকের নাম ও নিবন্ধন নম্বর, তথ্য এন্ট্রিকারী কর্মকর্তার পরিচিতি এবং তৈরি/হালনাগাদের তারিখ ও সময়।
সংবেদনশীল তথ্য সম্পর্কে: প্রতিবন্ধিতা ও স্বাস্থ্য সংক্রান্ত তথ্য অত্যন্ত সংবেদনশীল। এসব তথ্য কেবল সরকারি সেবা প্রদান, যাচাই ও পরিচয়পত্র প্রস্তুতের উদ্দেশ্যে ব্যবহৃত হয় এবং ২০২১ সালের নীতিমালার বাইরে কারও কাছে সরবরাহ করা হয় না।
গ) কারিগরি ও ডিভাইস সংক্রান্ত তথ্য
- অ্যাপের সংস্করণ যাচাই ও হালনাগাদ বার্তা প্রদানের জন্য প্রয়োজনীয় তথ্য;
- ইন্টারনেট সংযোগের অবস্থা (সংযুক্ত/বিচ্ছিন্ন) — অফলাইন বার্তা দেখানোর জন্য;
- সার্ভারে অনুরোধ প্রেরণের সময় স্বাভাবিকভাবে সৃষ্ট নেটওয়ার্ক লগ (যেমন আইপি ঠিকানা ও সময়), যা নিরাপত্তা ও নিরীক্ষার প্রয়োজনে সরকারি সার্ভারে সংরক্ষিত হয়।
এই অ্যাপ অবস্থান (GPS), কন্টাক্ট তালিকা, এসএমএস, কল লগ, মাইক্রোফোন বা বিজ্ঞাপন শনাক্তকারী (Advertising ID) সংগ্রহ করে না।
ঘ) ডিভাইসে সংরক্ষিত তথ্য
- লগইন সেশন ও ড্যাশবোর্ডের গণনা ডিভাইসের অ্যাপ-নির্দিষ্ট সংরক্ষণাগারে (SharedPreferences) রাখা হয়;
- ক্যামেরা বা গ্যালারি থেকে নেওয়া ছবি সাময়িকভাবে ডিভাইসে সংরক্ষিত হয় এবং সার্ভারে জমা দেওয়ার পর আর প্রয়োজন হয় না;
- লগআউট করলে বা অ্যাপ আনইনস্টল করলে ডিভাইসে রক্ষিত এসব তথ্য মুছে যায়।
৫. অ্যাপের অনুমতিসমূহ (Permissions)
| অনুমতি | কেন প্রয়োজন |
|---|---|
INTERNET |
ডিআইএস সার্ভারের সঙ্গে তথ্য আদান-প্রদানের জন্য। |
CAMERA |
নিবন্ধন ফরমে প্রতিবন্ধী ব্যক্তির ছবি ও স্বাক্ষর এবং প্রোফাইল ছবি তোলার জন্য। ব্যবহারকারী চাইলে গ্যালারি থেকেও ছবি নির্বাচন করতে পারেন। |
READ_EXTERNAL_STORAGE, WRITE_EXTERNAL_STORAGE |
গ্যালারি থেকে ছবি নির্বাচন, ছবি কাটাছাঁটা (crop) এবং পরিচয়পত্রের পিডিএফ প্রস্তুত ও প্রিন্টের জন্য। নতুন অ্যান্ড্রয়েড সংস্করণে এসব কাজ অ্যাপ-নির্দিষ্ট সংরক্ষণাগারেই সম্পন্ন হয়। |
FLASHLIGHT |
স্বল্প আলোয় ছবি তোলার সময় ক্যামেরার ফ্ল্যাশ ব্যবহারের জন্য। |
যেকোনো অনুমতি ডিভাইসের সেটিংস থেকে যেকোনো সময় প্রত্যাহার করা যায়। অনুমতি না দিলে কেবল সংশ্লিষ্ট সুবিধাটি (যেমন ছবি সংযুক্তকরণ) কাজ করবে না।
৬. তথ্য ব্যবহারের উদ্দেশ্য
সংগৃহীত তথ্য কেবল নিম্নলিখিত উদ্দেশ্যে ব্যবহৃত হয়:
- প্রতিবন্ধী ব্যক্তির নিবন্ধন গ্রহণ, যাচাই, সুপারিশ ও অনুমোদন;
- প্রতিবন্ধী পরিচয়পত্র (আইডি কার্ড) প্রস্তুত, প্রদর্শন ও মুদ্রণ;
- ফরম আইডি, এনআইডি বা ডিআইএস আইডি দিয়ে নিবন্ধনের সত্যতা যাচাই;
- ভাতা ও অন্যান্য সরকারি সেবা প্রাপ্যতা নির্ধারণে সহায়তা;
- ব্যবহারকারীর পরিচয় নিশ্চিতকরণ ও অ্যাকাউন্টের নিরাপত্তা (ওটিপি যাচাইসহ);
- নাম-পরিচয় বিহীন সমষ্টিগত পরিসংখ্যান তৈরি ও নীতি-পরিকল্পনায় ব্যবহার;
- দাপ্তরিক নিরীক্ষা, জবাবদিহি ও অভিযোগ নিষ্পত্তি।
এই তথ্য কখনোই বিক্রি, ভাড়া বা বিজ্ঞাপন, বিপণন কিংবা প্রোফাইলিংয়ের উদ্দেশ্যে ব্যবহার করা হয় না।
৭. তথ্য প্রকাশ ও বিনিময়
ডিআইএস-এর তথ্য কেবল নিম্নলিখিত ক্ষেত্রে এবং নির্ধারিত পদ্ধতিতে বিনিময় করা হয়:
- সরকারি দপ্তরের অভ্যন্তরে: সমাজসেবা অধিদপ্তর ও সমাজকল্যাণ মন্ত্রণালয়ের অনুমোদিত কর্মকর্তা এবং যাচাইকারী চিকিৎসকগণ নিজ নিজ ভূমিকা ও কর্মএলাকার সীমার মধ্যে তথ্য দেখতে পান।
- অন্য সরকারি/স্বায়ত্তশাসিত সংস্থা বা নিবন্ধিত বেসরকারি সংস্থা: প্রতিবন্ধী ব্যক্তির তথ্য-উপাত্ত ব্যবহার নীতিমালা, ২০২১ অনুযায়ী লিখিত আবেদন, নির্ধারিত ফরম পূরণ, যাচাই-বাছাই কমিটির অনুমোদন এবং অঙ্গীকারনামা সম্পাদন সাপেক্ষে কেবল নির্দিষ্ট উদ্দেশ্যে সীমিত তথ্য সরবরাহ করা হয়।
- এপিআই (API) সংযোগের মাধ্যমে: অনুমোদিত সংস্থাকে চুক্তি ও ব্যবহারকারীর নাম-পাসওয়ার্ড প্রদানের ভিত্তিতে সীমিত এপিআই প্রবেশাধিকার দেওয়া হয়; এ ক্ষেত্রে প্রকৃত আইপি ঠিকানা নিবন্ধন ও সংরক্ষণ বাধ্যতামূলক এবং প্রবেশাধিকার সময়ে সময়ে নবায়নযোগ্য ও প্রত্যাহারযোগ্য।
- আইনি বাধ্যবাধকতা: আদালতের আদেশ বা প্রযোজ্য আইনের অধীনে কর্তৃত্বসম্পন্ন কর্তৃপক্ষের বৈধ চাহিদা পূরণে।
অনুমোদিত গ্রহীতা সংস্থা প্রাপ্ত তথ্য অন্য কোনো উদ্দেশ্যে ব্যবহার করতে, তৃতীয় পক্ষকে হস্তান্তর করতে বা প্রকাশ করতে পারে না; উদ্দেশ্য পূরণের পর তথ্য ধ্বংস/মুছে ফেলার এবং অধিদপ্তরকে অবহিত করার বাধ্যবাধকতা রয়েছে। শর্ত লঙ্ঘনে অনুমোদন বাতিলসহ প্রযোজ্য আইনে ব্যবস্থা গ্রহণ করা হয়।
৮. সংরক্ষণকাল ও মুছে ফেলা
- প্রতিবন্ধী নিবন্ধন একটি স্থায়ী জাতীয় রেকর্ড। সেবা প্রদান, পরিচয়পত্র নবায়ন ও নিরীক্ষার প্রয়োজনে সরকারি রেকর্ড সংরক্ষণ বিধি অনুযায়ী তা সংরক্ষিত থাকে।
- ভুল বা অসম্পূর্ণ তথ্য নিকটস্থ সমাজসেবা কার্যালয়ের মাধ্যমে সংশোধন করা যায়; অ্যাপে সংশোধনের সুবিধা রয়েছে এবং প্রতিটি পরিবর্তন কে, কখন করেছেন তা লগ আকারে সংরক্ষিত হয়।
- দাপ্তরিক ব্যবহারকারীর অ্যাকাউন্ট বদলি, অবসর বা দায়িত্ব পরিবর্তনের সঙ্গে সঙ্গে নিষ্ক্রিয় করা হয়।
- তথ্য মুছে ফেলার অনুরোধ করা যায় (দেখুন অনুচ্ছেদ ১৫)। তবে আইনি বা দাপ্তরিক বাধ্যবাধকতার আওতায় থাকা রেকর্ডের ক্ষেত্রে সম্পূর্ণ বিলোপ সম্ভব না-ও হতে পারে; সে ক্ষেত্রে কারণ জানানো হয়।
- ডিভাইসে রক্ষিত তথ্য (লগইন সেশন, সাময়িক ছবি) লগআউট বা অ্যাপ আনইনস্টল করলেই মুছে যায়।
৯. তথ্যের নিরাপত্তা
তথ্যের গোপনীয়তা ও অখণ্ডতা রক্ষায় গৃহীত ব্যবস্থাসমূহ:
- দপ্তর কর্তৃক প্রদত্ত অ্যাকাউন্ট ছাড়া অ্যাপে প্রবেশ করা যায় না;
- চিকিৎসকের প্রবেশে মোবাইল নম্বরভিত্তিক ওটিপি (One-Time Password) যাচাই;
- ভূমিকা ও কর্মএলাকাভিত্তিক প্রবেশাধিকার — প্রত্যেকে কেবল নিজ এখতিয়ারের রেকর্ড দেখতে পান;
- সার্ভারে এপিআই কি ও প্রমাণীকরণ শিরোনাম (authentication header) দ্বারা নিয়ন্ত্রিত প্রবেশ;
- প্রতিটি এন্ট্রি, সংশোধন ও অনুমোদনের জন্য ব্যবহারকারী-চিহ্নিত নিরীক্ষা লগ;
- সরকারি ডেটা সেন্টারে তথ্য সংরক্ষণ এবং কর্মকর্তাদের জন্য গোপনীয়তা রক্ষার দাপ্তরিক বাধ্যবাধকতা।
এতদসত্ত্বেও, ইন্টারনেটে প্রেরিত বা ইলেকট্রনিক মাধ্যমে সংরক্ষিত কোনো তথ্যই শতভাগ নিরাপদ বলে দাবি করা যায় না। ব্যবহারকারীদের অনুরোধ করা হচ্ছে — পাসওয়ার্ড বা ওটিপি কারও সঙ্গে ভাগ করবেন না এবং সন্দেহজনক কিছু ঘটলে অবিলম্বে জানান।
১০. প্রতিবন্ধী ব্যক্তি ও অভিভাবকের অধিকার
- জানার অধিকার: তাঁর সম্পর্কে ডিআইএস-এ কী তথ্য রক্ষিত আছে তা জানার অধিকার;
- সংশোধনের অধিকার: ভুল বা অসম্পূর্ণ তথ্য সংশোধন করানোর অধিকার;
- সীমিত ব্যবহারের নিশ্চয়তা: নির্ধারিত উদ্দেশ্যের বাইরে তথ্য ব্যবহৃত না হওয়ার অধিকার;
- অভিযোগের অধিকার: তথ্যের অপব্যবহার সম্পর্কে অভিযোগ দাখিল ও প্রতিকার পাওয়ার অধিকার;
- প্রবেশগম্য মাধ্যমে যোগাযোগের অধিকার: অভিভাবক, আইনানুগ প্রতিনিধি বা সহায়তাকারীর মাধ্যমেও এই অধিকারগুলো প্রয়োগ করা যায়।
এসব অধিকার প্রয়োগের জন্য নিকটস্থ উপজেলা/শহর সমাজসেবা কার্যালয়ে অথবা অনুচ্ছেদ ১৫-এ উল্লিখিত ঠিকানায় যোগাযোগ করুন। পরিচয় যাচাইয়ের পর যুক্তিসঙ্গত সময়ের মধ্যে ব্যবস্থা নেওয়া হয়।
১১. শিশুদের তথ্য
প্রতিবন্ধী শিশুদের নিবন্ধন এই ব্যবস্থার অন্তর্ভুক্ত। শিশুর তথ্য কেবল তার পিতা-মাতা বা আইনানুগ অভিভাবকের সম্মতিক্রমে এবং তাঁদের উপস্থিতিতে সংগ্রহ করা হয়। শিশুদের তথ্য প্রাপ্তবয়স্কদের তথ্যের মতোই — বরং অতিরিক্ত সতর্কতার সঙ্গে — সুরক্ষিত রাখা হয় এবং কোনো অবস্থাতেই বিপণন বা প্রোফাইলিংয়ের কাজে ব্যবহার করা হয় না। অ্যাপটি শিশুদের স্বতন্ত্র ব্যবহারের জন্য নয়; এটি কেবল অনুমোদিত দাপ্তরিক ব্যবহারকারীদের জন্য।
১২. তৃতীয় পক্ষের সেবা, বিজ্ঞাপন ও ট্র্যাকিং
- এই অ্যাপে কোনো বিজ্ঞাপন প্রদর্শিত হয় না;
- কোনো বিজ্ঞাপন নেটওয়ার্ক, বিশ্লেষণ (analytics) বা আচরণ-ট্র্যাকিং এসডিকে যুক্ত নেই;
- ব্যবহারকারীর তথ্য কোনো বাণিজ্যিক প্রতিষ্ঠানের সঙ্গে বিনিময় করা হয় না;
- অ্যাপ হালনাগাদের বার্তা দেখানোর সময় ব্যবহারকারীকে গুগল প্লে স্টোরে পাঠানো হতে পারে; সে ক্ষেত্রে গুগলের নিজস্ব গোপনীয়তা নীতি প্রযোজ্য হবে।
১৩. প্রবেশগম্যতা (Accessibility)
এই অ্যাপ প্রতিবন্ধী ব্যক্তিদের সেবায় নিয়োজিত; তাই প্রবেশগম্যতা এর একটি মৌলিক শর্ত। অ্যাপটি WCAG 2.2 Level AA মান অনুসরণের লক্ষ্যে তৈরি — স্ক্রিন রিডার (TalkBack/VoiceOver) সমর্থন, বাংলা ভাষায় সঠিক উচ্চারণের জন্য ভাষা-চিহ্নিতকরণ, পর্যাপ্ত রঙ-বৈপরীত্য, বড় ফন্ট ও বর্ধিত স্পর্শ-এলাকা এতে অন্তর্ভুক্ত। এই গোপনীয়তা নীতির পাতাটিও একই নীতিতে তৈরি। প্রবেশগম্যতা সংক্রান্ত সমস্যা জানাতে অনুচ্ছেদ ১৫-এর ঠিকানায় যোগাযোগ করুন।
১৪. নীতির পরিবর্তন
আইন, নীতিমালা বা অ্যাপের কার্যক্রম পরিবর্তিত হলে এই গোপনীয়তা নীতি হালনাগাদ করা হতে পারে। হালনাগাদকৃত নীতি এই ঠিকানায় প্রকাশ করা হবে এবং “সর্বশেষ হালনাগাদ” তারিখ পরিবর্তন করা হবে। উল্লেখযোগ্য পরিবর্তনের ক্ষেত্রে অ্যাপের মাধ্যমে বা দাপ্তরিক বিজ্ঞপ্তির মাধ্যমে জানানো হবে।
১৫. যোগাযোগ ও অভিযোগ
এই নীতি, আপনার তথ্য বা কোনো অভিযোগ সম্পর্কে যোগাযোগ করুন:
Privacy Policy
1. Introduction and scope
DIS (Disability Information System) is the government information system operated by the Department of Social Services (DSS), Ministry of Social Welfare, Government of the People's Republic of Bangladesh, for the registration, medical verification, approval and identity-card management of persons with disabilities. This privacy policy applies to the DIS mobile application and explains what information is collected, why it is collected, with whom it is shared, how long it is kept, and what rights the people described in the records have.
All data held in DIS belongs to the Government of the People's Republic of Bangladesh and is held in custody by the Department of Social Services. This is not a private or commercial application.
2. Legal basis
Collection, storage and use of data in DIS is governed by:
- the Rights and Protection of Persons with Disabilities Act, 2013 and the rules made under it;
- the Policy on the Use of Data of Persons with Disabilities, 2021 (প্রতিবন্ধী ব্যক্তির তথ্য-উপাত্ত ব্যবহার নীতিমালা, ২০২১; Bangladesh Gazette, Extraordinary, 2 August 2021), which prescribes the only authorised procedure for supplying, exchanging and using DIS data;
- the United Nations Convention on the Rights of Persons with Disabilities (UNCRPD), ratified by Bangladesh;
- the Right to Information Act, 2009, including its limits on disclosing personal and sensitive information;
- applicable cyber-security legislation and government record-retention rules.
Under the 2021 policy, DIS data may be released only for a stated purpose, on a written application, with the approval of the competent authority, and subject to a signed undertaking by the recipient. This policy is written to conform to those requirements.
3. Who uses this app
This is a departmental application. An account issued by the Department of Social Services is required; there is no public self-registration. Authorised users are:
- field and office staff of the Department of Social Services;
- registered physicians (medical officers) who verify disability type and degree;
- officers who recommend and approve records.
Persons with disabilities and their guardians do not create accounts here. Their information is entered into the registration form by an authorised officer with their consent (or the consent of a legal guardian). This policy protects those individuals equally.
4. Information we collect
a) Account information of app users
- username, password and assigned role;
- name, email address, mobile number and profile photograph;
- posting details: division, district, upazila/city corporation and office identity;
- for physicians, the medical registration number and OTP verification sent to the registered mobile number.
b) Registration data of persons with disabilities (sensitive data)
The registration form collects the following categories:
- Identity: name in Bengali and English, father's name, mother's name, spouse's name, guardian's name, and the name and relationship of the information provider;
- Government identifiers: National ID (NID) number or birth registration number;
- Demographics: date of birth and age, place of birth, gender, marital status, religion, ethnicity, nationality, blood group;
- Addresses: permanent and present address (division, district, upazila/city corporation, ward, house/village);
- Contact: guardian's mobile number and email address;
- Socio-economic data: family composition, educational status, profession, yearly income, house ownership, and services or allowances already received;
- Health and disability data: disability type, cause and degree; the verifying physician's findings; answers to functional-assessment questions covering sight, hearing, mobility, speech, comprehension and behaviour; epilepsy; use of assistive devices such as hearing aids or spectacles; and family history of disability;
- Description of violence or abuse, where applicable;
- Biometric-type records: photograph and image of the signature;
- Administrative data: form number, verifying doctor's name and registration number, the identity of the data-entry officer, and creation and update timestamps.
About sensitive data: disability and health information is highly sensitive. It is used only to deliver government services, to verify records and to produce the disability identity card, and it is not released to anyone outside the procedure laid down in the 2021 policy.
c) Technical and device information
- information needed to check the app version and show update notices;
- network connectivity state (online/offline), used to show offline messages;
- ordinary network logs produced when the app calls the server (such as IP address and timestamp), retained on government servers for security and audit purposes.
The app does not collect location (GPS), contacts, SMS, call logs, microphone input or an advertising identifier.
d) Data stored on the device
- the login session and dashboard counters are kept in app-private storage (SharedPreferences);
- photographs taken with the camera or chosen from the gallery are stored temporarily and are no longer needed once submitted;
- signing out or uninstalling the app removes this locally stored data.
5. App permissions
| Permission | Why it is needed |
|---|---|
INTERNET |
To exchange data with the DIS server. |
CAMERA |
To capture the photograph and signature for the registration form and the user's profile picture. Images may also be chosen from the gallery instead. |
READ_EXTERNAL_STORAGE, WRITE_EXTERNAL_STORAGE |
To select an image from the gallery, crop it, and generate and print the identity-card PDF. On recent Android versions these operations take place in app-private storage. |
FLASHLIGHT |
To use the camera flash when capturing a photograph in low light. |
Any permission may be withdrawn at any time from the device settings. Declining a permission only disables the related feature, such as attaching a photograph.
6. How we use the information
Collected information is used only to:
- receive, verify, recommend and approve the registration of a person with a disability;
- produce, display and print the disability identity card;
- verify the authenticity of a registration by form ID, NID or DIS ID;
- support decisions on eligibility for allowances and other government services;
- authenticate users and protect accounts, including OTP verification;
- produce anonymous aggregate statistics for planning and policy;
- support departmental audit, accountability and grievance redress.
The information is never sold or rented, and is never used for advertising, marketing or profiling.
7. Disclosure and data sharing
DIS data is shared only in the following circumstances and by the prescribed procedure:
- Within government: authorised officers of the Department of Social Services and the Ministry of Social Welfare, and verifying physicians, may view records within the limits of their role and jurisdiction.
- Other government, autonomous or registered non-government organisations: under the Policy on the Use of Data of Persons with Disabilities, 2021, limited data is supplied for a specified purpose only, on a written application in the prescribed form, after approval by the competent committee and execution of an undertaking.
- Through API access: approved organisations may be granted limited API access under an agreement and with issued credentials. Registration and logging of the real IP address is mandatory, and access is time-limited, renewable and revocable.
- Legal obligation: to satisfy a lawful demand of a competent authority or an order of a court under applicable law.
An approved recipient may not use the data for any other purpose, transfer it to a third party or publish it, and is obliged to destroy or delete the data once the purpose is served and to inform the Department. Breach of these conditions leads to cancellation of access and action under applicable law.
8. Retention and deletion
- A disability registration is a permanent national record and is retained in accordance with government record-retention rules for service delivery, card renewal and audit.
- Incorrect or incomplete information can be corrected through the nearest Social Services office; the app supports correction, and every change is logged with the identity of the officer and the time.
- Departmental user accounts are deactivated on transfer, retirement or change of duty.
- A deletion request may be made (see section 15). Complete erasure may not be possible where a record is subject to a legal or administrative obligation; in that case the reason will be explained.
- Data held on the device (login session, temporary images) is removed on sign-out or uninstallation.
9. Security of information
Measures taken to protect the confidentiality and integrity of the data include:
- access to the app only with an account issued by the Department;
- OTP (one-time password) verification to the registered mobile number for physicians;
- role-based and jurisdiction-based access, so each user sees only the records within their remit;
- server access controlled by an API key and authentication headers;
- user-attributed audit logs for every entry, correction and approval;
- storage in government data-centre infrastructure and a duty of confidentiality on all officers.
Even so, no method of transmission over the internet or of electronic storage can be guaranteed to be completely secure. Users are asked never to share a password or OTP and to report anything suspicious immediately.
10. Rights of persons with disabilities and guardians
- Right to know what information about them is held in DIS;
- Right to correction of inaccurate or incomplete information;
- Right to purpose limitation — assurance that the data is not used beyond the stated purpose;
- Right to complain about misuse of the data and to obtain redress;
- Right to accessible channels — these rights may be exercised through a guardian, legal representative or support person.
To exercise these rights, contact the nearest upazila or city Social Services office or the address in section 15. Requests are acted on within a reasonable time after identity is verified.
11. Children's data
Registration of children with disabilities is part of this system. A child's information is collected only with the consent and in the presence of a parent or legal guardian. It is protected on the same basis as an adult's data — with additional care — and is never used for marketing or profiling. The app is not intended for independent use by children; it is for authorised departmental users only.
12. Third-party services, advertising and tracking
- the app shows no advertising;
- it embeds no advertising network, analytics or behavioural-tracking SDK;
- user data is not shared with any commercial organisation;
- when an update notice is shown, the user may be taken to the Google Play Store, where Google's own privacy policy applies.
13. Accessibility
This app exists to serve persons with disabilities, so accessibility is a fundamental requirement rather than an extra. The application is built to meet WCAG 2.2 Level AA: screen-reader support (TalkBack/VoiceOver), per-language tagging so Bengali and English are pronounced correctly, sufficient colour contrast, larger text and enlarged touch targets. This policy page follows the same principles. Report any accessibility problem to the contact in section 15.
14. Changes to this policy
This policy may be updated when the law, the governing policy or the app's functionality changes. The updated policy will be published at this address and the "last updated" date will change. Significant changes will be announced in the app or by departmental notice.
15. Contact and complaints
For questions about this policy, your data, or to make a complaint: