Use this working method to prepare a specific, testable project. It is an editorial planning guide, not an eligibility decision or a promise of funding.
Map the data before collecting it
List every field you want to collect, who needs it and why. Separate contact information from the substance of a report. If a field will not change a decision, consider removing it. Test the form without requiring identity documents or precise locations.
Explain participation in plain language
Tell people what is collected, who can access it, what will be published and how long it is retained. Do not equate a checked box with understanding. Provide a way to ask questions and a non-digital route where feasible.
Assess exposure
Citizen reports can disclose sensitive issues, affiliations or vulnerabilities. Decide whether information should be public, aggregated, delayed or restricted. Remove names and location clues from examples. Have a review process for material that could expose a person to retaliation.
Design access and retention
Give staff only the access their role requires. Define how access is removed when somebody leaves. Write down the retention period, the deletion process and who handles incidents. Backups also need a retention and access policy.
Test with an incident exercise
Imagine a lost device, an accidentally shared spreadsheet or a harmful public report. Identify who stops collection, contacts affected people and restores access safely. Record decisions and unresolved questions. Ask a qualified local adviser about applicable law; this checklist is not legal advice.