DFI Social Media Policy​

This privacy policy was last changed on September 16, 2026.

Contents

A. Definitions

A.1 Inappropriate Content

  1. Any post, comment, or content piece including (but not limited to) those that may be considered misleading, harmful, discriminatory, political, defamatory, hateful, harassing, sexual, illegal, antagonistic, or infringing material. This includes (but is not limited to) slurs, slang, idioms, violent imagery, or offensive language.

A.2 Content Piece

  1. Any work or production of text, imagery, graphics, audio, video, live-stream, AI-generated material, or other multimedia.

A.3 Social Media

  1. Any platform, network, group, website, or app that allows posting, commenting, messaging, or dialogue. As well as any emerging or future social networks/platforms as reviewed periodically by DFI.

A.4 Team Members

  1. Any DFI staff member (employee) or contractor.

A.5 DFI Association Members

  1. Any DFI member, volunteer, partner, or subordinate.

B. Internal Policy (Team members)

B.1 Values and Ethics

B.1.1 Conduct

  1. All social media spaces are considered public. Professional judgment, integrity, and caution must be applied.
    1. If you are unsure if the content or statements you are about to share or post are appropriate, seek advice from the social media manager, CISO, or Executive Director.
  2. Team Members may only post on their own behalf and must not share personal opinions contrary to DFI policies.
  3. Inappropriate content must be removed within 1 hour of notice.
  4. DFI reserves the right to monitor public content shared by Team Members.
  5. Do not post disparaging, harmful, or misleading content relating to DFI.
  6. Media inquiries or press attention must be referred to authorized spokespersons.
  7. Access to DFI social media accounts from personal (BYOD) devices must comply with the DFI’s (internal) BYOD Policy.

B.1.2 Honesty & Integrity

  1. Misleading, false, or inappropriate content will be removed immediately and may result in corrective action.

B.1.3 Authenticity

  1. Content officers must verify accuracy before posting. AI-generated material must be reviewed for accuracy, fairness, and bias mitigation.

B.2 Privacy and Confidentiality

  1. Team Members may not disclose private information of DFI members, staff, clients, or partners.
  2. Internal, operational, financial, legal, or client/member-related information must not be shared.
  3. DFI intellectual property and confidential data remain the sole property of DFI.
  4. Screenshots or saved ephemeral content must not be distributed without explicit consent.
  5. Under no circumstances may confidential, restricted or private information be disclosed via social media channels.

B.3 Attribution

  1. All original sources must be attributed clearly and transparently.
    Example: “This article by [author] was originally published in [source]. Link: [URL].”

B.4 Conflict of Interest

  1. A conflict of interest exists if you have an interest outside of your work at DFI that interferes with your responsibilities or may affect your judgment on behalf of DFI.
  2. Critical comments relating to DFI policies, procedures, practices, or related to other industry organizations may be considered a conflict of interest.
  3. Conflicting content must be removed/deleted within the provided timeframe, or further official action may be required at the discretion of the IT Director or Executive Director.

B.5 Security

  1. Passwords for DFI Social media accounts must be at least 16 characters (alphanumeric and special characters).
  2. Social media accounts must be protected with multi-factor authentication (MFA), where available.
  3. Passwords shall be reviewed at least annually and changed immediately if:
    1. Compromise is suspected,
    2. When staff roles change,
    3. Or as required by the Chief Information Security Officer (CISO) or Executive Director.
  4. Social media management tools require prior approval by CISO and/or Executive Director, as per the DFI Software Policy.
  5. All social media accounts and credentials remain the property of DFI.
  6. The use of unauthorized or unapproved tools (“Shadow IT”) is strictly prohibited and may result in immediate access revocation and corrective action.
  7. Access to social media accounts must be:
    1. Reviewed every six months.
    2. Granted only upon formal Exertive Director approval.
    3. Immediately revoked upon role change or termination.
    4. Reviewed during periodic access audits.
  8. DFI acknowledges that social media platforms are third-party services subject to external jurisdiction, data handling practices, and security risks. Platforms deemed high-risk (based on geopolitical, regulatory, or data protection concerns) may be restricted or prohibited by the CISO or Executive Director.

B.5.1 Owner Accounts

  1. All “Owner”, “Root”, or other top-level administrative accounts for DFI systems, platforms, and social-media assets must be defined, created, and controlled by the CISO, Executive Director or an approved delegate, and recorded in the Approved
    Software Register, as per the DFI Software Policy.
  2. All access to social media platforms must follow the principle of least privilege and be role-based.
  3. Access levels (e.g., Owner, Admin, Editor, Analyst) must be:
    1. Defined and documented in the DFI Access Register.
    2. Approved by the CISO or delegate.
    3. Reviewed biannually.
  4. Shared credentials are prohibited unless technically unavoidable and must be managed via an approved shared inbox.

B.6 AI-Generated Content

  1. AI tools used in social media activities must comply with the DFI AI Policy and be approved via the Software Approval Process as outlined in the DFI Software Policy.
  2. Use of AI must be risk-assessed in accordance with DFI AI policy requirements and may be subject to review by the Artificial Intelligence Oversight Team (AIOT).
  3. All AI-generated content must be disclosed internally and verified for:
    1. Accuracy and factual reliability.
    2. Fairness, bias, and ethical compliance.
    3. Transparency (clear labelling if automated responses are used).
  4. The following uses are prohibited unless explicitly approved:
    1. Fully autonomous posting without human review.
    2. Generation of synthetic personas or impersonation.
    3. Use of external AI tools that process DFI data without approved data protection controls.
  5. All AI-assisted outputs must be reviewed by a human prior to publication.

B.7 Advertising/Commercial Content

  1. No advertising or commercial content may be posted without approval, excluding official sponsored campaigns.

B.8 Crisis & Incident Response

  1. Inappropriate or hacked content must be deleted immediately.
  2. Social media incidents (hacks, phishing, impersonation) must be reported to the CISO and Executive Director within 30 minutes of discovery.
  3. Compromised accounts must be locked, passwords changed, and an incident report logged.
  4. Crisis communications must be coordinated across all platforms.

B.9 Violations

  1. Violations may result in corrective action up to and including dismissal, depending on severity, at the discretion of the Executive Director, as per the (internal) DFI Staff Guide.

C. Member Policy (DFI Association Members)

C.1 Conduct & Ethics

  1. Members must uphold professionalism, integrity, and caution across all social media platforms.
  2. Members may not misrepresent DFI or use its name/branding without authorization.
  3. Inappropriate posts must be removed within 1 hour of notice.
  4. Members should be aware that DFI may observe content and information made available by members through social media.
  5. Members should use their best judgment and avoid posting material that is
    inappropriate, or disparaging to, or that reflects negatively on DFI, its employees, members, or customers.
  6. Members are not permitted to post (over official DFI channels) any content considered as advertising or commercial in nature, unless approved.

C.2 Content Quality

  1. Content must be accurate, respectful, and aligned with DFI’s values.
  2. Deliberately misleading, manipulated, or “deepfake” content is prohibited.
  3. Live streams must adhere to DFI’s standards.
  4. All content generated (including live streaming) must satisfy DFI’s standards:
    1. High in quality.
    2. Professionally produced with appropriate equipment and methods.
  5. Lo-fi or “Dank”, deliberately low quality content pieces will not meet DFI’s standards and are subject to moderation/removal.
  6. DFI reserves the right to edit or amend any content piece as well as the right to delete posts, comments, or content pieces violating this policy.

C.3 Privacy & Intellectual Property

  1. Members may not disclose internal, financial, or operational information.
  2. Attribution and copyright compliance must always be observed.
  3. No user has the right to post any information or details pertaining to other members or users and/or their affiliations or organizations.
  4. Any post, content piece, or comment found to infringe on DFI’s or any other organization or individual’s intellectual property rights will be subject to immediate removal.
  5. DFI does not take any responsibility for member posts or content pieces found to be infringing on any organization or individual’s intellectual property or copyright.

C.3.1 Intellectual Property Ownership

  1. DFI retains ownership of all intellectual property, materials, and outputs created, developed, or produced as part of official DFI duties, projects, committees, or sponsored activities.
    1. Including materials produced by staff, contractors, committee or task force participants or association members in the course of DFI activities.
  2. This ownership does not extend to personal work, pre-existing materials (unless submitted to DFI for usage), or outputs developed independently of DFI activities.
  3. Contributors and members grant DFI a non-exclusive right to use and reproduce submitted materials for official purposes, while retaining personal rights to their independent work.
  4. DFI acknowledges authorship and credits contributors in accordance with its Attribution Policy.

C.4 Liability

  1. DFI assumes no responsibility for inappropriate member content and reserves the right to pursue legal action where reputational harm or third-party claims arise.

C.5 Violations

  1. Depending on the magnitude of a violation, a DFI member may be removed (account and association membership revocation) for a violation of the policies contained herein at the discretion of the CISO or Executive Director.
  2. Repeat offenses may result in a user’s name being recorded on a “Blacklist” preventing future membership or involvement with DFI.
    1. The DFI social media blacklist may be shared with partner organizations.

D. Grievances

DFI is committed to ensuring that social media platforms are used ethically, transparently, and responsibly. If stakeholders (including staff, contractors, members, or partners) have complaints or grievances regarding the use of social media under DFI’s name or affiliation, the following grievance procedure will be followed to address and resolve issues fairly, impartially, and in a timely manner.

D.1 Grievance Identification and Reporting

  1. Any stakeholder who believes that social media activity connected to DFI (official accounts, staff/member conduct, or affiliated channels) has violated this policy, ethical guidelines, or caused harm may submit a grievance. Examples include but are not limited to:
    1. Misuse of DFI branding.
    2. Harassment.
    3. Data/privacy breaches.
    4. Posting of inappropriate or misleading content.
    5. Reputational damage.
  2. Grievances may be submitted via the designated online Social Media Complaint Form.
  3. Anonymous grievances will not be accepted, in order to ensure proper investigation and resolution.
  4. DFI designates the CISO (or delegate) as the Social Media Complaints Officer responsible for:
    1. Investigating complaints impartially and thoroughly.
    2. Ensuring compliance with applicable privacy, legal, and regulatory requirements.
    3. Recording complaints in a Social Media Complaints Register, including date, nature, investigation, outcome, and corrective measures.
    4. Recommending/implementing improvements based on findings.
  5. Initial Review: All grievances will be acknowledged within five business days, with an initial review conducted to assess seriousness, scope, and relevance.

D.2 Investigation and Resolution

  1. Investigation Initiation: If the grievance is deemed legitimate, a formal investigation will be launched.
  2. Timeline for Resolution: Investigations will be resolved within 30 days, unless circumstances require an extension, in which case the complainant will be notified of the delay and updated timelines.
  3. Evidence Gathering: The investigation may include review of posts, comments, screenshots, internal records, and interviews with involved parties.
  4. Findings Report: At the conclusion, the Complaints Officer will provide a findings report, outlining the outcome and recommended corrective actions, which will be shared with relevant stakeholders and leadership.

D.3 Grievance Process

  1. Submitting a Complaint: Written submission through the official Social Media Complaint Form.
  2. Informal Resolution: Where possible, complaints may be resolved informally with corrective action documented.
  3. Formal Complaint Handling: If unresolved informally, the matter will be escalated to the Executive Director and/or the Board of Trustees.
  4. Investigation: The Complaints Officer will maintain impartiality, gather evidence, and liaise with decision-makers.
  5. Decision Letter: A written response outlining findings and corrective actions will be issued to the complainant. If unsatisfied, complainants may escalate to external authorities.

D.4 Corrective Actions and Outcomes

  1. Corrective Measures: Substantiated grievances may result in corrective actions (e.g., post removal, account suspension, member sanctions, or staff dismissal).
    1. Depending on seriousness, measures may include membership suspension, revocation, or permanent blacklisting from future involvement with DFI.
  2. Outcome Communication: The complainant will be informed of the findings and actions taken.

D.5 Post-Complaint Review and Analysis

  1. After resolution, a review will assess the impact of the grievance, including reputational effects, stakeholder harm, and process improvements.

D.6 Documentation and Reporting

  1. A Grievance Report will be compiled for each case and shared with relevant stakeholders.
  2. All records will be securely retained in the Social Media Complaints Register for a minimum of seven (7) years to meet compliance and audit requirements.

D.7 External Grievances

  1. If a complainant believes DFI has not acted in accordance with ethical, legal, or professional standards, grievances may be escalated to external regulators, associations, or legal authorities. DFI will cooperate fully with these bodies.

E. Incidents

DFI recognizes that social media incidents can pose risks to reputation, data security, and member trust. To safeguard stakeholders and ensure effective crisis management, the following incident response procedure shall be applied to all DFI-affiliated social media accounts and activities.

E.1 Incident Reporting

  1. Incident Officer: DFI designates the CISO as the Social Media Incident Officer (or delegate).
    1. Responsibilities include impartial investigation, coordination of response, and maintaining an Incident Register.
  2. Any staff member, contractor, volunteer, or stakeholder who identifies a potential social media incident must immediately notify the Incident Officer via the official Social Media Incident Form.
  3. Anonymous incident submissions will not be accepted.

E.1.1 Incident Identification and Notification

  1. Social media incidents include but are not limited to:
    1. Unauthorized access to DFI accounts (e.g., hacks, phishing).
    2. Posting of harmful, misleading, or offensive content on DFI-affiliated channels.
    3. Unauthorized disclosure of confidential, private, or member data.
    4. Impersonation of DFI or its representatives.
    5. Malfunction or misuse of third-party tools linked to DFI accounts.
  2. Notification reports should include the nature of the incident, platform involved, time of occurrence, and urgency, as per the Social Media Incident Form.

E.1.2 Risk Matrix

A table describing the different levels of Social Media risks.

E.1.3 Escalation

  1. Critical incidents must be reported to the Executive Director and CISO within 2 hours.
  2. Legal authorities or regulators will be notified if personal data, financial fraud, or harassment is involved.

E.2 Containment and Mitigation

  1. Immediate Containment: Compromised accounts must be locked and passwords reset using MFA.
  2. Content Removal: Harmful or inappropriate posts must be deleted as soon as practicable.
  3. Third-Party Tools: Disable or isolate compromised scheduling/analytics tools until secure.
  4. Root Cause Analysis: Incident Officer to determine cause (e.g., phishing, weak password, staff error, et al..).

E.3 Incident Resolution

  1. Corrective Actions: May include removal of content, revocation of access rights, retraining of staff, or dismissal.
  2. Resolution Documentation: Every incident response must be logged, detailing actions, timelines, and outcomes.

E.4 Post-Incident Review and Analysis

  1. After resolution, a formal review will be conducted to:
    1. Assess impact and scope.
    2. Identify control gaps.
    3. Recommend policy or training improvements.

E.4.1 Corrective Measures and Policy Updates

  1. Following the review, necessary improvements will be implemented (e.g., stronger authentication, revised staff training).
  2. The Social Media Policy will be updated if systemic issues or new risks are identified.

E.5 Documentation and Reporting

  1. Social Media Incident Report: A full report shall be compiled for each incident, summarizing findings, corrective actions, and outcomes.
  2. Social Media Incident Register: All incidents will be logged in the Social Media Incident Register and reviewed annually.
  3. Records will be securely retained for seven (7) years to ensure compliance and enable auditing.

F. Review and Appeal

F.1 Purpose

  1. To provide a fair, transparent, and timely mechanism for any individual or entity subject to an incident or grievance outcome to request a review or appeal of that decision.

F.2 Scope

  1. This process applies to:
    1. Staff, contractors, members, or volunteers directly involved in or affected by a DFI social media related incident or grievance investigation.
      1. Decisions issued under Sections 4.0 Grievances or 5.0 Incidents of this policy.

F.3 Review

  1. Any party subject to corrective action may submit a written Request for Review within ten (10) business days of receiving the formal outcome notice.
  2. The request must specify the grounds for review, which may include:
    1. New or previously unavailable evidence.
    2. Procedural error or bias.
    3. Disproportionate or inconsistent outcome.
  3. Requests for review must be provided to the CISO via email.

F.3.1 Review Process

  1. The CISO will assign a Review Officer independent of the original investigator(s).
  2. The Review Officer will:
    1. Examine the original findings, evidence, and requested grounds.
    2. Consult relevant parties and, if needed, request additional information.
    3. Complete the review and issue written findings within twenty (20) business days of receiving the request.
  3. The Review Officer may uphold, amend, or overturn the original decision, and may recommend additional corrective actions.
  4. The Review Officer’s decision will be provided in writing to the complainant, respondent, and CISO and Executive Director, and recorded in the relevant Register.

F.4 Appeal

  1. If the affected party disagrees with the review outcome, they may file a formal written Appeal to the Executive Director within ten (10) business days of receipt of the review decision.
  2. Requests must be provided to the Executive Director via email.

F.4.1 Appeal Process

  1. The Executive Director will consider:
    1. Whether due process was followed.
    2. Whether the decision was reasonable and supported by evidence.
    3. Whether additional action is warranted.
  2. The Executive Director may:
    1. Uphold, amend, or overturn the review decision, and may recommend additional corrective actions.
    2. Refer the matter for further investigation.
  3. The Executive Director’s decision will be provided in writing to the complainant, respondent, and recorded in the relevant Register.
  4. The Executive Director’s decision constitutes the final internal determination.

F.5 Recordkeeping

  1. All review and appeal documentation will be retained in the relevant register (Grievance Register or Incident Register) for a minimum of three (3) years, in accordance with DFI’s data retention and privacy obligations.

F.6 External Escalation

  1. Where legal, regulatory, or ethical concerns remain unresolved, complainants may refer the matter to applicable external authorities or regulatory bodies. DFI will cooperate fully with any lawful external investigation.

G. Updates

This policy will be reviewed annually and updated as required to reflect evolving technological, legal, and ethical considerations.

This policy may be updated with no warning or notice, please check regularly for the latest version.

Scroll to Top