MSI Kenya Data Protection Policy
Introduction
Management Systems International (MSI) Kenya (hereinafter “we”, “us”, or “our”) is committed to protecting the privacy and security of your personal data (hereinafter “personal information”). As part of our operations, we will need to collect, store, transmit, and otherwise process or use (hereinafter “process”) your personal information. Personal information will include any offline or online data that relates to you.
While some of the countries in which MSI Kenya operates have their own privacy laws, this is a global privacy policy statement (hereinafter this “policy”) supporting these country-specific laws. This policy summarizes how we look after any personal information processed.
Where there are differences in the way we process your personal information due to local laws, we will notify you of this through supplementary or specific privacy statements/notices.
MSI Kenya will process your personal information in accordance with this policy unless otherwise required by applicable law.
MSI Kenya is the “data controller.” This means that we are responsible for deciding how we hold and use personal information about you.
The terms used in this policy shall have the meanings ascribed to them under the applicable laws unless the context otherwise requires.
Scope
This policy applies to:
- MSI Kenya and all its operations in Kenya in relation to individuals located in Kenya;
- all persons engaged by MSI Kenya and who process personal information including permanent, fixed term and temporary/casual employees, consultants, interns and directors (hereinafter “employees”); and
- all third-party representatives, agents and related entities which process any personal information for or on behalf of MSI Kenya, (hereinafter “third parties”).
MSI Kenya, all employees and third parties are expected to comply with the Data Protection Act, 2019 and the applicable subsidiary legislation including the guidelines issued from time to time by the regulator (hereinafter the “applicable laws”) and this policy in so far as relates to the processing of any personal information and must ensure that all personal information is processed in accordance with this policy and the applicable laws.
Norah Ochiel, MSI’s Deputy Chief of Party for the USAID Communications for Development Project, is responsible for overseeing the implementation and review of this policy and can be contacted through [email protected].
Privacy principles
In line with applicable privacy laws, we will:
- protect your personal information and keep it secure.
- process your personal information lawfully, fairly, and in a transparent way.
- process your personal information in accordance with your right to privacy and only for valid purposes that we have clearly explained to you and not use in any way that is incompatible with those purposes without having informed you or sought your consent, where necessary.
- process your personal information relevant to the purposes we have told you about and limited only to those purposes.
- keep your personal information in a form which identifies you only as long as necessary for the purposes we have told you about or to satisfy our legal and regulatory obligations or for our legitimate purposes.
- keep your personal information accurate and where necessary kept up to date. You must check the accuracy of any personal information at the point of collection and regular intervals thereafter.
We are responsible for and must be able to demonstrate compliance with the privacy principles listed above.
Personal information we may collect about you
Personal information means any information about an individual from which that person can be identified or is identifiable by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social or social identity. Personal information includes sensitive personal data namely data revealing an individual’s race, health status, ethnic social origin, conscience, belief, genetic data, biometric data, property details, marital status, family details including names of the individual’s children, parents, spouse or spouses, sex or the sexual orientation of the individual. It does not include information where the identity has been permanently removed so that an individual is no longer identifiable (anonymized data).
The personal information we collect and process will depend on how you interact with us. This may include but is not limited to:
- identity data – such as first name, last name, username, images or videos or similar
- contact data – such as email address, location, and telephone number
- employment-related data including name, address, email address, education, and work information– if applying for a job vacancy
- marketing and communications data – including your preferences in receiving marketing information
How we collect your personal information
We collect your personal information through your direct interaction with MSI Kenya. Whenever we collect your personal information directly from you, we will provide you will all the information required by the applicable laws including the identity of the controller, and how and why we will use, process, disclose, protect, retain that personal information through a privacy notice which must in so far as practicable be provided before an individual provides their personal information or when an individual first provides their personal information.
We may also collect or otherwise process your personal information indirectly through other sources (for example, from any person other than the individual, publicly available publications or databases, surveillance cameras, information associated with web browsing, or biometric technology, including voice or facial recognition) in accordance with the applicable laws.
How we may use your personal information
We will process your personal information in line with applicable privacy laws. The applicable laws allow for the processing of your personal information where:
- you have consented to the processing for one or more specified purposes;
- the processing is necessary for the performance of a contract which you are a party or in order to take steps at your request before entering into a contract;
- the processing is necessary for compliance with a legal obligation to which we are subject; or
- the processing is necessary for our legitimate business purpose or purposes or for the legitimate interests pursued by a third party to whom the personal information is disclosed provided such purposes are not overridden by the interests or fundamental rights and freedoms of the individuals.
The following are examples of situations where we may use the personal information you provide to us:
- responding to an inquiry you have made via email.
- deciding about a job application you have submitted.
- to send you marketing information relating to MSI Kenya’s activities, if you have requested information from us and you have not opted out of receiving that marketing. We will get your express opt-in consent before we share your personal information with any third party for marketing purposes. You can opt out of marketing information at any time by clicking on the unsubscribe link on the email you have received from us.
- photo/video/audio and written content may be used for promotional materials, website, social media to the extent permitted by applicable laws.
We may also use your personal information in the following situations, where necessary:
- where we need to protect your interests (or someone else’s interests)
- where it is needed in the public interest or for official purposes
Where you have provided your personal information based on consent, the following guidelines shall apply:
- an individual consents to the processing of their personal information if they indicate agreement to the processing clearly – either by a statement or positive action. Consent requires affirmative action from an individual and as such silence, pre-ticked boxes, or inaction will not be sufficient.
- if consent is given in a document that deals with other matters, then we will keep the consent separate from those other matters.
- in obtaining consent of an individual, the individual will need to have the capacity to consent. Further, the individual must voluntarily give consent and the consent, will need to be specific to the purpose or purposes of processing. Consent may need to be refreshed if we intend to process personal information for a different and incompatible purpose which was not disclosed when the individual first consented.
- an individual will be able to withdraw consent to processing at any time. Further details about withdrawing consent can be found below.
- we will maintain a record of all consents in accordance with our applicable policies.
The legal basis being relied on for each processing activity will always be identified and documented in accordance with this policy.
Change of purpose
We will only use your personal information for the purposes for which we collected it unless we reasonably consider that we need to use it for another reason and that reason is compatible with the original purpose. If we need to use your personal information for an unrelated purpose, we will notify you and we will explain the legal basis that allows us to do so.
Please note that we may process your personal information without your knowledge or consent, in compliance with the above rules, where this is required or permitted by law.
Disclosure of your personal information
We will only share your personal information with third parties where required by law, where it is necessary to administer the working relationship with you, or where we have another legitimate interest in doing so. We may also need to disclose some of your personal data to third-party service providers such as payroll providers, pension providers, health insurers, financial institutions, and our professional advisers. Your personal information will only be shared with third parties in accordance with the privacy notice provided to you and if required, with your consent having been obtained.
MSI Kenya expects third-party providers of your personal information to only use that information for the purpose(s) for which it was originally collected or subsequently authorized by you, as well as respect the security of your data and to treat it in accordance with the applicable laws. All our third-party service providers and other entities in our group are required to take appropriate security measures to protect your personal information in line with our policies. We do not allow our third-party service providers to use your personal information for their own purposes.
We will not trade, sell, rent, or otherwise use your personal information for commercial purposes without your consent and in accordance with the applicable law, but may collect and/or provide aggregate statistics about users or reach and engagement of content containing photo/video/audio or written content on social media or other online platforms to other third-parties.
International transfers of your personal information
MSI Kenya is a subsidiary of Tetra Tech which is a global organization and an implementer of USAID/Kenya projects. Therefore, we may transfer your personal information to other Tetra Tech entities and third parties across the globe with an adequate level of protection that is consistent with, and which respects applicable privacy laws. This includes transferring to countries deemed “adequate” by the UK and European Commission and the Office of the Data Protection Commissioner in Kenya and using appropriate safeguards with countries that are not considered as having adequate data protection laws.
You must always comply with the MSI Kenya guidelines on international data transfers when dealing with personal information for or on behalf of MSI Kenya.
How we protect your personal information
We have put in place appropriate security measures to prevent your personal information from being accidentally lost, used or accessed in an unauthorized way, altered, or disclosed. In addition, we limit access to your personal information to those employees, agents, contractors, and other third parties who have a business need to know. They will only process your personal information on our instructions, and they are subject to a duty of confidentiality.
Third parties will only process your personal information on our instructions and where they have agreed to treat the information confidentially and to keep it secure.
We have put in place procedures to deal with any suspected data security breach and will notify you and any applicable regulator of a suspected breach where we are legally required to do so.
How long we will retain your personal information
We will only retain your personal information for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, contractual, or reporting requirements. To determine the appropriate retention period for personal information, we consider the amount, nature, and sensitivity of the personal information; the potential risk of harm from unauthorized use or disclosure of your personal information; the purposes for which we process your personal information and whether we can achieve those purposes through other means; and the applicable legal requirements.
In some circumstances, we may anonymize your personal information so that it can no longer be associated with you, in which case we may use such information without further notice to you.
Depending on where you are located, your information will be retained for the relevant period under MSI Kenya’s applicable data retention policies. Further information can be provided upon request – please see the “Contact us” section below.
Your rights in connection with your personal information
Under certain circumstances, and expressly subject to applicable laws, you may have the right to:
- Request access to your personal information (commonly known as a “data subject access request”). This enables you to receive a copy of the personal information we hold about you and to check that we are lawfully processing it.
- Request correction of the personal information that we hold about you. This enables you to have any incomplete or inaccurate information we hold about you corrected.
- Request erasure of your personal information. This enables you to ask us to delete or remove personal information where there is no good reason for us to continue to process it. You also have the right to ask us to delete or remove your personal information where you have exercised your right to object to processing (see below).
- Object to processing of your personal information, where we are relying on a legitimate interest (or those of a third party) and there is something about your particular situation that makes you want to object to processing on this ground. You also have the right to object where we are processing your personal information for direct marketing purposes.
- Request the restriction of processing of your personal information. This enables you to ask us to suspend the processing of personal information about you, for example, if you want us to establish its accuracy or the reason for processing it.
- Request the transfer of your personal information to another party.
- Right to withdraw consent where you may have provided your consent to the collection, processing, and transfer of your personal information for a specific purpose, you have the right to withdraw your consent for that specific processing at any time. To withdraw your consent, please contact one of the email addresses provided below in the “Contact us” section. Once we have received notification that you have withdrawn your consent, we will no longer process your information for the purpose or purposes you originally agreed to, unless we have another legitimate basis for doing so in law. Please note that such withdrawal of consent shall not affect the lawfulness of processing based on consent prior to its withdrawal.
If you want to review, verify, correct, or request erasure of your personal information, object to the processing of your personal information, or request that we transfer a copy of your personal information to another party, please contact one of the email addresses provided in the “Contact us” section below.
We will respond to your request within the timeframe(s) required by applicable law. Please note, we may also need to request specific information from you to help us confirm your identity and ensure your right to access the information (or to exercise any of your other rights). This is another appropriate security measure to ensure that personal information is not disclosed to any person who has no right to receive it.
You may not have to pay a fee to access your personal information (or to exercise any of the other rights, above). However, we may charge a reasonable fee in some cases, for example, if your request is clearly unfounded or excessive. Alternatively, we may refuse to comply with the request in such circumstances to the extent permissible by law. Where the request is declined, we shall notify you of rejection of the request and the reason for declining the request.
Automated decision making
We do not envisage that any decisions will be taken about you using automated means. However, we will notify you in writing if this position changes.
Children
We do not collect or process personal information of children except for specific services and upon the consent of the holder of parental responsibility.
Consequences of breach of this policy
This policy must be strictly adhered to by all parties to which it applies. A deliberate or negligent breach of this policy and other related policies may invoke the relevant action including but not limited to disciplinary action for employees, termination for contractors and such other legal action as may be appropriate in the circumstances.
Changes to this privacy statement
We reserve the right to update this privacy notice at any time. We may also notify you in other ways from time to time about the processing of your personal information.
Contact us
If you have any questions about this Privacy Statement or if you are dissatisfied with the manner in which your personal information is handled, please contact us at [email protected]. We shall upon receipt of the complaint, attempt to resolve the matter within a reasonable time in accordance with the applicable laws and this policy. If the matter cannot be resolved, we shall provide you with a notice of non-resolution and indicate why the issue cannot be resolved. Where the parties are unable to resolve the matter, you on receipt of the non-resolution notice may refer the complaint to the relevant regulator.