DATA PROTECTION POLICY
Summary
The FSD Africa Data Protection Policy (Version November 2023) establishes the framework for the collection, storage, and processing of personal data to ensure compliance with legal obligations, primarily the Kenya Data Protection Act 2019. The policy applies to all FSD Africa stakeholders, including board members, employees, and grant recipients, and defines the organization's role as a Data Controller.
Key insights
- FSD Africa operates as a Data Controller under the Kenya Data Protection Act 2019, meaning it determines the purpose and means of processing personal data for individuals located in Kenya, including employees, vendors, donors, and grant recipients.
- The organization adheres to several regulatory standards for data protection and privacy, specifically the Kenya Data Protection Act 2019, the Constitution of Kenya 2010, and the EU General Data Protection Regulations 2018.
- FSD Africa implements a four-tier information classification system to apply appropriate controls based on sensitivity: Restricted (highly sensitive, potential for irreparable damage), Confidential (potential for major financial loss or reputation damage), Internal Use Only (against best interests if disclosed), and Public (no protection required).
- Personal data is processed based on specific lawful grounds, including the performance of employment or service contracts, compliance with legal obligations (such as NHIF and NSSF deductions), protection of vital interests (such as medical cover), or legitimate interests of the employer.
- The policy mandates that data subjects be notified of their rights prior to data collection, including the right to access their data, object to processing, correct false information, and avoid automated individual decision making.
- FSD Africa has established a specific governance structure for data protection: Executive Management designates a Data Protection Officer for regulatory compliance and breach management (via dataprotection@fsdafrica.org), the Board provides overall oversight, and the IT Team/Security Committee coordinates company-wide compliance.
- Cross-border transfer of personal data is permitted under specific conditions, such as when the destination country ensures adequate protection, the transfer is necessary for a contract, or the data subject has consented. Sensitive personal data may only be transferred outside Kenya with the subject's consent and appropriate safeguards.
Cite the original document
- APA
- FSD Africa (2023). DATA PROTECTION POLICY. https://fsdafrica.org/wp-content/uploads/2025/05/FSD-Africa-Data-Protection-Policy.pdf
- Chicago
- FSD Africa. DATA PROTECTION POLICY. 2023. https://fsdafrica.org/wp-content/uploads/2025/05/FSD-Africa-Data-Protection-Policy.pdf.
- Wikipedia
- {{cite report |author=FSD Africa |title=DATA PROTECTION POLICY |date=November 2023 |url=https://fsdafrica.org/wp-content/uploads/2025/05/FSD-Africa-Data-Protection-Policy.pdf |access-date=17 August 2026 |via=Climate Insights Directory}}
- BibTeX
- @techreport{fsdafrica2023data, author = {{FSD Africa}}, title = {{DATA PROTECTION POLICY}}, institution = {FSD Africa}, year = {2023}, month = nov, url = {https://fsdafrica.org/wp-content/uploads/2025/05/FSD-Africa-Data-Protection-Policy.pdf}, urldate = {2026-08-17}, note = {Indexed by Climate Insights Directory} }
Full text
Collected · Record updated