Kenya General Election · 10 Aug 2027

Governance

Data Protection
& Security Policy

The operational policy behind our Privacy Policy — what personal data the Party holds through pewachange.org, where it lives, who may touch it, and the safeguards around it. Data Protection Act, 2019.

Owner: Party Secretary-General / designated Data Protection contact (info@pewachange.ke). Review: at least annually.

1. Purpose

To protect the personal data of members, supporters, volunteers, aspirants and the public; to meet the Party's obligations under the Data Protection Act, 2019 and the Political Parties Act; and to give every person handling this data one clear set of rules.

2. Data inventory — what we hold

RecordPersonal data fieldsSensitivity
Membership register Name, national ID / passport no., date of birth, gender, phone, email, county / constituency / ward, voter status, interests, free text, submission IP & timestamp. High — contains a national identifier.
Concerns (Sauti ya Wananchi) Chosen name or "Anonymous", county, topic, message, IP, timestamp, moderation status. Low–medium (user-controlled; may contain opinions).
Volunteer list Name, phone, email, location, skills, availability, message, IP. Medium.
Aspirant declarations Name, phone, email, seat sought, location, bio, LinkedIn, IP, status. Medium (bio/status may be published if approved).
Contribution records Contributor name, amount, date (received from the payment channel; no PINs or card numbers). Medium — financial, and politically sensitive.
Raw submission backup A line-by-line copy of every form submission (same fields as above). As above — treat as High.
Security log IP address, user-agent, endpoint, timestamp. Low; purged within 24 hours.

3. Where the data lives

Cross-border: some of these services store and process data outside Kenya, within the EU/EEA, and are contractually bound by EU data-protection law (the GDPR) — recognised under the Data Protection Act, 2019 as offering equivalent protection. Lawful basis for the transfer: the data subject's consent, collected on each form. The specific providers are named in the Party's internal processor register (not published here); that register is kept current and the transfers are declared to the ODPC on registration.

4. Access — who can touch what

RoleAccessControl
System administrator Full server & database access. SSH key only, no passwords; named individuals; access list reviewed quarterly.
Party officials (admin dashboard) View / moderate / export all records via /admin/. Two layers: an HTTP gateway password and a dashboard password (hashed); HTTPS only; session times out; shared only with officials who need it; credentials rotated when someone leaves.
Office/email service users Whatever the shared spreadsheet / inbox is shared with. info@pewachange.ke owner keeps sharing tight (named officials, not "anyone with link"); 2-Step Verification on all accounts.
The public Only approved concerns and approved aspirant profiles. Nothing is published without an official's explicit approval.
The website service account Insert new records; read approved concerns/aspirants for display. Cannot be logged into interactively; secrets stored with restricted file permissions outside the web root.

5. Technical & organisational measures

6. Retention & disposal

Retention periods are in the Privacy Policy (§6). When a period ends, records are deleted from the database, the backup file and the working spreadsheet. Exports downloaded by officials must be deleted from personal drives once the task is done.

7. Sharing & transfers

Personal data is shared only with officials for the stated purposes; with the cloud-based service providers that host the Party's website, database and email; or where compelled by law (courts, ORPP, IEBC, ODPC). Those providers are contractually bound by EU data-protection law and are named in the Party's internal processor register; any new processor is assessed first. Transfers outside Kenya (within the EU/EEA) rely on the data subject's consent plus the GDPR-equivalent protection the Act recognises, and are declared to the ODPC on registration. The Party never sells personal data.

8. Data subject requests

Requests to info@pewachange.ke are logged, the requester's identity is verified, and a response is given within the timeline in the Act. Erasure requests are actioned across all locations — the database, the backup file, the working spreadsheet, and the notification mailbox.

9. Breach response

  1. Contain — the administrator isolates the affected system and rotates credentials.
  2. Assess — what data, how many people, what harm is likely.
  3. Notify — if harm to individuals is likely, notify the Office of the Data Protection Commissioner within 72 hours of awareness, and notify affected people without undue delay.
  4. Record — every breach is documented (facts, effects, action taken) whether or not it is notifiable.
  5. Learn — fix the root cause; update this policy.

10. Responsibilities

This is a working template. The Party's officials and legal counsel should review, adjust and formally adopt it, and consider whether the Party must register with the ODPC as a data controller.

WhatsApp us