Governance
Data Protection
& Security Policy
The operational policy behind our Privacy Policy — what personal data the Party holds through pewachange.org, where it lives, who may touch it, and the safeguards around it. Data Protection Act, 2019.
Owner: Party Secretary-General / designated Data Protection contact (info@pewachange.ke). Review: at least annually.
1. Purpose
To protect the personal data of members, supporters, volunteers, aspirants and the public; to meet the Party's obligations under the Data Protection Act, 2019 and the Political Parties Act; and to give every person handling this data one clear set of rules.
2. Data inventory — what we hold
| Record | Personal data fields | Sensitivity |
|---|---|---|
| Membership register | Name, national ID / passport no., date of birth, gender, phone, email, county / constituency / ward, voter status, interests, free text, submission IP & timestamp. | High — contains a national identifier. |
| Concerns (Sauti ya Wananchi) | Chosen name or "Anonymous", county, topic, message, IP, timestamp, moderation status. | Low–medium (user-controlled; may contain opinions). |
| Volunteer list | Name, phone, email, location, skills, availability, message, IP. | Medium. |
| Aspirant declarations | Name, phone, email, seat sought, location, bio, LinkedIn, IP, status. | Medium (bio/status may be published if approved). |
| Contribution records | Contributor name, amount, date (received from the payment channel; no PINs or card numbers). | Medium — financial, and politically sensitive. |
| Raw submission backup | A line-by-line copy of every form submission (same fields as above). | As above — treat as High. |
| Security log | IP address, user-agent, endpoint, timestamp. | Low; purged within 24 hours. |
3. Where the data lives
- Primary store — the Party's database, held on a cloud-based hosting service, in a location not publicly accessible and readable only by the web service account. Daily backups.
- Raw backup file — same service, same protected location.
- Working copy — a spreadsheet in the Party's cloud-based office/email service, synced automatically, used by officials for outreach and reporting.
- Notifications — a copy of each submission is emailed to
info@pewachange.ke. - No personal data is stored in the website's code repository or on personal devices.
Cross-border: some of these services store and process data outside Kenya, within the EU/EEA, and are contractually bound by EU data-protection law (the GDPR) — recognised under the Data Protection Act, 2019 as offering equivalent protection. Lawful basis for the transfer: the data subject's consent, collected on each form. The specific providers are named in the Party's internal processor register (not published here); that register is kept current and the transfers are declared to the ODPC on registration.
4. Access — who can touch what
| Role | Access | Control |
|---|---|---|
| System administrator | Full server & database access. | SSH key only, no passwords; named individuals; access list reviewed quarterly. |
| Party officials (admin dashboard) | View / moderate / export all records via /admin/. |
Two layers: an HTTP gateway password and a dashboard password (hashed); HTTPS only; session times out; shared only with officials who need it; credentials rotated when someone leaves. |
| Office/email service users | Whatever the shared spreadsheet / inbox is shared with. | info@pewachange.ke owner keeps sharing tight (named
officials, not "anyone with link"); 2-Step Verification on all accounts. |
| The public | Only approved concerns and approved aspirant profiles. | Nothing is published without an official's explicit approval. |
| The website service account | Insert new records; read approved concerns/aspirants for display. | Cannot be logged into interactively; secrets stored with restricted file permissions outside the web root. |
5. Technical & organisational measures
- All traffic over HTTPS (TLS); the site redirects HTTP to HTTPS.
- Personal-data endpoints accept submissions only (POST), never list data publicly.
- Application secrets and the admin gateway file live outside the web root, permission-restricted to the service account.
- Spam / abuse controls: hidden honeypot field, minimum form-fill time, per-IP rate limiting.
- CSRF tokens on every admin action; admin area excluded from search engines.
- Explicit, unbundled consent checkbox on every form; a person may withdraw consent at any time.
- Data minimisation — we ask only for what each purpose needs; optional fields are marked optional.
- Security logs auto-expire within 24 hours.
- Server operating system and software kept patched.
6. Retention & disposal
Retention periods are in the Privacy Policy (§6). When a period ends, records are deleted from the database, the backup file and the working spreadsheet. Exports downloaded by officials must be deleted from personal drives once the task is done.
7. Sharing & transfers
Personal data is shared only with officials for the stated purposes; with the cloud-based service providers that host the Party's website, database and email; or where compelled by law (courts, ORPP, IEBC, ODPC). Those providers are contractually bound by EU data-protection law and are named in the Party's internal processor register; any new processor is assessed first. Transfers outside Kenya (within the EU/EEA) rely on the data subject's consent plus the GDPR-equivalent protection the Act recognises, and are declared to the ODPC on registration. The Party never sells personal data.
8. Data subject requests
Requests to info@pewachange.ke are logged, the requester's identity
is verified, and a response is given within the timeline in the Act. Erasure
requests are actioned across all locations — the database, the backup file, the
working spreadsheet, and the notification mailbox.
9. Breach response
- Contain — the administrator isolates the affected system and rotates credentials.
- Assess — what data, how many people, what harm is likely.
- Notify — if harm to individuals is likely, notify the Office of the Data Protection Commissioner within 72 hours of awareness, and notify affected people without undue delay.
- Record — every breach is documented (facts, effects, action taken) whether or not it is notifiable.
- Learn — fix the root cause; update this policy.
10. Responsibilities
- Every person with access follows this policy, uses strong unique passwords with 2-Step Verification, and reports anything suspicious immediately.
- The Data Protection contact keeps the inventory current, handles data subject requests and breaches, and runs the annual review.
- The administrator maintains the technical controls above.
This is a working template. The Party's officials and legal counsel should review, adjust and formally adopt it, and consider whether the Party must register with the ODPC as a data controller.