Privacy Policy

Kingdom Life Sacco treats members' personal information as a trust.

Document reference
KLS/DPP/2026/001
Version
1.0
Effective date
May 2026
Review date
May 2028

1. INTRODUCTION AND PURPOSE

This Data Protection and Privacy Policy (“the Policy”) has been developed as a guide to Kingdom Life Savings and Credit Co-operative Society Limited (“Kingdom Life Sacco,” “the Sacco,” “we,” “our” or “us”) in the management of stakeholders’ data. Kingdom Life Sacco obtains, uses, stores and otherwise processes personal data relating to its stakeholders such as potential and current members, employees, former staff, suppliers, visitors to Sacco premises, contractors, agents, guarantors and users of our digital platforms, collectively referred to in this Policy as “data subjects.” This Policy sets out how the Sacco manages those responsibilities.

In developing this Policy, the Board of Directors intends to have it serve as the primary reference point for all matters pertaining to data management in the Sacco. The contents of this Policy will therefore be carefully studied and implemented, as it constitutes an integral part of the Society’s risk management processes. The Policy will be circulated to all Sacco officials and management to enable them to familiarise themselves with the provisions herein.

The Sacco heavily draws its data policy guidelines from the Data Protection Act, No. 24 of 2019 and the Data Protection (General) Regulations, 2021. When processing personal data, the Sacco is obliged to fulfil individuals’ reasonable expectations of privacy by complying with the Act, related Regulations, and other relevant data protection legislation.

This Policy is therefore intended to ensure that Kingdom Life Sacco:

Is clear about how personal data must be processed and the Sacco’s expectations for all those who process personal data on its behalf;

Complies with existing data protection laws and with good practice;

Protects its reputation by ensuring the personal data entrusted to it is processed in accordance with data subjects’ rights;

Protects itself from risks of personal data breaches and other breaches of data protection law;

Meets its obligations under the Sacco Societies Act, 2008 and related SASRA regulations.

2. SCOPE OF THIS POLICY

This Policy applies to all personal data the Sacco processes regardless of the location where that personal data is stored (e.g. on an employee’s own device, Kingdom Life Sacco’s servers, Sacco website, mobile banking platforms, USSD platforms, or third-party service providers’ systems) and regardless of the data subject.

The Policy applies to all officials, employees, agents, contractors, consultants, and any other person who has access to or processes personal data on behalf of Kingdom Life Sacco.

This Policy shall be read in conjunction with the Sacco’s Human Resource Policy, ICT Policy, Credit Policy, and any other policies that reference the handling of personal data.

3. DEFINITION OF TERMS

For the purposes of this Policy, the following terms shall have the meanings assigned to them below:

Anonymisation
The removal of personal identifiers from personal data so that the data subject is no longer identifiable.
Biometric Data
Personal data resulting from specific technical processing based on physical, physiological or behavioural characterisation including blood typing, fingerprinting, deoxyribonucleic acid (DNA) analysis, earlobe geometry, retinal scanning and voice recognition.
Consent
Agreement which must be freely given, specific, informed and be an unambiguous indication of the data subject’s wishes by which they, by a statement or by a clear positive action, signifies agreement to the processing of personal data relating to them.
Data
Information which is processed by means of equipment operating automatically in response to instructions given for that purpose, or recorded with the intention that it should be processed by means of such equipment, or recorded as part of a relevant filing system.
Data Controller
The person or organisation that determines when, why and how to process personal data. Kingdom Life Sacco is the Data Controller of all personal data relating to it and used in facilitating its business operations.
Data Processing
Any activity that involves the use of personal data and includes obtaining, recording or holding the data, or carrying out any operation or set of operations on the data including organising, amending, retrieving, using, disclosing, erasing or destroying it. Processing also includes transmitting or transferring personal data to third parties.
Data Protection Impact Assessment (DPIA)
A tool or procedure for identifying and reducing risks involved in any processing activity that will involve personal data.
Data Protection Officer (DPO)
The person appointed as such under the Data Protection Act and in accordance with its requirements. The DPO is responsible for advising the Sacco (including employees) on their obligations under data protection laws, and for monitoring compliance with data protection law as well as with Kingdom Life Sacco policies.
Data Subject
A living, identified or identifiable individual about whom the Sacco holds personal data.
Office of the Data Protection Commissioner (ODPC)
The independent regulatory authority established under Section 5 of the Data Protection Act, 2019 to enforce data protection legislation in Kenya.
Personal Data
Any information identifying a data subject or information relating to a data subject that the Sacco can identify (directly or indirectly) from that data alone or in combination with other identifiers the Sacco possesses or can reasonably access. Personal data includes sensitive personal data and pseudonymised personal data but excludes anonymous data or data that has had the identity of an individual permanently removed.
Personal Data Breach
Any breach of security resulting in the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or unauthorised access to, personal data, where that breach results in a risk to the data subject.
Profiling
Any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to an individual, in particular to analyse or predict aspects concerning that individual’s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.
SASRA
The Sacco Societies Regulatory Authority, established under the Sacco Societies Act, 2008, with the responsibility to license, supervise and regulate Sacco Societies in Kenya.
Sensitive Personal Data
Data revealing a person’s race, health status, ethnic or social origin, conscience, belief, genetic data, biometric data, property details, marital status, family details, sex or sexual orientation, as defined in the Data Protection Act, 2019.
Third Party
Any natural or legal person other than the data subject, Kingdom Life Sacco, or any implementing partner.

4. LEGAL AND REGULATORY FRAMEWORK

This Policy has been developed in accordance with the following laws, regulations and guidelines:

The Constitution of Kenya, 2010 – Article 31 (Right to Privacy);

The Data Protection Act, No. 24 of 2019;

The Data Protection (General) Regulations, 2021;

The Data Protection (Registration of Data Controllers and Data Processors) Regulations, 2021;

The Data Protection (Compliance and Enforcement) Regulations, 2021;

The Data Protection (Conduct of Compliance Audit) Regulations, 2024;

The Sacco Societies Act, 2008 and SASRA Regulations;

The Co-operative Societies Act, Cap 490;

The Computer Misuse and Cybercrimes Act, 2018;

The Kenya Information and Communications Act;

Guidelines and Guidance Notes issued by the Office of the Data Protection Commissioner (ODPC).

4.1 Registration with the ODPC

Kingdom Life Sacco shall register with the Office of the Data Protection Commissioner as a data controller and data processor in accordance with the Data Protection Act and Regulations thereof. The Sacco shall display the certificate of registration issued by the ODPC in a conspicuous place, including the Sacco’s website, and shall renew the certificate at least thirty (30) days before its expiry.

5. JUSTIFICATION FOR COLLECTION OF PERSONAL INFORMATION

The Sacco may collect and use a data subject’s personal data under any of the following lawful bases:

Legitimate Interest: If it is necessary for the Sacco’s legitimate interest and so long as its use is fair, balanced and does not unduly impact data subject’s rights.

Consent: With the data subject’s consent. For example, to send marketing emails or SMS, to take and use a data subject’s photograph, to collect relevant medical information. The data subject may withdraw consent for this at any time.

Legal Obligation: As required to fulfil the Sacco’s legal obligations as a registered Deposit-Taking Co-operative Society and employer. This includes sharing personal information with bodies such as SASRA, the Ministry of the day responsible for Co-operatives, NSSF, NHIF, KRA, Courts, Police, EACC, Credit Reference Bureaus (CRBs), and other legal or statutory bodies.

Contractual Necessity: Where processing is necessary for the performance of a contract to which the data subject is party, or in order to take steps at the request of the data subject prior to entering into a contract.

Vital Interest: In extreme situations, the Sacco may share a data subject’s personal details with the emergency services if it believes it is in the data subject’s ‘vital interests’ to do so.

The Sacco will only process sensitive personal data if it has the data subject’s explicit consent, or where permitted by law.

6. SOURCES OF PERSONAL INFORMATION

The Sacco may collect information about data subjects from different sources, including:

6.1 Directly from the Data Subject When They:

Apply for membership of the Sacco;

Apply for account opening (FOSA or BOSA);

Apply for Sacco loan products or credit facilities;

Apply for employment or internship at the Sacco;

Are employed by the Sacco;

Apply as a supplier or service provider;

Register for or attend Sacco events, Annual General Meetings, or Special General Meetings;

Complete a survey or feedback form;

Visit Sacco premises and register as guests;

Subscribe for updates via the Sacco’s mobile and electronic services, including USSD, mobile banking apps, or the website.

6.2 Indirectly:

From other persons who believe that the data subject may be interested in membership or collaboration with the Sacco;

From the public domain when the data subject has deliberately made the data public;

From third parties such as previous or current employers to verify details about job applicants;

From external sources such as Credit Reference Bureaus, publications, and external reviewers or auditors;

From another source when the guardian appointed has consented to the collection, in cases where the data subject has a disability;

Where collection of data from another source is necessary for the prevention, detection, investigation, prosecution and punishment of crime; for the enforcement of a law which imposes a pecuniary penalty; or for the protection of the interests of the data subject or another person.

7. FORMS OF PERSONAL INFORMATION COLLECTED

The Sacco shall only collect personal information that is genuinely needed for its operations. This may include:

Contact details such as name, postal address, email address and phone numbers;

Biometric data such as fingerprints and facial recognition data;

Nationality;

National Identity Card and Passport information;

KRA Personal Identification Number (PIN);

Date of birth;

Gender;

Information about race and ethnicity;

Academic and professional qualifications;

Bank account details;

Medical information (where necessary and lawfully collected);

Employee benefits information;

Employment details and work history;

Photographs and video recordings;

Tax and residency status for statutory requirements;

References from previous employers or educational institutions;

Contact details for family members, next of kin and guarantors;

Details of criminal convictions (where lawfully required);

Transaction and financial data related to Sacco products and services;

Digital interaction data such as IP addresses, browser information and device identifiers when using Sacco digital platforms.

8. DATA PROTECTION PRINCIPLES

In processing personal data, Kingdom Life Sacco shall be guided by the principles of data protection as captured in Section 25 of the Data Protection Act, 2019, and requires the Sacco to ensure that personal data is:

Processed in accordance with the right to privacy of the data subject;

Processed lawfully, fairly and in a transparent manner in relation to any data subject;

Collected for explicit, specified and legitimate purposes and not further processed in a manner incompatible with those purposes;

Adequate, relevant, limited to what is necessary in relation to the purposes for which it is processed;

Collected only where a valid explanation is provided whenever information relating to family or private affairs is required;

Accurate and, where necessary, kept up to date, with every reasonable step being taken to ensure that any inaccurate personal data is erased or rectified without delay;

Kept in a form which identifies the data subjects for no longer than is necessary for the purposes for which it was collected; and

Not transferred outside the Sacco or the country, unless there is proof of adequate data protection safeguards or consent from the data subject.

In complying with the stated data protection principles, Kingdom Life Sacco will observe the following:

8.1 Fairness and Lawfulness

When processing personal data, the individual rights of the data subjects must be protected. Personal data must be collected and processed in a legal and fair manner.

8.2 Restriction to a Specific Purpose

Personal data shall be processed only for the purpose that was defined before the data was collected. Subsequent changes to the purpose are only possible to a limited extent and require substantiation.

8.3 Transparency

The data subject must be informed of how his/her data is being handled. In general, personal data must be collected directly from the individual concerned. When the data is collected, the data subject must either be aware of, or informed of:

The identity of the Data Controller (Kingdom Life Sacco);

The purpose of data processing;

Third parties or categories of third parties to whom the data might be transmitted, if applicable.

8.4 Data Minimisation and Economy

Before processing personal data, the Sacco will determine whether and to what extent the processing of personal data is necessary in order to achieve the purpose for which it is undertaken. Where the purpose allows and where the expense involved is proportionate to the goal being pursued, anonymised or statistical data must be used. Personal data may not be collected in advance and stored for potential future purposes unless required or permitted by national law.

8.5 Deletion

Personal data that is no longer needed after the expiration of legal or business process-related periods must be deleted. There may be an indication of interests that merit protection or historical significance of this data in individual cases. If so, the data must remain on file until the interests that merit protection have been clarified legally, or the Sacco has evaluated the data to determine whether it must be retained for historical purposes.

8.6 Factual Accuracy and Up-to-Date Data

Personal data on file must be correct, complete, and – if necessary – kept up to date. Suitable steps must be taken to ensure that inaccurate or incomplete data are deleted, corrected, supplemented or updated.

8.7 Confidentiality and Data Security

Personal data is subject to data secrecy and privacy. It must be treated as confidential on a personal level and secured with suitable organisational and technical measures to prevent unauthorised access, illegal processing or distribution, as well as accidental loss, modification or destruction.

9. RIGHTS OF THE DATA SUBJECT

Every data subject has the following rights as set out in the Data Protection Act, 2019:

Right to be informed: To be informed of the use to which their personal data is to be put;

Right of access: To access their personal data in the custody of the Sacco as data controller;

Right to object: To object to the processing of all or part of their personal data. This does not apply if a legal provision requires the data to be processed;

Right to rectification: To correction of false or misleading data;

Right to erasure: To deletion of false or misleading data about them, subject to any legal obligations requiring data retention;

Right to data portability: To receive their personal data in a structured, commonly used and machine-readable format;

Right to restrict processing: To request that the Sacco restricts the processing of their personal information;

Right to withdraw consent: To withdraw consent previously given for the processing of their personal data.

A right conferred on a data subject may be exercised:

By a person who has parental authority or by a guardian if the data subject is a minor;

By a person duly authorised to act as a guardian or administrator in a case where the data subject has a mental or other disability; or

By a person duly authorised by the data subject.

The Sacco shall respond to a data subject’s request to exercise any of the above rights within seven (7) days, in accordance with the Data Protection (General) Regulations, 2021.

10. DATA SUBJECT CONSENT

A data subject may prior to the processing of their personal data give consent either orally or in writing, and may include a handwritten signature, an oral statement, or use of an electronic or other medium to signify agreement.

The Sacco shall seek consent from data subjects through various means. These include the data subjects willingly:

Appending their signature of acceptance of terms and conditions of engagement on a physical consent form;

Ticking an opt-in box on paper or electronically;

Clicking an opt-in button or link online;

Responding to an email or SMS requesting consent;

Volunteering optional information for a specific purpose;

Selecting from equally prominent Yes/No options.

In obtaining consent from a data subject, the Sacco shall ensure that the data subject:

Has capacity to understand and communicate their consent;

Is informed of the nature of processing in simple and clear language that is understandable;

Is informed whether data is being transferred to third parties or implementing partners, or whether data is being collected by a third party on behalf of Kingdom Life Sacco;

Is informed of their duty to keep Kingdom Life Sacco informed of changes to their personal data;

Is informed of right to access their personal data, or correction or deletion of it;

Is informed of the procedure to lodge a complaint in case of suspected breach;

Is informed of the importance of providing accurate and complete data;

Voluntarily gives consent and that the consent is specific.

11. CONFIDENTIALITY OF DATA PROCESSING

Personal data is subject to data secrecy. Any unauthorised collection, processing, or use of such data by employees is prohibited. Any data processing undertaken by an employee that he/she has not been authorised to carry out as part of his/her legitimate duties is unauthorised.

The “need to know” principle applies. Employees may have access to personal information only as is appropriate for the type and scope of the task in question. This requires a careful breakdown and separation, as well as implementation, of roles and responsibilities.

Employees are forbidden to use personal data for private or commercial purposes, to disclose it to unauthorised persons, or to make it available in any other way. Supervisors must inform their employees at the start of the employment relationship about the obligation to protect data secrecy. All staff shall therefore sign an oath of secrecy at the time of engagement by the Sacco. This obligation shall remain in force even after employment has ended.

All officials, staff and stakeholders of the Sacco shall comply with the provisions of this Policy. To ensure compliance, officials and staff of the Sacco shall sign an oath of confidentiality committing to treat accessed personal information securely and in confidentiality. Stakeholders’ contracts shall include a clause on confidentiality of accessed personal information. The oath shall be binding during and after exit from service of the Sacco. Staff not complying with this Policy shall face disciplinary action in line with the Human Resource Policy.

12. DATA PROCESSING SECURITY

Personal data must be safeguarded from unauthorised access and unlawful processing or disclosure, as well as accidental loss, modification or destruction. This applies regardless of whether data is processed electronically or in paper form.

Before the introduction of new methods of data processing, particularly new IT systems, technical and organisational measures to protect personal data must be defined and implemented. These measures must be based on the state of the art, the risks of processing, and the need to protect the data.

The Sacco shall implement the following security measures:

Access controls and authentication mechanisms for all systems containing personal data;

Encryption of personal data in transit and at rest where appropriate;

Regular security assessments and vulnerability testing;

Physical security measures for premises where personal data is stored;

Regular backup of personal data with secure off-site storage;

Incident response procedures for security breaches;

Audit trails for access to and modification of personal data;

Secure destruction of personal data when it is no longer required.

The responsible department or staff may consult with the Data Protection Officer and the ICT Officer in implementing the above measures. The technical and organisational measures for protecting personal data are part of the Sacco’s data security management and will be adjusted continuously to technical developments and organisational changes.

13. DATA BREACH AND NOTIFICATION

A personal data breach includes but is not limited to:

Unauthorised access to, or use of, personal data;

Unauthorised disclosure of personal data;

Loss or theft of data or equipment on which data is stored;

Inappropriate access controls allowing unauthorised use;

Emails containing personal data sent to the wrong recipient;

Attempts (failed or successful) to gain unauthorised access to IT systems, data or information systems (e.g. via a hacking attack).

If any member of staff or other person learns of a suspected or actual personal data breach, it must be reported immediately or within twelve (12) hours to the Data Protection Officer and senior management.

Kingdom Life Sacco shall promptly notify the Office of the Data Protection Commissioner within seventy-two (72) hours upon becoming aware of a personal data breach involving data subjects within its records and properly record the breach. The Sacco shall also undertake to inform the data subject within a reasonable time of the breach on their personal data and explain mitigating measures taken to safeguard the data and address potential adverse effects of the breach.

The Sacco shall maintain a Data Breach Register documenting all breaches, including those that do not meet the threshold for notification to the ODPC.

14. DATA PROTECTION IMPACT ASSESSMENT

The Sacco, being a Data Controller, shall undertake to carry out a Data Protection Impact Assessment (DPIA) to identify and minimise risks involved in projects, processes and activities involving directly or indirectly the processing of personal data.

A DPIA will be required for processing where there is a likelihood of high risk to individuals and their personal data, and particularly where new technologies are involved. Examples include:

Introduction of new digital banking or mobile banking platforms;

Large-scale processing of sensitive personal data;

Systematic monitoring of members’ activities;

Engagement of new third-party data processors;

Significant changes to existing data processing activities.

The Data Protection Officer shall undertake the DPIA with the assistance of the relevant department and sign off the reports.

15. ROLES AND RESPONSIBILITIES

15.1 The Board of Directors

The Board is ultimately responsible for ensuring that the Sacco complies with all applicable data protection laws and this Policy. The Board shall approve this Policy and any amendments thereto.

15.2 The Chief Executive Officer

The CEO is responsible for overseeing the day-to-day implementation of this Policy, allocating resources for data protection compliance, and ensuring that data protection is integrated into the Sacco’s operations.

15.3 The Data Protection Officer (DPO)

The Data Protection Officer shall be responsible for:

Advising the Sacco and its staff on their obligations under relevant data protection laws and regulations;

Monitoring compliance with this Policy and other relevant data protection laws;

Conducting and monitoring training activities that relate to data protection;

Providing advice where requested on Data Protection Impact Assessments;

Acting as the contact point between the Sacco and the ODPC;

Maintaining a record of all data processing activities carried out by the Sacco;

Managing data subject access requests and complaints;

Conducting awareness training for staff members on data privacy and security.

15.4 Heads of Departments

Each Head of Department is responsible for ensuring that data protection practices are adhered to within their respective departments and for reporting any data protection concerns to the DPO.

15.5 All Staff

Every member of staff is responsible for ensuring that personal data is processed in accordance with this Policy and the Data Protection Act. Staff must complete data protection training as required and report any suspected or actual data breaches promptly.

16. CROSS-BORDER DATA TRANSFERS

Personal data processed by Kingdom Life Sacco shall not be transferred outside Kenya unless:

The recipient country has adequate data protection safeguards as determined by the ODPC;

The data subject has given explicit consent to the transfer;

The transfer is necessary for the performance of a contract between the data subject and the Sacco;

The transfer is necessary for important reasons of public interest;

Appropriate contractual clauses or binding corporate rules are in place to protect the data.

Any personal data made available by the Sacco, or collected in the course of work, shall not be stored or processed outside Kenya unless written consent to do so has been received from the Sacco. The Sacco and its service providers will ensure that appropriate measures are in place to protect data in transit and at rest.

17. THIRD-PARTY DATA PROCESSORS

Where the Sacco uses third-party processors (such as technology service providers, software vendors, auditors, or consultants), the Sacco shall ensure that:

A formal data processing agreement is in place that specifies the scope, nature and purpose of the processing;

The third party provides sufficient guarantees of compliance with data protection obligations;

All personal data is kept securely and confidentially by the third party;

All personal data is returned to the Sacco upon completion of the work, including any copies that may have been made, or alternatively that the data is securely destroyed and the Sacco receives written notification in this regard;

All practical and reasonable steps are taken to ensure that contractors, short-term or voluntary staff do not have access to any personal data beyond what is essential for the work to be carried out properly.

18. DURATION FOR HOLDING PERSONAL INFORMATION

The Sacco will hold personal information for as long as is necessary and will therefore not retain personal information if it is no longer required. In some circumstances, the Sacco may be legally required to retain a data subject’s personal information, for example for finance, employment, regulatory or audit purposes.

The following retention periods shall apply:

Active member dataDuration of membership plus seven (7) years after exit
Former member dataSeven (7) years after exit from the Sacco
Employee dataDuration of employment plus seven (7) years after separation
Unsuccessful job applicant dataTwelve (12) months after the recruitment process
Supplier/contractor dataDuration of contract plus seven (7) years
Loan and financial transaction recordsDuration of the loan plus ten (10) years after full repayment
CCTV and surveillance footageNinety (90) days, unless required for investigation
Website and digital platform dataTwelve (12) months from last interaction

Upon expiry of the retention period, personal data shall be securely deleted or anonymised. Physical records shall be shredded and electronic records shall be permanently erased using approved methods.

19. TRAINING AND AWARENESS

All Sacco officials and staff are expected to familiarise themselves with the content of this Policy. To enhance compliance with this Policy, the Sacco shall:

Organise periodic sensitisation forums for Sacco officials and staff members;

Include data protection awareness in the staff induction programme;

Conduct annual refresher training on data protection and privacy;

Maintain records of all data protection training conducted.

20. COMPLIANCE AND ENFORCEMENT

All officials, staff and stakeholders of the Sacco shall comply with the provisions of this Policy. Non-compliance shall constitute misconduct.

To ensure compliance, officials and staff of the Sacco shall sign an oath of confidentiality committing to treat accessed personal information securely and in confidentiality. Stakeholders’ contracts shall have a clause on confidentiality of accessed personal information. The oath shall be binding during and after exit from service of the Sacco.

Staff not complying with this Policy shall face disciplinary action in line with the Human Resource Policy. Serious breaches may result in summary dismissal and/or criminal prosecution under the Data Protection Act, 2019.

Any person who contravenes the provisions of the Data Protection Act is liable on conviction to a fine not exceeding Kenya Shillings three million (KES 3,000,000) or to an imprisonment term not exceeding ten (10) years, or both.

21. POLICY REVIEW AND AMENDMENT

This Policy shall be reviewed at least once every two (2) years, or earlier if necessitated by changes in legislation, regulations, or the Sacco’s operations. The review shall be led by the Data Protection Officer and approved by the Board of Directors.

Kingdom Life Sacco may update this Data Protection and Privacy Policy from time to time. Stakeholders will be notified of any significant changes by posting the new Policy on the Sacco’s website and/or through other appropriate communication channels.

22. CONTACT INFORMATION

If you have any questions about this Policy, would like to exercise any of your rights, or wish to make a complaint, please contact:

Email kingdomlifesacco@gmail.com or write to KINGDOM LIFE SACCO, Kingdom House, P.O. Box 14185-20100, Nakuru, Kenya.

This policy is published online for members to read. It is not offered as a downloadable file. For questions, contact kingdomlifesacco@gmail.com.

Contact Us