Introduction
Growing concerns surrounding the security of personal data in institutional hands have spurred governments all around the world to enact data protection regulations. In 2018, the European Union (EU) ushered in the General Data Protection Regulations (GDPR), outlining strict guidelines for companies handling personal data. Inspired by this move, Kenya enacted its own Data Protection Act in 2019. These regulations serve as shields for individual privacy, mandating responsible handling of personal data. Core principles enshrined in these regulations include lawful processing, minimizing data collection, ensuring data accuracy, and implementing robust security measures to safeguard personal information.
Policy Statement
Engishu Insurance Agency prioritizes ethical data practices, adhering to both Kenyan and global regulations. Recognizing the fundamental right to privacy, we are committed to protecting individuals through lawful, responsible, and legitimate use of their personal data. We guarantee data subject rights and ensure all data collection and processing aligns with mandated legislation. This policy is mandatory for all Engishu Insurance Agency staff, and non-compliance will result in disciplinary action.
Purpose
This policy establishes clear guidelines on how Engishu Insurance Agency will collect, use, and store personal data. The policy ensures compliance with relevant data protection laws, safeguards the rights and privacy of data subjects, and mitigates the risks of data breaches.
Definition of Terms
Scope
The policy applies to:
Data Protection Officer
Engishu Insurance Agency has designated the Principal Officer to be the Data Protection Officer (DPO). Accordingly, the DPO will:
Principles
Engishu Insurance Agency will ensure that data is:
Duty to Notify
Engishu Insurance Agency has a duty to notify data subjects of their rights before processing data. Engishu Insurance Agency will therefore inform the data subjects of their right:
Lawful and Fair Processing of Data
Engishu Insurance Agency will only process data where they have a lawful basis to do so. Processing personal data will only be lawful where the data subject has given their consent for one or more specific purposes or where the processing is deemed necessary:
What Personal Data Do We Collect?
Personal data that we may process, as appropriate throughout the insurance and claim process, but is not limited to:
We may also process sensitive or special personal data where relevant to the insurance and claim processes, including where necessary to accommodate any disability needs.
When exercising our rights and obligations under the insurance contracts, it may be necessary to process sensitive data categories. Such sensitive may include but not limited to;
Minimization of Collection
Engishu Insurance Agency prioritizes respecting your privacy and adheres to strict data handling practices. We are committed to processing only the personal data necessary for fulfilling our duties and obtaining your explicit consent if the intended purpose falls outside the initial scope.
We strictly prohibit unauthorized access to any data, and our staff are trained to collect and retain only the data relevant and strictly necessary for their assigned tasks. Once the data serves its purpose, it is securely deleted, destroyed, or anonymized. You can be confident that your information will be handled responsibly and ethically at Engishu Insurance Agency.
Accuracy of data
Engishu Insurance Agency is committed to maintaining the accuracy and integrity of your personal data. We implement robust measures to ensure that all collected information is kept up-to-date and promptly corrected or deleted upon your request or notification of inaccuracies. Should any staff member become aware of outdated or incorrect data, they are obligated to initiate the necessary updates immediately. Rest assured, any information deemed inaccurate or no longer relevant will be securely deleted or destroyed to safeguard your privacy.
Safeguards and security of data
Engishu Insurance Agency has instituted data security measures which are laid out in the Information security policy and procedures. These measures serve to safeguard personal data and must be complied with accordingly.
Consent
Where necessary, Engishu Insurance Agency will maintain adequate records to show that consent was obtained before personal processing data. Data will not be processed after the withdrawal of consent by a data subject.
Processing data relating to a child
Engishu Insurance Agency will not process data relating to a child unless consent is given by the child’s guardian or parent and the processing is in such a manner that protects and advances the rights and best interests of the child in line with Engishu Insurance Agency Safeguarding policy.
Engishu Insurance Agency will institute adequate mechanisms to verify the age and obtain consent before processing the data.
Data protection impact assessment
Engishu Insurance Agency will undertake a data protection impact assessment whenever they identify that the processing operation will likely result in a high risk to the rights and freedoms of any data subject. The data protection impact assessment will be done before processing the data. It is the responsibility of the DPO to carry out the impact assessment.
Processing sensitive personal data
Engishu Insurance Agency will process sensitive personal data only when:
Transferring personal data out of Kenya
Engishu Insurance Agency will transfer personal data out of Kenya only when they have:
Engishu Insurance Agency will process sensitive personal data out of Kenya only after obtaining the consent of a data subject and on receiving confirmation of appropriate safeguards.
Onward reporting
In line with regulatory requirements, Engishu Insurance Agency will report to the Data Protection Commissioner any data breach within 72 hours of being aware.
Engishu Insurance Agency will also communicate the data breach to the data subject as soon as is practical unless the identity of the data subject cannot be established.
Training and Awareness
Engishu Insurance Agency will train staff on the contents and implementation of this policy. Staff who join Engishu Insurance Agency will be required to go through an induction process that entails familiarisation with this policy.
Engishu Insurance Agency will ensure that the requirements of this policy form part of its agreement with its Insurance Partners and any third parties who Engishu Insurance Agency’s data.
Roles and Responsibilities
The Data Protection Officer is responsible for ensuring that employees are aware of this policy and are supported to implement and work by it, as well as creating a management culture that encourages a focus on data protection.
All staff must:
Independent Assurance
The adequacy and effectiveness of Engishu Insurance Agency’s data protection procedures is subject to the regular internal audit reviews. Where necessary, Engishu Insurance Agency may call an external review to provide assurance over the integrity of its data protection procedures.
Data Retention
The Data retention period in Engishu Insurance Agency is determined by legitimate needs. Adequate records of decision making will be maintained to show cause why various types of data has been retained for the respective durations of their retention.
Review of this Policy
The Data Protection Officer is responsible for ensuring that this policy is reviewed on a timely basis. This policy will be reviewed after every two years.