Harambee House +254 115 193 745 services@aicacafrica.org

Data Protection Policy

Data Protection Policy for Africa International Chamber of Accreditation and Compliance (AICAC)

1. Purpose

This Data Protection Policy governs the handling, storage, and use of personal data to ensure AICAC complies with applicable data protection laws and promotes data privacy.

2. Scope

This policy applies to all personal and sensitive data processed by AICAC regardless of the data format. It covers both data stored digitally on our IT systems, including third-party cloud services, and physical data stored in our offices.

3. Data Protection Principles

4. Rights of the Data Subject

Individuals have the right to access their personal data, correct inaccuracies, request the deletion of their data, and restrict processing. Additionally, individuals have the right to object to the processing of their data and the right to data portability.

5. Data Security

Data security is paramount at AICAC. We implement physical, technical, and administrative security measures to protect data from unauthorized access, disclosure, alteration, and destruction.

6. Data Breach Response

In the event of a data breach, AICAC will promptly investigate the matter and mitigate any potential harm to data subjects. Notifications will be made to the relevant authorities and affected individuals as required by law.

7. Data Retention

Personal data will not be retained longer than necessary to fulfill the purposes outlined in this policy, except where extended retention is required by law or to resolve disputes.

8. Policy Review and Updates

This policy is reviewed regularly and may be updated to reflect changes in legal requirements or our data handling procedures.

9. Contact Information

For any questions or concerns regarding this policy or data protection practices, please contact AICAC’s Data Protection Officer at:

services@aicacafrica.org

© AICAC. All Rights Reserved.