Version 2.0 — Effective 2026-09-02

1. Introduction and Purpose

The Nairobi Caucus Portal ("the Portal", "we", "us", or "our") is operated by National Counter Terrorism Centre (NCTC) ("the Organization") to support engagement activities carried out under Kenya's National Strategy for Preventing and Countering Violent Extremism (NSPCVE) 2025–2030.

This Privacy Policy explains how we collect, use, store, share, and protect personal data belonging to Portal users, and describes the rights available to you under Kenyan law. It is issued in accordance with Article 31(c) and (d) of the Constitution of Kenya, 2010, and the Data Protection Act, No. 24 of 2019 ("the Act"), together with the Data Protection (General) Regulations, 2021.

2. Who This Policy Covers

This policy applies to all registered users: Administrators, Photographers, Panelists, and Attendees.

3. Personal Data We Collect

  • Full name and email address, provided at registration.
  • Password, stored only as an irreversible cryptographic hash.
  • Your requested role, and any title, description, or caption you attach to an upload.
  • Content within documents, photographs, or videos you upload, which may include personal data of yourself or third parties.
  • Account activity, audit and security logs (including IP address and browser identifier), and a single session cookie used only to keep you signed in — not used for advertising, tracking, or analytics.

4. How and Why We Use Your Data

We process personal data only where a lawful basis under Section 30 of the Act applies:

PurposeLawful Basis
Creating and managing your accountConsent
Role-based access controlLegitimate interests
Storing and displaying uploaded content to authorized rolesPublic interest — NSPCVE community engagement mandate
Audit loggingLegal obligation and legitimate interests
Download limits and security controlsLegitimate interests
Breach notificationLegal obligation (Section 43)

5. Data Protection Principles We Follow

In line with Section 25 of the Act: lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; and integrity and confidentiality.

6. How We Share Your Data

We do not sell personal data, and we do not use third-party cloud services to render or process the content of your uploads — document previews are converted entirely on our own server, never sent to an external viewer. We disclose personal data only to authorized Administrators, where required by law or a lawful ODPC request, or to a data processor bound by written obligations equivalent to this policy.

7. How We Protect Your Data

  • Passwords are never stored in readable form.
  • Role-based access, re-verified by the server on every request.
  • Every file is streamed through permission and audit checks before it can be viewed or downloaded.
  • Uploaded files are validated and stored with randomized filenames outside the public web root.
  • A limit on the number of photographs a Panelist or Attendee may download.
  • An audit log of key actions, and account lockout after repeated failed logins.

8. How Long We Keep Your Data

Personal data is retained only as long as necessary. [The Organization should specify its retention periods for account data, uploaded content, and audit logs here.]

9. Your Rights as a Data Subject

Under Sections 26–40 of the Act, you have the right to: be informed of how your data is used; access your data; object to processing; request correction or erasure; request restriction of processing; receive your data in a portable format; not be subject to solely automated decisions; and lodge a complaint with the ODPC. Contact the Data Protection Officer below to exercise these rights.

10. Children's Data

The Portal is intended for adult users participating in official PCVE community engagement activities. Where a photo or video incidentally includes a minor, additional care and, where applicable, parental/guardian consent is required before upload, per Section 33 of the Act.

⚠ Important: Your Responsibility After Downloading

Once you download a photograph, video, or document from the Portal, you become responsible for how it is stored, used, and shared. The Portal's access controls and download limits no longer apply once a file is on your own device. If the file contains personal data of another person, any further processing you carry out may make you a data controller in your own right under the Data Protection Act, with your own legal obligations.

11. Acceptable Use of Downloaded Media

Do:

  • Use downloaded material only for the purpose it was made available to you.
  • Store downloaded files securely and delete them once no longer needed.
  • Assume identifiable individuals have not consented to publication beyond the original engagement context.
  • Report any accidental exposure or loss of a downloaded file immediately.

Do not:

  • Publish, post to social media, or distribute downloaded media without written authorization.
  • Use downloaded media for any commercial, political, or personal purpose unrelated to official PCVE engagement work.
  • Forward downloaded files to anyone not authorized to access them through the Portal.
  • Attempt to identify, tag, or publicly name individuals appearing in photographs or videos — particularly given the safety implications for participants in PCVE programming.
  • Use downloaded material in any way that could stigmatize, endanger, or expose a community member, panelist, or attendee.

Misuse may result in account suspension, referral to disciplinary processes, and, where personal data is involved, liability under the Data Protection Act, 2019 (administrative fines of up to KES 5 million or 1% of annual turnover) and other applicable law.

12. Data Breach Notification

If we become aware of a breach likely to compromise your personal data, we will notify the ODPC without undue delay and, where feasible, within 72 hours, per Section 43 of the Act, and notify affected users directly where the breach poses a high risk.

13. Data Protection Officer and Complaints

Contact: [Data Protection Officer Name] — [email] — [physical address].

You may also lodge a complaint with the Office of the Data Protection Commissioner: Britam Towers, 12th Floor, Hospital Road, Upper Hill, Nairobi (P.O. Box 30920–00100, Nairobi) — info@odpc.go.ke — www.odpc.go.ke

14. Changes to This Policy

We may update this policy from time to time. Material changes will be communicated to users, and the effective date above will be updated.

This policy is grounded in the Data Protection Act, No. 24 of 2019 (Kenya) and does not constitute legal advice. Bracketed placeholders above must be completed, and this document reviewed by qualified legal counsel, before being treated as final.