← Back to NAYA
NAYA logo

NAYA

Network for Adolescent and Youth of Africa

2025

Legal & Governance

Data Protection Policy

This is NAYA's official Data Protection Policy. It sets out how Network for Adolescent and Youth of Africa (NAYA) collects, uses, shares, and safeguards personal data — including the rights of data subjects, how NAYA handles data breaches and third-party transfers, and how to reach NAYA's Data Protection Officer. Use the document browser below to open one section at a time.

Front Matter

Introduction

Background

In the current world, information has increasingly become a critical resource that has to be managed carefully. Generally, much of today's information consists of personal and sensitive data relating to persons. As a result, the transformative developments in the current economy are presenting major concerns for privacy in the way information is processed, including data collection, handling, storage, sharing and destruction. Daily, vast amounts of data are collected, transmitted and stored by ever-growing computing and communication technologies.

On this premise, Article 31 of the Constitution of Kenya dictates that every person has a right to privacy. To further give effect to this Article, the Data Protection Act 2019 was passed in November 2019 to govern the collection and processing of personal data.

The Network for Adolescent and Youth of Africa (NAYA) is committed to processing data in accordance with the law, while still ensuring that all information of Stakeholders in its position is handles with utmost care and confidentiality. It is therefore apparent for NAYA to have a Data Protection policy to ensure responsible, purposeful, secure, transparent and time-bound processing of data subjects' personal data. The fundamental principles of this policy have been largely informed by the DPA and, to the acceptable and constitutional degrees, International Laws on Data Protection and Privacy.

Purpose of the policy

This policy is intended to mainly ensure that NAYA complies with the DPA in the processing of data.

The objectives of the policy are:

  • To provide guidance on how NAYA will process data;
  • To protect the rights of prospective employees, partners, beneficiaries, clients, and suppliers;
  • Safeguard NAYA from any risks of data breaches.

Scope of the policy

This Policy is intended to provide minimum standards with respect to the protection of personal data that we collect, process and store and will cover the use of personal data about all individuals, including consumers, employees, customers, stakeholders and other third parties, that deal with NAYA.

Every employee of NAYA has a duty to maintain the confidentiality and trust of the data subjects that share their personal data with the Company. Compliance with the Policy is mandatory and any breach of this Policy and related policies and procedures shall result in disciplinary action.

These conditions apply to all NAYAs' activities in relation to information, recommendations, research interventions, documents and services. Please refer to the disclaimer on our website.