Public notice for users of the Kisii Municipality Parking Management System. Read this policy before creating an account.
Policy version 2026.06

Privacy, Data Protection and User Consent Policy

This policy explains how the Kisii Municipality Parking Management System collects, uses, shares, protects, stores, and deletes personal data. It also explains the consent users must provide before account creation and the rights available to data subjects.

Effective date 16 June 2026
Applies to Users, officers, SACCOs, organisations and applicants
Controller Kisii Municipality Parking Authority
Consent status Required before signup
Executive summary

Privacy commitments at a glance

Transparent collection

We explain the personal data collected and why it is needed for parking services.

Purpose limitation

Data is used for account management, service delivery, security, compliance, and lawful administration.

Consent before signup

Users must actively confirm that they have read and accepted this policy before account creation.

Legal review notice: This page is a professional operational policy template for the parking system. It should be reviewed and approved by the Municipality's legal officer, Data Protection Officer, or Kenyan data protection counsel before final publication.
Key terms

2. Definitions used in this policy

Personal data means information relating to an identified or identifiable natural person.

Processing means any operation performed on personal data, including collection, storage, retrieval, use, sharing, restriction, deletion, or destruction.

Consent means a clear, affirmative, specific, informed, and voluntary indication that the user agrees to the processing described in this policy.

Data subject means the person whose personal data is processed.

Data controller means the party determining the purpose and means of processing personal data.

Data processor means a third party that processes personal data on behalf of the controller.

Collection notice

3. Personal data we collect

We collect only data reasonably necessary for parking administration, digital account management, compliance, enforcement, audit, and public service support.

Data category Examples Purpose
Account and identity data Name, email, phone number, password credentials, account status, verification records, roles and permissions. Create accounts, authenticate users, verify identity, manage access, and provide support.
Parking and application data SACCO or organisation data, reserved parking details, slot allocations, certificates, locations, vehicle records, KRA PIN where required. Process applications, reservations, allocations, certificate issuance, renewals, compliance checks, and reporting.
Payment and enforcement data Payment status, approval records, penalties, violations, compliance notes, enforcement history. Manage financial accountability, approvals, penalties, disputes, and lawful enforcement.
Technical and security data IP address, user agent, timestamps, session records, login events, audit logs, security events. Secure the system, investigate incidents, maintain audit trails, and prevent misuse.
Documents and communications Uploaded documents, messages, notifications, email/SMS delivery records, support requests. Review applications, communicate decisions, resolve support requests, and maintain official records.
Sensitive personal data: If sensitive personal data is ever required by law or system function, it must be handled with enhanced safeguards, strict access control, clear purpose limitation, and any additional legal approvals required by Kenyan law.
Purpose notice

4. How personal data is used

  1. Account management: create, verify, secure, and administer user accounts.
  2. Service delivery: process parking applications, reservations, slot allocation, certificates, renewals, payments, penalties, and compliance checks.
  3. Communication: send verification messages, status updates, system notifications, operational alerts, and support responses.
  4. Security and fraud prevention: detect unauthorised access, abuse, fraud, suspicious activity, and system misuse.
  5. Legal and administrative compliance: maintain audit logs, official records, financial accountability, enforcement records, and dispute evidence.
  6. Service improvement: improve reliability, accessibility, public reporting, and operational efficiency.
Lawful basis matrix

5. Lawful bases for processing

The system may rely on different lawful bases depending on the activity. Consent is required before signup, but some processing may also be necessary for public duty, contract, legal obligation, legitimate security needs, or compliance functions.

Processing activity Likely lawful basis Notes
Account creation Consent and service necessity User must accept this policy before signup. Account data is needed to provide the service.
Parking applications and allocations Public task, contract, legal obligation, or service necessity Processing supports parking administration and lawful public service delivery.
Payments, penalties, and compliance Legal obligation, public task, financial accountability Records may be retained for audit, enforcement, reporting, and dispute resolution.
Security logs and audit trails Legitimate security need, legal obligation, public task Used to protect users, officers, and public systems from misuse or unauthorised access.
Optional analytics or non-essential cookies Consent Should only be used after clear notice and any legally required opt-in.
Lawfulness Fairness Transparency Data minimisation Accuracy Storage limitation Integrity and confidentiality Accountability
Disclosure controls

7. Data sharing and disclosure

Personal data may be shared only where necessary, authorised, proportionate, and lawful.

  • Municipality officers and administrators: for approved operational, compliance, and support functions.
  • Service providers: payment, SMS, email, hosting, storage, security, analytics, and technical support providers acting under appropriate safeguards.
  • Regulators and public authorities: where required by law, court order, investigation, audit, or lawful request.
  • Professional advisers: auditors, legal advisers, investigators, or insurers where needed for compliance, claims, or dispute resolution.
No sale of personal data: The system does not sell or rent user personal data. Data must not be shared for unrelated marketing purposes.
Protection measures

8. Data security safeguards

Safeguard System expectation
Password protection Passwords are stored using secure hashing and are not stored in plain text.
Access control Role-based permissions restrict sensitive functions to authorised users.
Audit trails Important administrative and security activities should be logged for accountability.
Authentication Two-factor authentication may be used to strengthen account security.
Operational controls Access should be reviewed periodically and removed when no longer required.
Supplier safeguards Hosting, SMS, email, payment, and technical providers should maintain reasonable security controls.
Lifecycle management

9. Data retention, archiving and deletion

Personal data is retained only for as long as required for service delivery, public records, legal obligations, audit and financial accountability, enforcement, dispute resolution, and system security.

  • Account records may be retained while the account is active and for a reasonable period after closure where required for audit or legal purposes.
  • Parking, payment, compliance, and enforcement records may be retained according to public records, audit, finance, and enforcement requirements.
  • Technical logs may be retained for a limited period needed for security, investigation, debugging, and audit.
  • Where data is no longer required, it should be deleted, anonymised, archived, or access-restricted according to an approved retention schedule.
Data subject rights

10. User rights and requests

Subject to applicable law and lawful exceptions, users may request:

Right What it means
Access Request a copy of personal data held about them.
Correction Request correction of inaccurate, outdated, or incomplete records.
Deletion or restriction Request deletion or restriction where legally permitted and where records are no longer required.
Objection Object to certain processing where the law allows.
Information Request details about purposes, categories, recipients, safeguards, and retention.
Withdrawal of consent Withdraw consent where consent is the lawful basis, without affecting lawful processing already carried out.

Requests may require identity verification. Some requests may be limited where records are needed for public duty, enforcement, finance, audit, security, legal claims, or statutory obligations.

Technical notice

11. Cookies, sessions and technical logs

The system may use necessary cookies and storage for:

  • Keeping users logged in during a session.
  • Protecting forms against cross-site request forgery.
  • Remembering security state and login context.
  • Detecting suspicious activity and system errors.

Non-essential analytics, advertising, or tracking cookies should not be introduced unless users receive clear notice and any required consent options.

Age and authority

12. Children's data

The parking system is intended for adults, authorised representatives, organisations, SACCOs, and public officers. Children should not create accounts or submit personal data unless a lawful basis and appropriate guardian or legal authorisation applies.

Cross-border safeguards

13. International transfers and third-party hosting

If personal data is transferred, hosted, backed up, or processed outside Kenya, the Municipality should ensure that the transfer is lawful and protected by appropriate safeguards. These may include contractual commitments, security requirements, supplier due diligence, access controls, and compliance with applicable data protection requirements.

Incident response

14. Personal data breach response

A personal data breach may include accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored, or otherwise processed by the system.

  1. Identify and contain: preserve evidence, limit further exposure, and secure affected systems.
  2. Assess risk: determine affected data, users, systems, severity, and likely harm.
  3. Escalate: notify responsible officers, legal/data protection contacts, and system administrators.
  4. Notify where required: notify the ODPC and affected data subjects within applicable legal timelines where required.
  5. Remediate: fix root causes, improve controls, and document lessons learned.
Governance

15. Accountability, review and changes

  • This policy should be reviewed when the law changes, system functionality changes, new service providers are added, or processing purposes change.
  • Material changes should be published clearly and users may be asked for renewed consent where required.
  • System administrators should maintain auditable records of consent, access, security events, and sensitive administrative activity.
  • Officers and processors with access to personal data should be trained or briefed on confidentiality, lawful access, and incident escalation.
Contact and complaints

16. Contact, requests and complaints

Privacy requests, corrections, complaints, and security concerns may be sent to the Municipality's designated data protection or system administration contact.

Email: denoayiera@gmail.com

Phone: +254727953020

Users may also contact the Office of the Data Protection Commissioner where they believe their data protection rights have been violated.

Reference material

17. Legal and design references

This page is informed by Kenyan privacy law, internationally recognised privacy principles, and public-sector privacy notice patterns.