Privacy commitments at a glance
Transparent collection
We explain the personal data collected and why it is needed for parking services.
Purpose limitation
Data is used for account management, service delivery, security, compliance, and lawful administration.
Consent before signup
Users must actively confirm that they have read and accepted this policy before account creation.
1. Legal basis and regulatory framework
This policy is founded on Kenya's constitutional and statutory privacy framework and is aligned with widely recognised international privacy and data protection principles.
Kenyan constitutional foundation
Article 31 of the Constitution of Kenya, 2010 recognises the right to privacy, including protection against unnecessary revelation of private or family information and infringement of communications. The Data Protection Act, No. 24 of 2019 gives effect to privacy protections relating to personal data.
Kenyan statutory and regulatory framework
- The Constitution of Kenya, 2010, Article 31.
- The Data Protection Act, No. 24 of 2019.
- The Data Protection (General) Regulations, 2021.
- The Data Protection (Registration of Data Controllers and Data Processors) Regulations, 2021.
- The Data Protection (Complaints Handling Procedure and Enforcement) Regulations, 2021.
- The Computer Misuse and Cybercrimes Act, 2018, where system misuse, fraud, or unauthorised access is involved.
- Applicable public finance, county records, audit, procurement, and enforcement requirements.
International principles considered
- EU General Data Protection Regulation principles, including transparency, lawful basis, data minimisation, rights, and security by design.
- Universal Declaration of Human Rights, Article 12, on protection from arbitrary interference with privacy.
- International Covenant on Civil and Political Rights, Article 17, on privacy and correspondence.
- African Union data protection and cybersecurity principles, where applicable.
2. Definitions used in this policy
Personal data means information relating to an identified or identifiable natural person.
Processing means any operation performed on personal data, including collection, storage, retrieval, use, sharing, restriction, deletion, or destruction.
Consent means a clear, affirmative, specific, informed, and voluntary indication that the user agrees to the processing described in this policy.
Data subject means the person whose personal data is processed.
Data controller means the party determining the purpose and means of processing personal data.
Data processor means a third party that processes personal data on behalf of the controller.
3. Personal data we collect
We collect only data reasonably necessary for parking administration, digital account management, compliance, enforcement, audit, and public service support.
| Data category | Examples | Purpose |
|---|---|---|
| Account and identity data | Name, email, phone number, password credentials, account status, verification records, roles and permissions. | Create accounts, authenticate users, verify identity, manage access, and provide support. |
| Parking and application data | SACCO or organisation data, reserved parking details, slot allocations, certificates, locations, vehicle records, KRA PIN where required. | Process applications, reservations, allocations, certificate issuance, renewals, compliance checks, and reporting. |
| Payment and enforcement data | Payment status, approval records, penalties, violations, compliance notes, enforcement history. | Manage financial accountability, approvals, penalties, disputes, and lawful enforcement. |
| Technical and security data | IP address, user agent, timestamps, session records, login events, audit logs, security events. | Secure the system, investigate incidents, maintain audit trails, and prevent misuse. |
| Documents and communications | Uploaded documents, messages, notifications, email/SMS delivery records, support requests. | Review applications, communicate decisions, resolve support requests, and maintain official records. |
4. How personal data is used
- Account management: create, verify, secure, and administer user accounts.
- Service delivery: process parking applications, reservations, slot allocation, certificates, renewals, payments, penalties, and compliance checks.
- Communication: send verification messages, status updates, system notifications, operational alerts, and support responses.
- Security and fraud prevention: detect unauthorised access, abuse, fraud, suspicious activity, and system misuse.
- Legal and administrative compliance: maintain audit logs, official records, financial accountability, enforcement records, and dispute evidence.
- Service improvement: improve reliability, accessibility, public reporting, and operational efficiency.
5. Lawful bases for processing
The system may rely on different lawful bases depending on the activity. Consent is required before signup, but some processing may also be necessary for public duty, contract, legal obligation, legitimate security needs, or compliance functions.
| Processing activity | Likely lawful basis | Notes |
|---|---|---|
| Account creation | Consent and service necessity | User must accept this policy before signup. Account data is needed to provide the service. |
| Parking applications and allocations | Public task, contract, legal obligation, or service necessity | Processing supports parking administration and lawful public service delivery. |
| Payments, penalties, and compliance | Legal obligation, public task, financial accountability | Records may be retained for audit, enforcement, reporting, and dispute resolution. |
| Security logs and audit trails | Legitimate security need, legal obligation, public task | Used to protect users, officers, and public systems from misuse or unauthorised access. |
| Optional analytics or non-essential cookies | Consent | Should only be used after clear notice and any legally required opt-in. |
6. User consent before signup
Before creating an account, every user must confirm that they have read, understood, and accepted this policy. The signup form requires a clear affirmative checkbox. If the user does not consent, account creation is blocked.
Consent record captured by the system
- Policy version accepted.
- Date and time of acceptance.
- IP address used during signup.
- Browser user agent used during signup.
Consent limits
Consent does not remove any legal rights of the user and does not prevent processing that is required by law, public duty, financial accountability, security, enforcement, legal claims, or other valid lawful bases.
8. Data security safeguards
| Safeguard | System expectation |
|---|---|
| Password protection | Passwords are stored using secure hashing and are not stored in plain text. |
| Access control | Role-based permissions restrict sensitive functions to authorised users. |
| Audit trails | Important administrative and security activities should be logged for accountability. |
| Authentication | Two-factor authentication may be used to strengthen account security. |
| Operational controls | Access should be reviewed periodically and removed when no longer required. |
| Supplier safeguards | Hosting, SMS, email, payment, and technical providers should maintain reasonable security controls. |
9. Data retention, archiving and deletion
Personal data is retained only for as long as required for service delivery, public records, legal obligations, audit and financial accountability, enforcement, dispute resolution, and system security.
- Account records may be retained while the account is active and for a reasonable period after closure where required for audit or legal purposes.
- Parking, payment, compliance, and enforcement records may be retained according to public records, audit, finance, and enforcement requirements.
- Technical logs may be retained for a limited period needed for security, investigation, debugging, and audit.
- Where data is no longer required, it should be deleted, anonymised, archived, or access-restricted according to an approved retention schedule.
10. User rights and requests
Subject to applicable law and lawful exceptions, users may request:
| Right | What it means |
|---|---|
| Access | Request a copy of personal data held about them. |
| Correction | Request correction of inaccurate, outdated, or incomplete records. |
| Deletion or restriction | Request deletion or restriction where legally permitted and where records are no longer required. |
| Objection | Object to certain processing where the law allows. |
| Information | Request details about purposes, categories, recipients, safeguards, and retention. |
| Withdrawal of consent | Withdraw consent where consent is the lawful basis, without affecting lawful processing already carried out. |
Requests may require identity verification. Some requests may be limited where records are needed for public duty, enforcement, finance, audit, security, legal claims, or statutory obligations.
12. Children's data
The parking system is intended for adults, authorised representatives, organisations, SACCOs, and public officers. Children should not create accounts or submit personal data unless a lawful basis and appropriate guardian or legal authorisation applies.
13. International transfers and third-party hosting
If personal data is transferred, hosted, backed up, or processed outside Kenya, the Municipality should ensure that the transfer is lawful and protected by appropriate safeguards. These may include contractual commitments, security requirements, supplier due diligence, access controls, and compliance with applicable data protection requirements.
14. Personal data breach response
A personal data breach may include accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored, or otherwise processed by the system.
- Identify and contain: preserve evidence, limit further exposure, and secure affected systems.
- Assess risk: determine affected data, users, systems, severity, and likely harm.
- Escalate: notify responsible officers, legal/data protection contacts, and system administrators.
- Notify where required: notify the ODPC and affected data subjects within applicable legal timelines where required.
- Remediate: fix root causes, improve controls, and document lessons learned.
15. Accountability, review and changes
- This policy should be reviewed when the law changes, system functionality changes, new service providers are added, or processing purposes change.
- Material changes should be published clearly and users may be asked for renewed consent where required.
- System administrators should maintain auditable records of consent, access, security events, and sensitive administrative activity.
- Officers and processors with access to personal data should be trained or briefed on confidentiality, lawful access, and incident escalation.
16. Contact, requests and complaints
Privacy requests, corrections, complaints, and security concerns may be sent to the Municipality's designated data protection or system administration contact.
Email: denoayiera@gmail.com
Phone: +254727953020
Users may also contact the Office of the Data Protection Commissioner where they believe their data protection rights have been violated.
17. Legal and design references
This page is informed by Kenyan privacy law, internationally recognised privacy principles, and public-sector privacy notice patterns.
- Constitution of Kenya, 2010 - Kenya Law
- Data Protection Act, No. 24 of 2019 - Kenya Law PDF
- Office of the Data Protection Commissioner resources
- EU General Data Protection Regulation - EUR-Lex
- Universal Declaration of Human Rights - United Nations
- GOV.UK privacy notice structure
- U.S. Web Design System public-service design patterns