Privacy Policy for the Registrar of Societies Online Registration Portal
The Registrar of Societies Registration Portal (“the Portal”) is an electronic platform managed by the Office of the Registrar of Societies within the Office of the Attorney-General for the registration, regulation, and administration of societies registered in Kenya.
The Registrar of Societies is committed to protecting the privacy and personal data of all users of the Portal in accordance with:
- The Constitution of Kenya, 2010;
- The Data Protection Act, No. 24 of 2019;
- The Data Protection (General) Regulations, 2021;
- The Data Protection (Registration of Data Controllers and Data Processors) Regulations, 2021;
- The Societies Act (Cap. 108);
- The Computer Misuse and Cybercrimes Act, 2018;
- The Access to Information Act, 2016;
- The Kenya Information and Communications Act;
- The Public Archives and Documentation Service Act;
- Any other applicable law governing privacy, cybersecurity, public records, and data protection in Kenya.
This Privacy Policy explains how personal data is collected, used, stored, disclosed, retained, and protected through the Portal.
Types of data we collect
We may collect, use, store, transfer or otherwise process personal data about you or persons connected to you, including, but not limited to, identification information such as name and national identity card number or passport number, KRA PIN, nationality, gender, date of birth, passport photographs, biometric data, contact information such as email address, telephone number and postal address, residential address, bank account information and CCTV video surveillance when you visit the Registrar of Societies offices. If we need information about other individuals connected to you, we may ask you to provide it. If you share someone else’s information with us, please ensure they are aware and consent to you doing so. You may find it helpful to share this Privacy Notice with them and encourage them to contact us if they have any questions or concerns.
How we use your personal data and the legal basis for processing
We use your personal data, including sensitive personal data in certain instances, for the following purposes:
- To consider your application for any service that you have applied for;
- To meet our legal and regulatory compliance obligations; and
- To use data analytics to improve our website, services, customer relationships and experiences.
Purpose of processing
The Registrar of Societies processes personal data for purposes including: registration of societies; verification of applicants; conducting due diligence; compliance monitoring; maintaining statutory registers; processing annual returns; investigation of complaints; enforcement of the Societies Act; communication with applicants; generation of certificates; statistical reporting; audit purposes; security monitoring; and prevention of fraud and cybercrime.
Personal data shall not be processed for purposes incompatible with those stated unless authorised by law.
Who do we share your personal data with?
Based on the Registrar of Societies’ compliance with any legal obligation and for the performance of our tasks as a public authority, we may share your personal data with third parties, such as law enforcement agencies where required by law, competent authorities, supervisors or regulators of financial institutions and designated non-financial businesses and professionals where required by law, any government agency in charge of implementing anti-money laundering and countering financing of terrorism measures, our third-party service providers who help us manage our services including those service providers who maintain our IT and office systems, provide application processing, fraud monitoring, call centre and/or other customer services, and where disclosure of personal information is pursuant to a court order.
Personal information shall not be sold or disclosed for commercial purposes.
Personal data shall not be transferred outside Kenya unless such transfer complies with the Data Protection Act and any applicable regulations, including ensuring appropriate safeguards and legal protections.
Data security
The Registrar of Societies has put in place appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed.
In addition, the Registrar of Societies has implemented appropriate administrative, technical and physical safeguards including: secure authentication; encryption of sensitive information during transmission and, where appropriate, at rest; role-based access controls; multi-factor authentication for administrative users where implemented; audit trails; firewalls; intrusion detection and prevention systems; regular security assessments; backup and disaster recovery mechanisms; and continuous monitoring of system activity.
Users are responsible for safeguarding their passwords and reporting any suspected unauthorised access.
Retention of personal data
The Registrar of Societies shall only retain your personal data for a period necessary to fulfil statutory obligations, resolve disputes, conduct audits and satisfy any legal and regulatory compliance or reporting obligations.
Upon expiry of applicable retention periods, the data shall be securely archived or disposed of in accordance with the law.
Your rights as a data subject
Subject to applicable legal limitations, data subjects have the right to:
- Be informed about the collection and use of their personal data;
- Access their personal data;
- Request correction of inaccurate or incomplete data;
- Object to processing where legally permissible;
- Request restriction of processing in appropriate circumstances;
- Request deletion of personal data where applicable.
Certain rights may be limited where processing is necessary for compliance with legal obligations, public interest, national security, law enforcement, or the exercise of statutory functions.
Third-party services
The Portal may interface with other government systems or authorised third-party service providers for verification, payment, identity validation, or related statutory purposes. Such integrations shall comply with applicable data protection and cybersecurity requirements.
Confidentiality
All officers, employees, contractors and authorised users with access to personal data are required to maintain confidentiality and process such data strictly within the scope of their lawful duties.
Amendments to this Policy
The Registrar may amend this Privacy Policy from time to time to reflect changes in legislation, technology, or operational requirements. Updated versions shall be published on the Portal and shall take effect upon publication unless otherwise specified.
Contact information
For enquiries relating to this Privacy Policy or the processing of personal data, users may contact:
- Email: Societies@ag.go.ke
- Physical address: Ground Floor, Sheria House, Harambee Avenue, Nairobi
- Postal address: P.O. Box 40112 – 00100, Nairobi
- Telephone: +254 20 2227460 / 2251355 / 0700 072929 / 0732 529995
We will respond to your questions or concerns in a timely manner and in compliance with the relevant laws.
Acceptance
By accessing or using the Registrar of Societies Registration Portal, you acknowledge that you have read and understood this Privacy Policy and agree to the processing of personal data in accordance with applicable law and this Policy, to the extent permitted by law.