Data Protection & Security Statement
Protecting personal data through responsible governance, security, accountability, and privacy
Spice Without Borders (SWOB) and the Spicy Awards (“we,” “our,” or “us”) are committed to maintaining strong standards of data protection and information security for individuals whose personal data we collect, use, store, or otherwise process.
This Data Protection & Security Statement explains the organizational and technical measures we use to protect personal data and support responsible data processing in accordance with applicable laws and recognized international data protection practices.
Our approach is guided by:
- Kenya Data Protection Act, 2019
- EU General Data Protection Regulation (GDPR), where applicable
- Other applicable data protection and privacy laws
- Recognized international data protection and information security practices
01 | Our Data Protection Principles
- Lawfulness, fairness & transparency — personal data is processed lawfully, fairly, and transparently.
- Purpose limitation — personal data is collected and processed only for specified, explicit, and legitimate purposes.
- Data minimization — we seek to collect only the personal data that is reasonably necessary for the relevant purpose.
- Accuracy — we take reasonable steps to keep personal information accurate and up to date where necessary.
- Storage limitation — personal data is retained only for as long as reasonably necessary for the purpose for which it was collected, subject to legal, contractual, archival, or operational requirements.
- Integrity & confidentiality — personal data is protected through appropriate technical and organizational security measures.
- Accountability — we take responsibility for our data processing activities and seek to demonstrate compliance with applicable data protection requirements.
02 | Organizational Measures
- Staff, volunteers, and relevant personnel training on data protection.
- Confidentiality obligations and agreements for staff, partners, and processors.
- Data Protection Impact Assessments (DPIAs) where required or appropriate.
- Role-based access controls based on responsibilities and legitimate need.
- Internal data protection, privacy, and information security procedures.
- Documented data retention and disposal practices.
- Processes for identifying and managing data protection risks.
03 | Technical Security Measures
- Encrypted servers and data storage.
- Secure Sockets Layer (SSL/TLS) encryption for supported website connections.
- Password-protected systems and databases.
- Multi-factor authentication for relevant staff and administrative accounts.
- Role-based access controls and account permissions.
- Security monitoring and system reviews.
- Firewalls and appropriate malware and antivirus protections.
- Secure backup and recovery procedures.
- Software, platform, and security updates where appropriate.
04 | Breach Detection & Response
- Detecting and documenting suspected security incidents.
- Assessing the nature, scope, and potential impact of an incident.
- Taking reasonable steps to contain and mitigate the incident.
- Investigating the circumstances and identifying affected systems or data.
- Notifying affected individuals where required by applicable law.
- Reporting incidents to relevant regulatory authorities within legally required timelines.
- Implementing corrective and preventative measures to reduce the likelihood of recurrence.
05 | Third-Party Processors & Service Providers
- Maintain appropriate technical and organizational security measures.
- Process personal data only for authorized purposes.
- Maintain confidentiality obligations.
- Comply with applicable data protection requirements.
- Enter into appropriate Data Processing Agreements (DPAs) where required.
- Assist with applicable data protection obligations and incident response.
06 | International Data Processing & Transfers
07 | Data Retention & Secure Disposal
- Program and service delivery requirements.
- Legal and regulatory obligations.
- Contractual requirements.
- Financial, accounting, or audit requirements.
- Historical records and legitimate organizational purposes.
- Research, reporting, and impact assessment requirements.
08 | Your Role in Protecting Data
- Use strong and unique passwords where passwords are required.
- Avoid sharing passwords or account credentials with others.
- Keep your devices, browsers, and software reasonably up to date.
- Exercise caution when responding to suspicious emails, messages, or links.
- Use secure networks when submitting sensitive information.
- Report suspected unauthorized access or suspicious activity promptly.
09 | Your Data Protection Rights
10 | Children & Young People
11 | Monitoring & Continuous Improvement
- Security reviews and assessments.
- Policy and procedure updates.
- Staff and volunteer awareness training.
- Review of third-party service providers.
- Incident and breach response reviews.
- Updates to technical and organizational safeguards.
12 | Contact & Data Protection Concerns
See Other Terms of Use
By using our websites, you agree to be bound by our applicable policies and terms: