Goblis FoundationEmpowering Communities
Policy

Data Protection & GDPR

Goblis Foundation’s data-protection approach under applicable Kenyan law and, where its territorial scope applies, the EU/UK GDPR framework.

01

Kenyan data-protection baseline

Goblis Foundation treats applicable Kenyan data-protection law as the primary baseline for its Kenyan operations, alongside sectoral, contractual and evidentiary obligations.

02

GDPR scope

GDPR is applied where the relevant EU or UK territorial/material scope applies to a particular processing activity or data-subject relationship. This page does not claim that every Foundation activity is governed by GDPR.

03

Lawfulness and purpose

Personal data is processed for defined purposes such as enquiries, programme administration, partnership management, donations, legal compliance, safeguarding, security, research/MERM or legitimate institutional operations.

04

Rights workflow

Access, correction, deletion, restriction, objection, portability or consent-related requests are logged with a reference, verified proportionately and completed or refused with a documented basis.

05

International and processor controls

Where data is handled by external processors or across borders, Goblis Foundation assesses purpose, access, safeguards, contractual controls and applicable transfer requirements.

06

Security and accountability

Least privilege, audit logs, evidence records, incident handling, secure configuration and controlled partner access support accountability. No website policy can eliminate all risk, so security controls are reviewed continuously.

Need a policy or rights-related response?

Use the Contact route so the request receives a case reference and accountable follow-up.

Contact Goblis Foundation