Kenyan data-protection baseline
Goblis Foundation treats applicable Kenyan data-protection law as the primary baseline for its Kenyan operations, alongside sectoral, contractual and evidentiary obligations.
Goblis Foundation treats applicable Kenyan data-protection law as the primary baseline for its Kenyan operations, alongside sectoral, contractual and evidentiary obligations.
GDPR is applied where the relevant EU or UK territorial/material scope applies to a particular processing activity or data-subject relationship. This page does not claim that every Foundation activity is governed by GDPR.
Personal data is processed for defined purposes such as enquiries, programme administration, partnership management, donations, legal compliance, safeguarding, security, research/MERM or legitimate institutional operations.
Access, correction, deletion, restriction, objection, portability or consent-related requests are logged with a reference, verified proportionately and completed or refused with a documented basis.
Where data is handled by external processors or across borders, Goblis Foundation assesses purpose, access, safeguards, contractual controls and applicable transfer requirements.
Least privilege, audit logs, evidence records, incident handling, secure configuration and controlled partner access support accountability. No website policy can eliminate all risk, so security controls are reviewed continuously.
Use the Contact route so the request receives a case reference and accountable follow-up.