Skip to main content
Advanced Search
Search Terms
Content Type

Exact Matches
Tag Searches
Date Options
Updated after
Updated before
Created after
Created before

Search Results

28 total results found

Introduction

AHEEN Data Protection AHEEN Data Protection Policy

Purpose and Scope The African Higher Education in Emergencies Network (AHEEN) is a nonprofit initiative dedicated to delivering academic diplomas, degrees, and employability-focused programs to refugees and internally displaced persons (IDPs) across Africa. Ho...

Data Protection Principles

AHEEN Data Protection AHEEN Data Protection Policy

AHEEN adheres to core principles from the DPA, UoN policies, and ICRC handbook, adapted for humanitarian education. Principle Description Application to AHEEN Lawfulness, Fairness, and Transparency Processing must have a legal basis (e.g., consent, vita...

Roles and Responsibilities

AHEEN Data Protection AHEEN Data Protection Policy

Data Protection Officer (DPO): Oversees compliance; reports to UoN's DPO (contact: dataprotection@uonbi.ac.ke). Conducts DPIAs and training. Staff/Volunteers: Handle data securely; report incidents immediately. Managers: Ensure team adherence; approve data sh...

Data Classification

AHEEN Data Protection AHEEN Data Protection Policy

Classify data to determine handling: Classification Examples Handling Requirements Public Aggregated program reports (no identifiers). Minimal protection; share freely. Internal General operational emails. Access limited to AHEEN staff. Confidential...

Data Lifecycle Management

AHEEN Data Protection AHEEN Data Protection Policy

Collection Obtain explicit consent where possible; use vital interests/public interest in emergencies. Provide privacy notices at collection (e.g., via intake forms). Minimize: Collect only essentials (e.g., name, emergency context for enrollment). Processin...

Cloud Storage

AHEEN Data Protection AHEEN Data Protection Policy

Cloud services enable scalable storage for AHEEN's distributed programs but introduce risks like data sovereignty and access by foreign governments (e.g., US CLOUD Act). Guidelines Approved Providers: Use UoN-vetted services (e.g., Microsoft Azure with Kenyan...

Storage on Private PCs (BYOD Policy)

AHEEN Data Protection AHEEN Data Protection Policy

Personal devices (laptops, mobiles) are common in field operations but pose risks like loss/theft in emergencies. Guidelines Approval: Register devices with IT; use only for AHEEN work. Security Measures: Full-disk encryption (e.g., BitLocker/FileVault). MFA...

Use of AI

AHEEN Data Protection AHEEN Data Protection Policy

[TBD] Use of AI for analysis. OpenSources etc

Risk Assessments

AHEEN Data Protection AHEEN Data Protection Policy

Conduct DPIAs for high-risk activities (e.g., biometric enrollment): Identify risks (e.g., data leakage in refugee camps). Assess impacts on vulnerable groups. Mitigate via minimization/proportionality. Review annually or post-incident.

Data Sharing

AHEEN Data Protection AHEEN Data Protection Policy

Legal Basis: Consent, contract, or public interest (e.g., sharing with partners for degree validation). Humanitarian Contexts: Balance urgency with "do no harm"; use aggregated data for reports. Third-Party Sharing: No sharing without a Data Processing Agree...

Incident Response

AHEEN Data Protection AHEEN Data Protection Policy

Follow UoN/DPA protocols: Detection: Monitor for breaches (e.g., unauthorized access). Containment: Isolate affected systems; notify DPO within 1 hour. Assessment: Evaluate scope/impact. Notification: Report to ODPC within 72 hours if high-risk; inform subjec...

Training and Awareness

AHEEN Data Protection AHEEN Data Protection Policy

Mandatory annual training on principles, tools (e.g., encryption). Field-specific modules for emergency contexts (e.g., data risks in camps). Awareness campaigns: Posters/notices in multiple languages.

Compliance and Auditing

AHEEN Data Protection AHEEN Data Protection Policy

Internal audits quarterly; external every 2 years. DPO reports to AHEEN Board/UoN. Violations: Disciplinary action per UoN code.

References and Appendices

AHEEN Data Protection AHEEN Data Protection Policy

Kenya Data Protection Act, 2019 University of Nairobi - Data Privacy Policy Approved 02022024 V1.pdf ICRC Handbook on Data Protection in Humanitarian Action Appendix A: DPIA Template Appendix B: Data Processing Agreement Sample For queries, contact AHEEN DPO...

AHEEN Data Protection

AHEEN Data Protection Quick Do's & Don'ts Guide

Quick Do's & Don'ts Guide 🌟 For All Members (Staff, Volunteers, Partners) 🌟Protecting vulnerable students & beneficiaries in emergencies – "Do No Harm" principle. Follow Kenya DPA & UoN policies.Questions? Contact DPO: dataprotection@aheen.netLast Updated: Nov...

General DPIA Checklist

AHEEN Data Protection Checklists

Version: 1.0 | Last Updated: 11 November 2025 Purpose: This checklist guides AHEEN staff in conducting DPIAs for high-risk data processing (e.g., biometric enrollment, cloud sharing in emergencies). Required under Kenya DPA Section 31 and ICRC Handbook (Ch. 3)...

Physical Device Security Checklist

AHEEN Data Protection Checklists

Version: 1.0 | Last Updated: November 11, 2025 Purpose: This checklist ensures staff, volunteers, and partners secure physical devices (e.g., laptops, mobiles, USBs) handling personal data (e.g., student records) in emergency contexts. Complies with Kenya DPA ...

Why an AHEEN Safeguarding Framework?

AHEEN Safeguarding Framework

AHEEN is a whole-of-society network that promotes access, retention, and completion of Higher Education degrees by forcibly displaced youth, with a strong employability focus. Safeguarding is not a compliance exercise; it is an enabling condition that underpin...