Data Governance Policy

Precision Engineering. Unrivaled Performance.
INTERNAL POLICY

Data Governance Policy

This Data Governance Policy establishes the framework by which Royal-Sceptre Company Ltd classifies, stores, accesses, and manages all data assets. It applies to all employees, contractors, and authorised third parties who process data on behalf of Royal-Sceptre.

Royal-Sceptre has an office in Nairobi, Kenya, and serves clients across East Africa, Uganda, Rwanda, Malawi, Tanzania, Ethiopia, COMESA markets, and the wider Eastern and Southern Africa region.

4Data Classifications
72 hrsBreach Notification SLA
Art. 30GDPR Compliance
7 YearsFinancial Retention

1. Data Classification Framework

All data held or processed by Royal-Sceptre is classified into one of four tiers. Classification determines storage requirements, access rights, and handling procedures.

Public

Information intentionally available to the general public: product catalogues, website content, press releases, published pricing. No access restrictions. Standard integrity controls apply.

Internal

Business operational data intended for employees only: internal procedures, supplier pricing lists, staff directories. Shared only within the organisation on approved channels.

Confidential

Sensitive business or customer data: customer personal data, financial records, contract terms, employee HR records. Access restricted on a need-to-know basis. Encryption at rest mandatory.

Restricted

Highest-sensitivity data: payment credentials, authentication tokens, legal privilege documents, unreleased product roadmaps. Strictly role-based access. Audit trail required for every access event.

2. Storage Standards

  • Confidential and Restricted data must be stored on encrypted volumes (AES-256 minimum) whether at rest or in transit (TLS 1.2+).
  • Customer personal data must reside on servers physically located withacross Eastern and Southern Africa or a country with an adequate level of data protection as determined by the ODPC.
  • Backups of Confidential and Restricted data must be encrypted and stored in a geographically separate location from the primary store. Backup integrity is tested quarterly.
  • Removable media (USB drives, external disks) containing Confidential or Restricted data must be encrypted and their use logged. Loss must be reported immediately.
  • Cloud storage for Confidential data is permissible only on pre-approved platforms with Data Processing Agreements (DPAs) in place.

3. Employee Access Controls

  • Principle of Least Privilege: Every employee and contractor is granted only the minimum data access required for their role.
  • Role-Based Access Control (RBAC): Access rights are assigned to roles (e.g., Sales, Finance, IT Admin) and reviewed quarterly by the Data Protection Officer.
  • Multi-Factor Authentication (MFA): Mandatory for all systems containing Confidential or Restricted data.
  • Off-boarding: All access is revoked within 24 hours of an employee's last working day. Credentials are invalidated; company devices are remotely wiped.
  • Third-Party Access: External contractors may access Internal or Confidential data only under a signed Data Processing Agreement and only via audited, time-limited credentials.

4. Breach Notification Procedure

In the event of a confirmed or suspected personal data breach, Royal-Sceptre follows a structured 72-hour response protocol in line with GDPR Article 33 and the Kenya Data Protection Act 2019:

  • Hour 0–4: Incident detected, contained, and escalated to the DPO and IT Security Lead. Preliminary scope assessment conducted.
  • Hour 4–24: Full investigation initiated. Affected data categories and individuals identified. Evidence preserved for forensic review.
  • Hour 24–72: Notification submitted to the Office of the Data Protection Commissioner (ODPC) if the breach poses a risk to individuals' rights and freedoms. Affected individuals notified without undue delay if high risk.
  • Post-72hrs: Remediation actions implemented. Root cause analysis completed. Lessons-learned report distributed to Senior Management.

5. Retention Schedules

  • Customer financial records: 7 years (KRA statutory requirement)
  • Employee HR records: Duration of employment + 7 years
  • Customer personal data (non-financial): 3 years from last active transaction
  • Marketing data: 2 years from last engagement or until consent withdrawal
  • Website access logs: 12 months rolling
  • Supplier contracts: Duration + 6 years

Data due for deletion is permanently destroyed via verified secure deletion tools. Certificates of Destruction are issued for Restricted data.

6. GDPR Article 30 — Record of Processing Activities

Royal-Sceptre maintains a formal Record of Processing Activities (ROPA) as required by GDPR Article 30. This record documents: the purpose of each processing activity, the categories of data subjects and personal data involved, the legal basis for processing, data recipients, international transfers, and retention periods. The ROPA is reviewed annually and made available to the ODPC upon request.

Last Updated: March 2026
Chat on WhatsApp