Data Processing Policy | Kenya

TransUnion Kenya

Last revised: 22 September 2022 

Version 1.0 

© 2022 TransUnion LLC
All Rights Reserved

No part of this publication may be reproduced or distributed in any form or by any means, electronic or otherwise, now known or hereafter developed, including, but not limited to, the Internet, without the express written permission of TransUnion. This document is protected by U.S. and International copyright laws. This document and the subject matter contained herein is TransUnion proprietary and confidential information, and may not be shared or used for any purposes other than the purpose for which it was provided by TransUnion, without the express written permission of TransUnion. By using this document, you are agreeing that you will not attempt, directly or indirectly, to reverse engineer, decompile, or disassemble any TransUnion services or service information, any confidential or proprietary criteria developed or used by TransUnion relating to services you receive from TransUnion, or any of the TransUnion confidential and proprietary information contained herein. The entire right, title and interest in and to this document and TransUnion services, and all copyrights, patents, trade secrets, trademarks, trade names, and all other intellectual property rights associated with any and all ideas, concepts, techniques, inventions, processes, or works of authorship including, but not limited to, all materials in written or other tangible form developed or created by TransUnion, shall at all times vest exclusively in TransUnion. You acknowledge that any misuse, misappropriation or threatened misappropriation of TransUnion’s intellectual property rights, or any breach or threatened breach of the foregoing restrictions, may cause immediate and irreparable injury to TransUnion, and in such event, TransUnion shall be entitled to seek injunctive relief. Nothing stated herein will be construed to limit any other remedies available to TransUnion including, but not limited to suspension and/or termination of the services provided to you.

Requests for permission to reproduce or distribute any part of, or all of, this publication should be mailed to:

Law Department
Delta Corner Annex, 2nd Floor, Ring Road,
Westlands, Nairobi.

The “tu” logo, TransUnion, and other trademarks, service marks, and logos (the “Trademarks”) used in this publication are registered or unregistered Trademarks of TransUnion LLC or their respective owners. Trademarks may not be used for any purpose whatsoever without the express written permission of the Trademark owner.

Table of contents


  1. Purpose of policy
  2. Application of policy
  3. Definitions
  4. Compliance with laws and associated bodies
  5. Information security
  6. Consents
  7. Submission of data to TransUnion
  8. Use of information
  9. The parties obligation concerning protection of personal data
  10. Audit rights
  11. Return and retention of Personal Data
  12. Indemnities
  13. Confidentiality
  14. Breach and termination
  15. Payment profile information
  16. Removal of adverse listings
  17. Information requested in respect of juristic persons and their principals
  18. Consequences of termination
  19. Waiver
  20. Severability


TransUnion is a credit bureau licensed by the Central Bank of Kenya in accordance with the provisions of the Banking Act (Credit Reference Bureau Regulations, 2020; Registration Number C.82122). Its operations are regulated by the CRB Regulations and other applicable Laws, including the Data Protection Act No. 24 of 2019. TransUnion protects the integrity of all information housed by it, ensuring the information is kept secure.

TransUnion is committed to conducting its operations in an ethical manner and in compliance with all applicable Laws and guidelines. To successfully ensure this, it’s vital all entities doing business with TransUnion ascribe to the same standards. Accordingly, TransUnion has set out, in this policy, obligations that need to be adhered to when an entity processes (including but not limited to the receipt and usage of), personal data from or supplies personal data to TransUnion.

NOTE: This policy may be updated from time to time to reflect any amendments made to applicable Laws or association/industry policy directives and guidelines.

1. Purpose of policy

To outline obligations for protecting the integrity and confidentiality of information transmitted to and from TransUnion’s systems as required by applicable laws and guidelines relevant to the information services and risk services industry.

2. Application of policy

  • This policy is applicable to all entities who (a) procure and/or use and/or process Personal Data from TransUnion (whether directly OR through an authorised TransUnion channel partner/reseller), and who (b) supply information to TransUnion (whether directly OR through an authorised TransUnion channel partner/reseller) – such parties referred to hereafter as an “Applicable Party.
  • The terms of this policy shall be deemed to form part of the Applicable Party’s contract with TransUnion or with a TransUnion channel partner/TransUnion reseller (as the case may be) as if specifically incorporated therein. A breach of any obligation by the Applicable Party herein (and a contravention of the CRB Regulations and/or the Data Protection Act) shall therefore be regarded as a breach of the contract concluded with TransUnion or the channel partner/reseller, and shall be managed as such. Therefore, this policy shall continue to be of force and in effect for as long as either Party remains in possession of any Personal Data of the Data Subjects, regardless of the termination of any agreement or contract with TransUnion.
  • In the event of a conflict between the provisions of this policy and any other agreement between TransUnion and the Applicable Party; and, any applicable agreement in place between an authorised TransUnion channel partner/reseller and the Applicable Party, the provisions of this policy will take precedence in regard to all aspects pertaining to any processing of Personal Data.

3. Definitions

For purposes of this policy, capitalised terms shall have the meanings ascribed to them below:

  • CRB Regulations” means the Banking Act, Credit Reference Bureau Regulations, 2020 as amended from time to time
  • Data Controller” shall have the meaning ascribed thereto in Data Protection Act, and for purposes of this policy shall mean either Party as the context may require
  • Data Processor” has the meaning set out in the Data Protection Act, and for purposes of this policy means the Party who Processes Personal Data on behalf of the other Party or any authorised subcontractor of either of the Parties
  • Data Protection Act ” means the Data Protection Act No. 24 of 2019 together with the Regulations as amended from time to time
  • Data Subject” means any identified or identifiable natural person who is the subject of personal data — as contemplated in the Data Protection Act
  • Laws” means all laws, regulations, by-laws, rules, directives, guidelines, circulars, orders and other requirements of any government or any government agency, body or authority, including any regulator or court
  • Party” or “Parties” means either the Applicable Party or TransUnion or both, as the context may require
  • Payment Profile Information” means the payment history and financial information relating to a debt or credit transaction, including relevant payment dates, both negative and positive information and/or signs depicting action taken in respect of such debt or credit transaction
  • Personal Data” shall have the meaning set out in section 2 of the Data Protection Act, and includes sensitive personal Data as defined in the Data Protection Act and relates to the Personal Data of which either Party is the Data Controller in relation to which TransUnion renders the services to the Applicable Party
  • Processing” or “Process” shall have the meaning set out in the Data Protection Act
  • TransUnion” means Credit Reference Bureau Africa Limited, registration number C.82122; a private company with limited liability registered in accordance with the Companies Act, 2015

4. Compliance with laws and associated bodies

In its dealings with TransUnion and usage of TransUnion’s service offerings, the Applicable Party shall at all times comply with the requirements for the receipt, compilation and reporting of information as prescribed by the CRB Regulations and other applicable Laws and associated bodies.

5. Information security

  • The Applicable Party shall ensure all persons accessing TransUnion’s services on its behalf have been duly authorised by the Applicable Party to do so. In addition, the Applicable Party shall ensure only it or its authorised representatives have access to any PIN and/or password PIN issued for the purposes of requesting TransUnion services. The Applicable Party shall be liable for transactions, fees and other costs arising out of the use by any person of TransUnion’s services via the PIN and/or Password —whether or not such use is or has been authorised by the Applicable Party.
  • The Applicable Party shall immediately notify TransUnion in writing of any breach or attempted breach of security of which the Applicable Party may become aware or ought to have become aware of, and the Applicable Party shall take reasonable steps to prevent a recurrence thereof and mitigate the effects of such breach. TransUnion shall be entitled to fully investigate such breach or attempted breach, and the Applicable Party shall give TransUnion its full cooperation with such investigation. Furthermore, the Applicable Party shall be liable for transactions, fees and other costs arising out of the use by any person of the TransUnion services, including use of such services arising from a security breach in accordance with applicable Laws.
  • The Applicable Party shall install, implement and maintain the necessary software and IT security systems to ensure no destructive elements are introduced into TransUnion’s systems. Destructive Elements means code that:
    • is intentionally designed to disrupt, disable, harm or otherwise impede in any manner, including aesthetic disruptions or distortions; the operation of TransUnion’s software, hardware, computer systems or networks; or any other associate hardware, software, firmware, computer system or network used in relation to TransUnion’s services; or
    • would disable TransUnion’s software, hardware, computer systems or network, or impair in any way their operation based on the elapsing of a period of time, exceeding the authorised number of copies, advancement to particular date or numeral; or
    • would permit an unauthorised person to access TransUnion’s software, hardware, computer systems or network of and/or of third parties to cause a disruption, disablement, harm or impairment, or which contains any other similar harmful, malicious or hidden procedures, routines or mechanisms which would cause such programs to cease functioning; or that can cause damage to data, storage media, programs, equipment or communications, or otherwise interfere with the operations thereof.

6. Consents

  • The Applicable Party:
    • shall ensure prior to submitting to and/or requesting any information from TransUnion (whether directly or via a TransUnion channel partner or TransUnion reseller) it shall have validly obtained all consents (whether from natural or juristic persons – as applicable) that may be required in terms of the CRB Regulations and the Data Protection Act, or any other applicable Laws to submit, request and/or receive such information;
    • shall obtain upfront, written, express, ongoing and lawfully valid consent in respect of any requests for TransUnion to provide monitoring and account management services; and
    • shall retain and store all consents obtained, and be able to make same available to TransUnion without delay if ever requested.

7. Submission of data to TransUnion

  • The Applicable Party shall ensure any information requested from or submitted to TransUnion (whether directly or indirectly):
    • shall contain, in relation to a natural person, the minimum criteria as set out in Regulation 18 of the CRB Regulations; and
    • shall contain, in relation to a juristic person, the juristic person’s registered and trading name, registration number, registered address, physical and postal address.
  • When submitting any information to TransUnion (whether directly or indirectly), the Applicable Party shall:
    • be lawfully entitled to submit such information to TransUnion;
    • ensure all information reported to TransUnion is accurate, up-to-date, relevant, complete, valid and not duplicated;
    • submit only information as required in the Credit Reference Bureau Regulations; and
    • before submitting adverse credit information, (a) ensure such default is as defined in the Banking Act, the Micro Finance Act and the Sacco Societies Act or any other applicable law; and give its customers the requisite notices, as required by Regulation 63 of the CRB Regulations, of its intention to submit adverse information regarding the customer before such information is submitted to TransUnion. Also ensure the customer is informed of the submission of such adverse information after the same has been submitted to TransUnion as required by the aforementioned Regulations.
  • The Applicable Party shall under no circumstances submit the following information to TransUnion:
    • Negative information in respect of a debt where amount related does not exceed Kenya Shillings One Thousand as prescribed by the CRB Regulations.
    • Duplicate listings or inaccurate information where the party is aware of such inaccuracy.
    • Disputed adverse credit information – that is a default listing relating to an outstanding amount that had been disputed by a person prior to the date of the submission of the disputed adverse information (i.e., where such dispute had not been resolved at the time of listing). For purposes of this obligation, “disputed” refers to any instance where it can be proven a person had communicated to the Applicable Party an uncertainty around being liable for the whole or part of the relevant debt, whether or not through the institution of legal proceedings.
    • Information which the Applicable Party had already submitted to TransUnion in respect of a person, which information the person had successfully disputed in accordance with the dispute process provided for in the CRB Regulations. For purposes of clarity, the Applicable Party shall not be entitled to modify the successfully disputed information in any way so as to resubmit same.
  • The Applicable Party will fully and timeously cooperate with TransUnion’s requests for credible evidence related to an adverse credit listing when that listing has been disputed as part of any customer Dispute Resolution Mechanism process (including but not limited to Data Subject access requests, queries or challenges as contemplated in the CRB Regulations, Data Protection Act or any other applicable Laws) provided for in the CRB Regulations. Should an Applicable Party fail to respond to TransUnion within the legislated period set out in the CRB Regulations, the adverse listing in dispute will be permanently removed from the relevant person’s credit profile.

8. Use of information

  • All information received as part of services provided by TransUnion shall:
    • be used by the Applicable Party solely and exclusively for a purpose permitted in terms of the CRB Regulations or the Data Protection Act. The Applicable Party shall not (whether directly or indirectly) sell or use any such information for any commercial purpose; and
    • be for the Applicable Party's exclusive, one-time use, which usage shall be strictly related to the lawful purpose for which the service is intended.
  • The Applicable Party shall only access a person’s information for the purposes of assessing an employment application where that person has (a) consented to such access; AND (b) is being considered for a position that requires honesty in dealing with cash or finances, and where the job description of such position has been clearly outlined in the applicable contract of employment.
  • The Applicable Party acknowledges the information supplied to it pursuant to a testing request will contain information that’s regulated by Laws. This test data shall be used by the Applicable Party solely and exclusively for the purpose of the test and the Applicable Party shall not share the test data with or distribute that data to any third party. The Applicable Party shall not (whether directly or indirectly) use the test data for internal business or operational purposes or sell/use the test data for any purpose whatsoever. The Applicable Party shall destroy the test data, and upon completion of the testing exercise shall provide TransUnion with written confirmation of the destruction. The Applicable Party shall furthermore be able to evidence the destruction to TransUnion should TransUnion request such evidence.

9. The parties obligation concerning protection of personal data:

  • It is recorded that, pursuant to the obligations under this policy, either Party will Process Personal Data of Data Subjects in connection with and for the purposes of the provision of TransUnion’s services and will act as the other Party’s Data Processor.
  • Unless required by Law, each Party shall Process the Personal Data only:
    • in compliance with this policy;
    • for the purposes connected with the provision of the Services as provided for in any agreement or contract with TransUnion or as specifically otherwise instructed or authorised by the other Party in writing;
    • to the extent permissible in terms of applicable Laws; and
    • The Parties shall treat Personal Data that comes to their knowledge or into their possession as confidential, and shall not disclose it without the prior written consent of the other Party, unless permissible by law.
  • Without limiting either Party’s obligations under this policy, each Party shall comply with applicable industry or professional rules, regulations and Laws (including any applicable technical or organizational security measures) in regard to the safeguarding of Personal Data.
  • Each Party shall:
    • take steps to keep abreast and ensure it and its Staff comply fully with all applicable laws and regulations applicable to the Services;
    • limit the Processing of and access to the Personal Data to those Staff who need to know the Personal Data to enable the rendering of the Services;
    • deal promptly, but at all times without exceeding 5 (five) business days, with all reasonable inquiries from the other Party relating to its Processing of the Personal Data;
    • immediately inform the other Party of its inability to comply with the other Party’s instructions and this clause 9, in which case the other Party is entitled to suspend the other’s Processing of Personal Data and/or terminate any agreement or contract with TransUnion; and
    • provide the other with full cooperation and assistance in relation to any requests for access to, correction of or complaints made by the Data Subjects relating to their Personal Data.
  • Each Party (the “Notifying Party”) shall notify the other Party in writing:
    • within 1 (one) business day, or otherwise as soon as reasonably possible, if any Personal Data under the control of the Notifying Party as a result of any agreement or contract between Parties has been or may reasonably believe to have been accessed or acquired by an unauthorised person; or if a breach has occurred with reference to the Notifying Party’s use of the Personal Data under this policy, furnish the other Party with details of the Data Subjects affected by the compromise and the nature and extent of the compromise, including details of the identity of the unauthorised person who may have accessed or acquired the Personal Data, as well as daily reports on progress made at resolving the compromise;
    • of any request by a Data Subject for correction of the Personal Data, or complaints received by the Notifying Party, relating to any Personal Data submitted by the other Party in relation to that Data Subject’s obligations in terms of the CRB Regulations, and provide the other Party with full details of such request or complaint; and
    • to the extent lawfully permissible, promptly advise of any legally binding request for disclosure of Personal Data or any other notice or communication that relates to the Processing of the Personal Data from any supervisory or governmental body.
    • Each Party acknowledges and agrees the other Party retains all right, title and interest in and to the Personal Data.

10. Audit rights

  • TransUnion shall have the right to audit the Applicable Party’s Processing facilities in respect of the services upon separate and specific written policy regarding such audit first being reached with the other Party on each occasion at least once per year — or if there’s a reasonable suspicion the Applicable Party is not complying with the provisions of this policy, or where there’s suspicion the confidentiality, integrity and accessibility of Personal Data is likely to be compromised. The Party being audited shall offer reasonable assistance and cooperation to the other Party and/or its auditors or inspectors in the carrying out of such auditing exercise. Nothing in this clause 10 should be read as providing either Party with unlimited access to audit the other Party without just cause. If an audit takes place, TransUnion shall have no right of access to any confidential information of the Applicable Party’s clients or any confidential information in general (including Personal Data TransUnion is not responsible for in terms of CRB Regulations or the Data Protection Act).

11. Return and retention of Personal Data

  • Each Party (“requesting Party”) may, at any time on written request to the other Party, require, where it is practically and lawfully possible, that (a) the other Party immediately return to it any Personal Data and may, in addition, require that the other Party furnish a written statement to the effect that upon such return, it has not retained in its possession or under its control (whether directly or indirectly) any such Personal Data or material; or (b) as and when required by the requesting party on written request, destroy all such Personal Data and material and furnish TransUnion with a certificate of destruction to the effect the same has been destroyed. Where, by the nature of the services that the other Party provides to different clients, the return of information or destruction thereof is not possible, the Party shall provide the requesting Party with written reasons as to why this is the case, and seek to reach written policy with the requesting Party as to how to regulate the relevant Personal Data going forward.
  • Each Party shall comply with any request in terms of this clause 11 within 7 (seven) days of receipt of such request.


  • Subject to the provisions contained in the Any agreement or contract with TransUnion, each Party hereby indemnifies and holds the other Party harmless from any and all losses arising from any claim or action brought against the other Party arising from or due to the one’s Party’s breach of its obligations set out in this policy or any law with respect to the protection of Personal Data.


  • The Parties agree and undertake:
    • Except as permitted by this policy, not to disclose or publish any Confidential Information (which for purposes of this clause shall mean any information or data (a) which by its nature or content is identifiable as confidential and/or proprietary to either Party and/or any third party; or (b) which is provided or disclosed in confidence by the one Party (“Disclosing Party”) to the other Party (“Receiving Party”); and (c) which Disclosing Party or any person acting on its behalf may disclose or provide to Receiving Party, or which may come to the knowledge of Receiving Party by whatsoever means) in any manner for any reason or purpose whatsoever without the prior written consent of the other Party, and provided that in the event of the Confidential Information being proprietary to a third party, it shall also be incumbent on the Parties to obtain the consent of such third party.
    • Except as permitted by this policy, not to utilise, employ, exploit or in any other manner whatsoever use the Confidential Information for any purpose whatsoever without the prior written consent of the other Party, and provided that in the event of the Confidential Information being proprietary to a third party, it shall also be incumbent on the Applicable Party to obtain the consent of such third party.
    • To restrict the dissemination of the Confidential Information to only those of each Party’s staff who are actively involved in activities for which use of Confidential Information is authorized (and then only on a “need to know” basis) and each Party shall initiate, maintain and monitor internal security procedures reasonably acceptable to the other to prevent unauthorised disclosure by its staff.
    • To take all practical steps, both before and after disclosure, to impress upon its staff who are given access to Confidential Information the secret and confidential nature thereof.
  • The obligations of each Party with respect to each item of Confidential Information shall endure for an indefinite period from receipt of that item of Confidential Information. The obligations referred to in this clause 13 shall endure notwithstanding any termination of this policy, any other policy entered into between the Parties or any discussions between the Parties.
  • Each Party hereby indemnifies and holds the harmless from any and all losses arising from, or in connection with, any claim or action arising from the other Party’s breach of any obligation with respect to Confidential Information.

14.Breach and termination

  • In the event either Parties commits a breach of any of the conditions of this policy, and failing to remedy such breach within 7 (seven) Business Days of receipt of a notice from the other Party requesting it to remedy such breach, the other Party shall be entitled to cancel this entire policy forthwith and claim such losses as it may have suffered. In the event of termination of this policy, the Party terminating this policy shall have a right to also exercise its rights of termination under any agreement or contract with TransUnion.
  • Notwithstanding anything to the contrary contained in this policy, the Parties shall be entitled to terminate this policy by mutual policy in writing.
  • The provisions of this clause 14 shall not affect or prejudice any other rights/remedies which the Parties may have in law or in any other written agreement or contract between the Parties.

15.Payment profile information

  • Payment Profile Information may be requested by an Applicable Party who is a Subscriber or entitled to such information in terms of the CRB Regulations.
  • Where supplying Payment Profile Information, the Applicable Party shall ensure compliance with CRB Regulations as may be amended from time to time.

16.Removal of adverse listings

  • To the extent required by the CRB Regulations, adverse credit information must be removed from a person’s credit profile if that person has paid up the debt associated with that listing. The Applicable Party shall provide TransUnion with details regarding settlement of any obligations under a credit agreement as required by the CRB Regulations.
  • To the extent required by the CRB Regulations, judgments must be removed from a person’s credit profile if that person has settled the capital amount of the judgment. The Applicable Party shall upon settlement by the person of the capital amount of a judgment advise TransUnion within seven days of settlement of such obligation.
  • An Applicable Party shall only be entitled to remove a default listing if it is factually incorrect, related to fraud or a duplicate listing.
  • The Applicable Party shall not, unless lawfully entitled to do so, take an upfront fee in order to remove adverse credit information from a person’s credit profile.

17.Information requested in respect of juristic persons and their principals.

  • The Applicable Party acknowledges to the event that it requests information in relation to any juristic person/s, the relevant report to be provided to it may contain information relating to that juristic person’s directors, senior leadership and/or key stakeholders in the business (“Principals”). The Applicable Party shall be (a) fully authorised, as required by all applicable Laws, to obtain the information in respect of the Principals; and (b) in the event it requests information relating to both juristic persons and their Principals, be fully compliant with the requirements as set out in the CRB Regulations. It shall furthermore have obtained all required consents for obtaining and having sight of information regarding the Principals.

18.Consequences of termination

  • The termination of this policy shall not affect the rights of either of the Parties that accrued before termination of this policy or which specifically survives the termination of the policy.
  • Upon termination of this policy and upon request by either Party, the other Party shall return or destroy any material containing, pertaining or relating to the Personal Data disclosed pursuant to this policy to the requesting Party. Such request will be regulated in accordance with clause 18 and/applicable Laws pertaining to the Processing of Personal Data.


  • Failure or delay by either Party in exercising any right will not constitute a waiver of that right.
  • No waiver of any of right under this policy will be binding unless it is in writing and signed by the Party waiving the right.


If any part of this policy is found to be invalid or unenforceable, it shall be severed from the remainder of this policy, which shall remain valid and enforceable.