Kenya Privacy Centre

Data Processing Policy

Introduction

 

TransUnion is a Credit Reference Bureau licensed by the Central Bank of Kenya in accordance with the provisions of the Banking Act (Credit Reference Bureau Regulations, 2020; Registration Number C.82122). Its operations are regulated by the CRB Regulations and other applicable Laws, including the Data Protection Act No. 24 of 2019.

TransUnion is committed to protecting the integrity, confidentiality and security of all Personal Data  processed in the course of its operations and is sensitive to privacy considerations.

TransUnion implements appropriate technical and organisational measures to safeguard personal data and ensure that such data is processed lawfully, fairly, and transparently.

Where applicable, TransUnion aligns its practices with recognised industry standards and requires all entities interacting with TransUnion to maintain equivalent levels of data protection when processing personal data.

This notice covers the following topics:

  1. Purpose
  2. Scope and Application
  3. Definitions
  4. Compliance with Laws
  5. Information Security
  6. Lawful Basis and Consent
  7. Submission and Quality of Information
  8. Use of Information
  9. Protection of Personal Data
  10. Data Breach Notification
  11. Retention and Disposal
  12. Confidentiality
  13. Credit Information and Payment Profiles
  14. Removal of Adverse Credit Information
  15. Contact and Queries
  16. Policy Updates

 

1.  Purpose

 

This Policy sets out the requirements and standards for the lawful processing, protection, and secure handling of personal data collected, shared with, or processed by TransUnion in the course of its operations.

 

2.  Scope and Application

 

1.    This policy applies to:

a.    TransUnion, including its employees, contractors, and internal operations that handle personal data; and 

b.    all external organisations that access, use, process, or provide personal data to or from TransUnion (whether directly or through an authorised TransUnion partner or reseller) (“Applicable Parties”).

2.    This policy sets out the minimum standards for how personal data must be handled and protected. For external parties, this policy forms part of the terms under which they work with TransUnion and must be read together with any agreement in place. 

3.    If an Applicable Party does not comply with this policy, this may be treated as a breach of their agreement with TransUnion and may be dealt with in terms of that agreement and applicable law.

4.    This Policy continues to apply for as long as TransUnion or any Applicable Party holds or uses personal data, even if the commercial relationship has ended.

5.     If there is any conflict between this policy and another agreement between TransUnion and an Applicable Party, this Policy will apply to matters relating to how personal data is handled, unless the law requires otherwise.

 

3.  Definitions

 

Key terms used in this policy include:

  1. “CRB Regulations” means the Banking Act, Credit Reference Bureau Regulations, 2020 as amended from time to time
  2. “Data Controller” means the party that decides why and how your personal data is used. Depending on the situation, this could be TransUnion or another party.
  3. “Data Processor” means a party that processes personal data on behalf of a Data Controller, following their instructions. This may include authorised service providers.
  4. “Data Protection Act” means the Data Protection Act, No. 24 of 2019, and any updates or regulations issued under it.
  5. “Data Subject” means an individual whose personal data is being collected or used.
  6. “Laws” means all applicable laws, regulations, and requirements issued by government authorities or regulators.
  7. “Party” or “Parties” means either TransUnion or another organisation working with TransUnion, or both.
  8. “Payment Profile Information” means information about how a person pays their debts, including payment history, missed payments, and other related financial behaviour.
  9. “Personal Data” means any information that can identify a person, either directly or indirectly. This includes sensitive personal data as defined under the Data Protection Act.
  10. “Processing” means any action taken with personal data, such as collecting, storing, using, sharing, or deleting it.
  11. “TransUnion” means Credit Reference Bureau Africa Limited, a company registered in Kenya and licensed by the Central Bank of Kenya.

 

4.  Compliance with Laws

 

When processing personal data or using TransUnion’s services, TransUnion and all Applicable Parties must comply with all relevant legal and regulatory requirements. This includes the Data Protection Act, 2019, the Banking Act, the Credit Reference Bureau Regulations, 2020, and any other applicable laws, regulations, or industry standards.

 

5.  Information Security

 

TransUnion is committed to protecting personal data and has implemented appropriate technical and organisational measures to safeguard it against unauthorised access, loss, misuse, or damage.

These measures include restricting access to authorised individuals and securing systems against potential risks. Where third parties process personal data on our behalf, they are required to apply appropriate security standards.

If a security incident occurs, TransUnion will take reasonable steps to investigate, contain, and address the issue in line with applicable legal requirements.

 

6.  Lawful Basis and Consent

 

TransUnion processes personal data in a lawful, fair, and transparent manner.

Where required, we ensure that appropriate consent is obtained before processing takes place and that such consent can be demonstrated. For ongoing services, we take steps to ensure that consent remains valid and up to date.

We may also process personal data where permitted by law, including where it is necessary for contractual obligations, legal requirements, or legitimate business purposes.

 

7.  Submission and Quality of Information

 

1.    TransUnion and all parties processing Personal Data must ensure that any information collected, used, or submitted is:

  • Accurate, complete, and up to date 
  • Not duplicated or misleading 
  • Processed lawfully and with proper authorisation 
  • Limited to categories of information permitted by applicable law

2.    Where information is submitted to TransUnion or used for credit reporting purposes, additional requirements apply:

  • Only information permitted under applicable laws and regulations may be submitted;
  • Data must meet required minimum standards and reporting criteria
  • All submissions must comply with applicable legal and regulatory requirements 

3.    The following types of information must not be submitted to TransUnion:

  • Prescribed debt
  • Duplicate or erroneous listings
  • Unresolved disputed information
  • Restricted categories as defined by law
  • Information that has previously been successfully challenged and removed 

All parties must take reasonable steps to ensure data accuracy and must cooperate in resolving disputes and correcting any inaccurate information.

 

8.  Use of Information

 

Personal data must be used responsibly and only for lawful purposes, such as:

Personal data must:

  • Be used only for the purpose for which it was collected;
  • Not be used in a way that is incompatible with that purpose; and
  • Not be shared with third parties for unauthorised purposes.

In limited cases, credit information may be used for employment-related checks, where:

  • The individual has provided consent; and
  • The role requires a position of trust (for example, handling finances).

TransUnion takes steps to ensure that Personal Data is handled in a fair and responsible manner at all times.

 

9.  Protection of Personal Data

 

TransUnion takes appropriate steps to ensure personal data is processed securely and responsibly.

Access to personal data is limited to individuals who need it to perform their duties, and safeguards are in place to prevent unauthorised access, loss, or misuse.

Where third parties process personal data on our behalf, they are required to meet appropriate data protection standards.

We also support individuals in exercising their rights under applicable laws, including the right to access and correct their personal data.

 

10.  Data Breach Notification

 

TransUnion takes the protection of Personal Data seriously and has measures in place to identify, manage, and respond to any security incidents that may affect such information.

If a security incident occurs, TransUnion will take appropriate steps to investigate the incident, contain it, and minimise any potential impact on affected individuals. This may include securing systems, reviewing what information was affected, and taking steps to prevent a recurrence.

Where required by law, we will notify affected individuals and the relevant regulator (including the Office of the Data Protection Commissioner).

TransUnion remains committed to handling any such incidents responsibly and transparently, and to supporting affected individuals where appropriate.

 

11.  Retention and Disposal

 

TransUnion retains Personal Data only for as long as necessary to fulfil the purpose for which it was collected, or as required by applicable laws and regulatory obligations.

Once Personal Data is no longer required, TransUnion takes appropriate steps to ensure that it is securely deleted, destroyed, or de-identified in a manner that protects privacy and prevents unauthorised access.

 

12.  Confidentiality

 

TransUnion treats Personal Data as confidential and takes appropriate steps to protect it from unauthorised access, disclosure, or misuse. 

Access to Personal Data is limited to authorised individuals who require it to perform their roles. 

TransUnion remains committed to maintaining the confidentiality of Personal Data, even after its relationship with an individual or organisation has ended, where required by law.

 

13.  Credit Information and Payment Profiles

 

Payment Profile Information relates to an individual’s payment behaviour and credit activity.

TransUnion processes and shares this information in accordance with applicable laws and regulatory requirements. Access is restricted to authorised entities for lawful purposes such as credit assessments and risk management.

All sharing of such information is subject to safeguards to ensure accuracy, fairness, and responsible use.

 

14.  Removal of Adverse Credit Information

 

TransUnion processes adverse credit information in accordance with the Banking Act, the Credit Reference Bureau Regulations, 2020, and other applicable legal and regulatory requirements.

Adverse credit information relating to a credit facility may be updated, retained, or removed from a person’s credit profile in accordance with applicable laws and regulatory guidelines, including where the underlying obligation has been settled or the information is no longer required to be retained.

Judgments and other credit-related information are reflected and updated in line with information received from authorised sources and applicable legal requirements.

Adverse listings will only be amended or removed where permitted by law, including where the information is found to be inaccurate, incomplete, fraudulent, duplicated, or subject to a valid dispute.

TransUnion does not permit the unlawful or unauthorised removal of adverse credit information and does not support the charging of upfront fees for the removal of such information, except where permitted under applicable law.

 

15.  Contact and Queries

 

If you have any questions about this policy or how your Personal Data is processed, you may contact TransUnion using the following details:

  • Location: 2nd Floor Delta Corner Annex Ring Road, Westlands,Kenya
  • Postal Address:  P. O. Box 46406 – 00100 Nairobi
  • Telephone:  +254 (020) 7603717
  • Email: DPO_KE@transunion.com

 

16.  Policy Updates

 

This policy may be updated from time to time to reflect changes in applicable laws, regulations, or industry practices. 

TransUnion will take reasonable steps to inform relevant stakeholders of any material changes to this policy. The latest version of this policy will always reflect the most recent effective date.

Effective date: 1 June 2026