Privacy policy
LATEST ELECTRONICS STORE
Privacy Policy
Effective Date: 22 June 2026 | Last Updated: 22 June 2026
This Privacy Policy is issued in compliance with the Data Protection Act, No. 24 of 2019 (Kenya) and the Data Protection (General) Regulations, 2021, giving effect to Article 31(c) and (d) of the Constitution of Kenya, 2010.
1. Introduction and Identity of the Data Controller
Latest Electronics Store ("we," "us," or "our") is a data controller registered with the Office of the Data Protection Commissioner (ODPC) as required under Section 18 of the Data Protection Act, No. 24 of 2019 ("the Act"). Our ODPC Registration Number is: [INSERT ODPC REG. NO.].
This Privacy Policy describes how we collect, use, store, share, and protect your personal data when you interact with our website, mobile application, or physical stores in Kenya. It also sets out your rights as a data subject under Kenyan law.
By using our services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree, please refrain from using our services.
2. Lawful Basis for Processing (Section 30, DPA 2019)
We process your personal data only where we have a lawful basis to do so. The lawful bases we rely on are:
• Consent — where you have freely given, specific, informed, and unambiguous consent for a defined purpose (e.g., marketing communications). You may withdraw consent at any time without detriment.
• Contractual Necessity — where processing is necessary to perform a contract with you, such as processing your purchase order or managing your account.
• Legal Obligation — where we are required to process your data to comply with a legal or regulatory obligation applicable in Kenya.
• Legitimate Interests — where processing is necessary for our legitimate business interests (e.g., fraud prevention, IT security), provided such interests do not override your fundamental rights and freedoms.
• Vital Interests — where processing is necessary to protect your vital interests or those of another person.
For sensitive personal data (as defined under Section 2 of the Act — including data relating to health, biometric data, race, ethnic origin, religious beliefs, genetic data, property details, marital status, family details, sex life, or criminal history), we will rely on explicit consent or another permitted ground under the Act.
3. Personal Data We Collect
3.1 Data You Provide Directly
• Identity data: full name, national ID or passport number (where required for warranty or compliance)
• Contact data: email address, phone number, physical and/or postal address
• Account data: username, password, account preferences
• Transaction data: purchase history, billing and delivery address, payment details
• Communication data: customer service queries, feedback, reviews
• Marketing preferences: consent records for promotional communications
3.2 Data Collected Automatically
• Technical data: IP address, browser type, operating system, device identifiers
• Usage data: pages visited, time spent on site, links clicked, search queries
• Location data: general geographic location derived from IP address (precise location only with your explicit consent)
• Cookie data: see Section 6 below
3.3 Data from Third Parties
We may receive personal data about you from third parties such as payment processors, logistics partners, credit-reference bureaus (for fraud prevention only), and social media platforms (where you choose to link your account). We will inform you of such receipt and ensure any third-party sharing complies with the Act.
4. Purposes of Processing
We process your personal data only for the explicit, specified, and legitimate purposes set out below, in accordance with Section 25(c) of the Act. We will not process your data in a manner incompatible with these stated purposes:
• Processing and fulfilling your purchase orders and delivering goods
• Managing your account and providing after-sales and customer support
• Sending transactional communications (order confirmations, receipts, shipping updates)
• Sending marketing and promotional content — only with your prior consent, and you may opt out at any time
• Personalising your shopping experience and recommending relevant products
• Conducting analytics and improving our products, services, and website
• Detecting, preventing, and investigating fraud, theft, or other unlawful activity
• Complying with our legal and regulatory obligations under Kenyan law
• Operating warranty, loyalty, and rewards programmes
• Conducting Data Protection Impact Assessments (DPIAs) as required
5. Data Minimisation and Accuracy
Consistent with Section 25(d) and (f) of the Act, we collect only the personal data that is adequate, relevant, and limited to what is necessary for the stated purposes. We take all reasonable steps to ensure that personal data we hold is accurate and, where necessary, kept up to date. You may request correction of inaccurate data at any time (see Section 9 below).
6. Cookies and Tracking Technologies
We use cookies, web beacons, and similar technologies to enhance your experience on our website and app. Cookies may be:
• Strictly necessary cookies — essential for the website to function; no consent required
• Functional cookies — remember your preferences and settings; activated with your consent
• Analytical cookies — help us understand how visitors use our site; activated with your consent
• Marketing cookies — used to deliver targeted advertising; activated with your explicit consent
On your first visit, you will be presented with a cookie consent banner. You may accept, reject, or manage your cookie preferences at any time through our Cookie Settings page. Withdrawing consent for non-essential cookies will not affect the lawfulness of prior processing.
7. Sharing of Personal Data
We do not sell your personal data. We may disclose your personal data to the following categories of recipients, each bound by contractual data protection obligations consistent with the Act:
7.1 Data Processors (Service Providers)
We engage third-party data processors to support our operations, including payment processors (e.g., M-Pesa, card payment gateways), logistics and courier companies, cloud hosting and IT service providers, email and SMS marketing platforms, and analytics providers. All processors are bound by written data processing agreements as required under Section 36(2) of the Act, and may only process data on our documented instructions.
7.2 Business Partners
With your consent, we may share data with electronics manufacturers, extended warranty providers, or authorised service centres to fulfil product-related services.
7.3 Legal and Regulatory Disclosure
We may disclose your personal data where required by law, court order, or lawful request from a competent Kenyan authority (e.g., the ODPC, Kenya Revenue Authority, or law enforcement), or where necessary to protect our legal rights or prevent fraud.
7.4 Business Transfers
In the event of a merger, acquisition, restructuring, or sale of business assets, your personal data may be transferred as part of that transaction. We will provide notice and, where required, seek your consent before such transfer.
8. Transfer of Personal Data Outside Kenya
Consistent with Section 25(h) and Section 48 of the Act, personal data will not be transferred outside Kenya unless:
• The destination country has been determined to have adequate data protection safeguards; or
• We have implemented appropriate safeguards (e.g., binding contractual clauses approved by the Data Commissioner); or
• You have given explicit informed consent to the transfer.
Where we transfer data outside Kenya, we will notify you and, where required, notify the ODPC. We maintain at least one serving copy of personal data on servers located within Kenya.
9. Your Rights as a Data Subject (Sections 26–32, DPA 2019)
Under the Act, you have the following rights with respect to your personal data:
• Right to be Informed — to receive clear, accessible information about how your data is being processed (this Privacy Policy fulfils that obligation).
• Right of Access (Section 26) — to request confirmation of whether we process your data and to obtain a copy of that data.
• Right to Rectification (Section 27) — to request correction of inaccurate or incomplete personal data without undue delay.
• Right to Erasure / Right to be Forgotten (Section 28) — to request deletion of your personal data where it is no longer necessary, or where you withdraw consent, or where processing is unlawful.
• Right to Restriction of Processing (Section 29) — to request that we limit processing of your data in certain circumstances.
• Right to Data Portability (Section 30) — to receive your personal data in a structured, commonly used, machine-readable format and to transmit it to another controller.
• Right to Object (Section 31) — to object to processing based on legitimate interests or for direct marketing purposes.
• Right not to be Subject to Automated Decision-Making — not to be subject to a decision based solely on automated processing, including profiling, that significantly affects you, unless you have given consent or it is necessary for a contract.
To exercise any of these rights, please submit a written request to our Data Protection Officer (see Section 13). We will respond within 30 days of receipt. We may ask you to verify your identity before processing your request. Requests are free of charge, but we reserve the right to charge a reasonable fee for manifestly unfounded or excessive requests.
If you are dissatisfied with our handling of your request, you have the right to lodge a complaint with the Office of the Data Protection Commissioner (ODPC) at:
Office of the Data Protection Commissioner (ODPC)
Britam Towers, 12th Floor, Hospital Road, Upper Hill, Nairobi, Kenya
Website: www.odpc.go.ke | Email: info@odpc.go.ke
10. Data Retention (Section 25(g), DPA 2019)
We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by Kenyan law (including tax and commercial record-keeping obligations). Our general retention periods are:
• Transaction and account records: 7 years from the date of transaction (as required by the Tax Procedures Act, 2015)
• Marketing consent records: until consent is withdrawn, plus 3 years
• Customer service records: 3 years from resolution of the matter
• Website analytics data: 13 months (rolling)
• Employee data: duration of employment plus 7 years
Upon expiry of the applicable retention period, personal data is securely deleted, anonymised, or destroyed, unless a legal obligation requires further retention.
11. Data Security (Sections 40–42, DPA 2019)
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, destruction, or alteration, as required under Sections 40–42 of the Act. Our security measures include:
• SSL/TLS encryption for all data transmissions
• Payment Card Industry Data Security Standard (PCI DSS) compliance
• Role-based access controls and multi-factor authentication
• Regular security audits, penetration testing, and vulnerability assessments
• Staff training on data protection and information security obligations
• Written data processing agreements with all data processors
• Physical security controls at our premises
Where we engage data processors, we require by written contract that they implement equivalent security measures and process data only on our documented instructions (Section 36, DPA 2019).
12. Personal Data Breaches (Section 43, DPA 2019)
In the event of a personal data breach that is likely to result in risk to the rights and freedoms of data subjects, we will:
• Notify the Office of the Data Protection Commissioner (ODPC) within 72 hours of becoming aware of the breach, as required under Section 43 of the Act. Where notification is delayed beyond 72 hours, we will provide the ODPC with reasons for the delay.
• Notify affected data subjects without undue delay where the breach is likely to result in a high risk to their rights and freedoms, providing clear information about the nature of the breach, likely consequences, and remedial measures taken.
• Maintain an internal breach register recording all incidents (including those that do not meet the notification threshold) as evidence of compliance.
If you suspect your personal data has been compromised, please contact our Data Protection Officer immediately (see Section 13).
13. Data Protection Officer (DPO)
We have appointed a Data Protection Officer (DPO) in accordance with the Act and the Data Protection (General) Regulations, 2021. The DPO is responsible for overseeing our compliance with the Act, advising on DPIAs, serving as a contact point for data subjects, and liaising with the ODPC.
DPO Name: [Insert DPO Name]
Email: dpo@latestelectronics.store
Phone: +254 700 000 000
Postal Address: P.O. Box [XXXXX], Nairobi, Kenya
The DPO's details have been registered with the ODPC as required.
14. Processing of Children’s Personal Data (Section 33, DPA 2019)
Our services are not directed to children under the age of 18. We do not knowingly collect or process the personal data of minors without verifiable parental or guardian consent, as required under Section 33 of the Act. If you believe we have inadvertently collected a child's data, please contact our DPO immediately and we will delete the information without undue delay.
15. Data Protection Impact Assessments (Section 31, DPA 2019)
Before undertaking any processing activity likely to result in high risk to the rights and freedoms of data subjects (including large-scale processing of sensitive data, systematic monitoring, or use of new technologies), we conduct a Data Protection Impact Assessment (DPIA) as required under Section 31 of the Act. Where the DPIA indicates high residual risk that cannot be adequately mitigated, we will consult the ODPC before processing commences, at least 60 days prior to commencement.
16. Third-Party Websites and Services
Our website and app may contain links to third-party websites, social media platforms, or manufacturer portals. We are not responsible for the privacy practices of those third parties. We encourage you to review their respective privacy policies before providing any personal data.
17. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, the law, or ODPC guidance. When we make material changes, we will notify you by posting the updated policy on our website, updating the effective date above, and — where appropriate — sending you a direct notification by email or SMS. Continued use of our services after the effective date of any revision constitutes your acceptance of the updated policy.
18. Governing Law and Jurisdiction
This Privacy Policy is governed by and construed in accordance with the laws of Kenya, including the Data Protection Act, No. 24 of 2019, the Data Protection (General) Regulations, 2021, and the Constitution of Kenya, 2010. Any disputes shall be subject to the jurisdiction of the courts of Kenya.
19. Contact Us
For any questions, concerns, or requests relating to this Privacy Policy or the exercise of your data subject rights, please contact:
You also have the right to lodge a complaint directly with the ODPC at www.odpc.go.ke if you are dissatisfied with how we handle your personal data.