Demonstrating our commitment to data protection, regulatory compliance, and industry best practices across East Africa
At Virtual Support Services, we recognize that trust is the foundation of every client relationship. We are committed to maintaining the highest standards of data protection, regulatory compliance, and information security. Our compliance programme is built on the Kenya Data Protection Act, 2019 and aligned with international best practices.
As a registered Data Controller and Data Processor with the Office of the Data Protection Commissioner (ODPC), and as an ICTA-accredited Government ICT supplier, we demonstrate our ongoing commitment to protecting personal data and upholding the rights of data subjects.
Virtual Support Services Limited has demonstrated compliance with the Government IT Governance Standard, Criteria for accreditation of Government ICT Suppliers/Contractors and has been accredited under Category ICTA 4: CLOUD COMPUTING for the provision of ICT services.
Virtual Support Services Limited has demonstrated compliance with the Government IT Governance Standard, Criteria for accreditation of Government ICT Suppliers/Contractors and has been accredited under Category ICTA 4: SYSTEMS AND APPLICATIONS for the provision of ICT services.
The Data Protection Act, No. 24 of 2019, gives effect to Article 31(c) and (d) of the Constitution of Kenya. It establishes the Office of the Data Protection Commissioner and provides for the regulation of the processing of personal data, the rights of data subjects, and obligations of data controllers and processors. VSS is fully compliant with this Act.
Personal data is processed lawfully, fairly and in a transparent manner in relation to the data subject.
Personal data is collected and processed for specified, explicit and legitimate purposes only.
Personal data collected is limited to what is necessary for the specified, explicit and legitimate purposes.
Personal data is accurate and, where necessary, kept up to date with every reasonable step taken to ensure accuracy.
Personal data is stored for no longer than is necessary for the specified, explicit and legitimate purposes.
VSS takes responsibility for personal data and ensures individuals can exercise their rights while providing clear information on data processing.
Personal data is secured and protected against unauthorized or unlawful processing and against accidental loss, destruction or damage.
Under the Kenya Data Protection Act, 2019 (Section 26), data subjects have the following rights which VSS fully upholds and facilitates:
Data subjects have the right to access their personal data held by VSS and obtain information about how it is processed.
Data subjects can request correction of inaccurate or incomplete personal data.
Data subjects can request deletion of their personal data where there is no compelling reason for continued processing.
Data subjects can request a copy of their personal data in a structured, commonly used format.
Data subjects can object to the processing of their personal data in certain circumstances.
Data subjects can request limitation on the processing of their personal data.
Data subjects have the right not to be subject to decisions based solely on automated processing, including profiling.
Full compliance with Kenya's data protection legislation giving effect to Article 31(c) and (d) of the Constitution of Kenya.
Registered with the Office of the Data Protection Commissioner as both a Data Controller and Data Processor.
Accredited by ICTA for Cloud Computing and Systems & Applications under the Government ICT Suppliers/Contractors criteria.
Adherence to Microsoft's data protection standards and partner compliance requirements.
Information security management practices aligned with international standards.
For applicable international clients, we maintain awareness of and alignment with GDPR requirements.
In accordance with Section 43 of the Data Protection Act, 2019, VSS has established comprehensive data breach notification procedures:
Immediate assessment of any breach or suspected breach to determine scope, severity, and impact on data subjects.
Notification to the Data Commissioner within 72 hours of becoming aware of a personal data breach, as required by law.
Communication to affected data subjects without unreasonable delay, including the nature of the breach and recommended protective measures.
The ODPC is an Independent State Office under the Ministry of Information, Communications and the Digital Economy. It is responsible for ensuring compliance with data protection laws in Kenya.
If you believe your personal data has been mishandled or your data protection rights have been violated, you have the right to lodge a complaint with the ODPC:
Visit the ODPC websiteOur Data Protection Officer is available to address any questions about our compliance practices, data protection measures, or to help you exercise your data subject rights.