Privacy Policy
We take your privacy seriously. This policy explains how we collect, use, and protect your personal information when you use the NextGen Platform.
Effective: April 1, 2026
DPA 2019 Compliant
Our Privacy Promise
1. Introduction
Last updated: March 15, 2026
NextGen ("we," "our," or "us") is a joint initiative of the United Nations Development Programme (UNDP) Kenya and the Kenya Private Sector Alliance (KEPSA). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the NextGen Platform.
1.1 Scope
This policy applies to all users of the NextGen Platform, including candidates, company representatives, and administrators. By using the Platform, you consent to the data practices described in this policy.
1.2 Data Controller
For the purposes of Kenya's Data Protection Act, 2019, the joint data controllers are:
- UNDP Kenya, UN Complex, Gigiri, Nairobi
- KEPSA, KEPSA Building, 5th Floor, Muthaiga, Nairobi
2. Data We Collect
We collect information to provide, improve, and secure the NextGen Platform. The types of data we collect depend on how you interact with us.
2.1 Information You Provide
When you create an account or apply to the programme, you may provide:
- Identity Data: Full name, national ID number, date of birth, gender
- Contact Data: Email address, phone number, county of residence, emergency contact details
- Educational Data: Institution name, degree, field of study, graduation year, GPA
- Professional Data: Work experience, skills, certifications
- Disability Information: If voluntarily disclosed, for accommodation purposes
- Documents: Academic transcripts, national ID copies, professional certifications
2.2 Information We Collect Automatically
When you use the Platform, we automatically collect:
- Usage Data: Pages visited, features used, time spent on Platform
- Device Data: IP address, browser type, operating system, device identifiers
- Log Data: Access times, error logs, performance metrics
2.3 Sensitive Personal Data
Certain information we collect may be considered "sensitive" under Kenyan law, including:
- National ID number
- Disability status and accommodation needs
- Biometric data (if ID verification is implemented)
We collect sensitive data only with your explicit consent and use it solely for the purposes disclosed.
3. How We Use Your Data
We use your personal data exclusively for purposes related to the NextGen Programme:
3.1 Automated Decision-Making
We use automated scoring algorithms to evaluate applications based on:
- Academic performance relative to institution and field
- Relevance and depth of skills and experience
- Application completeness and quality
You have the right to request human review of any automated decision. See Section 8 (Your Rights) for details.
4. Legal Basis for Processing
Under Kenya's Data Protection Act, 2019, we rely on the following legal bases for processing your personal data:
✓ Consent
You consent to processing when you create an account and submit your application. You may withdraw consent at any time (subject to contractual/legal restrictions).
✓ Contractual Necessity
Processing is necessary to evaluate your application and, if successful, facilitate your internship placement.
✓ Legal Obligation
We process certain data to comply with Kenyan law, including tax, employment, and anti-fraud regulations.
✓ Legitimate Interests
We process usage data to improve Platform security, prevent fraud, and enhance user experience, balanced against your privacy rights.
5. Data Sharing
We share your data only as necessary to operate the NextGen Programme. We never sell your personal data.
5.1 Programme Partners
Your data is shared with:
- UNDP Kenya: Programme administration, verification, oversight
- KEPSA: Employer coordination, matching, placement management
- Partner Companies: When your application is forwarded for placement consideration. Companies receive only information necessary for evaluation.
5.2 Service Providers
We engage trusted third-party service providers who assist with:
- Cloud hosting and data storage
- Email and notification delivery
- Document verification services
- Analytics and performance monitoring
All service providers are bound by strict data processing agreements and may not use your data for their own purposes.
5.3 Legal Disclosures
We may disclose your data if required by law, court order, or government regulation, or if we believe disclosure is necessary to protect the rights, property, or safety of NextGen, our users, or the public.
6. Data Security
We implement appropriate technical and organizational measures to protect your personal data.
6.1 Security Measures
6.2 Document Security
Uploaded documents receive additional protection:
- Virus scanning upon upload
- Access restricted to authorized verification personnel only
- Documents are never publicly accessible
- Secure, time-limited viewing URLs for verification
6.3 Your Responsibilities
You are responsible for maintaining the confidentiality of your account credentials. Notify us immediately if you suspect unauthorized access to your account.
7. Data Retention
We retain your personal data only as long as necessary to fulfill the purposes outlined in this policy, unless a longer retention period is required by law.
7.1 Retention Periods
Active Applications
Throughout application and placement process
Placed Interns
Programme duration plus follow-up period
Unsuccessful Applications
For programme analysis and improvement
Account Data
If inactive, after last login
7.2 Data Deletion
After the retention period expires, we securely delete or anonymize your personal data. You may also request earlier deletion (see Section 8).
8. Your Rights
Under Kenya's Data Protection Act, 2019, you have the following rights regarding your personal data:
Right to Access
Request a copy of the personal data we hold about you.
Right to Rectification
Correct inaccurate or incomplete data.
Right to Erasure
Request deletion of your data (subject to legal requirements).
Right to Restrict Processing
Limit how we use your data in certain circumstances.
Right to Data Portability
Receive your data in a structured, machine-readable format.
Right to Object
Object to processing based on legitimate interests.
8.1 How to Exercise Your Rights
To exercise any of these rights, contact our Data Protection Officer at dpo@nextgen.ke. We will respond within 30 days as required by law.
8.2 Right to Lodge a Complaint
If you believe your data protection rights have been violated, you have the right to lodge a complaint with the Office of the Data Protection Commissioner (ODPC) of Kenya:
ODPC Kenya, Britam Centre, 8th Floor, Hospital Road, Upper Hill, Nairobi
Email: info@odpc.go.ke | Website: www.odpc.go.ke
10. Children's Privacy
The NextGen Platform is intended for users aged 18 and above. We do not knowingly collect personal data from individuals under 18.
10.1 Age Verification
We verify age through national ID and date of birth information. Applications from individuals under 18 are automatically rejected.
10.2 Parental Rights
If you believe we have inadvertently collected data from a minor, please contact us immediately at privacy@nextgen.ke. We will promptly delete such information.
11. International Data Transfers
As part of UNDP's global operations, your data may be transferred to and processed in countries outside Kenya. UNDP maintains appropriate safeguards for all international data transfers in accordance with its Data Privacy Principles.
11.1 Safeguards
When we transfer data internationally, we ensure adequate protection through:
- Standard contractual clauses approved by the ODPC
- UNDP's internal data protection policies and procedures
- Data processing agreements with strict confidentiality requirements
12. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements.
12.1 Notification of Changes
When we make material changes, we will:
- Post the updated policy on this page with a new "Effective" date
- Send an email notification to registered users
- Display a notice on the Platform for at least 30 days
12.2 Your Acceptance
Your continued use of the Platform after changes become effective constitutes your acceptance of the revised Privacy Policy. If you disagree with the changes, you must stop using the Platform and may request deletion of your data.
13. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Data Protection Officer
dpo@nextgen.ke
For privacy-related inquiries and to exercise your data rights.
Security Team
security@nextgen.ke
Report security vulnerabilities or suspected data breaches.
Physical Address
UNDP Kenya, United Nations Complex, Gigiri, P.O. Box 30218-00100, Nairobi, Kenya
By continuing to use NextGen, you acknowledge that you have read and understood this Privacy Policy.
