Privacy Policy
Effective Date: 3 July 2027
Last Updated: 3 July 2027
1. Introduction
The National Museums of Kenya (NMK) is committed to protecting your privacy and handling your personal data with transparency, integrity, and in accordance with the Data Protection Act, 2019 (Kenya) and other applicable laws.
This Privacy Policy outlines how we collect, use, disclose, and safeguard your information when you visit our websites, engage with our services, attend our museums, or interact with our research, education, heritage, or digital platforms.
2. Data Controller Information
National Museums of Kenya
Museum Hill, Nairobi, Kenya
P.O. Box 40658-00100, Nairobi, Kenya
Tel: +254 20 3742161
Email: info@museums.or.ke
Website: https://www.museums.or.ke
3. Personal Data We Collect
We may collect and process the following types of personal data:
a) Information You Provide to Us
- Name, title, and contact details (email, phone, address)
- Identification details (ID/passport number) for ticketing or research access
- Payment information (when purchasing tickets, merchandise, or services)
- Educational or institutional affiliation (for academic access or training)
- Images or video (from CCTV, events, or media coverage)
- Feedback, surveys, and communication records
b) Information Collected Automatically
- Device type, browser type, IP address
- Cookies and tracking data (website usage, time spent, pages visited)
- Location data (if location services are enabled)
4. Legal Basis for Processing
We collect and process your personal data based on the following lawful bases:
- Consent: You have given clear consent for us to process your personal data for a specific purpose.
- Contractual necessity: Processing is necessary for a contract with you (e.g., event registration or service delivery).
- Legal obligation: To comply with applicable laws or regulatory requirements.
- Legitimate interests: To improve our services, ensure security, or promote cultural heritage, provided these do not override your rights.
5. Purpose of Collecting Data
Your personal data may be used for the following purposes:
- To provide access to museums, exhibitions, and educational programs
- To respond to inquiries, feedback, or complaints
- To process payments and issue tickets
- To maintain security via CCTV surveillance
- To conduct research, heritage documentation, or digital archiving
- To provide newsletters, updates, or promotional content (only with consent)
- To comply with statutory reporting and archival requirements
6. Data Sharing and Disclosure
NMK does not sell your personal data. We may share it with:
- Government agencies or regulators (when required by law)
- Academic or research institutions (with consent)
- ICT or payment service providers who support our systems (under strict confidentiality and data processing agreements)
- Law enforcement bodies (for security and legal obligations)
- 7. International Data Transfers
Where data is transferred outside Kenya (e.g., for international research collaborations), NMK ensures adequate data protection safeguards are in place in accordance with Section 48 of the Kenya Data Protection Act.
8. Data Retention
We retain your personal data only for as long as is necessary for the purposes outlined in this policy, and in line with our statutory archiving obligations under the National Museums and Heritage Act (2006). Retention periods may vary:
- CCTV footage: up to 30 days (unless required for investigation)
- Event registration: up to 2 years
- Research permits: up to 7 years
- Archival/research records: indefinite (for historical purposes)
9. Your Data Rights
As a data subject, you have the following rights under the Kenya Data Protection Act:
- Right to be informed: About how your data is being used
- Right of access: To request a copy of your personal data
- Right to rectification: To correct inaccurate or incomplete data
- Right to erasure: To request deletion of your data (subject to legal obligations)
- Right to object: To processing of your data for direct marketing or legitimate interest
- Right to data portability: To obtain your data in a structured, machine-readable format
- Right to lodge a complaint: With the Office of the Data Protection Commissioner (ODPC)
To exercise any of these rights, contact us at: privacy@museums.or.ke
10. Data Security Measures
We implement appropriate organizational, technical, and physical safeguards to secure your data, including:
-
Encrypted digital systems and databases
-
Secure storage for physical documents
-
Access control and staff confidentiality agreements
-
Regular staff training on data protection
11. Use of Cookies
Our website uses cookies to enhance user experience. You can accept or reject cookies through your browser settings. Types of cookies we use include:
-
Necessary cookies (site functionality)
-
Analytics cookies (site usage and performance)
-
Preference cookies (language, session settings)
12. Third-Party Links
Our platforms may contain links to third-party websites or services. NMK is not responsible for their privacy practices. We encourage users to review the privacy policies of external sites before sharing personal data.
13. Children’s Privacy
We offer educational programs for children and young people. Where we collect personal data from minors (under 18), we obtain verifiable parental/guardian consent, as required by law.
14. Changes to This Policy
NMK may revise this Privacy Policy from time to time. We will notify users of significant changes via our website and update the “Last Updated” date.
15. Contact Us
For questions, concerns, or to exercise your data rights, contact:
Data Protection Officer (DPO)
National Museums of Kenya
Email: privacy@museums.or.ke
Phone: +254 20 3742161