Mombasa County
County Government of Mombasa
Department of Youth
In partnership with Bloomberg Philanthropies

Data Privacy Notice

Youth Climate Action Fund (YCAF) - County Government of Mombasa
Effective Date: July 15, 2026 | Compliant with Section 26 of the Kenya Data Protection Act, 2019

1. Introduction & Data Controller Information

The County Government of Mombasa ("County Lead", "We", "Us") operates the Youth Climate Action Fund (YCAF) data collection system to receive, review, disburse, and monitor youth-led climate microgrant projects. The County Government acts as the Data Controller under the Kenya Data Protection Act, 2019.

Data Protection Contact: Office of the Governor / YCAF Program Secretariat, County Government of Mombasa.
Email: [email protected] / [email protected]
Address: P.O. Box 90440 - 80100, Mombasa, Kenya

2. Personal Data We Collect

We collect personal data through our digital intake portals, application forms, pulse-check surveys, and program reporting tools. The data collected includes:

  • Identity & Contact Data: Full name, date of birth, age (target group: 15-24 years), national ID/passport number (or student ID for minors), phone number, physical address, and email address.
  • Project & Organization Data: Affiliation with youth-led, youth-serving, or sponsor organizations, bank account details (held in the name of eligible registered non-profit/civic entities), and project role.
  • Media & Audio-Visual Data: Photographs, quotes, stories, and video footage collected during project site visits, workshops, and grant award ceremonies.
  • De-identified / Anonymous Survey Data: Survey feedback measuring youth engagement and local policy understanding (submitted anonymously).
3. Purpose & Lawful Basis of Processing

Your personal data is collected and processed under the following lawful bases pursuant to Section 30 of the Data Protection Act, 2019:

Purpose of ProcessingLawful Basis under DPA 2019
Evaluating Grant Applications & Eligibility: assessing 15-24 youth project leads, independent selection committee reviews, and eligibility checks. Consent (Sec. 30(1)(a)) and Performance of Contract/Grant (Sec. 30(1)(b)).
Fund Disbursement & Financial Compliance: verifying eligible non-profit bank accounts and preventing duplicate/sanctioned disbursements. Legal Obligation (Sec. 30(1)(c)) and Public Interest (Sec. 30(1)(e)).
Program Monitoring, Amplification & Media: publishing program milestones, mayoral events, media releases, and social stories. Explicit Consent (Sec. 30(1)(a) & Sec. 33).
AI System Training & Program Improvement: de-identifying application text to train program assistance AI tools. Consent / Legitimate Interest (Sec. 30(1)(f))

* All personally identifiable information (PII) is permanently removed prior to AI processing.

4. Special Protections for Minors (Ages 15-17)

Pursuant to Section 33 of the Data Protection Act, 2019, processing the personal data of a child (defined under Kenyan law as any individual under 18 years) requires explicit parental or legal guardian consent, verified through reasonable technical mechanisms. Youth applicants aged 15 to 17 MUST have their parent/guardian complete Section B of the YCAF Consent Form before application processing occurs. Youth aged 18 to 24 may consent independently.

5. Disclosure & International Data Transfers

Your data may be shared with the following entities solely for program administration and evaluation:

  • Program Delivery Partners: Bloomberg Philanthropies, Bloomberg Center for Public Innovation (BCPI) at Johns Hopkins University, C40 Cities, UCLG, and Rockefeller Philanthropy Advisors (RPA).
  • Independent Selection Committee: External advisors evaluating proposal eligibility.
  • International Transfers: Where program data or de-identified reports are transferred outside Kenya (e.g., to RPA or JHU servers in the USA), such transfers adhere to Sections 48 & 49 of the DPA, ensuring appropriate safeguards, contractual clauses, or explicit consent.
6. Data Retention & Security Measures
  • Retention Period: Personal data will be retained for the duration of the Round 1 program cycle (April 2026 - May 2027) and held for a maximum of 3 years thereafter to satisfy statutory auditing requirements under public financial management regulations, after which it will be permanently deleted or anonymized.
  • Security Safeguards: We employ encryption, role-based access controls, and secure database storage to prevent unauthorized access, loss, or disclosure.
7. Your Rights under Section 26 of the DPA

As a Data Subject under the Data Protection Act, 2019, you have the following rights:

  1. Right to Information: Right to be informed of how your personal data is being used.
  2. Right to Access: Right to access personal data held in our systems.
  3. Right to Object: Right to object to the processing of all or part of your data.
  4. Right to Correction: Right to request correction/rectification of false, inaccurate, or misleading data.
  5. Right to Erasure: Right to request deletion/erasure of irrelevant or unlawfully held data.
  6. Right to Withdraw Consent: Right to withdraw consent at any time without penalty (withdrawal does not affect processing carried out prior to withdrawal).

To exercise any of these rights, please contact the Data Protection Secretariat at [email protected].