Data Privacy Statement
MTRH Data Protection Officer
MTRH is registered as a Data Controller and Data Processor. Data Protection Officer was appointed to oversee and ensure compliance to the Data Protection Act, 2019 whose contact details are as follows;
Ms. Margaret C. Koech
P.O Box 3-30100,
Eldoret.
Email address: dpo@mtrh.go.ke
1. PRIVACY STATEMENT
This privacy statement sets out how we collect, use, process, and protect your personal
information in accordance with the Data Protection Act, 2019 and its regulations.
This statement should be read together with the Terms and Conditions of use for other MTRH
Services. Where there is a conflict as regards data privacy, this privacy statement will prevail.
This statement applies to all patients, staff, students, suppliers, consultants, 3 rd parties,
parastatals, development partners and all visitors to MTRH.
2. DEFINITIONS
“MTRH” means Moi Teaching and Referral Hospital established by Legal Notice No. 78 of
1998 pursuant to the State Corporations Act CAP 446 Law of Kenya.
“Data Protection Officer” is a person designated or appointed by MTRH to monitor compliance
with the Data Protection Act, No. 24 of 2019 and the Regulations made under the Act.
“Data Collection” means gathering of information that relates to you.
“Personal data” means information about you that identifies you directly or indirectly as a
unique individual such as name, an identification number, location data, an online identifier or
one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or
social identity of a natural person.
“Processing” means any operation or sets of operations which is performed on your personal data
whether or not by automated means, such as: collection, recording, organization or structuring;
Storage, adaptation or alteration; Retrieval, consultation or use; Disclosure by transmission,
dissemination, or otherwise making available; Alignment or combination, restriction, erasure or
destruction.
“Sensitive personal data” is data revealing your racial or ethnic origin, political opinions,
professional membership, and the processing of genetic data, biometric data for the purpose of
uniquely identifying a natural person, data concerning health or data concerning a natural
person’s gender.
“Third Party” means a natural or legal person, public authority, agency or body other than you
and MTRH, who under the direct authority of MTRH are authorized to process your personal
data.
3. LAWFUL BASIS
MTRH shall process your personal data as per the applicable law:
- With your consent
- Where processing is necessary for carrying out the mandate of the Authority
- For the performance of a contract to which you are party to or at your request before entering a
contract. - In compliance with any legal obligation to which MTRH is subject.
- For protecting the vital and legitimate interests of MTRH or another person.
- For the performance of a task carried out in public interest.
- For historical, statistical, or scientific research.
3.1 Collection of Personal Data
MTRH collects your personal data both directly and indirectly in accordance with the law. We collect your personal information with your knowledge and consent with exception to cases where prior consent cannot be obtained for real reasons and the processing of the data is permitted by law.
We may collect personal information from you, such as your name, email address, phone number, and any other personal information you choose to provide to us. We may also collect non-personal information, such as your IP address and browser type, through cookies or other tracking technologies through your consent by accepting cookies.
During the nature of offering services to you we may also collect sensitive data that are in line with regulations such as those under Ministry of Health, Kenya and other relevant government bodies.
3.1.1 Sensitive Personal Data
MTRH collects special category of personal data about you revealing details about your race, health status, ethnic origin, belief, property details, marital status, family details including details of your children, parents, spouse or spouses, gender and biometric data.
MTRH shall ensure that sensitive personal data about you is processed in accordance to your right of privacy and as permitted in Part V of the Data Protection Act, 2019.
Stakeholder | Personal data collected | Purpose |
---|---|---|
Patients | Name, ID.No, Next of Kin, Phone Number, County of residence, address, date of birth, gender | For medical care and management |
Students | Name, ID.No, gender, Next of Kin, Phone Number, County of residence, address, date of birth, name of the parents, guardian and contacts | For education purposes |
Staff | name, postal and physical address, location, phone number, date of birth, email address, age, gender, dependant details, academic details, profession, biometric information such as fingerprints, Closed circuit Television surveillance recordings, health records | Management of Employment relationship and benefit processing |
Staff dependent’s | Identity type, name, postal and physical address, location, phone number, date of birth, email address, age, gender | Employee dependant benefit processing |
Interns and attachees | Identity type, name, postal and physical address, location, phone number, date and place of birth, email address, age, gender, account details, family details-next of kin, academic details, profession, closed circuit television surveillance recordings, | |