Data Privacy and Protection Policy

Savannah Communications Limited (SCOMM)
Effective Date: January 2023
Jurisdiction: Republic of Ghana

1. Introduction and Corporate Context

Welcome to the official Data Privacy and Protection Policy of Savannah Communications Limited (hereinafter referred to as “SCOMM”, “We”, “Us”, or “Our”). This document serves as a comprehensive, binding framework detailing how SCOMM collects, processes, stores, transmits, and protects personal data.

As a multifaceted organization based in Ghana, SCOMM specializes in strategic communications, the implementation of development interventions, the development of communication materials, stakeholder and media management, and comprehensive training and facilitation. Due to the varied and highly interactive nature of these services, we regularly interact with individuals, corporate organizations, bilateral and multinational entities, and local communities. This necessitates the collection and processing of diverse data sets to fulfill our operational mandates effectively.

This policy has been architected to ensure absolute transparency and to guarantee that every data subject interacting with SCOMM understands the lifecycle of their personal information within our technological and administrative ecosystems.

2. Statutory and Regulatory Framework

This Privacy Policy is strictly governed by and drafted in comprehensive adherence to the primary data protection and electronic transaction legislations of the Republic of Ghana:

  • The Data Protection Act, 2012 (Act 843): This legislative instrument establishes the foundational legal framework for the protection of personal privacy and personal data in Ghana. SCOMM mandates compliance with the regulatory oversight of the Data Protection Commission (DPC) of Ghana and structures all data processing activities around the statutory principles of privacy.
  • The Electronic Transactions Act, 2008 (Act 772): This Act provides for and facilitates electronic communications and related transactions. SCOMM aligns its digital data collection, electronic record keeping, digital consent mechanisms, and online consumer protection protocols with the stringent standards required by this Act.

 

3. Core Principles of Data Processing

In strict compliance with Section 17 of the Data Protection Act (Act 843), SCOMM embeds the following eight fundamental principles into every facet of our operations:

  1. Accountability: SCOMM assumes full responsibility for all personal data under its control and ensures that all personnel, contractors, and multinational partners adhere to this policy.
  2. Lawfulness of Processing: All personal data is processed fairly, lawfully, and in a manner that does not infringe upon the privacy rights of the data subject.
  3. Specification of Purpose: Data is collected solely for explicit, explicitly defined, and lawful purposes directly related to SCOMM’s operational services.
  4. Compatibility of Further Processing: We strictly prohibit the processing of personal data for reasons incompatible with the original purpose of collection unless explicitly authorized by the data subject or mandated by law.
  5. Quality of Information: SCOMM implements robust verification protocols to ensure that all personal data is accurate, complete, and kept up to date.
  6. Openness: We maintain an environment of absolute transparency regarding our data processing practices, ensuring data subjects are fully informed about the identity of the data controller and the nature of the processing.
  7. Data Security Safeguards: SCOMM deploys enterprise-grade technical and organizational measures to prevent unauthorized access, accidental loss, destruction, or damage to personal data.
  8. Data Subject Participation: We guarantee and facilitate the rights of data subjects to access, rectify, or demand the erasure of their personal information.

4. Exhaustive Categorization of Collected Data

To effectively execute our professional mandates across our various operational pillars, SCOMM collects multiple categories of personal data. The scope of this collection is strictly limited to what is necessary for the specific engagement.

A. Strategic Communications and Media Management Data

To provide guidelines and interventions aimed at branding and reputation management for individuals, corporate organizations, and associations, as well as to provide tailored stakeholder management, we collect:

  • Identity Data: Full legal names, professional titles, organizational affiliations, and biographical profiles.
  • Contact Data: Corporate and personal email addresses, physical office addresses, primary and secondary telephone numbers.
  • Media and Public Relations Data: Historical press coverage, public sentiment metrics, social media handles, and stakeholder mapping profiles.

B. Development Interventions and Partnerships Data

In our capacity working with bilateral and multinational organizations to harness skills in community development, community mobilization, animation, and agribusiness, we collect:

  • Demographic Data: Age, gender, community residency status, and linguistic preferences necessary for targeted community interventions.
  • Socio-Economic Data: Information related to agribusiness participation, community roles, and developmental aspirations required to fulfill global goals and policies.
  • Sensitive Personal Data: In rare instances, and strictly subject to explicit, written consent as mandated by Act 843, we may collect health, biometric, or religious data if strictly necessary for the targeted implementation of a specific community health or development intervention.

C. Training and Facilitation Data

To deliver capacity building and development programs in communications, media, and development interventions, we gather:

  • Educational and Professional Data: Resumes, current skill levels, institutional affiliations, and post-training assessment scores.
  • Logistical Data: Dietary requirements, accessibility needs, and attendance records for rehearsed methods relating to capacity building.

D. Communication Materials Production Data

For the development and production of communication materials using modern production equipment, we collect:

  • Digital Media Assets: Photographs, voice recordings, and video footage of individuals participating in SCOMM productions. Consents and release forms are mandate-critical for this category.

E. Electronic and Website Data (Act 772 Compliance)

When users interact with SCOMM’s digital platforms, we automatically collect:

  • Technical Data: IP addresses, browser types, operating systems, and time-zone settings.
  • Usage Data: Granular analytics detailing how users navigate our website, the duration of page visits, and interaction pathways.

5. Methodologies of Data Collection

SCOMM employs a multi-tiered approach to data collection, ensuring that all methods are lawful and transparent:

  • Direct Provision: Data provided directly by the subject via physical intake forms, digital registration portals, email correspondence, or contractual agreements.
  • Automated Collection: Data harvested through digital interactions utilizing cookies, server logs, and web beacons in compliance with the Electronic Transactions Act.
  • Third-Party Acquisition: Data obtained through our authorized bilateral and multinational organizational partners, strictly contingent upon the partner demonstrating that the data was collected lawfully and with the requisite consent for sharing.
  • Publicly Available Sources: Gathering professional and public information from public corporate registries or open media platforms for the purpose of stakeholder and media management.

6. Legal Basis and Purpose for Processing

Under the Data Protection Act (Act 843), SCOMM must establish a legal foundation for every data processing activity. We process your data based on the following justifications:

  • Contractual Necessity: Processing data required to fulfill a formalized agreement, such as providing tailored and targeted services in managing stakeholders or executing an agribusiness intervention.
  • Explicit Consent: Processing activities that rely on the unambiguous, informed, and freely given consent of the data subject (e.g., utilizing an individual’s image in the production of communication materials).
  • Legitimate Interests: Processing necessary for SCOMM’s internal administrative and operational efficiency, provided these interests do not override the fundamental rights of the data subject.
  • Legal Obligation: Processing required to comply with statutory mandates, tax laws, or judicial orders within the Republic of Ghana.

7. Data Sharing, Dissemination, and Third-Party Disclosures

SCOMM does not monetize, rent, or indiscriminately sell personal data. However, the collaborative nature of our work necessitates strategic data sharing under strict contractual safeguards.

  • Bilateral and Multinational Partners: To contribute towards individual and community aspirations, we may share aggregated and, where necessary, anonymized demographic data with our development partners.
  • Service Providers: We engage third-party vendors (e.g., cloud hosting providers, modern production equipment technicians, legal advisors) who process data strictly on our behalf and under binding Data Processing Agreements (DPAs).
  • Regulatory Authorities: SCOMM will disclose personal data to the Data Protection Commission, law enforcement agencies, or the judiciary if legally compelled under Ghanaian law.

8. Trans-Border Data Flows

Given our engagement with multinational organizations, personal data may be transferred to jurisdictions outside the Republic of Ghana. In accordance with Act 843, SCOMM strictly prohibits the cross-border transfer of personal data unless:

  1. The receiving jurisdiction possesses adequate data protection laws commensurate with those of Ghana.
  2. The data subject has given explicit consent to the transfer.
  3. The transfer is governed by standard contractual clauses or binding corporate rules that enforce Ghanaian data protection standards on the recipient entity.

9. Exhaustive Data Security Safeguards

SCOMM treats the security of personal data as a paramount operational imperative. We implement a defense-in-depth strategy encompassing both technical and organizational controls:

  • Technical Controls:
    • Encryption: All personal data is encrypted both at rest (using AES-256 standard) and in transit (utilizing TLS 1.3 protocols).
    • Access Management: Implementation of strict Role-Based Access Control (RBAC) and Multi-Factor Authentication (MFA) for all personnel accessing SCOMM databases.
    • Network Security: Deployment of enterprise firewalls, Intrusion Detection Systems (IDS), and regular vulnerability scanning of our digital infrastructure.
  • Organizational Controls:
    • Personnel Training: Mandatory, biannual data privacy training for all staff, especially those involved in community mobilization and animation.
    • Data Minimization: Operational protocols ensuring that only the absolute minimum data required for a task is extracted from secure storage.
    • Incident Response Plan: A formalized protocol for detecting, containing, investigating, and reporting data breaches to the DPC and affected data subjects within 72 hours of discovery.

10. Data Retention and Destruction Protocols

SCOMM adheres strictly to the principle of storage limitation. Personal data is retained only for the duration explicitly required to fulfill the purpose for which it was collected, or as mandated by statutory retention periods (e.g., financial transaction records under the Electronic Transactions Act).

  • Project-Specific Data: Data related to specific capacity building or developmental interventions is securely archived upon project closure and completely destroyed after a maximum period of five (5) years, barring legal holds.
  • Destruction Methodology: Digital data is purged using secure cryptographic erasure techniques. Physical documents are destroyed via cross-cut shredding by authorized personnel.

11. Exhaustive Rights of the Data Subject

Pursuant to the Data Protection Act (Act 843), individuals interacting with SCOMM possess comprehensive rights over their personal data. SCOMM guarantees the facilitation of these rights without undue delay:

  • The Right of Access: Subjects may request a comprehensive copy of all personal data held by SCOMM, alongside the purposes of processing and the identities of any third-party recipients.
  • The Right to Rectification: Subjects may demand the immediate correction or completion of inaccurate or outdated personal data.
  • The Right to Erasure (“Right to be Forgotten”): Subjects may request the deletion of their personal data when it is no longer necessary for the original purpose, or when consent is withdrawn.
  • The Right to Restriction of Processing: Subjects may mandate that SCOMM freeze the processing of their data during disputes regarding data accuracy or the lawfulness of processing.
  • The Right to Object: Subjects retain the absolute right to object to the processing of their data for direct marketing, or for purposes based on legitimate interests.
  • The Right to Automated Decision Making: Subjects have the right not to be subject to decisions based solely on automated processing, including profiling, which produces legal or significant effects.

12. Cookies and Electronic Tracking Policies

To ensure compliance with the Electronic Transactions Act (Act 772), SCOMM provides transparent notifications regarding electronic tracking technologies utilized on our digital platforms.

  • Functional Cookies: Essential for the core operation of the SCOMM website, enabling secure logins and session management.
  • Analytical Cookies: Utilized to aggregate anonymized data on website traffic and user engagement, allowing us to optimize our digital presence.
  • User Control: Visitors are presented with a granular cookie consent banner upon their first visit, allowing them to explicitly accept or reject non-essential tracking technologies.

13. Policy Amendments and Revisions

SCOMM reserves the right to iteratively update, modify, or completely overhaul this Data Privacy and Protection Policy to reflect changes in our operational services, advancements in modern production equipment, or amendments to Ghanaian jurisprudence. Material changes will be communicated to active clients and partners via official digital channels thirty (30) days prior to their enforcement.

14. Contact Information and Dispute Resolution

For any inquiries, requests to exercise data subject rights, or to report a suspected privacy violation, please direct correspondence to the designated Data Protection Supervisor at SCOMM:

Savannah Communications Limited (SCOMM)
Attention: Office of the Data Protection Supervisor
Address: Dorado Street, Choggu Low-Cost, Choggu, Tamale, Ghana
Email: info@savannahcommunications.org
Phone: +233-55-962-2360

If a data subject feels that SCOMM has not adequately addressed a privacy concern, they retain the statutory right to lodge a formal complaint directly with the Data Protection Commission (DPC) of Ghana.