Updated: September 2026
The Insurance Institute of East Africa (IIEA) respects your privacy and is committed to protecting personal information entrusted to us.
This Privacy Policy explains how IIEA collects, uses, stores, shares and protects personal information when you visit our website, make an enquiry, register for a programme or workshop, use our online learning services, or otherwise interact with us.
- Who We Are
The Insurance Institute of East Africa (IIEA) is a professional education and training institution providing insurance, compliance, financial services and related professional education and capacity-development programmes.
For purposes of applicable data-protection legislation, IIEA may act as a data controller in relation to personal information it collects and determines how to use.
- Information We May Collect
Depending on how you interact with IIEA, we may collect information including:
- your name and contact details;
- email address and telephone number;
- country, organisation, employer and professional information;
- educational and professional background;
- programme applications and enrolment information;
- identification or supporting documents where required;
- payment and transaction information;
- assessment, examination and academic records;
- learning progress and certification information;
- correspondence and enquiries submitted to IIEA;
- workshop and event registrations;
- information generated through your use of our learning platforms; and
- technical information relating to your use of our website, including device, browser and website usage information where applicable.
We seek to collect only information reasonably necessary for the purpose for which it is required, consistent with the data-minimisation principle under Kenyan data-protection law.
- How We Collect Personal Information
We may collect personal information when you:
- submit an enquiry through our website;
- apply or register for a programme;
- enrol in an online course;
- register for a workshop, conference or event;
- create or use a learning-platform account;
- undertake an assessment or examination;
- request certification or professional membership services;
- make a payment;
- communicate with IIEA by email, telephone or other channels;
- participate in surveys, evaluations or feedback exercises; or
- otherwise interact with IIEA or its authorised representatives.
Information may also be received from an employer, sponsoring organisation, professional body, educational partner or other authorised organisation where appropriate.
- How We Use Your Information
IIEA may process personal information for purposes including:
- responding to enquiries;
- assessing applications and eligibility;
- registering and enrolling learners;
- administering programmes and learning activities;
- providing access to online learning platforms;
- managing examinations and assessments;
- issuing or facilitating certificates and professional credentials;
- administering workshops and corporate training;
- processing payments and maintaining financial records;
- providing learner and customer support;
- communicating important programme information;
- maintaining academic and certification records;
- improving our programmes, services and digital platforms;
- meeting contractual, regulatory and legal obligations;
- preventing fraud, misuse and security incidents; and
- providing information about relevant IIEA programmes and services where permitted.
Personal data must be collected for explicit, specified and legitimate purposes and should not subsequently be processed incompatibly with those purposes.
- Legal Basis for Processing
Depending on the circumstances, IIEA may process personal information on the basis of:
- your consent;
- performance of a contract or steps taken at your request before entering into a contract;
- compliance with legal or regulatory obligations;
- legitimate interests of IIEA or another party where those interests do not override your rights; or
- another lawful basis permitted under applicable law.
Where consent is the applicable basis, it should be informed and appropriately obtained. The ODPC’s current guidance emphasises transparency regarding collection, intended use and disclosure to third parties.
- Sharing Personal Information
IIEA does not sell personal information.
Where reasonably necessary for delivering our programmes and services, information may be shared with authorised third parties, including:
- awarding organisations and professional bodies;
- examination and assessment providers;
- accreditation and certification partners;
- educational and institutional partners;
- technology and learning-platform providers;
- payment and financial-service providers;
- hosting, communications and other authorised service providers;
- employers or sponsoring organisations where appropriate and authorised; and
- government, regulatory or law-enforcement authorities where required by law.
Only information reasonably required for the relevant purpose should be shared.
Third-party service providers processing personal information on IIEA’s behalf should be subject to appropriate confidentiality, security and data-protection requirements.
- International Partners and Data Transfers
IIEA works with professional, educational and certification organisations located both within and outside Kenya.
Accordingly, certain personal information may need to be transferred outside Kenya where necessary for matters such as programme registration, examinations, certification, professional membership or other services requested by the learner.
Where personal data is transferred internationally, IIEA will seek to ensure that the transfer is undertaken in accordance with applicable data-protection requirements and appropriate safeguards.
Kenyan law specifically addresses transfers outside Kenya and requires appropriate data-protection safeguards or another recognised legal basis. The Data Protection (General) Regulations also provide specific requirements relating to international transfers.
- Marketing Communications
IIEA may communicate information about programmes, qualifications, workshops, professional development opportunities and related services to persons who have expressed an interest or where otherwise permitted by law.
Where consent is required for direct marketing, appropriate consent will be obtained.
You may unsubscribe from non-essential marketing communications at any time using the unsubscribe mechanism provided or by contacting IIEA.
Kenya’s Data Protection Act places specific conditions on the commercial use of personal information.
- Cookies and Website Technologies
The IIEA website may use cookies and similar technologies to enable website functionality, improve performance, understand website usage and enhance the visitor experience.
Where required, visitors will be given appropriate information and choices concerning non-essential cookies.
Users may also manage cookies through their browser settings, although disabling certain cookies may affect some website functionality.
- Information Security
IIEA takes reasonable organisational and technical measures to protect personal information against:
- unauthorised access;
- accidental loss;
- alteration;
- disclosure;
- misuse; and
- destruction.
Access to personal information is restricted, where appropriate, to persons who require it for legitimate business, educational or administrative purposes.
No internet-based system can, however, be guaranteed to be completely secure.
- Retention of Information
IIEA retains personal information only for as long as reasonably necessary for the purposes for which it was collected and to satisfy applicable educational, certification, contractual, financial, regulatory and legal requirements.
Certain academic, assessment and certification records may need to be retained for longer periods where necessary to verify qualifications or credentials.
Information that is no longer required will, where appropriate, be securely deleted, anonymised or otherwise disposed of.
Storage limitation is one of the principles expressly recognised under Kenya’s data-protection framework.
- Your Data Protection Rights
Subject to applicable law, individuals have rights concerning their personal information, including rights to:
- be informed about how their personal information is used;
- access personal information held about them;
- request correction of inaccurate or misleading information;
- object to certain processing;
- request deletion where applicable;
- restrict processing in applicable circumstances; and
- exercise applicable data-portability rights.
The ODPC confirms these as core rights available to data subjects under Kenya’s data-protection framework.
Requests concerning personal information may be submitted to IIEA using the contact information below.
IIEA may need to verify the identity of the person making a request before disclosing or changing personal information.
- Third-Party Websites
The IIEA website may contain links to websites operated by professional bodies, educational institutions, awarding organisations and other third parties.
Those organisations operate their own websites and privacy practices. IIEA is not responsible for the privacy practices, security or content of third-party websites.
Users are encouraged to review the privacy policies of those organisations when visiting their websites.
- Children’s Personal Information
IIEA’s professional education services are primarily intended for adults and professionals.
Where personal information relating to a minor is processed, IIEA will take appropriate measures in accordance with applicable legal requirements, including obtaining necessary consent or authorisation where required.
- Changes to This Privacy Policy
IIEA may update this Privacy Policy periodically to reflect changes in legislation, technology, our services or our information-management practices.
The latest version will be published on the IIEA website together with the date of the most recent update.
- Questions, Requests and Complaints
For questions about this Privacy Policy, requests relating to your personal information, or concerns regarding how IIEA handles personal information, please contact:
Insurance Institute of East Africa (IIEA)
Brunei House, 3rd Floor
Witu Road, off Lusaka Road
P.O. Box 16481 – 00100
Nairobi, Kenya
Email: info@iiea.co.ke
Website: www.iiea.co.ke
Tel: +254 20 6530128 I +254 20 6530298
Mobile: +254 723 334408 I +254 733 812695