Governance & Compliance

Data Protection Policy

Grange Investments Ltd is committed to protecting personal data in accordance with Ugandan law and to embedding sound data-protection practice across its operations.

← All governance & compliance policies

1. Purpose and scope

This policy sets out the principles and responsibilities governing how the Company, its directors, employees, contractors and partners handle personal data. It applies to all personal data we collect, process or control, in any format, in Uganda and wherever our engagements reach.

2. Our data-protection principles

We process personal data lawfully, fairly and transparently; for specified and legitimate purposes; in a manner that is adequate, relevant and limited to what is necessary; accurately and kept up to date; for no longer than necessary; and with integrity and confidentiality.

3. Registration and the Data Protection Officer

The Company recognises the obligation under the Act and Regulations for data collectors, controllers and processors to register with the Personal Data Protection Office and to designate a person responsible for data-protection compliance. The Company maintains, or will maintain, current registration and has assigned data-protection responsibility within the Business & Legal Team.

4. Lawful basis and special categories

We identify a lawful basis before processing and apply additional safeguards to special categories of data and to the personal data of children, consistent with the Act.

5. Security and breach response

We maintain technical and organisational safeguards proportionate to risk. Where a personal-data breach occurs, we will assess, contain and document it, notify the Personal Data Protection Office and affected individuals where required, and take steps to prevent recurrence.

6. Third parties and processors

Where we engage processors, we do so under written terms requiring equivalent protection, confidentiality and security, and processing only on our documented instructions.

7. Accountability

The Board of Directors is accountable for data protection. All personnel are required to comply with this policy; breaches may result in disciplinary action and, where the law is contravened, personal and corporate liability under the Act.