Data Protection & Compliance Policy
1. Introduction
Pickseat Transport Services ("Pickseat", "we", "our", or "us") is committed to protecting the privacy and security of personal data entrusted to us. This Data Protection & Compliance Policy outlines our obligations under the Data Protection Act, 2012 (Act 843) of Ghana, the General Data Protection Regulation (GDPR) where applicable, and other relevant data protection laws.
We handle personal data with the utmost care and respect, ensuring that all processing activities comply with applicable legal requirements and industry best practices.
This policy applies to:
- All personal data processed by Pickseat
- All employees, contractors, and third-party processors
- All systems, applications, and services operated by Pickseat
- All data processing activities, whether automated or manual
2. Legal Framework
Pickseat complies with the following data protection laws and regulations:
2.1 Data Protection Act, 2012 (Act 843) - Ghana
- Data Protection Principles (Section 1)
- Collection and Processing of Personal Data (Section 17)
- Rights of Data Subjects (Section 21-28)
- Data Security Measures (Section 29)
- Data Retention and Disposal (Section 30)
- Compliance and Enforcement (Section 31-40)
2.2 General Data Protection Regulation (GDPR)
- Lawfulness, Fairness, and Transparency (Article 5)
- Purpose Limitation (Article 5)
- Data Minimization (Article 5)
- Accuracy (Article 5)
- Storage Limitation (Article 5)
- Integrity and Confidentiality (Article 5)
- Data Subject Rights (Articles 12-22)
2.3 Other Applicable Laws
- Electronic Communications Act, 2008 (Act 775)
- National Identity Register Act, 2008 (Act 750)
- Banking Act, 2004 (Act 673) - Financial Data Protection
- Road Traffic Act, 2004 (Act 683) - Driver and Vehicle Data
3. Data Protection Principles
Pickseat adheres to the following data protection principles:
3.1 Lawfulness, Fairness, and Transparency
- Processing is lawful, fair, and transparent to data subjects
- Data subjects are informed about how their data is used
- Consent is obtained where required
3.2 Purpose Limitation
- Data is collected for specified, explicit, and legitimate purposes
- Data is not processed in a manner incompatible with those purposes
3.3 Data Minimization
- Only data that is adequate, relevant, and limited to what is necessary is collected
- Unnecessary data is not collected or retained
3.4 Accuracy
- Personal data is accurate and kept up to date
- Inaccurate data is corrected or deleted without delay
3.5 Storage Limitation
- Data is kept only as long as necessary for the intended purpose
- Data is securely disposed of when no longer needed
3.6 Integrity and Confidentiality
- Data is processed in a manner that ensures security
- Appropriate technical and organizational measures are in place
3.7 Accountability
- We are responsible for and can demonstrate compliance with these principles
- Records of processing activities are maintained
4. Data Subject Rights
Under the Data Protection Act, 2012 (Act 843) and GDPR, data subjects have the following rights:
| Right | Description | Response Time |
|---|---|---|
| Right to Access | Request access to personal data we hold about you | 30 days |
| Right to Correction | Request correction of inaccurate or incomplete data | 30 days |
| Right to Deletion | Request deletion of personal data ("right to be forgotten") | 30 days |
| Right to Restriction | Request restriction of data processing | 30 days |
| Right to Object | Object to processing based on legitimate interests | 30 days |
| Right to Portability | Request transfer of data to another controller | 30 days |
| Right to Withdraw Consent | Withdraw consent where processing is based on consent | Immediate |
To exercise your rights: Submit a request to makosagroups@gmail.com. We may require verification of identity before processing certain requests.
5. Categories of Personal Data
Pickseat processes the following categories of personal data:
| Category | Examples | Processing Purpose |
|---|---|---|
| Identity Data | Full name, Ghana Card, driver's license | Verification, compliance, safety |
| Contact Data | Email address, phone number, physical address | Communication, account management |
| Location Data | GPS coordinates, route history, stop data | Service provision, tracking, analytics |
| Payment Data | Transaction references, billing details, payment status | Payment processing, accounting |
| Vehicle Data | Vehicle registration, insurance, inspection records | Verification, safety, compliance |
| Usage Data | App interactions, features used, search history | Service improvement, analytics |
| Technical Data | IP address, device information, operating system | Security, troubleshooting, compatibility |
5.1 Special Categories of Data
Pickseat does not knowingly collect special categories of personal data (sensitive data) including:
- Racial or ethnic origin
- Political opinions
- Religious or philosophical beliefs
- Trade union membership
- Health data
- Biometric data
- Sexual orientation
If we inadvertently collect special categories of data,it will be immediately deleted unless required by law.
6. Data Processing Activities
6.1 Collection
- Data is collected directly from data subjects during registration
- Data is collected through app usage and interactions
- Data may be collected from third-party verification services
- Data is collected only for specified, legitimate purposes
6.2 Storage
- Data is stored securely on encrypted servers
- Data is stored in Ghana and internationally (with appropriate safeguards)
- Access to stored data is strictly controlled
- Data is retained only as long as necessary
6.3 Processing
- Data is processed only for legitimate, specified purposes
- Processing is automated and manual as appropriate
- Processing is documented and auditable
- Processing is subject to appropriate security controls
6.4 Sharing
- Data is shared only with legitimate recipients
- Data sharing is governed by data processing agreements
- Data is not sold to third parties
- International transfers are subject to appropriate safeguards
6.5 Deletion
- Data is securely deleted when no longer needed
- Deletion is documented and auditable
- Data may be anonymized instead of deleted for research purposes
- Legal retention requirements are respected
7. Data Security Measures
Pickseat implements comprehensive security measures to protect personal data from unauthorized access, disclosure, alteration, or destruction.
7.1 Technical Measures
- Encryption: Data is encrypted at rest (AES-256) and in transit (TLS 1.3)
- Access Control: Role-based access controls (RBAC) with least privilege principle
- Authentication: Multi-factor authentication for critical systems
- Monitoring: 24/7 system monitoring and intrusion detection
- Backup: Regular encrypted backups with disaster recovery plans
- Firewall: Next-generation firewalls for network protection
- Vulnerability Management: Regular security assessments and penetration testing
7.2 Organizational Measures
- Policies: Comprehensive data protection and security policies
- Training: Regular employee training on data protection
- Audits: Regular internal and external audits
- Incident Response: Documented incident response procedures
- Data Protection Officer: Dedicated DPO responsible for compliance
7.3 Physical Measures
- Secure office premises with access controls
- Secure server facilities with environmental controls
- Document and media disposal procedures
- Visitor access management
8. Data Protection Impact Assessments
Pickseat conducts Data Protection Impact Assessments (DPIAs) for high-risk processing activities.
8.1 When DPIAs are Conducted
- New processing activities that may pose high risks
- Significant changes to existing processing activities
- Processing of special categories of data
- Implementation of new technologies
- Large-scale processing of personal data
8.2 DPIA Process
- Systematic description of the processing
- Assessment of necessity and proportionality
- Identification of risks to data subjects
- Identification of measures to mitigate risks
- Consultation with the Data Protection Authority where required
9. Data Breach Management
Pickseat has robust procedures in place to detect, report, and investigate personal data breaches.
9.1 Breach Detection
- 24/7 monitoring for suspicious activity
- Automated intrusion detection systems
- Regular security audits and assessments
- Employee reporting procedures
9.2 Breach Response
- Immediate containment of the breach
- Assessment of the risk to data subjects
- Notification of affected data subjects
- Notification of the Data Protection Authority
- Investigation and root cause analysis
- Implementation of corrective measures
9.3 Reporting Timelines
- Data Protection Authority: Within 72 hours of becoming aware of the breach
- Data Subjects: Without undue delay where high risk
- Internal Reporting: Immediately upon detection
Data breaches can have serious consequences. All employees must report suspected breaches immediately to the Data Protection Officer.
10. Third-Party Processing
Pickseat engages third-party processors for various services. All processors are carefully vetted and subject to data processing agreements.
10.1 Processor Requirements
- Must comply with applicable data protection laws
- Must have appropriate technical and organizational measures
- Must process data only on documented instructions
- Must ensure adequate security of processing
- Must report breaches immediately
10.2 Categories of Processors
- Cloud hosting providers
- Payment processing services
- Authentication providers
- Analytics services
- Customer support systems
- Mapping and location services
10.3 Processor Oversight
- Regular audits of processors
- Review of processor security practices
- Sub-processor approval requirements
- Termination rights for non-compliance
11. International Data Transfers
Pickseat may transfer personal data to countries outside Ghana and the European Economic Area (EEA). Such transfers are subject to appropriate safeguards.
11.1 Transfer Mechanisms
- Standard Contractual Clauses: EU-approved clauses for data transfers
- Adequacy Decisions: Where the destination country has been deemed adequate
- Derogations: Where specific exceptions apply (e.g., explicit consent)
11.2 Data Localization
- Ghana Data: Primary data storage is in Ghana
- International Storage: Some data may be stored in other jurisdictions
- Reasonable Efforts: We make reasonable efforts to keep data within Ghana where feasible
12. Children's Data
Pickseat does not knowingly collect personal data from children under the age of 18. Our platform is intended for adults.
- Age Verification: We require users to confirm they are 18 or older during registration
- Detection: We take reasonable steps to detect if a child is using the platform
- Removal:If we become aware of children's data, we will delete it promptly
- Parental Consent:In rare cases where children's data is required, we will obtain parental consent
13. Data Subject Requests
Pickseat has procedures in place to handle data subject requests efficiently and in compliance with legal requirements.
13.1 Request Process
- Submit request via email to makosagroups@gmail.com
- We will verify the identity of the requester
- We will respond within 30 days
- We may extend the response time for complex requests
13.2 Verification
- We will request additional information to verify identity
- We will not disclose data without proper verification
- We may use authentication methods to verify requesters
13.3 Fees
- Standard Requests: Free of charge
- Excessive Requests: May be subject to a reasonable fee
- Manifestly Unfounded: May be refused or subject to a fee
14. Data Protection Officer
Pickseat has appointed a Data Protection Officer (DPO) responsible for overseeing data protection compliance.
14.1 DPO Responsibilities
- Monitor compliance with data protection laws
- Provide advice on data protection matters
- Cooperate with supervisory authorities
- Act as a point of contact for data subjects
- Conduct data protection training
14.2 Contact the DPO
- Email: makosagroups@gmail.com
- Address: Spintex Road, Accra-Ghana
15. Compliance Monitoring
Pickseat continuously monitors compliance with data protection laws and internal policies.
15.1 Internal Audits
- Regular internal audits of data protection practices
- Review of processing activities
- Assessment of security controls
15.2 External Audits
- Independent external audits as required
- Audits by supervisory authorities
- Third-party security assessments
15.3 Reporting
- Quarterly compliance reports to management
- Annual data protection reports
- Reporting to supervisory authorities as required
16. Record of Processing Activities
Pickseat maintains detailed records of all data processing activities as required by law.
16.1 Record Contents
- Purpose of processing
- Categories of data processed
- Categories of data subjects
- Recipients of data
- Retention periods
- Security measures
16.2 Record Management
- Records are kept up to date
- Records are accessible to supervisory authorities
- Records are retained for the required period
17. Data Subject Complaints
If you have a complaint about how we handle your personal data, please contact us.
17.1 Internal Complaint Process
- Contact our Data Protection Officer
- We will investigate your complaint
- We will respond within 30 days
- We will work to resolve the issue
17.2 External Complaint Process
If you are not satisfied with our response, you may lodge a complaint with the Data Protection Commission:
- Data Protection Commission (Ghana)
- Location: Accra, Ghana
- Website: www.dataprotection.org.gh
18. Training and Awareness
Pickseat provides regular data protection training to all employees and relevant contractors.
- Induction Training: All new employees receive data protection training
- Annual Training: Regular refresher training for all employees
- Specialized Training: Role-specific training for data handlers
- Awareness Campaigns: Regular awareness communications
19. Policy Review and Updates
This Data Protection & Compliance Policy is reviewed regularly to ensure it remains current and effective.
- Annual Review: Comprehensive review of the policy
- Triggered Reviews: When there are changes in law or business practices
- Post-Breach Review: After any significant data breach
- Continuous Improvement: We update our practices based on lessons learned
Version Control: This policy is version-controlled, and all changes are documented.
20. Contact Information
For questions about this policy or data protection matters, please contact:
Pickseat Data Protection Office
Company: Pickseat Transport Services
Email: makosagroups@gmail.com
Address: Spintex Road, Accra-Ghana
Data Protection Officer: Available at makosagroups@gmail.com
21. Acceptance
By using Pickseat, you acknowledge that you have read, understood, and agreed to this Data Protection & Compliance Policy.
We are committed to protecting your privacy and handling your personal data with the utmost care and respect.