Last updated: 12th November, 2025
Version: 2.0
INTRODUCTION
This Privacy Notice applies to collection of personal/sensitive data from: individuals applying for insurance policies, Agents, Financial Advisors, Intermediaries/Brokers, Third Parties (including all suppliers/vendors), on premises visitors, and data collected through our websites and/or any related services, sales, marketing or events.
Here you can find out more about:
- The Personal Data we collect and how we use it
- Management of usage data
- Data transfers
- Retention of your Personal Data
- Your privacy rights and how the law protects you
- Disclosure of your Personal Data
- Security of your data
- Children’s privacy
- Changes to this Privacy Notice
- Contact details to enable you to access your data, exercise your rights, and lodge any complaints you may have
By submitting your application/contract and/or using our website and services you agree to the collection and use of information in accordance with this Privacy Notice.
Kindly read through this Privacy Notice carefully and if there are any provisions that you disagree with, please discontinue use of our site and/or our services.
DEFINITIONS
We/Us means Prudential Life Assurance Kenya Limited and its affiliates.
Prudential Group means any affiliates of Prudential Life Assurance Kenya (including, Prudential Plc, Prudential Africa Holdings Limited and Prudential Corporation Asia).
Service Provider means any natural or legal person who processes the data on behalf of the Company. It refers to third-party companies or individuals employed by the company to facilitate the service, to provide the service on behalf of the company, to perform services related to the service or to assist the Company in analyzing how the service is used. It includes accountants, auditors, IT service and platform providers, intermediaries, reinsurers, investment managers, agents, selected third party financial and insurance product providers and our professional advisers.
Third-party Social Media Service refers to any website or any social network website through which a user may log in or create an account to use the site/service.
Personal Data is any information that relates to an identified or identifiable individual.
Sensitive personal data means data that reveals your: race, health status (physical or mental health condition), ethnic social origin, conscience, belief, genetic data, biometric data, property details, marital status, family details (including names of children, parents, spouse), and sex or sexual orientation.
Cookies are small files that are placed on your computer, mobile device or any other device by a website, containing the details of your browsing history on that website among its many uses.
Usage Data refers to data collected automatically, either generated using the site/service or from the Service infrastructure itself (for example, the duration of a page visit).
PERSONAL DATA WE COLLECT
| Type of Personal Information | Examples |
|---|---|
| 1. Contact information | Name, address, email, telephone number and social networking profile details. |
| 2. General information | Date and place of birth, physical characteristics (appropriate to the circumstances), your status as director or partner, or other ownership or management interest in an organisation, your signature, and other identifiers. |
| 3. Education and employment information | Educational background, employer details and employment history, skills and experience, professional licences, performance metrics, memberships and affiliations. |
| 4. Insurance and claim information | Policy and claim numbers, relationship to policyholder, insured, claimant or other relevant individual, date and cause of property damage, loss or theft, injury, disability or death, activity records (for example, driving records), and other information relevant to insurance policy issuance, and claim assessment and settlement. For liability insurance, this will include details of the dispute, claim or proceedings involving you. |
| 5. Government and other official identification numbers | National ID, passport number, tax identification number, or other government issued identification number or documents. |
| 6. Financial information and account details | Payment card number (credit or debit card), bank account number, MPESA details, or other financial account number and account details, assets, income, salary and other financial information, account log-in information and passwords for accessing insurance policy. |
| 7. Medical condition and health status | Current or previous physical, mental or medical condition, health status, injury or disability information, medical diagnosis, medical procedures performed and treatment given, personal habits (for example, smoking or consumption of alcohol), prescription information, and medical history. |
| 8. Other sensitive personal data | Gender, marital and family status, information about ethnicity, sexual life and orientation, or genetic or biometric information. We may obtain information about criminal records or civil litigation history (for example, for preventing, detecting and investigating fraud). Information provided voluntarily to us (for example, preferences expressed regarding medical treatment based on religious beliefs) (where collected). |
| 9. Telephone recordings | Recordings of telephone calls with our representatives. |
| 10. Photographs and video recordings | Images (including photographs and pictures) or video recordings created in connection with our insurance activities, including for claims assessment, administration and settlement, claim disputes, or for other relevant purposes as permitted by law, as well as CCTV recordings captured by equipment on our premises. |
| 11. Information to detect, investigate or prevent crime, including fraud and money laundering | Insurers commonly collect, hold and share information about their previous dealings with policyholders and claimants with the intention of the detection, investigation and prevention of fraud, money laundering and other criminal activities. In this regard, we may have a duty at law to disclose such information to the relevant regulators, government authorities, enforcement agencies and/or other government bodies. |
| 12. Marketing preferences, marketing activities and customer feedback (Marketing data is only collected and applicable where you have provided consent) | Marketing preferences, or responses to voluntary customer satisfaction surveys. To improve our marketing communications, we may collect information about interaction with, and responses to, our marketing communications. |
| 13. Online activity information | Usage Data is collected automatically when using the site/service. Usage Data may include information such as your device’s Internet Protocol address (IP address), browser type, browser version, the pages of our service that you visit, the time and date of your visit, the time spent on those pages, unique device identifiers and other diagnostic data. When you access the service by or through a mobile device, we may collect certain information automatically, including, but not limited to, the type of mobile device you use, your mobile device unique ID, the IP address of your mobile device, your mobile operating system, the type of mobile Internet browser you use, unique device identifiers and other diagnostic data. We may also collect information that your browser sends whenever you visit our service or when you access the service by or through a mobile device. We use cookies and similar tracking technologies to track the activity on our site/service and store certain information. You can instruct your browser to refuse all cookies or to indicate when a cookie is being sent. However, if you do not accept cookies, you may not be able to use some parts of our site/service. These cookies are essential to provide you with services available through the website and to enable you to use some of its features. They help to authenticate users and prevent fraudulent use of user accounts. These cookies allow us to remember choices you make when you use the website, such as remembering your login details or language preference. The purpose of these cookies is to provide you with a more personal experience and to avoid you having to re-enter your preferences every time you use our site. |
| 14. Supplemental information from other sources | We and our service providers may supplement the personal information we collect with information obtained from other sources (for example, publicly available information from online social media services and other information resources, third-party commercial information sources, and information from our group companies and business partners). We will use any such supplemental information in accordance with applicable law (including obtaining your consent where required). |
USE OF YOUR PERSONAL DATA
We will use your personal data for the following purposes:
- To communicate with you.
- To enable us to administer, process and service our products and services for you.
- To comply with legal or regulatory requirements.
- To improve our products and services.
- To send you marketing and promotional material where you have provided consent.
- To request feedback.
- To track and analyse sales performance, distribute commissions and manage clawbacks.
- To enhance security and safety on premises, including preventing and detecting crime and safeguarding staff and visitors.
- To carry out checks using third party agencies or publicly available information.
- For fraud prevention and detection.
- If appropriate, we may also pass on your personal information to financial crime prevention agencies and any legal, regulatory or government bodies.
- For certain products or services, we’ll need to process your sensitive personal data, such as information relating to health.
- We may share your data with third party vendors, service providers, contractors or agents who perform services for us or on our behalf and require access to such information perform their services. We will not share, any of your information with third parties for their promotional purposes or any without your consent.
- Keeping your information on record as well as carrying out other internal business purposes.
MANAGEMENT OF USAGE DATA
The Company may use Usage Data for the following purposes:
- To provide and maintain our site/service including to monitor its usage.
- To manage your registration as a user of the Service. The Personal Data you provide can give you access to different functionalities of the Service that are available to you as a registered user.
- To contact You by email, telephone calls, SMS, or other equivalent forms of electronic communication, such as a mobile application’s push notifications regarding updates or informative communications related to the functionalities, products or contracted services, including the security updates, when necessary or reasonable for their implementation.
- To provide you with news, special offers and general information about other services and events which we offer that are similar to those that you have already purchased or enquired about unless you have opted not to receive such information.
- To attend to and manage your requests to us.
- To contact you by email, telephone calls, SMS, or other equivalent forms of electronic communication, such as a mobile application’s push notifications regarding updates or informative communications related to the functionalities, products or contracted services, including the security updates, when necessary or reasonable for their implementation.
- We may share your personal information with Service Providers to monitor and analyze the use of our Service, to show advertisements to you to help support and maintain our Service, to contact you, to advertise on third party websites to you after you visited our Service or for payment processing.
DATA TRANSFER
We may use systems and Cloud (technology) storage solutions located in South Africa, Singapore, Australia and Europe to ensure efficiency, security, and Disaster Recovery preparedness, when it comes to protecting your data. In some instances, technical support provided may be from overseas territories. When transferring personal data to other countries, we will prioritize countries that have demonstrated a comparable or higher level of data protection standards. In the unlikely event that personal data is transferred to a country which is deemed not to have the same standards of protection for personal data as Kenya, PLAK will ensure appropriate safeguards are in place.
Your information, including Personal Data, is processed at our operating offices and in any other places where the parties involved in the processing are located. This information may be transferred to other jurisdictions where the data protection laws may differ from those in Kenya. As we, the Prudential Group, and some of our Business Partners are global companies, we might need to send your personal information overseas. Any transfer of personal data overseas will be in accordance with applicable local law requirements.
You acknowledge and accept that submitting personal data and executing any contract with Prudential Life Assurance Kenya Limited, processing of your personal information will be in accordance with the terms set forth in this Privacy Notice which may also include local and international data transfers.
The Company will take all steps reasonably necessary to ensure that your data is treated securely and in accordance with this Privacy Notice and no transfer of your Personal Data will take place to an organization or a country unless there are adequate controls in place including the security of your data and other personal information.
When you share personal information (e.g. by posting comments, contributions or other content to the sites) or otherwise interact with public areas of the Site such personal information may be viewed by all users and may be publicly distributed outside the Site.
If you interact with other users of our Sites and register through a social network your contacts on the social network will see your name, profile photo, and descriptions of your activity. Similarly, other users will be able to view descriptions of your activity, communicate with you within our Sites, and view your profile.
RETENTION OF YOUR PERSONAL DATA
We will retain your Personal Data only for as long as is necessary for the purposes set out in this Privacy Notice. We will retain and use your Personal Data to the extent necessary to comply with our legal obligations as per the Data Protection Act, resolve disputes, and enforce our legal agreements and internal policies. All your information will be kept in line with our data retention policy.
We will also retain Usage Data for internal analysis purposes. Usage Data is generally retained for a shorter period, except when this data is used to strengthen the security or to improve the functionality of our Service, or we are legally obligated to retain this data for longer time periods.
When we have no ongoing legitimate business need to process your personal information, we will either delete or anonymize it in accordance with our internal data deletion policies, or, if this is not possible, we will securely store your personal information and isolate it from any further processing until deletion is possible.
USE OF YOUR PERSONAL DATA
We will use your personal data for the following purposes:
- To communicate with you.
- To enable us to administer, process and service our products and services for you.
- To comply with legal or regulatory requirements.
- To improve our products and services.
- To send you marketing and promotional material where you have provided consent.
- To request feedback.
- To track and analyse sales performance, distribute commissions and manage clawbacks.
- To enhance security and safety on premises, including preventing and detecting crime and safeguarding sta and visitors.
- To carry out checks using third party agencies or publicly available information.
- For fraud prevention and detection.
- If appropriate, we may also pass on your personal information to financial crime prevention agencies and any legal, regulatory or government bodies.
- For certain products or services, we’ll need to process your sensitive personal data, such as information relating to health.
- We may share your data with third party vendors, service providers, contractors or agents who perform services for us or on our behalf and require access to such information perform their services. We will not share, any of your information with third parties for their promotional purposes or any without your consent.
- Keeping your information on record as well as carrying out other internal business purposes.
MANAGEMENT OF USAGE DATA
The Company may use Usage Data for the following purposes:
- To provide and maintain our site/service including to monitor its usage.
- To manage your registration as a user of the Service. The Personal Data you provide can give you access to different functionalities of the Service that are available to you as a registered user
- To contact You by email, telephone calls, SMS, or other equivalent forms of electronic communication, such as a mobile application’s push notifications regarding updates or informative communications related to the functionalities, products or contracted services, including the security updates, when necessary or reasonable for their implementation.
- To provide you with news, special offers and general information about other services and events which we offer that are similar to those that you have already purchased or enquired about unless You have opted not to receive such information
- To attend to and manage Your requests to Us
- To contact you by email, telephone calls, SMS, or other equivalent forms of electronic communication, such as a mobile application’s push notifications regarding updates or informative communications related to the functionalities, products or contracted services, including the security updates, when necessary or reasonable for their implementation.
We may share your personal information with Service Providers to monitor and analyze the use of our Service, to show advertisements to you to help support and maintain our Service, to contact you, to advertise on third party websites to you after you visited our Service or for payment processing.
RETENTION OF YOUR PERSONAL DATA
We will retain your Personal Data only for as long as is necessary for the purposes set out in this Privacy Policy. We will retain and use your Personal Data to the extent necessary to comply with our legal obligations as per the Data Protection Act, resolve disputes, and enforce our legal agreements and internal policies. All your information will be kept in line with our data retention policy.
We will also retain Usage Data for internal analysis purposes. Usage Data is generally retained for a shorter period, except when this data is used to strengthen the security or to improve the functionality of Our Service, or we are legally obligated to retain this data for longer time periods.
When we have no ongoing legitimate business need to process your personal information, we will either delete or anonymize it, or, if this is not possible we will securely store your personal information and isolate it from any further processing until deletion is possible.
YOUR RIGHTS (INCLUDING EXERCISE OF RIGHTS BY MINORS)
You have legal rights under the Data Protection Act in relation to your personal information.
Upon making such a request, we may ask you for proof of identity to exercise any of these rights. We take these measures to verify the recipient's identity before disclosing any information.
Your rights include:
- Being informed about how your personal data is used.
- Accessing your personal data.
- Objecting to the processing of all or part of your personal data. Where you request to withdraw consent for use of your personal data, we may not be able to provide certain products and services to you of which you will be notified upon your request.
- To request correction of false or misleading data about yourself.
- To request deletion of false or misleading data about yourself.
- Requesting us to erase your personal information.
- Right to data portability.
- Contesting decisions based on automated decision making.
- The option to refuse/withdraw consent to receive marketing/promotional material.
If you want to exercise any of your rights as stated above, please contact our Data Protection team by either emailing them at complianceke@prudentiallife.co.ke or writing to the Data Protection Officer, Ground Floor, Vienna Court, State House Crescent Road, Nairobi.
We, Prudential Life Assurance Kenya and the Prudential Group will send you information including marketing material you may have subscribed to, by text, email, telephone, post or other means about our products and services.
DISCLOSURE OF YOUR PERSONAL DATA
We will be compelled to disclose your personal data without informing you or requesting for specific consent under the following circumstances:
- If we are involved in a merger, acquisition or asset sale, your Personal Data may be transferred. We will provide notice before your Personal Data is transferred and becomes subject to a different Privacy Policy
- Under certain circumstances, the Company may be required to disclose your Personal Data if required to do so by law or in response to valid requests by public authorities (e.g. a court or a government agency).
- We may disclose your Personal Data in the good faith if such action is necessary to: Comply with a legal obligation , protect and defend the rights or property of the Company, Prevent or investigate possible wrongdoing in connection with the Service, protect the personal safety of Users of the Service or the public and/or protect against legal liability
SECURITY OF YOUR PERSONAL DATA
We are committed to ensuring the security and protection of your personal data through the execution of appropriate policies and procedures to protect all your personal information held by us. We have implemented and maintain appropriate, reasonable technical and organisational measures designed to prevent the loss of, damage to, or unauthorised destruction of personal information, and unlawful access to or processing of personal information.
The security of your Personal Data is important to us but no method of transmission over the Internet, or method of electronic storage is 100% secure. While we use commercially acceptable means to protect and secure your Personal Data, we cannot guarantee its absolute security. Please note to access our sites within a secure environment.
Our site may contain links to other websites that are not operated by us. If you click on a third-party link, you will be directed to that third party’s site. We strongly advise you to review the Privacy Policy of every site you visit.
We have no control over and assume no responsibility for the content, privacy policies or practices of any third-party sites or services.
CHILDREN’S PRIVACY
We do not knowingly collect personally identifiable information from children (any person under 18 years of age). If you are a parent or guardian and you are aware that your child provided us with Personal Data, please contact us via complianceke@prudentiallife.co.ke. If we become aware that we have collected Personal Data from children without verification of parental consent, we take steps to remove that information from our database.
By using our site, you represent that you are at least 18 or that you are the parent or guardian of such a minor and consent to such minor use of the Site.
CHANGES TO THIS PRIVACY POLICY
We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on our website
If we make a material change to the policy, we will let you know via notice on Our website, prior to the change becoming effective and update the “Last updated” date at the top of this Privacy Policy.
You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page.
CONTACT US
If you have any questions, comments, complaints or requests regarding this Privacy Notice and to exercise the aforementioned rights regarding the processing of your personal data, please contact our Data Protection team by either emailing them at complianceke@prudentiallife.co.ke or by post at Prudential Life Assurance Kenya, Ground Floor, Vienna Court, State House Crescent Road, P.O Box 25363-00100, Nairobi, Kenya.