DACORIS

Compliance & Trust

A configurable compliance-support framework for data protection, research governance, information security and institutional accountability.

Important compliance statement

DACORIS CRIS supports compliance; it does not automatically make an institution compliant. Legal and regulatory accountability remains shared according to the roles of the institution, DACORIS, authorised users and relevant third parties. Configuration, contracts, operating procedures, training and actual user behaviour are all essential.

3.1 Data protection and privacy

For Kenyan deployments, DACORIS CRIS is intended to be operated consistently with the Data Protection Act, 2019 and the Data Protection (General) Regulations, 2021, together with applicable guidance issued by the Office of the Data Protection Commissioner. Where processing falls within the territorial scope of the European Union General Data Protection Regulation, appropriate GDPR obligations should be addressed through the applicable contract, data-processing agreement, configuration and operating procedures.

Purpose limitation and data minimisation: collect and use only the information needed for defined research-management, contractual, security and support purposes.

Transparency: provide clear notices to researchers, staff, students and other data subjects about what is collected, why it is processed, who receives it and how long it is retained.

Role clarity: define whether the institutional customer acts as data controller and DACORIS acts as data processor, or whether another role allocation applies to a particular service.

Rights handling: provide operational channels for access, correction, objection, restriction, deletion and portability requests, subject to applicable legal limitations and institutional obligations.

Privacy by design and default: configure access, retention, visibility and data flows around the sensitivity and purpose of each information category.

Data protection impact assessment: support institutional assessment before high-risk processing, large-scale sensitive-data processing or significant integration is introduced.

Cross-border safeguards: document data-hosting locations, subprocessors and lawful transfer mechanisms where personal data moves between jurisdictions.

3.2 Research governance and ethics

DACORIS CRIS can be configured to support institutional scientific and ethical review workflows, research licensing evidence, approval records, amendment tracking, expiry monitoring and research-governance reporting. In Kenya, research licensing and ethical review requirements may arise under the Science, Technology and Innovation framework and guidance administered by the National Commission for Science, Technology and Innovation. The platform should be configured to the institution's approved research policies and the requirements applicable to the relevant discipline, population and data category.

Ethics applications, decisions, conditions, certificates, amendments, renewals and expiry dates.

Links between ethics approval, project records, investigators, study sites, datasets and outputs.

Controls for sensitive research, including restricted access and additional approval steps where required.

Regulatory and funder documentation, including research licences, data-management plans, consent documentation, material-transfer records and reporting obligations where applicable.

Full audit history for submissions, reviews, decisions and authorised changes.

3.3 Information security controls

Control domain

Operational approach

Identity and access

Unique user accounts, role-based permissions, least-privilege access and configurable approval authority.

Authentication

Support for strong authentication controls and, where agreed, institutional single sign-on and multi-factor authentication.

Encryption

Encryption in transit and appropriate encryption at rest, subject to the selected hosting architecture and implementation agreement.

Auditability

Logging of important user and administrative actions to support accountability, investigation and control testing.

Secure development

Change control, code review, dependency management, testing, vulnerability remediation and controlled release processes.

Availability and resilience

Backups, recovery procedures, environment monitoring, capacity planning and business-continuity arrangements aligned to the service tier.

Incident response

Documented escalation, containment, investigation, recovery and notification processes, including contractual and legal notification duties.

Third-party risk

Due diligence, contractual safeguards and ongoing review for hosting providers, integrations and subprocessors.

Data lifecycle

Configurable retention, archival, export and secure deletion processes aligned to institutional policy and legal requirements.

3.4 Standards alignment and certification claims

DACORIS CRIS may use recognised information-security and privacy principles, including controls associated with ISO/IEC 27001, as a reference framework for governance and continuous improvement. This statement is not a claim that DACORIS CRIS, DACORIS Group or any specific hosting environment is certified to ISO/IEC 27001 or any other standard. Any certification claim must be supported by a valid, current certificate that identifies the certified scope and legal entity.

3.5 Institutional compliance features

Configurable workflows, stage gates and segregation of duties.

Approval histories and audit trails that preserve who did what and when.

Deadline, renewal, expiry and reporting reminders.

Controlled document repositories linked to the relevant grant, project, student, ethics or partnership record.

Role-specific dashboards and exception reports for overdue actions and incomplete requirements.

Data exports and reporting tools for authorised institutional, funder and regulatory reporting.

Configurable data residency, hosting and integration choices subject to technical feasibility and contract.

3.6 Customer responsibilities

Each institutional customer remains responsible for defining lawful purposes, providing required notices, identifying lawful bases, approving access roles, maintaining accurate records, obtaining approvals and consents where required, training users, responding to data-subject requests, setting retention rules and ensuring that the platform configuration reflects institutional policy and applicable law. DACORIS should provide the agreed technical and organisational measures, documentation, support and contractual commitments necessary for the selected service.