Privacy Policy

Data Privacy Policy

Lucy Bridge Private Limited Company

Last updated: August 19, 2026

Glossary

DPOData Protection Officer
DPAData Processing Agreement
ICTInformation Communication Technology
ITInformation Technology
PIIPersonally Identifiable Information

Definitions

AnonymizationThe process of altering personal data so that it can no longer be associated with an identified or identifiable individual.
CompanyMeans Lucy Bridge PLC, a legal entity incorporated under Ethiopian law, duly licensed to operate in Ethiopia
ConsentAny freely given, specific, informed, and unambiguous indication by which a data subject signifies agreement to the processing of their personal data.
Data BreachA confirmed or suspected incident leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data transmitted, stored, or otherwise processed.
Data ControllerA person or entity that determines the purposes and means of processing personal data. For the purposes of this Policy.
Data ProcessorA person or entity that processes personal data on behalf of the Data Controller under a contractual or legal obligation.
Data Protection OfficerThe individual appointed by the Company to oversee compliance with data protection laws and this Policy.
Data RetentionThe period during which personal data is stored by the Company in active or archived systems before being securely disposed of in accordance with legal and regulatory requirements.
Data SubjectAny natural person whose personal data is collected, held, or processed by the Company or its agents.
EncryptionA technical measure that converts data into a coded format to prevent unauthorized access or disclosure.
Personal DataAny information relating to an identified or identifiable natural person ("data subject"); an identifiable person is one who can be identified directly or indirectly by reference to identifiers such as a name, identification number, location data, online identifier, or factors specific to physical, physiological, mental, economic, cultural, or social identity.
ProclamationThe Personal Data Protection Proclamation No. 1321/2024
ProcessingAny operation or set of operations performed on personal data, including collection, recording, organization, storage, adaptation, alteration, retrieval, consultation, use, disclosure, transmission, dissemination, alignment, combination, restriction, erasure, or destruction.
Third Party RecipientAny entity or person, other than the data subject, the Data Controller, or the Data Processor, to whom personal data is disclosed or made available.
Sensitive Personal DataPersonal data revealing racial or ethnic origin, political opinion, religious or philosophical beliefs, trade union membership, health or biometric data, sexual orientation, or other data that require enhanced protection under the Proclamation.

General Policy Statement

This Data Privacy Policy (the "Policy") aims to establish a comprehensive framework for the lawful, fair, and transparent collection, processing, use, retention, and disposal of personal data handled by the Company in the course of its operations as an investment Company service provider.

This Policy Operationalizes the obligation towards of data protection, ensuring that the Company`s system, technological tools, and data management practices respect the privacy right of clients, employees, counterparties, and other stakeholders. In particular this Policy seeks to:

  • Safeguard personal data from unauthorized access, disclosure, alteration, or destruction.
  • Promote accountability and transparency in all personal data processing activities.
  • Strengthen compliance with applicable data protection legislation, regulatory directives, and international best practices.
  • Build and sustain the confidence of clients, investors, and regulators in the Company's data protection and information governance framework.

Scope

The Policy applies to:

  • All Personal Data collected, processed, or stored by the Company, whether in electronic, paper, or any other format.
  • All employees, officers, directors, consultants, agents, contractors, service providers, and third parties who have authorized access to the Company's information systems or handle personal data on its behalf.
  • All business units, subsidiaries, and branches of the Company, including joint ventures and outsourced functions where the Company remains the Data Controller.
  • All information systems, databases, and digital platforms developed, procured, or used by the Company in delivering capital market services, advisory, or investment Companying operations.

The provisions of this Policy extend to all jurisdictions in which the Company operates and shall apply equally to data collected both within and outside the Federal Democratic Republic of Ethiopia, subject to applicable data transfer restrictions.

Objective

The objective of this Policy is to:

  • Ensure Legal and Regulatory Compliance: To align the Company's data handling practices with the applicable laws.
  • Protect Data Confidentiality, Integrity, and Availability: To prevent unauthorized access, misuse, loss, or destruction of personal data through robust technical and organizational safeguards.
  • Promote Ethical Data Practices: To embed data privacy and protection principles in the Company's corporate culture, ensuring that employees act with integrity and accountability in handling client and stakeholder information.
  • Enable Sustainable Digital Transformation: To ensure that all technological systems, tools, and applications deployed by the Company are designed and implemented with privacy considerations integrated by design and by default.
  • Support Effective Supervision and Oversight: To provide a framework for monitoring compliance, reporting breaches, and ensuring continuous improvement of data protection controls.

Data Collection and Processing

  • The Company recognizes that Personal Data is a protected asset and shall implement governance, risk management, and internal control measures to ensure integrity, confidentiality, and accountability in all data processing operations.
  • The Company shall ensure that all Personal Data collection, processing, storage, and transfer activities are carried out lawfully, fairly, and transparently. The Company adopts a Privacy by Design and by Default approach to data management, ensuring that privacy considerations are integrated into every stage of its business and technology lifecycle.
  • The Company shall maintain detailed privacy notices, ensuring disclosure at the point of data collection.
  • Personal Data shall be collected only for specified, explicit, and legitimate purposes directly related to the Company's operational, compliance, or regulatory functions. The data shall not be further processed in a manner incompatible with those original purposes unless explicitly authorized by law or with the data subject's informed consent.
  • The Company shall ensure that the Personal Data collected is adequate, relevant, and limited to what is necessary for the intended purpose.
  • Data collection mechanisms, forms, and digital systems shall be periodically reviewed.
  • The Company shall take reasonable steps to ensure that Personal Data is accurate, complete, and kept up to date. Where inaccuracies are identified, corrective measures shall be applied without delay, and Data Subjects shall be provided with accessible channels to request rectification.
  • Personal Data shall be retained only for as long as necessary to fulfill the purpose for which it was collected, or as required by law, regulation, or contractual obligation. Data exceeding its retention period shall be securely deleted or anonymized.
  • The Company shall process Personal Data using appropriate technical and organizational safeguards to prevent unauthorized access, alteration, disclosure, or destruction.
  • The Company shall be fully accountable for its data processing activities and demonstrate compliance with the principles set forth in this Policy.
  • Sensitive personal data shall be subject to heightened protection standards.

The Company shall ensure that all processing of personal data:

  • Has a clear and lawful basis as prescribed under the Personal Data Protection Proclamation or other relevant laws.
  • Is fair to the data subject, ensuring no undue disadvantage or harm.
  • Is transparent, providing the data subject with clear and accessible information on how their data is collected, used, and retained.

Security measures shall include:

  • Access control protocols and user authentication mechanisms.
  • Encryption of data at rest and in transit.
  • Secure storage and controlled transmission procedures.
  • Regular information security audits.

Accountability shall be operationalized through

  • The appointment of a Data Protection Officer
  • Maintenance of detailed processing records
  • Regular data protection impact assessments
  • Continuous monitoring and reporting to the Compliance Committee and the Board.

The Company shall collect and process sensitive personal data only when:

  • Explicit consent is obtained from the data subject.
  • Processing is required by law or necessary for compliance with legal obligations.
  • It is necessary to protect the vital interests of the data subject or others.

Cross Border Data Transfer

Personal Data shall not be transferred outside Ethiopia unless adequate protection measures are in place and the transfer complies with applicable data protection laws. Before any cross-border transfer, the Company shall:

  • Verify that the destination jurisdiction provides adequate data protection safeguards.
  • Execute data transfer agreements with receiving entities.
  • Obtain regulatory clearance where required.

Data Classification, Handling, and Security Controls

The Company shall ensure that all personal and confidential information processed by the Company is identified, classified, and protected according to its level of sensitivity, regulatory importance, and business criticality.

Data Classification Framework

The Company shall adopt a formal Data Classification Framework to categorize all data assets into specific protection levels based on their sensitivity and potential impact if disclosed, altered, or destroyed.

Classification LevelDescriptionAccess Restriction
Public DataInformation intended for public disclosure with no adverse impact on the Company or clients if shared.No restriction
Internal DataInformation meant for internal use, where unauthorized disclosure could cause limited operational impact.Restricted to staff
Confidential DataInformation whose unauthorized disclosure could cause reputational, financial, or legal damage.Restricted to authorized business units
Highly Confidential/ Restricted DataInformation subject to strict legal or regulatory protection, including personal data, financial account details, or trade secrets.Access limited to specifically authorized personnel with multi-factor authentication

The DPO shall oversee the classification process and ensure that each business unit maintains an updated data inventory and classification register.

Data Handling and Protection Principles

  • Personal and confidential data shall be stored only in approved systems, databases, or physical locations.
  • All electronic data in transit or at rest shall be encrypted using strong cryptographic standards.
  • Paper-based records shall be securely stored in locked cabinets and protected against unauthorized access or environmental risks.
  • All user accounts shall be authenticated through secure credentials and, where feasible, multi-factor authentication.
  • Access rights shall be reviewed quarterly and revoked immediately upon employee transfer, termination, or role change.
  • Client data shall be logically or physically segregated from system and administrative data to prevent cross-access or inadvertent disclosure.
  • Third-party systems integrated with the Company's infrastructure must ensure equivalent segregation and security standards.
  • All data processing activities shall be logged in audit trails that capture user IDs, access timestamps, and actions performed.
  • System logs shall be retained for a minimum of two (2) years or longer where required by relevant authority.
  • Log data shall be regularly reviewed to detect and investigate unauthorized or suspicious activities.
  • Backups shall be encrypted and stored offsite in secure, access-controlled environments.

Data Security Controls

  • Firewalls, intrusion detection systems, and intrusion prevention systems shall be implemented and monitored continuously.
  • Vulnerability assessments and penetration tests shall be conducted semi-annually.
  • Security patches and system updates shall be applied in accordance with the Company's IT Security Maintenance Schedule.
  • Data loss prevention tools shall be deployed to prevent unauthorized transfer of sensitive information.
  • Employees shall be granted access to systems only after completing mandatory data protection training.
  • Each department shall assign a Data handling officer responsible for monitoring adherence to classification and handling standards.
  • Security incidents shall be immediately reported to the Information Security Officer and DPO through the established Incident Reporting Procedure.

Data Breach Response and Notification

  • Any suspected or actual data breach shall be reported immediately to the DPO and Chief Compliance Officer through the Company's internal breach reporting system.
  • The DPO shall conduct a preliminary assessment within 24 hours of notification to determine the scope, nature, and potential impact of the breach.
  • Appropriate measures shall be taken to contain the breach, isolate affected systems, and prevent further data loss.
  • IT team led by the DPO shall be activated to investigate root causes and document findings.
  • Where a breach poses a risk to data subjects' rights or freedoms, the DPO shall notify the relevant authority within 72 hours of becoming aware of the incident.
  • Affected Data Subjects shall also be notified without undue delay, including guidance on protective measures they may take.
  • A comprehensive post-incident review shall be conducted to identify control weaknesses, implement corrective actions, and update the Company's Incident Response Plan.
  • All breaches and resolutions shall be recorded in the Data Breach Register maintained by the DPO.
  • Regular internal audits shall be conducted to assess compliance with this policy and data protection laws.
  • External audits may be commissioned periodically to validate the robustness of the Company's privacy and security controls.
  • Findings and recommendations shall be reported to the Compliance Committee for oversight and corrective follow-up.

Data Retention and Disposal

The Company shall ensure it retains personal data only for as long as necessary to fulfill the purposes for which it was collected, in compliance with applicable laws and regulatory requirements, and disposes of data securely to prevent unauthorized access, use, or disclosure.

Data Retention

  • Personal Data shall be retained only for the period necessary to fulfill the specific purposes for which it was collected, including legal, regulatory, and contractual obligations.
  • For key categories of data, minimum retention periods shall be defined in accordance with applicable laws, industry standards, and internal risk assessments.
  • Retention periods shall be periodically reviewed to ensure that data no longer required for operational, regulatory, or legal purposes is identified for secure disposal.
  • All retention periods and the rationale for their duration shall be documented in the Company's data inventory and retention schedule.

Data Disposal

  • Personal data no longer required shall be disposed of securely using methods appropriate to the data format.
  • Disposal procedures shall ensure that Personal Data cannot be reconstructed, retrieved, or restored.
  • Data required to be retained for legal, regulatory, or investigative purposes shall be exempted from standard disposal procedures.
  • Data required to fulfill ongoing contractual obligations or operational purposes may be retained beyond the standard retention period, subject to approval from DPO.
  • IT teams shall implement technical and procedural measures for secure deletion or destruction of data.

Third-Party Data Sharing and Cross-Border Transfers

The Company shall establish controls and procedures governing the sharing, transfer, and processing of Personal Data by third parties, including cross border data transfers.

Third party data sharing principles shall include:

  • Personal Data shall only be shared with third parties when a lawful basis exists, including contractual necessity, legal obligation, client consent, or legitimate business interest consistent with applicable laws.
  • Prior to engaging any third-party service provider or partner that may process Personal Data on behalf of the Company, comprehensive due diligence shall be conducted to assess their data protection policies and practices, technical and organizational safeguards for data privacy and security, compliance history with relevant data protection and cyber security standards.
  • All third parties engaged in data processing must enter into a formal DPA with the Company that clearly defines the scope, nature, and purpose of data processing, obligations of both the Company and the third party.
  • Third-party access to Personal Data shall be strictly limited to authorized personnel with a defined business need. Such access must be controlled, monitored, and periodically reviewed.

6.3. Any transfer of Personal Data outside Ethiopia shall comply with the conditions and safeguards stipulated under the Personal Data Protection Proclamation No. 1321/2024 and other relevant legal instrument.

6.4. Cross border data transfers shall only occur to jurisdictions that ensure an adequate level of data protection as determined by the relevant authority.

6.5. All international data transfers shall be documented in a Data Transfer Register, maintained by the DPO, including details of the receiving entity, location, purpose, and legal basis for transfer.

6.6. In case of a data breach involving transferred data, the third party must notify the Company immediately and cooperate in containment, investigation, and notification procedures as required by law.

Training and Awareness

  • The Company recognizes that data protection and privacy compliance depend on the continuous awareness and competence of all staff, contractors, and service providers.
  • The Company shall conduct awareness activities that includes periodic email reminders, intranet updates on emerging data privacy issues, department level refresher sesshins led by the DPO and IT team. And compliance alerts and e-learning modules for remote staff.
  • Attendance and completion of all training sessions shall be recorded and monitored by the Human Resources and Compliance Departments.
  • The DPO shall evaluate the effectiveness of training programs annually and recommend updates based on regulatory changes or audit findings.

Training shall be mandatory for:

  • All employees upon hiring and annually thereafter.
  • Members of the Board and Executive Management.
  • IT and compliance personnel handling Sensitive Data.
  • Third-party service providers with access to Personal Data.

Training modules shall include, but not be limited to:

  • Core principles of the Proclamation
  • The Company's internal data protection policies and procedures
  • Data Subject rights and procedures for handling requests
  • Secure data handling, transfer, and retention practices
  • Data breach identification and reporting
  • Roles and responsibilities of each unit under this Policy

Roles and Responsibilities

Effective implementation of this Policy requires clear allocation of roles and accountability across all governance levels of the Company. The following structure establishes defined responsibilities for oversight, execution, and compliance.

Executive Management

Executive Management shall be responsible for operationalizing the Board's directives on data protection. It shall:

  • Integrate data protection principles into all business processes, systems, and new product development initiatives ("Privacy by Design").
  • Ensure all business units adhere to this Policy and related procedures.
  • Allocate adequate financial, human, and technical resources to maintain compliance and security controls.
  • Support the DPO, IT, and Compliance functions in implementing corrective measures following audit or breach investigations.
  • Report significant data protection incidents to the Board through the Compliance Committee within prescribed timelines.

Data Protection Officer

The DPO is the central authority responsible for coordinating and overseeing the implementation of this Policy. The DPO shall:

  • Monitor the Company's overall compliance with data protection laws, regulations, and internal policies.
  • Advise management on obligations under the relevant laws
  • Maintain the Data Protection Register, including records of processing activities, cross-border transfers, and consents.
  • Oversee and coordinate responses to data subject requests and data breaches.
  • Prepare periodic compliance and performance reports to the Compliance Committee and the Board.

8.4 Compliance Unit

The Compliance Unit shall:

  • Support the DPO in implementing this Policy and ensure alignment with the Company's compliance framework.
  • Conduct periodic compliance reviews and follow up on remediation of identified deficiencies.
  • Collaborate with Internal Audit and IT Security to verify the adequacy and effectiveness of technical and organizational measures.
  • Facilitate staff training and certification programs in coordination with HR and the DPO.
  • Maintain a compliance incident register covering privacy and security breaches.

Information Technology (IT) & Information Security Division

The IT and Information Security Division shall:

  • Implement and maintain appropriate technical controls, including encryption, access management, vulnerability assessment, and secure system configurations.
  • Conduct semi-annual vulnerability and penetration tests as required by the applicable law.
  • Ensure secure configuration of data storage, transmission, and disposal systems.
  • Promptly notify the DPO and Compliance Function of any actual or suspected data breach.
  • Support Privacy-by-Design assessments for new technological tools or system upgrades prior to deployment.

Business Units and Employees

All employees, contractors, and business units shall:

  • Comply with the principles and procedures set out in this Policy.
  • Ensure data is collected, processed, stored, and transmitted strictly for lawful and authorized purposes.
  • Immediately report any data breach, loss, or misuse to the DPO or Compliance Function.
  • Complete mandatory privacy and data protection training annually.

Third-Party Service Providers

Third-party service providers who process data on behalf of the Company shall:

  • Enter into written DPAs defining their data protection obligations.
  • Implement equivalent security and confidentiality standards to those applied by the Company.
  • Promptly report any data incident involving the Company's information.
  • Submit to periodic data protection audits by or on behalf of the Company.

Compliance, Monitoring, and Governance

The Company shall maintain a structured oversight framework to ensure continuous compliance with applicable data protection laws and the internal controls prescribed under this Policy.

Oversight and Reporting Structure

  • The Board of Directors shall provide overall strategic oversight and receive quarterly reports on data protection performance and any breaches.
  • The Compliance Committee shall act as the primary governance body responsible for reviewing the adequacy of the Policy, monitoring its implementation, and evaluating reports submitted by the DPO and Internal Audit.
  • The DPO shall provide a semi-annual compliance report to the Compliance Committee, summarizing audits, incidents, data subject requests, and improvement measures.
  • Internal Audit shall conduct annual audits of data privacy practices and controls to independently verify compliance and effectiveness.

9.2 Compliance Monitoring

  • Routine monitoring shall be carried out jointly by the DPO, Compliance Function, and IT Security teams to ensure adherence to policy requirements.
  • Metrics shall include breach frequency, training completion rates, consent accuracy, and access control audits.
  • Findings from monitoring activities shall be documented and submitted to the Compliance Committee for review and corrective action.
  • Corrective and preventive action plans shall be tracked to completion under the oversight of the DPO.

9.3 Breach Reporting and Escalation

  • All actual or suspected data breaches shall be immediately reported to the DPO and Compliance Function.
  • The DPO shall assess each incident and, where applicable, notify the relevant authority and affected Data Subjects within the prescribed timeframes by law.
  • Root cause analyses shall be performed for every material breach, and remedial actions documented in the incident register.

9.4 Internal Audit and Review

  • Internal Audit shall perform independent reviews of this Policy and associated controls at least once per year.
  • Audit results shall be presented to the Compliance Committee and Board, with recommendations for improvement.
  • The DPO and Compliance Function shall ensure that all audit recommendations are implemented within agreed timelines.

9.5 Policy Review and Continuous Improvement

  • This Policy shall be reviewed at least annually or earlier where regulatory or operational changes occur.
  • The review process shall be led by the DPO in collaboration with the Compliance Function and IT Security Division.
  • Amendments to the Policy shall require approval by the Compliance Committee and final endorsement by the Board.
  • Lessons learned from breaches, audits, or regulatory updates shall inform periodic revisions and staff training enhancements.

Questions about this document?

Reach LucyBridge at hello@lucybridgeacademy.com.

Contact us