Legal & Policies
Privacy Policy & Data Protection Notice
How FIPS collects, uses, stores, shares and protects the personal data of all data subjects.
Preamble
The Festari Institute of Professional Studies (FIPS) recognises that the personal data entrusted to it by applicants, students, alumni, employees, lecturers, partners, employers, sponsors, website visitors and other stakeholders is held under a duty of confidence, care and lawful purpose. This Privacy Policy and Data Protection Notice (hereinafter "this Policy" or "this Notice") sets out, in plain language and in compliance with the Data Protection Act, 2012 (Act 843) of the Republic of Ghana, how FIPS collects, uses, stores, shares, transfers, protects, retains and disposes of personal data.
FIPS is a Ghanaian-registered Technical and Vocational Education and Training (TVET) institution currently seeking accreditation from the Commission for Technical and Vocational Education and Training (CTVET), and a member of the Festari Group of Companies. It delivers programmes independently and in collaboration with international awarding bodies including the Institute for Professional and Executive Development United Kingdom (iPED UK), the World Safety Organization (WSO), the CPD Standards Office (UK) and The CPD Group (UK). The processing of personal data is essential to the lawful discharge of these institutional functions.
FIPS, in its capacity as a Data Controller registered (or in the process of registration) with the Data Protection Commission of Ghana, commits unreservedly to the eight (8) data protection principles set out in section 17 of the Data Protection Act, 2012:
- Accountability: FIPS takes responsibility for personal data in its custody and demonstrates compliance with this Act.
- Lawfulness of processing: FIPS processes personal data only on lawful grounds expressly permitted by law.
- Specification of purpose: Personal data is collected for explicit, specified and legitimate purposes communicated at the point of collection.
- Compatibility of further processing with purpose of collection: Personal data is not further processed in a manner incompatible with the original purpose.
- Quality of information: Personal data is kept accurate, complete and up-to-date.
- Openness: FIPS maintains documentation of its processing activities and makes this Policy publicly available at fips.ac.
- Data security safeguards: Appropriate technical and organisational measures are implemented to protect personal data.
- Data subject participation: Data subjects can access, rectify, restrict, port, object to and (where applicable) erase their personal data.
This Policy is a public-facing instrument and a binding internal standard. It supplements, and does not replace, the Data Protection and Privacy chapter (Chapter 10) of the FIPS Student Handbook, which remains the operational reference for student records. Where there is any inconsistency between this Notice and any other internal FIPS document, this Notice prevails on matters of data protection and privacy.
Disclosure of AI-Assisted Drafting: In accordance with FIPS's commitment to transparency, the Institute discloses that this Policy was drafted with the assistance of artificial intelligence tools used as a research, structuring and authoring aid, under the editorial supervision and final approval of the Executive Director, the Registrar and the Institute's Legal Advisor. The substantive content, legal positions and institutional commitments expressed herein are those of FIPS.
Questions concerning this Policy should be directed to the Data Protection Officer at the address provided in Section 18.
How to Use this Notice
This Notice is organised so that any reader can quickly find the provisions that apply to them. The guidance below explains how to navigate this document:
- All Data Subjects: Read Sections 1 (Preliminary), 2 (Roles), 10 (Your Rights), 11 (Security), 18 (How to Contact Us / Complain) and the relevant retention entries in Schedule A.
- Applicants and Prospective Students: In addition, read Sections 3.1, 5.1, 14 (Marketing) and 15 (Children's Data) if you are or are applying on behalf of a minor.
- Enrolled Students: Read Sections 3.2, 5.2, 7 (Sharing with iPED UK, WSO, CPD), 8 (International Transfers), 13 (LMS and Online Services) and 17 (Image and Photography).
- Alumni: Read Sections 3.3, 5.3, 9 (Retention), and 14 (Marketing).
- Employees, Lecturers and Contractors: Read Sections 3.4 and 5.4 alongside the FIPS HR Policy.
- Website Visitors and Online Service Users: Read Section 13 (Website, Cookies and Online Services).
- Employers, Sponsors and Verification Requestors: Read Sections 3.6, 5.6 and 7.
- Vendors, Processors and Auditors: Read Sections 2.3, 7.4 and 8.
Defined terms: Words written with an initial capital letter (e.g. "Data Subject", "Data Controller", "Processor", "Personal Data", "Special Category Data") carry the meanings assigned in Section 1.7 (Definitions). Where this Notice refers to a statute by short title, the full citation is given on first use and the short title thereafter.
Statutory references: All references to statutes are to the laws of the Republic of Ghana, namely: the Data Protection Act, 2012 (Act 843) (hereinafter "the Act"); the Cybersecurity Act, 2020 (Act 1038); the Electronic Transactions Act, 2008 (Act 772); the Copyright Act, 2005 (Act 690); and the Education Regulatory Bodies Act, 2020 (Act 1023) as may be applicable.
Exercising your rights: To make a Data Subject Rights Request, use the form at Schedule C or write to dpo@fips.ac. There is no charge for a standard request. FIPS responds within thirty (30) calendar days of receiving a valid request, as required by section 35 of the Act.
1. PRELIMINARY PROVISIONS
1.1 Title and Citation
This instrument shall be known and may be cited as the "Festari Institute of Professional Studies (FIPS) Privacy Policy and Data Protection Notice" (hereinafter "this Policy" or "this Notice").
1.2 Issuing Authority
This Policy is issued by the Office of the Executive Director of the Festari Institute of Professional Studies (FIPS), with the approval of the Board of Directors of the Festari Group of Companies, pursuant to the institution's data governance framework and in conformity with the Data Protection Act, 2012 (Act 843) of the Republic of Ghana.
1.3 Effective Date
This Policy takes effect on 1 January 2026 and supersedes any prior data protection or privacy notice or statement published or issued by FIPS. Personal data already in the custody of FIPS at the effective date shall, from that date, be processed in accordance with this Policy.
1.4 Purpose
The purposes of this Policy are to:
- Inform every Data Subject, in clear language, of how FIPS processes their personal data;
- Discharge FIPS's statutory obligation of openness under section 17(f) and section 30 of the Act;
- Establish a single, institution-wide standard of data protection practice for all FIPS staff, lecturers, consultants, processors and partners;
- Set out the rights of Data Subjects and the practical procedures for exercising those rights;
- Document the lawful bases on which FIPS relies for each category of processing;
- Specify the retention period applicable to each category of personal data; and
- Provide a contact point for data protection enquiries, requests and complaints.
1.5 Scope
This Policy applies to:
- All personal data, in any format (paper, electronic, audio, image, biometric), collected or processed by FIPS in connection with its institutional activities;
- All categories of Data Subjects, including but not limited to applicants, students, alumni, employees, lecturers, contractors, consultants, website visitors, employers, sponsors, regulators, vendors and visitors to FIPS premises;
- All processing operations carried out by FIPS itself or by any third party acting as a Processor on behalf of FIPS;
- All physical locations from which FIPS operates, including its head office in Tarkwa, satellite delivery centres, training venues and online platforms; and
- All cross-border transfers of personal data initiated or received by FIPS.
1.6 Legal Basis
This Policy is made pursuant to and shall be interpreted in accordance with:
- Data Protection Act, 2012 (Act 843): the principal statute governing the protection of personal data in Ghana;
- 1992 Constitution of the Republic of Ghana: Article 18(2), which guarantees the right to privacy;
- Cybersecurity Act, 2020 (Act 1038): governing the protection of critical information infrastructure and incident reporting;
- Electronic Transactions Act, 2008 (Act 772): governing electronic records, signatures and communications;
- Education Regulatory Bodies Act, 2020 (Act 1023): in the context of regulatory reporting to CTVET;
- Children's Act, 1998 (Act 560): in the context of personal data of minors;
- Companies Act, 2019 (Act 992): in the context of records of officers, members and statutory filings;
- Subsidiary legislation, directives and guidelines issued by the Data Protection Commission and other competent authorities from time to time.
1.7 Definitions
In this Policy, the following terms have the meanings set out below. Other terms have the meanings ascribed to them by the Act:
"Applicant" means a person who has submitted an application for admission to a programme of FIPS, whether or not the application has been accepted.
"Awarding Body" means an external accrediting or qualification-awarding organisation with which FIPS has a formal collaboration, including iPED UK, WSO, the CPD Standards Office (UK) and The CPD Group (UK).
"Data Controller" means a person or entity who, alone or jointly with others, determines the purposes and means of processing personal data. FIPS is the Data Controller in respect of all processing described in this Policy unless expressly stated otherwise.
"Data Processor" or "Processor" means a person or entity that processes personal data on behalf of FIPS, including cloud service providers, payment processors, examination platforms and other vendors.
"Data Protection Commission" or "DPC" means the Data Protection Commission of Ghana established under section 1 of the Act.
"Data Protection Officer" or "DPO" means the person designated by FIPS as the focal point for data protection matters in accordance with section 58 of the Act.
"Data Subject" means an identifiable natural person whose personal data is processed by FIPS.
"Data Subject Rights Request" or "DSR" means a request by a Data Subject to exercise any of the rights conferred by Part Five of the Act.
"Personal Data" means data about an individual who can be identified from that data, or from that data and other information in the possession of, or likely to come into the possession of, FIPS.
"Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed.
"Processing" means any operation or activity, whether automated or not, concerning personal data, including collection, recording, organisation, structuring, storage, adaptation, retrieval, consultation, use, disclosure, dissemination, alignment, combination, restriction, erasure or destruction.
"Special Personal Data" has the meaning given in section 96 of the Act and includes information about a Data Subject's race, colour, ethnic or tribal origin, religious or philosophical beliefs, political opinions, trade union membership, physical or mental health, sexual orientation, criminal behaviour, or the alleged commission of any offence.
"Working Day" means any day other than a Saturday, Sunday or public holiday in Ghana.
2. ROLES AND RESPONSIBILITIES
2.1 FIPS as Data Controller
FIPS is the Data Controller for all personal data processed in connection with its institutional functions. As Data Controller, FIPS is accountable for compliance with the Act and answerable to Data Subjects and to the Data Protection Commission for the lawfulness of its processing.
Where FIPS jointly determines the purposes and means of processing with another organisation (for example, an Awarding Body whose qualification framework prescribes the assessment data to be recorded), FIPS and that organisation are joint Data Controllers in respect of that specific processing, and their respective responsibilities are governed by the underlying collaboration agreement.
2.2 The Data Protection Officer (DPO)
FIPS has designated a Data Protection Officer in accordance with section 58 of the Act. The DPO is responsible for:
- Monitoring institution-wide compliance with the Act and this Policy;
- Advising the Executive Director, the Registrar, the Academic Board and operational managers on data protection matters;
- Serving as the primary point of contact for Data Subjects and the Data Protection Commission;
- Receiving, registering, investigating and responding to Data Subject Rights Requests;
- Coordinating Data Protection Impact Assessments (DPIAs) for high-risk processing;
- Maintaining the Record of Processing Activities (ROPA) summarised in Schedule B;
- Investigating and reporting Personal Data Breaches in accordance with Section 12 of this Policy; and
- Delivering and tracking data protection awareness training for FIPS personnel.
Contact details of the Data Protection Officer: Email: dpo@fips.ac | Postal: The Data Protection Officer, Festari Institute of Professional Studies, P.O. Box 237, Tarkwa, Western Region, Ghana | Telephone: +233 54 160 3237.
2.3 Data Processors and Sub-Processors
FIPS engages a limited number of third-party Processors to perform specific data-processing activities on its behalf (for example, payment processing, cloud storage, email delivery, examination administration and ICT support). Every Processor engaged by FIPS is required to:
- Enter into a written Data Processing Agreement with FIPS that complies with section 30 of the Act;
- Process personal data only on documented instructions from FIPS;
- Implement appropriate technical and organisational security measures equivalent to, or more stringent than, those required by Section 11 of this Policy;
- Notify FIPS without undue delay of any actual or suspected Personal Data Breach;
- Assist FIPS in responding to Data Subject Rights Requests;
- Return or securely destroy personal data at the end of the engagement;
- Not engage a sub-processor without the prior written authorisation of FIPS; and
- Submit to audits of their data protection practices.
A current list of FIPS's principal Processors and the purpose of each engagement is available on request from the Data Protection Officer.
3. CATEGORIES OF PERSONAL DATA COLLECTED
FIPS collects only such personal data as is necessary for its lawful purposes. The categories collected vary by Data Subject category, as set out below. FIPS does not collect personal data speculatively or "just in case".
3.1 Applicants and Prospective Students
FIPS may collect the following categories of personal data from applicants and persons making enquiries about programmes:
- Identification data: full name, date of birth, gender, nationality, national identification number (e.g. Ghana Card), passport or other government-issued identification details;
- Contact data: postal address, residential address, email address, mobile telephone number, emergency contact name and number;
- Educational background: schools attended, qualifications obtained, transcripts, certificates and supporting documentation;
- Employment background where relevant to admission: current employer, job title, years of experience;
- Financial data limited to admission: sponsor or self-funding declarations, scholarship applications;
- Application data: preferred programme, intake cycle, mode of study, personal statement;
- Photographic image: for identification on admitted-applicant records.
3.2 Enrolled Students
In addition to the data described in section 3.1, FIPS collects from enrolled students:
- Student index number and FIPS-issued account credentials;
- Programme registration data: courses, modules, electives, cohort and intake;
- Academic records: coursework, assessment scripts, marks, grades, transcripts, awards, classifications;
- Attendance records and class participation data;
- Disciplinary records and investigation files (where applicable);
- Financial records: fees paid, balances, instalment schedules, scholarships, receipts;
- ICT usage logs from FIPS systems including the Learning Management System (LMS);
- Medical fitness declarations limited to specific programmes where physical capacity is material (e.g. fieldwork or industrial-attachment placements);
- Health and safety records related to industrial visits, laboratory work and emergencies;
- Image and likeness data: student identity card photograph, classroom and event photography (subject to Section 17);
- Examination submissions and authorship metadata where automated proctoring or plagiarism-detection is used.
3.3 Alumni
On graduation or completion of a programme, the following data is retained or collected:
- Permanent academic record (transcripts, certificates, classification): retained as part of the academic archive;
- Updated contact details and current employment status (where voluntarily provided);
- Alumni-association membership data;
- Career-outcome data collected by employability tracer studies (only with consent and with the option to opt out);
- Certificate verification records.
3.4 Employees, Lecturers and Contractors
Personal data of FIPS employees, lecturers (full-time, part-time and visiting), administrators and contractors is processed under a separate FIPS Human Resources Privacy Notice. The principal categories are summarised here for completeness: identification and contact data, recruitment records, employment contract, qualifications and references, payroll and statutory deduction data, performance and disciplinary records, leave and attendance records, training records, health and safety records, and (where applicable) bank account details for salary payment. Detailed treatment of staff personal data is provided in the HR Privacy Notice issued under FIPS/HR/PRV/2026.
3.5 Website Visitors and Online Users
When you visit fips.ac or use any FIPS online service (including the LMS), FIPS may collect:
- Technical data: IP address, device type, operating system, browser type and version, referring URL, pages visited, time-on-page, click paths;
- Cookie data: strictly necessary cookies always; performance, functional and analytics cookies only with your consent (see Section 13.2);
- Form-submission data: any name, email, phone number or message you voluntarily enter into a contact, enquiry, application or feedback form;
- Account data: if you register for a FIPS online account, your account credentials, profile data and activity logs.
3.6 Employers, Sponsors and Verification Requestors
Where an employer sponsors a participant, or where a third party requests verification of a FIPS-issued qualification, FIPS may collect:
- Organisational data: name, registration number, business address, billing details;
- Contact-person data: name, job title, email, telephone number, of the individual representing the sponsoring or requesting organisation;
- Written authorisation from the data subject, where required (e.g. for transcript or certificate verification).
3.7 Visitors to FIPS Premises
Visitors to FIPS premises may be required to record their name, organisation, contact number, purpose of visit and time of arrival in the visitors' register. CCTV recordings of the premises are also processed in accordance with Section 16.
4. SOURCES OF PERSONAL DATA
Personal data processed by FIPS is obtained from the following sources:
- Directly from the Data Subject: at the point of enquiry, application, enrolment, employment, contracting or website interaction. This is the primary source for the great majority of personal data held by FIPS.
- From educational institutions previously attended: for the purpose of verifying transcripts, certificates and qualifications submitted in support of an application.
- From sponsoring employers: where an employer enrols a participant under a sponsorship arrangement and provides identification, qualification or contact data on the participant's behalf, in which case FIPS will require evidence of the participant's consent or another lawful basis.
- From referees: where the Data Subject has nominated a referee to support an application for admission, employment or scholarship.
- From Awarding Bodies: where examination results, certifications or registration confirmations are returned to FIPS by partner Awarding Bodies (iPED UK, WSO, CPD Standards Office, The CPD Group).
- From public sources: limited to publicly available information necessary to verify identity, accreditation, regulatory standing or commercial details of an organisation.
- From FIPS information systems: through the routine operation of the LMS, library system, finance system, CCTV and ICT logs.
Where personal data is obtained from any source other than directly from the Data Subject, FIPS shall, at the earliest practical opportunity and not later than the first communication with the Data Subject, inform the Data Subject of the source of the data, the categories of data held, the purpose of processing and the Data Subject's rights.
5. PURPOSES OF PROCESSING AND LAWFUL BASES
FIPS processes personal data only where it has a lawful basis under section 20 of the Act. The principal lawful bases relied upon by FIPS are: (i) the Data Subject's consent; (ii) performance of a contract to which the Data Subject is party or steps taken at the request of the Data Subject prior to entering into a contract; (iii) compliance with a legal obligation to which FIPS is subject; (iv) protection of the vital interests of the Data Subject or another natural person; (v) performance of a task carried out in the public interest; and (vi) the legitimate interests pursued by FIPS or by a third party, save where these are overridden by the rights and freedoms of the Data Subject.
The lists in the subsections below set out, for each category of Data Subject, the purpose of processing and the lawful basis on which FIPS relies.
5.1 Applicants and Prospective Students
- Receiving and processing applications for admission: performance of contract / pre-contractual steps;
- Verifying academic and identity credentials: legitimate interest in the integrity of admissions; legal obligation under CTVET admissions standards;
- Communicating with applicants about their application: performance of contract / pre-contractual steps;
- Sending information about programmes, intakes and open days the applicant has requested: consent;
- Maintaining unsuccessful-application files for institutional records and audit: legitimate interest, limited to the retention period in Schedule A;
- Statistical reporting (in aggregated, anonymised form) for institutional planning: legitimate interest.
5.2 Enrolled Students
- Administering the student's programme: performance of contract;
- Maintaining academic records, conducting assessments and issuing transcripts, certificates and awards: performance of contract; legal obligation under CTVET regulations and Awarding Body requirements;
- Managing fees, refunds and financial accounts: performance of contract; legal obligation under tax, accounting and audit law;
- Operating the LMS, library and ICT services: performance of contract; legitimate interest in service delivery and ICT security;
- Monitoring attendance and academic progress: performance of contract; legitimate interest in academic-standards assurance;
- Investigating misconduct and conducting disciplinary processes: legitimate interest; legal obligation;
- Safeguarding the health and safety of students on premises and during industrial visits: vital interest; legal obligation under occupational health and safety law;
- Communicating institutional notices, schedule changes and emergency announcements: legitimate interest;
- Reporting to CTVET and other regulators: legal obligation;
- Reporting to Awarding Bodies: performance of contract (between FIPS and the Data Subject, where the Data Subject has elected to pursue a partner-awarded qualification); legitimate interest.
5.3 Alumni
- Maintaining the permanent academic record: legal obligation; legitimate interest in archival integrity;
- Issuing duplicate or replacement transcripts and certificates on request: performance of contract;
- Verifying certificates to third-party verifiers (employers, regulators, foreign institutions): performance of contract; legitimate interest of the requester, subject to lawful access;
- Alumni-engagement communications, surveys and tracer studies: consent (alumni may opt out at any time);
- Fundraising or alumni-association activities: consent.
5.4 Employees, Lecturers and Contractors
- Recruitment, employment and contracting: performance of contract;
- Payroll, pension, tax and statutory-deduction processing: legal obligation;
- Performance management, training and development: legitimate interest;
- Workplace health and safety: legal obligation; vital interest;
- Disciplinary and grievance processes: legitimate interest;
- Investigations and audit: legitimate interest; legal obligation.
Further details are set out in the FIPS HR Privacy Notice.
5.5 Website Visitors and Online Users
- Operating the website and online services: legitimate interest in service delivery;
- Ensuring security and integrity of the website and online services: legitimate interest in cyber-security and lawful obligations under the Cybersecurity Act, 2020;
- Responding to enquiries and form submissions: pre-contractual steps or legitimate interest in customer service;
- Measuring and improving website performance with analytics cookies: consent;
- Delivering targeted marketing (where used): consent.
5.6 Employers, Sponsors and Verification Requestors
- Administering sponsorship and corporate-training arrangements: performance of contract;
- Invoicing, payment processing and financial reconciliation: performance of contract; legal obligation;
- Responding to certificate or transcript verification requests with the Data Subject's written authorisation: performance of contract / legal obligation;
- Maintaining a register of corporate clients: legitimate interest.
6. SPECIAL CATEGORY AND SENSITIVE PERSONAL DATA
Section 96 of the Act defines "Special Personal Data" as information about a Data Subject's race, colour, ethnic or tribal origin, religious or philosophical beliefs, political opinions, trade union membership, physical or mental health, sexual orientation, alleged commission of an offence, or criminal record.
FIPS minimises its processing of Special Personal Data. Where such data is processed, it shall be on one of the additional bases set out in section 25 of the Act, including:
- Explicit consent of the Data Subject, freely given for a specified purpose;
- Necessity for the establishment, exercise or defence of legal claims ;
- Necessity for the protection of vital interests where the Data Subject is physically or legally incapable of giving consent;
- Necessity for compliance with employment, social security or social-protection obligations ;
- Public interest, scientific, statistical or historical research subject to appropriate safeguards, including anonymisation where practical.
Typical and limited examples of Special Personal Data processed by FIPS are:
- Physical or mental health information voluntarily disclosed by a Data Subject in support of a request for reasonable adjustments, special examination arrangements or absence on medical grounds;
- Health and disability information necessary for the safe conduct of fieldwork, laboratory, industrial-attachment or practical components of a programme;
- Religious information disclosed in support of a request for examination accommodation on religious-observance grounds;
- Ethnic-origin information collected (where collected at all) for the purpose of equal-opportunities monitoring on an aggregated, anonymised basis;
- Information about an alleged or actual criminal offence, where relevant to a disciplinary process or to the safeguarding of other Data Subjects.
Special Personal Data is held under heightened access controls. Only the smallest practical number of authorised personnel has access. Such data is not shared with Awarding Bodies, employers or third parties except as expressly required and with the explicit consent of the Data Subject or as required by law.
7. DISCLOSURE AND SHARING OF PERSONAL DATA
FIPS discloses personal data to third parties only where a lawful basis applies and only to the minimum extent necessary. The principal categories of recipient are set out below.
7.1 Regulators and Statutory Bodies
FIPS shares personal data with regulators and statutory bodies where required to do so by law. These include:
- The Commission for Technical and Vocational Education and Training (CTVET): enrolment returns, programme reports, examination results and audit records;
- The Ghana Revenue Authority (GRA): tax-related reporting on employees, contractors and payments where required;
- The Social Security and National Insurance Trust (SSNIT): for employee social-security contributions;
- The Data Protection Commission: in connection with notifications, registration, audits and investigations;
- The National Cyber Security Authority: in connection with incident reporting under the Cybersecurity Act, 2020;
- Any other regulator, ministry or statutory authority lawfully entitled to receive the data.
7.2 Awarding Bodies and Partner Institutions
Where a Data Subject is registered for a programme leading to a qualification awarded by a partner Awarding Body, FIPS will share the personal data necessary for that body to register, assess and certify the Data Subject. The principal Awarding Bodies and the typical data shared are:
- Institute for Professional and Executive Development United Kingdom (iPED UK): full name, date of birth, identification number, contact details, programme registration data, assessment marks and certification outcomes.
- World Safety Organization (WSO): full name, contact details, programme registration data, examination results and certification status.
- CPD Standards Office (UK) / The CPD Group (UK): programme accreditation reports, participant numbers and (where applicable) certificate-issuance records.
Each Awarding Body is itself a Data Controller in respect of the data it receives and is subject to its own privacy notice and the data-protection laws of its jurisdiction. FIPS's collaboration agreements require Awarding Bodies to maintain data protection standards substantially equivalent to those imposed by the Act.
7.3 Payment, Financial and Audit Service Providers
To process fee payments, pay refunds and meet its financial-reporting obligations, FIPS shares limited personal data with:
- Banks and licensed payment-service providers: to process fee payments, instalments and refunds;
- Mobile-money operators: where mobile-money is used as a payment channel;
- External auditors (John Allotey & Associates and any successor firm): under a confidentiality undertaking and a Data Processing Agreement, for the sole purpose of statutory and management audit;
- Legal advisors (Lawyer John Wilmot Baidoo and any successor): in connection with the establishment, exercise or defence of legal claims.
7.4 Cloud, ICT and Software Providers
FIPS uses cloud-based and software-as-a-service tools to deliver its institutional functions. Each such provider operates as a Data Processor under a written agreement that requires compliance with this Policy and the Act. Categories of providers include:
- Cloud productivity and email platforms: for institutional email, document collaboration and file storage;
- Learning Management System (LMS) hosting providers: for delivery of online learning content, assessments and student communications;
- Website hosting and content-delivery providers: for the operation of fips.ac;
- Customer-relationship and admissions-management providers: for processing applications and enquiries;
- Cybersecurity, backup and ICT-support providers: for ICT operations, security monitoring and disaster recovery.
7.5 Employers, Sponsors and Reference Verifiers
FIPS shares personal data with employers, sponsors and reference verifiers only:
- With the express written authorisation of the Data Subject (for example, for transcript or certificate verification);
- In the case of corporate-sponsored participants, on the basis of the participant's acknowledged sponsorship contract; or
- In response to a lawful order or statutory request.
7.6 Law Enforcement and Legal Process
FIPS will disclose personal data to law-enforcement agencies, courts or other competent authorities where compelled to do so by law, by court order or by other lawful instrument. Where the law permits, FIPS will notify the affected Data Subject before disclosure, except where notification would prejudice the lawful purpose of the disclosure or contravene an order of court.
7.7 No Sale or Commercial Trading of Personal Data
FIPS does not sell, rent, lease, trade or otherwise commercialise personal data, and does not share personal data with advertisers, data brokers or third-party marketers. Any future change to this position would require an amendment to this Policy and fresh consent from affected Data Subjects.
8. INTERNATIONAL TRANSFERS OF PERSONAL DATA
Some of the third parties to whom FIPS discloses personal data are located outside the Republic of Ghana. These include, in particular, the United Kingdom (iPED UK, CPD Standards Office, The CPD Group), the United States (WSO and certain cloud and SaaS providers), and other jurisdictions in which cloud infrastructure is located.
FIPS transfers personal data outside Ghana only where one or more of the following conditions, set out in section 47 of the Act, is satisfied:
- The Data Subject has consented to the transfer after being informed of the destination and the protections that will apply;
- The transfer is necessary for the performance of a contract between FIPS and the Data Subject, or for the implementation of pre-contractual measures taken at the Data Subject's request: for example, registration with an Awarding Body to obtain a certified qualification;
- The transfer is necessary for the conclusion or performance of a contract concluded in the interest of the Data Subject between FIPS and a third party;
- The transfer is necessary for the establishment, exercise or defence of legal claims;
- The receiving country offers an adequate level of data protection; or
- FIPS and the recipient have entered into appropriate contractual safeguards, such as standard contractual clauses or binding corporate rules, that provide a level of protection equivalent to that required by the Act.
Where personal data is transferred to a country whose data protection regime FIPS considers may not be equivalent to that of Ghana, FIPS shall implement additional safeguards including encryption-in-transit, encryption-at-rest, pseudonymisation, and contractual restrictions on onward transfer. The Data Subject may obtain a copy of the relevant safeguards from the Data Protection Officer.
9. DATA RETENTION
FIPS retains personal data for no longer than is necessary for the purposes for which it is processed. The retention periods applicable to the principal categories of data are set out in Schedule A. The general principles are:
- Academic records: transcripts, certificates and course grades are retained permanently as part of the institutional academic archive, in keeping with longstanding practice in higher education and the need to issue replacements and verifications indefinitely.
- Admissions records of unsuccessful applicants: retained for two (2) years after the application cycle to which they relate, then deleted.
- Financial and tax records: retained for seven (7) years to comply with the Income Tax Act, 2015 (Act 896), Companies Act, 2019 (Act 992) and the requirements of statutory audit.
- Employment records: retained for the duration of employment and seven (7) years thereafter; statutory contribution records retained for the longer period mandated by the relevant social-security legislation.
- Disciplinary records: retained for five (5) years after the Data Subject's last date of enrolment or employment, unless the record relates to expulsion or dismissal, in which case retained permanently.
- Attendance records: retained for three (3) years after the student's last date of enrolment.
- CCTV recordings: retained for a period not exceeding thirty (30) days unless a recording is preserved as evidence in connection with an incident, in which case it is retained for the duration of the related proceedings and the applicable appeal period.
- Website logs and analytics: retained for not more than twelve (12) months in identifiable form; aggregated, anonymised statistics may be retained indefinitely.
- Marketing-list data: retained for as long as consent remains current, and reviewed at least every twenty-four (24) months.
At the end of the applicable retention period, personal data is securely destroyed or anonymised. Paper records are cross-shredded; electronic records are deleted using methods that prevent reconstruction; back-up media are securely overwritten or destroyed in accordance with the institution's ICT Disposal Procedure.
10. DATA SUBJECT RIGHTS
10.1 The Eight Statutory Rights
Subject to the conditions and limitations set out in Part Five of the Act, every Data Subject has the following rights in respect of personal data held by FIPS:
- Right of access: to be informed whether FIPS holds personal data about you, to receive a description of the data and the purposes of processing, and to obtain a copy of the data.
- Right to rectification: to require correction of personal data that is inaccurate, misleading, incomplete or out-of-date.
- Right to erasure: to require deletion of personal data where it is no longer necessary for the purpose for which it was collected; where the processing is unlawful; where you have withdrawn consent and no other lawful basis exists; or where erasure is required for compliance with a legal obligation. The right of erasure is subject to FIPS's overriding obligations to retain academic records (see Section 9) and certain financial and disciplinary records.
- Right to restrict processing: to require FIPS to limit processing while accuracy or lawfulness is being verified.
- Right to object: to object to processing carried out on the basis of legitimate interests or for direct-marketing purposes.
- Right to data portability: to receive personal data you have provided to FIPS in a structured, commonly used and machine-readable format, and to have that data transmitted to another controller where technically feasible.
- Right to withdraw consent: where processing is based on consent, to withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
- Right to lodge a complaint: with the Data Protection Commission of Ghana (see Section 18).
10.2 How to Make a Request
A Data Subject Rights Request should be submitted using the form at Schedule C, by email to dpo@fips.ac, by post to the address at Section 2.2, or in person at the FIPS administration office. The request should:
- Identify the Data Subject clearly;
- Specify which right is being exercised;
- Provide enough information for FIPS to locate the personal data concerned;
- Where requesting rectification, specify the correction required and provide supporting evidence;
- Provide a contact channel (email or postal) for FIPS's response.
10.3 Verification of Identity
FIPS will take reasonable steps to verify the identity of the requester before disclosing personal data or making changes to records. This is to protect Data Subjects against fraudulent or impersonated requests. Acceptable forms of verification include the Ghana Card, passport, driver's licence, or, in the case of an enrolled student or alumnus, the FIPS student index number together with a matching email address of record.
10.4 Response Time
FIPS will respond to a valid Data Subject Rights Request within thirty (30) calendar days of receipt, as required by section 35 of the Act. Where a request is particularly complex or where the requester has made multiple related requests, FIPS may extend the response period by a further period not exceeding sixty (60) calendar days, and will notify the requester of the extension and the reasons for it within the original thirty-day period.
10.5 Fees
There is no charge for a standard Data Subject Rights Request. Where requests are manifestly unfounded, excessive or repetitive, FIPS may either charge a reasonable administrative fee reflecting the cost of compliance, or refuse to act on the request, in each case with a statement of reasons.
10.6 Limits to Rights
Data Subject rights are not absolute. FIPS may decline a request, in whole or in part, where:
- Compliance would disclose personal data of another individual whose rights would thereby be prejudiced and whose consent has not been obtained;
- Compliance is inconsistent with a legal obligation to which FIPS is subject (including the obligation to retain academic records);
- The request relates to data already lawfully held in the public interest, including academic archives, where erasure or anonymisation would defeat the legitimate purpose of the archive;
- The request relates to data necessary for the establishment, exercise or defence of legal claims;
- The request is manifestly unfounded or excessive.
Where FIPS declines a request, the Data Subject shall be informed in writing of the refusal, the reasons for the refusal, and the right to lodge a complaint with the Data Protection Commission.
11. SECURITY OF PERSONAL DATA
FIPS implements appropriate technical, organisational and physical measures to protect personal data against unauthorised access, accidental loss, destruction or alteration, in accordance with section 28 of the Act and good ICT security practice.
11.1 Technical Measures
- Role-based access controls over institutional information systems, applying the principle of least privilege;
- Password complexity standards, periodic password rotation, and multi-factor authentication on all administrator and finance accounts;
- Encryption-at-rest for institutional databases that hold student, financial or staff personal data, where supported by the platform;
- Encryption-in-transit (HTTPS/TLS) for all personal-data communications over public networks;
- Regular backup of electronic data, with backup integrity testing;
- Patch management and vulnerability assessment of ICT systems;
- Endpoint protection (anti-malware and host-based monitoring) on staff devices that access personal data;
- Logging and monitoring of access to information systems holding personal data, with periodic review of logs for anomalies;
- Secure deletion routines for personal data at the end of its retention period.
11.2 Organisational Measures
- Designation of a Data Protection Officer with institution-wide oversight;
- A written Information Security Policy and Acceptable Use Policy applicable to all staff, lecturers and contractors;
- Confidentiality undertakings in employment contracts and contractor agreements;
- Mandatory data protection awareness training at induction and at least annually thereafter;
- Written Data Processing Agreements with every external Processor;
- A Personal Data Breach Response Procedure setting out detection, containment, escalation, notification and lessons-learned steps;
- Periodic internal review of compliance with this Policy.
11.3 Physical Measures
- Locked filing cabinets and limited-access record stores for paper records;
- Restricted access to server rooms and ICT facilities;
- CCTV surveillance of public areas of the premises in accordance with Section 16;
- Visitor registration and supervised access to non-public areas;
- Secure on-site disposal (cross-shredding) of paper records at the end of the retention period.
No system can be guaranteed to be completely secure. Where, despite these measures, a Personal Data Breach occurs, FIPS shall act in accordance with Section 12 below.
12. PERSONAL DATA BREACH MANAGEMENT
In the event of an actual or suspected Personal Data Breach, FIPS shall, in accordance with section 31 of the Act:
- Contain the incident at the earliest practical opportunity to prevent further unauthorised disclosure, alteration or loss of personal data;
- Assess the nature, scope, categories of data subjects affected, approximate number of records, likely consequences and the risk to the rights and freedoms of affected Data Subjects;
- Notify the Data Protection Commission as soon as reasonably practicable and in any event without undue delay after the Institute becomes aware of the breach, providing the information prescribed under the Act;
- Notify affected Data Subjects without undue delay, where the breach is likely to result in a high risk to their rights and freedoms, by email, telephone or other available channel, with information about the nature of the breach, the likely consequences and the steps being taken to mitigate them;
- Where applicable, notify the National Cyber Security Authority under the Cybersecurity Act, 2020 and any Awarding Body, Processor or partner whose data or systems are affected;
- Document the breach, the response and the lessons learned in a Breach Register maintained by the Data Protection Officer;
- Take such corrective measures as are necessary to prevent recurrence.
Where a breach occurs at a Processor, FIPS's contractual arrangements require the Processor to notify FIPS without undue delay so that FIPS can discharge its obligations under this Section.
13. WEBSITE, COOKIES, AND ONLINE SERVICES
13.1 The FIPS Website (fips.ac)
FIPS operates a public-facing website at fips.ac for the dissemination of information about its programmes, news and policies, and for the receipt of enquiries and applications. The website processes personal data in accordance with Section 3.5 and the lawful bases set out in Section 5.5.
13.2 Cookies and Similar Technologies
A "cookie" is a small text file placed on your device when you visit a website. FIPS uses the following categories of cookies on fips.ac:
- Strictly necessary cookies: required for the website to function (e.g. session continuity, security tokens). These cookies are always set and cannot be refused without disabling features of the website. Lawful basis: legitimate interest.
- Functional cookies: remember user preferences (e.g. language). Lawful basis: consent.
- Analytics cookies: measure aggregated usage of the website to inform improvements. Lawful basis: consent.
- Marketing cookies: used (where used at all) to deliver content of relevance. Lawful basis: consent.
On first visit, fips.ac displays a cookie-consent notice that allows the visitor to accept all cookies, reject all non-essential cookies, or choose preferences by category. Consent may be withdrawn at any time by reopening the cookie preferences from the footer of the website. Cookies set with consent shall not be retained for longer than is necessary for their stated purpose.
13.3 Analytics
Where FIPS uses third-party analytics providers (such as privacy-preserving open-source or commercial analytics tools), it does so on the following basis:
- Analytics are configured to anonymise or truncate IP addresses where supported by the provider;
- Analytics data is processed for the purpose of measuring aggregated usage and improving the website, and not for individual-level profiling;
- Analytics scripts are loaded only after the visitor consents through the cookie banner.
13.4 Learning Management System (LMS)
The FIPS LMS processes personal data of enrolled students for the purpose of delivering instructional content, conducting assessments, recording participation and providing feedback. The LMS is hosted by a third-party Processor under a written Data Processing Agreement that complies with section 30 of the Act. Activity logs generated by the LMS (course access times, assessment submissions, communications) are processed on the basis of performance of contract and legitimate interest in academic-standards assurance.
13.5 Social Media Pages
FIPS maintains pages on selected social media platforms for the purpose of public communication about its activities. Each social media platform is itself a Data Controller in respect of data it collects from visitors to its platform, and its privacy practices are governed by its own privacy policy. FIPS processes the limited data it sees about its followers (such as comments and direct messages) on the basis of legitimate interest in maintaining a public-communication channel.
13.6 Third-Party Links and Embeds
fips.ac may contain links to, or embedded content from, third-party websites (for example, video platforms used to host instructional videos, or partner Awarding Body websites). FIPS does not control these third parties and is not responsible for their privacy practices. Data Subjects should review the privacy notices of those third parties before interacting with their content.
14. MARKETING COMMUNICATIONS AND CONSENT
FIPS may send marketing or programme-information communications by email, SMS, WhatsApp or other channel to:
- Applicants and prospective students who have requested information about programmes;
- Enrolled students, in respect of programmes related to those for which they are already enrolled (on the basis of an existing relationship);
- Alumni who have consented to alumni-engagement communications;
- Employers and sponsors who have engaged with FIPS for corporate training.
Marketing communications are conducted on the following terms:
- Opt-in: for non-existing relationships, consent is obtained before the first marketing communication.
- Opt-out: every marketing communication contains a clear, simple mechanism (an unsubscribe link or "STOP" reply) by which the recipient can withdraw consent.
- Frequency: FIPS calibrates the volume of marketing communications to be reasonable and not intrusive.
- Suppression: recipients who opt out are suppressed from future marketing lists, but the suppression record itself is retained to give effect to the opt-out.
FIPS does not send unsolicited marketing communications to persons with whom it has no prior relationship, except where they have voluntarily provided contact details with their consent.
15. CHILDREN'S DATA
In accordance with the Children's Act, 1998 (Act 560), a "child" means a person under the age of eighteen (18) years.
Where an applicant or registered student is a child:
- A parent or legal guardian must consent in writing to the application and to the processing of personal data for the purposes set out in this Policy;
- Communications regarding the child's admission, enrolment, fees, attendance and academic progress shall be addressed to the parent or guardian as well as to the child;
- Special Personal Data of a child shall be processed only where strictly necessary and only with the written consent of the parent or guardian;
- Marketing communications shall not be directed at a child;
- Photographs and images of a child shall be processed only with the express written consent of the parent or guardian, and shall not be used in marketing materials without such consent.
Where it comes to the attention of FIPS that personal data of a child has been collected without parental or guardian consent in circumstances where such consent was required, FIPS shall delete the data promptly upon becoming aware of the position, unless there is an overriding lawful basis to continue processing.
16. CCTV AND PREMISES SURVEILLANCE
FIPS operates closed-circuit television (CCTV) surveillance at its premises for the purposes of:
- Safeguarding the safety of students, staff, visitors and property;
- Preventing, detecting and investigating crime and serious misconduct;
- Providing evidence in disciplinary, insurance or legal proceedings.
CCTV processing is governed by the following safeguards:
- CCTV cameras are sited in public and common areas only. They are not installed in toilets, changing areas, prayer rooms, counselling rooms or other places where Data Subjects have a reasonable expectation of privacy;
- Visible signage informs persons entering the premises that CCTV is in operation and identifies the Data Controller;
- Access to live and recorded footage is restricted to a small number of authorised personnel under the supervision of the Head of Operations and the Data Protection Officer;
- Routine footage is retained for not more than thirty (30) days and then automatically overwritten, unless preserved as evidence in an active incident;
- Footage is not shared with third parties except in response to a lawful request from law enforcement or under court order, in which case the disclosure is logged in the CCTV Disclosure Register.
A Data Subject may request access to CCTV footage in which they appear by submitting a Data Subject Rights Request in accordance with Section 10. Where compliance would prejudice the rights of third parties whose images also appear in the footage, FIPS may redact or refuse the request to that extent.
17. PHOTOGRAPHY, VIDEO AND USE OF IMAGE
From time to time, FIPS records still photographs and video footage of classes, practical sessions, graduations, sporting events, industrial visits and other institutional activities, for documentary, accreditation, archival, educational and promotional purposes.
The following principles apply:
- At enrolment, each Data Subject is informed that photography and video recording may take place at institutional activities and is asked to indicate whether they consent to the use of their image for promotional and external-communications purposes;
- Consent is recorded and can be withdrawn at any time; withdrawal applies prospectively and does not require the recall of materials already published in good faith;
- Where consent has not been given for promotional use, the Data Subject's image shall not be used in marketing or external publications without their fresh, specific written consent;
- Where a Data Subject is a child, the consent of a parent or legal guardian is required (see Section 15);
- Recording of examinations, assessment sessions and disciplinary hearings is governed by separate Academic Regulations and the FIPS Code of Conduct, and is not authorised under this Policy.
18. COMPLAINTS, ENQUIRIES AND THE DATA PROTECTION COMMISSION
FIPS welcomes feedback and seeks to resolve complaints quickly and constructively. Data Subjects who wish to raise an enquiry, exercise a right or lodge a complaint about FIPS's handling of personal data should contact:
| Contact Point | Details |
| Data Protection Officer | Email: dpo@fips.ac | Postal: P.O. Box 237, Tarkwa, Western Region, Ghana | Tel: +233 54 160 3237 |
| Registrar | Email: registrar@fips.ac | For escalation if a DPO response is not received within thirty (30) days. |
| Executive Director | Email: director@fips.ac | For final internal escalation. |
A Data Subject who is dissatisfied with FIPS's response, or who wishes to bypass the internal process, has the right to lodge a complaint directly with the Data Protection Commission of Ghana, the independent regulator established under the Act:
| Contact Point | Details |
| Data Protection Commission of Ghana | Address, telephone and email of the Commission are published at the Commission's official website. Data Subjects are advised to consult the Commission's current contact details before lodging a complaint, as these are updated by the Commission from time to time. |
Nothing in this Policy limits a Data Subject's right to seek a judicial remedy in the courts of Ghana.
19. CHANGES TO THIS POLICY
FIPS keeps this Policy under regular review and will update it from time to time to reflect changes in law, regulatory guidance, institutional practice or technology. The current version is identified by the version number and effective date set out on the cover page and in Schedule D.
Where a change is material: meaning a change that affects the rights of Data Subjects, the categories of data processed, the purposes of processing or the recipients of disclosure: FIPS shall:
- Publish the revised Policy on fips.ac;
- Notify enrolled students and active staff of the change through institutional channels;
- Where the change is based on a new lawful basis requiring consent, obtain fresh consent before relying on that basis.
Non-material changes (corrections of typographical or formatting errors, updates to contact details, clarifications that do not affect substance) may be made without notification. A complete version history is maintained at Schedule D.
20. GOVERNING LAW
This Policy is governed by, and shall be construed in accordance with, the laws of the Republic of Ghana. The courts of Ghana have exclusive jurisdiction in respect of any matter arising out of or in connection with this Policy, without prejudice to:
- The supervisory jurisdiction of the Data Protection Commission under the Act;
- The dispute-resolution arrangements that may apply to a Data Subject's separate contract with FIPS (such as the FIPS Terms of Service and Refund Policy, document reference FIPS/GOV/TOS/2026/v1.0); and
- The rights of Data Subjects to pursue remedies in the courts of any other jurisdiction with which they have a sufficient connection and in which a recipient of a cross-border transfer is established.
SCHEDULE A: DATA RETENTION SCHEDULE
This Schedule sets out the retention period applicable to each principal category of personal data held by FIPS. Retention periods may be extended where required by law, by an ongoing investigation or by the establishment, exercise or defence of legal claims.
| Category of Data | Retention Period | Trigger / Basis |
| Applications: unsuccessful applicants | 2 years after application cycle | Then deleted; audit-trail summary may be retained in aggregated form |
| Applications: admitted applicants | Merged with student record | See "Student academic records" below |
| Student academic records (transcripts, certificates, grades, awards) | Permanent | Institutional academic archive; needed to issue replacements and verifications indefinitely |
| Student attendance records | 3 years after last date of enrolment | Then securely destroyed |
| Student disciplinary records (non-expulsion) | 5 years after last date of enrolment | Then securely destroyed |
| Student disciplinary records (expulsion) | Permanent | Linked to academic record |
| Student financial records (fees, refunds, receipts) | 7 years | Income Tax Act, 2015 (Act 896); Companies Act, 2019 (Act 992); audit requirements |
| Medical fitness declarations | Duration of programme + 5 years | Then securely destroyed |
| Health and safety incident records | 7 years | Statutory and insurance requirements |
| LMS activity logs | Duration of programme + 1 year | Then anonymised |
| Alumni contact data | Until withdrawal of consent or no contact for 5 years | Whichever is earlier |
| Career-outcomes / tracer-study data | Per study cycle + 3 years | Then anonymised for longitudinal research |
| Employee records: current employee | Duration of employment | - |
| Employee records: after end of employment | 7 years from end of employment | Statutory tax and pension records may be retained longer where required |
| Recruitment records of unsuccessful candidates | 1 year from end of recruitment | Then securely destroyed |
| CCTV recordings | 30 days | Unless preserved as evidence for an active incident |
| Visitor register entries | 6 months | Then securely destroyed |
| Website logs and analytics (identifiable) | 12 months | Aggregated, anonymised statistics may be retained indefinitely |
| Cookie-consent records | 24 months | Or until withdrawn |
| Marketing-consent records | 24 months from last activity | Then re-consent requested or contact removed |
| Marketing opt-out / suppression records | Permanent | To give effect to the opt-out |
| Data Subject Rights Request records | 3 years from closure of request | - |
| Personal Data Breach records | 7 years from closure of incident | Data Protection Commission requirements |
| Vendor / processor Data Processing Agreements | Duration of engagement + 7 years | Audit and statutory limitation periods |
SCHEDULE B: RECORD OF PROCESSING ACTIVITIES (ROPA): SUMMARY
FIPS maintains, in accordance with section 27 of the Act, a Record of Processing Activities ("ROPA") which documents in detail every processing activity carried out by, or on behalf of, the Institute. The full ROPA is held by the Data Protection Officer and is provided to the Data Protection Commission on request. This Schedule sets out a summary of the principal processing activities for public reference.
| # | Processing Activity | Categories of Data Subject | Lawful Basis |
| 1 | Admissions and applications management | Applicants | Pre-contractual steps; legitimate interest |
| 2 | Student records and academic administration | Enrolled students | Performance of contract; legal obligation |
| 3 | Assessment, examinations and certification | Enrolled students; Awarding Bodies | Performance of contract; legal obligation |
| 4 | Fees, refunds and financial administration | Students; sponsors | Performance of contract; legal obligation |
| 5 | Learning Management System operation | Enrolled students; lecturers | Performance of contract; legitimate interest |
| 6 | Library and learning-resource administration | Students; staff | Performance of contract; legitimate interest |
| 7 | Industrial attachment and placement | Students; host employers | Performance of contract; consent |
| 8 | Disciplinary processes and investigations | Students; staff | Legitimate interest; legal obligation |
| 9 | Alumni engagement and tracer studies | Alumni | Consent |
| 10 | Marketing and prospect communications | Prospective applicants; alumni | Consent |
| 11 | Recruitment of staff and contractors | Job applicants | Pre-contractual steps; consent |
| 12 | Employment administration and payroll | Employees; contractors | Performance of contract; legal obligation |
| 13 | Health and safety management | Students; staff; visitors | Legal obligation; vital interest |
| 14 | Website operation and analytics | Website visitors | Legitimate interest; consent |
| 15 | CCTV surveillance | Persons entering FIPS premises | Legitimate interest; legal obligation |
| 16 | Photography, video and institutional communications | Students; staff; visitors | Consent; legitimate interest |
| 17 | Certificate verification and reference handling | Alumni; verification requestors | Consent of Data Subject; legitimate interest of requester |
| 18 | Regulatory and statutory reporting | Students; staff | Legal obligation |
| 19 | Audit (statutory and quality) | All categories, as relevant | Legal obligation; legitimate interest |
| 20 | Personal Data Breach response and reporting | Affected Data Subjects | Legal obligation |
A full ROPA, including for each activity the purpose, retention period, categories of recipients, international transfers and security measures, is held by the Data Protection Officer in accordance with section 27 of the Act and is available for inspection by the Data Protection Commission on request.
SCHEDULE C: DATA SUBJECT RIGHTS REQUEST FORM
Use this form to exercise any of the rights listed in Section 10. Submit the completed form to dpo@fips.ac, by post to the Data Protection Officer at the address in Section 2.2, or in person at the FIPS administration office. There is no charge for a standard request.
Part 1: Identification of the Data Subject
| Full Name | |
| Date of Birth | |
| National ID / Passport Number | |
| Relationship to FIPS (Applicant / Student / Alumnus / Staff / Other) | |
| FIPS Student Index No. (if applicable) | |
| Email Address | |
| Telephone Number | |
| Postal Address |
Part 2: Right Being Exercised
Please tick the right(s) you wish to exercise:
- ☐ Right of access: to obtain a copy of the personal data FIPS holds about me
- ☐ Right to rectification: to correct inaccurate or incomplete data
- ☐ Right to erasure: to delete personal data (subject to lawful retention)
- ☐ Right to restrict processing: to pause processing pending verification
- ☐ Right to object: to processing on grounds of legitimate interest or for direct marketing
- ☐ Right to data portability: to receive my data in a portable format
- ☐ Right to withdraw consent: for processing based on consent
Part 3: Description of the Request
Please describe your request as specifically as possible (the records or data concerned, the correction required, the basis for objection, etc.):
Part 4: Verification of Identity
Please attach a copy of a government-issued identification document (Ghana Card, passport or driver's licence). FIPS may not disclose personal data without satisfactory verification of identity.
Part 5: Declaration and Signature
I declare that the information given in this form is true and complete and that I am the Data Subject named in Part 1 (or the duly authorised representative of that Data Subject, in which case proof of authority is attached).
| Signature of Data Subject | Date |
| Signature of Authorised Representative (if applicable) | Date |
FOR FIPS USE ONLY
| Date Received | |
| Reference Number | |
| Identity Verified By | |
| Response Due | |
| Outcome | |
| Closed By (DPO) |
SCHEDULE D: VERSION HISTORY AND APPROVAL
Version History
| Version | Effective Date | Summary of Changes |
| 1.0 | 1 January 2026 | Initial issue of the FIPS Privacy Policy and Data Protection Notice. Establishes the institution-wide data protection framework in accordance with the Data Protection Act, 2012 (Act 843). |
Document Control
| Document Reference | FIPS/GOV/PRV/2026/v1.0 |
| Document Owner | Office of the Executive Director, FIPS |
| Document Custodian | Data Protection Officer, FIPS |
| Reviewer (Operations & QA) | Mr. Sylvester Nana Awuah, Head of Operations and Quality Assurance |
| Reviewer (Academic) | Mr. Kofi Ntim Siaw, Head of Academics |
| Reviewer (Registry) | Mrs. Jemimah Offei Kunkyin-Saadaari, Registrar |
| Reviewer (Legal) | Lawyer John Wilmot Baidoo, Legal Advisor |
| Approver | Dr. Festus Kunkyin-Saadaari, Executive Director |
| Effective Date | 1 January 2026 |
| Review Cycle | Annual, or upon legislative change |
| Next Scheduled Review | 1 January 2027 |
| Classification | Public: Binding on FIPS and applicable to all Data Subjects |
| Distribution | fips.ac website; on request from the Data Protection Officer |
Approval
The persons named below have, by their signatures, approved this Policy for issue with effect from the Effective Date stated above:
| Name and Office | Signature and Date |
| Mr. Sylvester Nana Awuah Head of Operations and Quality Assurance | Signature: ___________________________ Date: _________________________________ |
| Mr. Kofi Ntim Siaw Head of Academics | Signature: ___________________________ Date: _________________________________ |
| Mrs. Jemimah Offei Kunkyin-Saadaari Registrar and Director (Co-Founder) | Signature: ___________________________ Date: _________________________________ |
| Lawyer John Wilmot Baidoo Legal Advisor | Signature: ___________________________ Date: _________________________________ |
| Dr. Festus Kunkyin-Saadaari Executive Director (Approver) | Signature: ___________________________ Date: _________________________________ |
Issued by the Office of the Executive Director, Festari Institute of Professional Studies (FIPS), Tarkwa, Western Region, Ghana. © Festari Institute of Professional Studies, 2026. Copyright Act 2005 (Act 690) of the Republic of Ghana applies.