Top

DATA PROTECTION ADDENDUM (DPA)

DATA PROTECTION ADDENDUM

QR Pay Africa Limited

Version 2.0  |  Effective: May 2026

Covering: QR Code Payments  | Remittance  |  Bill Payments

Multi-Jurisdictional: Africa | Asia | United States

PARTIES

This Data Protection Addendum ("DPA") forms part of and is incorporated into the Agreement (as defined below) between:

 

Processor / Independent Controller
EntityQR Pay Africa Limited
RoleData Processor and/or Independent Data Controller, as applicable
Registered inKenya (with operations across Africa, Asia, and the United States)
ServicesQR code payments, cross-border remittance, bill payments, merchant tooling, agent network management

 

Controller / Client
EntityThe Business Client, Merchant, Partner, or API Integrator
RoleData Controller
Referred to as"Client," "Controller," or "Business" throughout this DPA

 

By executing the Agreement or integrating with QR Pay Africa APIs, the Client agrees to be bound by this DPA.

 

1. DEFINITIONS

For purposes of this DPA, the following terms shall have the meanings set out below:

1.1 "Agreement" means the master services agreement, API integration agreement, merchant agreement, or other services contract between the Parties into which this DPA is incorporated.

1.2  "Applicable Data Protection Law" means all applicable privacy, data protection, cybersecurity, and financial data regulations in any jurisdiction in which QR Pay Africa or the Client operates or processes Personal Data, including but not limited to the laws enumerated in Schedule A of this DPA.

1.3  "Personal Data" means any information relating to an identified or identifiable natural person ("Data Subject"), including, without limitation, names, national identification numbers, biometric data, financial account details, mobile money identifiers, IP addresses, QR code transaction metadata, and geolocation data.

1.4  "Sensitive Personal Data" means a subset of Personal Data that warrants heightened protection, including biometric data, national identity numbers, financial account credentials, health data, and data relating to minors, as defined under applicable law in the relevant jurisdiction.

1.5  "Payment Data" means Personal Data processed in connection with a payment transaction, including QR code scan data, transaction amount, merchant/agent identifiers, mobile money numbers, bank account details, bill reference numbers, and remittance beneficiary details.

1.6 "Processing" means any operation performed on Personal Data, including collection, recording, storage, adaptation, retrieval, transmission, encryption, verification, fraud screening, reporting, and deletion.

1.7  "Data Controller" means the entity that determines the purposes and means of Processing Personal Data.

1.8  "Data Processor" means the entity that Processes Personal Data on behalf of a Data Controller under this DPA.

1.9 "Sub-Processor" means any third party engaged by QR Pay Africa to Process Personal Data in connection with the Services.

1.10  "Data Breach" means any confirmed breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data.

1.11 "Services" means QR code payment processing, cross-border remittance, bill payment collection, merchant settlement, agent network services, and related fintech products as described in the Agreement.

1.12  "Standard Contractual Clauses (SCCs)" means the data transfer mechanisms approved by applicable regulatory authorities to facilitate lawful cross-border transfers of Personal Data, including the EU Commission SCCs (2021), Kenya Office of the Data Protection Commissioner (ODPC) prescribed mechanisms, and equivalent frameworks in other jurisdictions.

 

2. ROLE OF THE PARTIES

2.1  QR Pay Africa as Independent Data Controller

QR Pay Africa acts as an Independent Data Controller when Processing Personal Data for its own legitimate purposes, including:

  • Regulatory compliance: Anti-Money Laundering (AML), Know Your Customer (KYC), Counter-Financing of Terrorism (CFT), and sanctions screening under financial regulation applicable in each market of operation.
  • Transaction monitoring and fraud prevention, including QR code abuse detection, duplicate payment detection, and agent fraud screening.
  • Remittance compliance, including beneficiary verification, correspondent banking due diligence, and cross-border transaction reporting.
  • Bill payment reconciliation and settlement with billers, utilities, and government agencies.
  • Regulatory reporting to financial intelligence units (FIUs), central banks, and data protection authorities.
  • Risk management, security monitoring, incident detection, and business continuity.

In such cases, QR Pay Africa determines the purpose and means of Processing independently and shall comply with all Applicable Data Protection Laws in its capacity as an Independent Controller.

 

2.2  QR Pay Africa as Data Processor

QR Pay Africa acts as a Data Processor when:

  • Processing transaction data on behalf of the Client through the QR payment infrastructure.
  • Providing API-based payment processing, settlement, or remittance services under Client instructions.
  • Hosting payment flows, digital wallets, or bill payment portals on behalf of the Client.
  • Processing data submitted by the Client's customers, merchants, or agents within QR Pay Africa's platform.

In such cases, the Client acts as the Data Controller and QR Pay Africa Processes Personal Data solely in accordance with the Client's documented instructions, subject to the terms of this DPA.

 

2.3  Joint Controllership

In circumstances where both Parties independently determine the purposes of Processing the same Personal Data (e.g., shared fraud prevention, shared transaction analytics), the Parties may be deemed Joint Data Controllers. The Parties agree to enter into a separate Joint Controller Agreement upon reasonable request, as required by applicable law.

 

3. APPLICABLE LEGAL FRAMEWORK

Given QR Pay Africa's operations across Africa, Asia, and the United States, this DPA is designed to comply with the multi-jurisdictional framework set out in Schedule A. The principal laws and frameworks include:

 

3.1  Africa

JurisdictionLaw / RegulationKey Obligations for QR Pay Africa
KenyaData Protection Act, 2019 & Regulations 2021Lawful basis, DPO appointment, data subject rights, cross-border transfer restrictions, breach notification to ODPC
NigeriaNigeria Data Protection Act (NDPA), 2023; NDPR 2019Data localisation obligations, mandatory DPO, NDPC registration, sensitive data rules
South AfricaProtection of Personal Information Act (POPIA), 2013 (eff. 2021)8 conditions of lawful processing, Information Officer, Data Subject rights, POPIA Section 72 transfer rules
GhanaData Protection Act, 2012 (amendments pending)Registration with DPC, lawful basis, consent, data minimisation, cross-border transfer controls
TanzaniaPersonal Data Protection Act, 2022Controller/processor obligations, consent, breach notification, data localisation for certain categories
UgandaData Protection and Privacy Act, 2019Lawful processing, data subject rights, PDPO registration, cross-border transfer conditions
RwandaLaw No. 058/2021 on Protection of Personal DataData subject rights, breach notification, controller obligations, cross-border rules
EgyptPersonal Data Protection Law No. 151 of 2020Consent, sensitive data rules, PDPA Authority oversight, cross-border transfer safeguards
BotswanaData Protection Act, 2024 (eff. January 2025)Enhanced processor obligations, sensitive data categories, higher penalties
RegionalAU Malabo Convention; ECOWAS Data Protection FrameworkRegional harmonisation obligations; cross-border transfer mechanisms within AU member states

 

3.2  Asia

JurisdictionLaw / RegulationKey Obligations for QR Pay Africa
SingaporePersonal Data Protection Act (PDPA) 2012, Amendment Act 2024DPO mandatory (eff. June 2025), data processor obligations (eff. April 2025), breach notification to PDPC, data transfer accountability
IndiaDigital Personal Data Protection (DPDP) Act, 2023 & Rules, 2025Consent-led processing, Significant Data Fiduciary obligations, DPO in India, cross-border transfer blacklist, breach notification to DPBI
ChinaPersonal Information Protection Law (PIPL), 2021; Data Security Law (DSL), 2021Data localisation, strict cross-border transfer conditions (CAC security assessment), Separate Consent, PIPL Article 38 transfer mechanisms
IndonesiaPersonal Data Protection Law (PDPL), 2022 (eff. 2024)Controller/processor obligations, consent, breach notification to BSSN, cross-border transfer agreements
MalaysiaPersonal Data Protection Act (PDPA) 2010, Amendment Act 2024DPO appointment, enhanced processor obligations, breach notification, cross-border transfer controls
ThailandPersonal Data Protection Act (PDPA), 2019 (eff. June 2022)Explicit consent for sensitive data, extraterritorial scope, DPIA requirement, data transfer adequacy
PhilippinesData Privacy Act (DPA), 2012; NPC CircularsNPC registration for processing systems, PIAs, DPO appointment, breach notification to NPC within 72 hrs
VietnamPersonal Data Protection Decree (PDPD) No. 13/2023Consent, data localisation for core/important data, cross-border transfer security assessment
JapanAct on Protection of Personal Information (APPI), 2022 amendmentsThird-party transfer rules, data subject rights, breach notification to PPC, sensitive data handling

 

3.3  United States

JurisdictionLaw / RegulationKey Obligations for QR Pay Africa
FederalGramm-Leach-Bliley Act (GLBA) & Safeguards Rule (amended 2023)Annual risk assessments, encryption, access controls, incident response, annual reporting to Board
FederalBank Secrecy Act (BSA) / FinCEN AML/CFT RulesSAR/CTR filing, customer due diligence (CDD), beneficial ownership, record retention
FederalFair Credit Reporting Act (FCRA)Limitations on use of consumer report data; dispute obligations
CaliforniaCalifornia Consumer Privacy Act (CCPA) / CPRA & 2025 RegulationsNo entity-level GLBA exemption; data subject rights; mandatory risk assessments & cybersecurity audits (eff. 2026-2027); ADMT restrictions
Multi-state20+ Comprehensive State Privacy Laws (VA, CO, CT, TX, OR, NJ, MN, etc.)Consumer rights (access, delete, correct, opt-out); GLBA entity/data-level exemptions vary by state; annual compliance review required
State (Financial)State Money Transmission Laws; MSB Registration RequirementsData handling as part of money transmission licensing conditions

 

4. SUBJECT MATTER AND CATEGORIES OF PERSONAL DATA

4.1  Categories of Personal Data Processed

In connection with QR code payments, remittance, and bill payment Services, QR Pay Africa may Process the following categories of Personal Data:

 

Identification Data

  • Full legal name, date of birth, nationality
  • National Identity Card (NIC), Passport, or equivalent government-issued document number
  • Biometric identifiers: fingerprint, facial recognition data (where used for KYC or QR authentication)

Contact and Account Data

  • Phone number (including mobile money-linked numbers: M-Pesa, Airtel Money, MTN MoMo, GCash, etc.)
  • Email address, physical address
  • Bank account numbers, IBAN, SWIFT/BIC codes
  • Digital wallet identifiers and QR code credentials

Transaction and Payment Data

  • QR code scan data: timestamp, merchant ID, terminal ID, location data
  • Transaction amount, currency, exchange rate applied, settlement amount
  • Bill reference numbers, biller identifiers, utility account numbers
  • Remittance: sender and beneficiary details, originating country, destination country, corridor data
  • Payment method details: mobile money numbers, card (masked PAN), bank account identifiers
  • Transaction history, failed transaction logs, dispute records

Technical and Device Data

  • IP addresses, device identifiers (IMEI, IMSI), operating system and app version
  • Geolocation data (where applicable to QR payment, remittance, or fraud detection)
  • Session tokens, API keys (hashed), and authentication logs

Compliance and Regulatory Data

  • KYC and Enhanced Due Diligence (EDD) documentation
  • Sanctions screening results, PEP status
  • Suspicious Activity / Transaction Reports (SAR/STR) — subject to tipping-off restrictions
  • AML risk ratings and customer due diligence (CDD) records

 

4.2  Special/Sensitive Categories

The following categories are treated as Sensitive Personal Data under this DPA and subject to heightened safeguards:

  • Biometric data (facial recognition, fingerprint) used for identity verification or QR authentication
  • National identification numbers
  • Financial account credentials and transaction-level financial data
  • Data relating to minors, where child accounts or family remittance products are offered
  • Health data (if collected in connection with insurance-linked payment products)

 

5. OBLIGATIONS OF QR PAY AFRICA AS DATA PROCESSOR

Where acting as Data Processor on behalf of the Client, QR Pay Africa shall:

 

5.1  Instruction-Based Processing

  • Process Personal Data only on documented instructions from the Client, including with regard to cross-border transfers, unless required to do so by applicable law.
  • Promptly inform the Client if, in QR Pay Africa's reasonable opinion, an instruction infringes Applicable Data Protection Law. QR Pay Africa may suspend processing of such instructions pending clarification.

5.2  Confidentiality

  • Ensure all personnel authorised to Process Personal Data are subject to binding confidentiality obligations, and receive appropriate data protection training.

5.3  Security Measures

  • Implement and maintain appropriate technical and organisational security measures as described in Section 8, taking into account the nature, scope, context, and purposes of Processing, and the risks to Data Subjects.
  • Comply with the GLBA Safeguards Rule (16 C.F.R. Part 314) where US consumer financial data is processed, including maintaining a written information security programme.

5.4  Sub-Processing

  • Not engage a Sub-Processor without prior written authorisation from the Client (general written authorisation is granted for categories listed in Schedule B). Notify the Client of any changes to Sub-Processors with at least 30 days' prior notice, allowing the Client to object.

5.5  Data Subject Rights Assistance

  • Notify the Client of any Data Subject requests received directly, where legally permissible (including restrictions under AML tipping-off rules), within 5 business days.
  • Assist the Client in fulfilling Data Subject rights (access, rectification, erasure, restriction, portability, objection) to the extent technically feasible and legally permissible.

5.6  Data Protection Impact Assessments

  • Assist the Client in carrying out Data Protection Impact Assessments (DPIAs) or Privacy Impact Assessments (PIAs), as required by applicable law, including for high-risk processing activities such as biometric QR authentication and large-scale remittance data processing.

5.7  Breach Notification

  • Notify the Client of any confirmed or reasonably suspected Data Breach without undue delay, and in any event within the timeframes required by Applicable Data Protection Law (see Section 9).

5.8  Deletion and Return

  • At the Client's choice and upon termination of the Agreement, delete or return Personal Data and delete existing copies, subject to retention obligations under applicable law.

5.9  Audit Cooperation

  • Provide the Client with all information necessary to demonstrate compliance with this DPA, and allow for and contribute to audits as described in Section 11.

 

6. OBLIGATIONS OF THE CLIENT (DATA CONTROLLER)

The Client warrants, represents, and undertakes that:

  • It has established and maintains a valid and documented lawful basis for each Processing activity involving Personal Data submitted to QR Pay Africa (e.g., contractual necessity, legal obligation, consent, legitimate interests).
  • It has provided all required privacy notices and disclosures to Data Subjects, including information about cross-border data transfers in connection with QR code payments, remittance, and bill payment services.
  • It has complied with all Applicable Data Protection Laws relevant to the Client's jurisdiction(s) of operation, including applicable African, Asian, and US laws.
  • It will not instruct QR Pay Africa to Process Personal Data in a manner that would violate Applicable Data Protection Law, including any instruction that would require QR Pay Africa to circumvent its AML, KYC, or financial crime compliance obligations.
  • It is solely responsible for the accuracy, completeness, and lawfulness of Personal Data submitted to QR Pay Africa.
  • It will promptly notify QR Pay Africa of any changes to applicable laws in its jurisdiction that may affect this DPA.
  • It will maintain appropriate security controls for any Personal Data held in the Client's own environment.

The Client shall indemnify, defend, and hold harmless QR Pay Africa from and against any claims, liabilities, fines, and costs arising from the Client's failure to comply with its obligations under this DPA or Applicable Data Protection Law.

 

7. DATA SUBJECT RIGHTS

QR Pay Africa acknowledges and supports the following Data Subject rights, subject to applicable legal limitations including AML tipping-off restrictions, court orders, and regulatory obligations:

 

RightApplicable Law / Jurisdictions
Right to AccessKenya DPA; NDPA (Nigeria); POPIA (South Africa); GDPR; DPDP (India); Singapore PDPA; CCPA/CPRA; 20+ US state laws
Right to Rectification / CorrectionKenya DPA; NDPA; POPIA; GDPR; DPDP; Singapore PDPA; CCPA; most US state laws
Right to Erasure / DeletionKenya DPA; NDPA; POPIA; Ghana DPA; GDPR; DPDP; Singapore PDPA; CCPA/CPRA; most US state laws (subject to retention laws)
Right to Restrict ProcessingKenya DPA; GDPR; POPIA; Singapore PDPA; DPDP
Right to Data PortabilityGDPR; Kenya DPA; POPIA; CCPA/CPRA (right to know and copy)
Right to Object / Opt-OutGDPR; Kenya DPA; POPIA; all US comprehensive state laws
Right Not to be Subject to Automated DecisionsGDPR; Kenya DPA; DPDP; Minnesota MCDPA; CCPA 2025 ADMT rules
Right to Withdraw ConsentAll jurisdictions where consent is the lawful basis
Right to Lodge a ComplaintApplicable DPA/regulator in each jurisdiction (ODPC, NDPC, InfoReg, PDPC, etc.)

 

QR Pay Africa will respond to Data Subject requests within the timeframes mandated by the applicable law of the Data Subject's jurisdiction. Where requests cannot be fulfilled due to legal obligations (e.g., AML retention requirements), QR Pay Africa will provide a written explanation to the Data Subject within the applicable statutory deadline.

 

8. SUB-PROCESSORS

8.1  Authorised Sub-Processors

QR Pay Africa may engage Sub-Processors to support the provision of Services. The Client grants general written authorisation for the categories of Sub-Processors listed in Schedule B. QR Pay Africa's current Sub-Processor categories include:

  • Cloud infrastructure and hosting providers (e.g., AWS, GCP, Azure — Africa and/or Asia region deployments)
  • Payment network partners: card networks, mobile money operators (M-Pesa, MTN MoMo, Airtel Money, GCash, bKash, etc.)
  • Correspondent banks, forex partners, and remittance settlement partners
  • Fraud detection and transaction monitoring providers
  • Identity verification and biometric KYC providers
  • Bill aggregation and biller connectivity platforms
  • QR code generation and management infrastructure providers
  • Regulatory reporting and compliance technology providers
  • Customer support and communication platforms

8.2  Sub-Processor Obligations

QR Pay Africa shall ensure that all Sub-Processors are bound by data protection obligations at least equivalent to those set out in this DPA, including appropriate security measures and restrictions on further sub-processing.

8.3  Sub-Processor Changes

QR Pay Africa will provide at least 30 days' prior written notice of any intended changes to Sub-Processors. The Client may object to a new Sub-Processor within 15 days of notification by providing written reasons. Where the Parties cannot resolve a reasonable objection, either Party may terminate the affected Services on reasonable notice.

8.4  QR Pay Africa's Liability

QR Pay Africa remains fully responsible for the performance of its Sub-Processors under this DPA.

 

9. CROSS-BORDER DATA TRANSFERS

9.1  Transfer Necessity

Given the nature of QR code payments, remittance, and bill payment services, Personal Data will necessarily flow across borders. This includes transfers between African corridors, transfers from Africa to Asia (for remittance processing), and transfers to or from the United States (for global platform infrastructure, card network processing, and AML screening).

9.2  Transfer Mechanisms by Jurisdiction

  • Kenya: Transfers are made in compliance with Section 49 of the Kenya Data Protection Act, 2019, using mechanisms approved by the ODPC, including adequacy determinations, standard contractual clauses, binding corporate rules, or explicit consent.
  • Nigeria: Cross-border transfers comply with the Nigeria Data Protection Act, 2023, Section 43, including NDPC-approved transfer mechanisms.
  • South Africa: Transfers comply with POPIA Section 72, including conditions equivalent to those under POPIA.
  • Ghana, Tanzania, Uganda, Rwanda, Botswana: Transfers comply with applicable national law requirements, including appropriate safeguards, contractual protections, or regulatory authorisation.
  • EU/UK data (where applicable): Transfers rely on EU Standard Contractual Clauses (2021) or UK International Data Transfer Agreements (IDTAs).
  • India (DPDP): Transfers comply with the permitted countries framework under the DPDP Act, 2023, avoiding blacklisted jurisdictions as notified by the Government of India.
  • China (PIPL): Transfers from or involving Chinese Personal Information comply with PIPL Article 38 mechanisms, including CAC security assessments where required, Standard Contracts, or PIPL Certification.
  • Singapore: Transfers comply with PDPA contractual arrangements or the Global Cross-Border Privacy Rules (CBPR) framework.
  • Indonesia, Malaysia, Thailand, Philippines, Vietnam: Transfers comply with applicable national law requirements in each jurisdiction, including consent, contractual safeguards, or regulatory approval.
  • United States: Transfers comply with GLBA data sharing requirements, applicable state privacy laws, and BSA/FinCEN record-keeping obligations.

9.3  Data Localisation

QR Pay Africa acknowledges emerging data localization requirements in certain jurisdictions, including Nigeria (sector-specific financial data), China (PIPL critical data), Vietnam (core data), and India (pending DPDP rules). QR Pay Africa will implement localization where required and will notify the Client of any localization obligations that affect the Services.

9.4  Client Authorization

By executing the Agreement or integrating with QR Pay Africa APIs, the Client acknowledges the necessity of cross-border transfers described in this Section and provides the authorisation required under applicable law to facilitate such transfers, subject to the safeguards set out herein.

 

10. SECURITY MEASURES

10.1  Technical Safeguards

  • End-to-end encryption of Payment Data in transit (TLS 1.2 or higher) and at rest (AES-256 or equivalent)
  • QR code integrity verification and anti-tampering controls
  • Tokenization of Sensitive Payment Data (card numbers, mobile money identifiers)
  • Multi-factor authentication (MFA) for platform access, agent logins, and API integrations
  • Secure API gateway with rate limiting, anomaly detection, and automated threat response

10.2  Organisational Safeguards

  • Documented information security program compliant with the GLBA Safeguards Rule (16 C.F.R. Part 314, amended 2023)
  • Designated Data Protection Officer (DPO) and/or Information Officer, as required by applicable law
  • Annual staff data protection and security training program
  • Role-based access control (RBAC) with least-privilege principles
  • Regular penetration testing and vulnerability assessments

10.3  Operational Safeguards

  • 24/7 security monitoring, logging, and incident detection systems
  • Documented incident response and breach notification procedures
  • Business continuity and disaster recovery plans, tested at least annually
  • Third-party vendor security assessments prior to Sub-Processor engagement
  • Annual Board-level reporting on the information security program as required under the GLBA Safeguards Rule

10.4  Acknowledgement

QR Pay Africa does not guarantee absolute security but maintains commercially reasonable security practices consistent with fintech industry standards, including PCI DSS compliance where applicable to card data processing.

 

11. DATA BREACH NOTIFICATION

11.1  Notification to Client

In the event of a confirmed or reasonably suspected Data Breach affecting Client-controlled Personal Data, QR Pay Africa shall notify the Client without undue delay — and in any event within 72 hours of becoming aware — with the following information (to the extent available):

  • Nature of the Data Breach, including categories and approximate number of Data Subjects affected
  • Categories and approximate number of Personal Data records affected
  • Name and contact details of the Data Protection Officer or other contact point
  • Likely consequences of the Data Breach
  • Measures taken or proposed to address the breach, including mitigation steps

11.2  Notification to Regulators

QR Pay Africa will cooperate with the Client in meeting the following regulatory notification timelines:

  • Kenya ODPC: Without undue delay, and within 72 hours where feasible (DPA 2019, Section 43)
  • Nigeria NDPC: 72 hours (NDPA 2023)
  • South Africa Information Regulator: As soon as reasonably possible after discovery (POPIA Section 22)
  • Ghana DPC, Tanzania, Uganda, Rwanda: In accordance with applicable national law requirements
  • Singapore PDPC: 3 calendar days for significant breaches (PDPA Amendment Act 2024, effective June 2025)
  • India DPBI: Within 72 hours (DPDP Rules 2025)
  • Philippines NPC: Within 72 hours of discovery (NPC Circular 16-03)
  • Indonesia BSSN: Within 14 days of discovery (PDPL 2022)
  • Malaysia PDPC: Within 72 hours of discovery (PDPA Amendment 2024)
  • US federal (GLBA Safeguards Rule): Within 30 days of discovery
  • US state laws: Within 30-72 hours depending on state (CA, WA, NY: 30 days; others may vary)

11.3  Delayed Notification

QR Pay Africa may delay notification where required or permitted by law enforcement, regulatory authorities, or applicable AML/CFT tipping-off restrictions. QR Pay Africa will notify the Client as soon as such restrictions are lifted.

 

12. DATA RETENTION AND DELETION

12.1  Retention Periods

QR Pay Africa retains Personal Data for the minimum period necessary to fulfil the purpose for which it was collected, subject to the following minimum mandatory retention obligations:

 

Data CategoryMinimum RetentionLegal Basis
AML/KYC records and CDD documentation7–10 years post-relationship endKenya Proceeds of Crime and AML Act; FATF Recommendations; national AML laws
Transaction records (QR payments, remittance, bill payments)7 years (10 years in some jurisdictions)Financial services regulations; GLBA; national banking laws; card scheme rules (Visa/Mastercard)
Remittance beneficiary records5–7 yearsFATF Recommendation 16; national wire transfer rules; BSA/FinCEN Travel Rule
Fraud and dispute records7 years or duration of legal proceedingsRisk management; legal defence
Tax and financial records7 years (varies by jurisdiction)Tax authority requirements in each operating jurisdiction
Regulatory filings (SARs/STRs)5–10 years (varies)National FIU / BSA / FATF requirements — subject to tipping-off restrictions
Consent records and marketing data3 years post-consent withdrawalData Protection Laws (Kenya DPA, NDPA, GDPR, CCPA)
Technical logs (API, system)12–24 monthsSecurity monitoring; incident investigation

 

12.2  Deletion Requests

Data Subject requests for erasure may be declined where retention is required by: (i) applicable AML, financial services, or tax regulation; (ii) active fraud investigation or legal proceedings; (iii) card scheme compliance obligations; or (iv) legitimate legal defense. QR Pay Africa will provide written reasons for any refusal within the applicable statutory timeframe.

 

13. AUDITS AND COMPLIANCE DEMONSTRATION

Where QR Pay Africa acts as Data Processor, the Client may request reasonable documentation demonstrating compliance with this DPA, subject to the following conditions:

  • Audit requests must be made in writing with a minimum of 30 days' prior notice.
  • Audits must be conducted during normal business hours and must not unreasonably disrupt QR Pay Africa's operations.
  • Audits are limited to once per calendar year, unless required by a regulatory authority or triggered by a confirmed Data Breach.
  • All auditors must execute a confidentiality agreement acceptable to QR Pay Africa prior to the audit.
  • The Client shall reimburse QR Pay Africa for reasonable costs incurred in supporting any audit.
  • QR Pay Africa may provide ISO 27001 certification, SOC 2 Type II reports, PCIDSS compliance reports, or independent third-party audit summaries in lieu of direct audit access, where these adequately address the Client's compliance questions.

 

14. DATA PROTECTION OFFICER

14.1  QR Pay Africa DPO

QR Pay Africa has appointed a Data Protection Officer (DPO) / Information Officer as required by:

  • Kenya Data Protection Act, 2019 — registered with the ODPC
  • Nigeria Data Protection Act, 2023 — registered with the NDPC
  • South Africa POPIA — Information Officer registered with the Information Regulator
  • Singapore PDPA (Amendment Act 2024, effective June 2025) — mandatory DPO
  • India DPDP Act, 2023 (for Significant Data Fiduciary designation, when applicable) — India-based DPO
  • Philippines DPA, 2012 — DPO registered with the NPC
  • GDPR Article 37 (where applicable) — DPO for EU-related processing

The DPO contact details are available on QR Pay Africa's privacy policy webpage and will be provided to the Client upon written request.

14.2  Client DPO

The Client is responsible for appointing a DPO or equivalent privacy contact where required by applicable law in the Client's jurisdiction, and for communicating that contact's details to QR Pay Africa.

 

15. PRIVACY BY DESIGN AND DATA MINIMIZATION

QR Pay Africa integrates data protection into the design of its QR payment, remittance, and bill payment infrastructure by default. This includes:

  • Collecting only the minimum Personal Data necessary for each transaction type (data minimization).
  • QR code session data is pseudonymized or anonymized where technically feasible after transaction completion.
  • Biometric data collected for QR authentication is not used for any purpose other than the specific authentication for which it was collected, unless separately consented to by the Data Subject.
  • Remittance data is compartmentalized to restrict access to only those personnel and systems with a legitimate processing need.
  • Bill payment reference data is not enriched with additional personal data beyond what is strictly necessary for settlement.
  • Privacy impact assessments (PIAs) and Data Protection Impact Assessments (DPIAs) are conducted for new high-risk processing activities prior to deployment.

 

16. ARTIFICIAL INTELLIGENCE AND AUTOMATED DECISION-MAKING

QR Pay Africa may use automated systems and AI-driven tools for fraud detection, AML transaction monitoring, and QR code risk scoring. The Parties acknowledge the following:

  • Solely automated decisions with significant effects on Data Subjects will only be taken where a lawful basis exists under applicable law, including explicit consent or legal authorization for financial crime prevention purposes.
  • Data Subjects retain the right to request human review of automated decisions, explanation of the logic involved, and the ability to contest adverse decisions, subject to financial crime and regulatory exemptions.
  • QR Pay Africa will comply with CCPA 2025 Automated Decision-Making Technology (ADMT) regulations, the Kenya DPA provisions on automated processing, GDPR Article 22 (where applicable), and India DPDP Act obligations for significant data fiduciaries.
  • AI models used for fraud scoring or biometric verification are subject to regular bias audits and accuracy reviews.

 

17. SPECIFIC PROVISIONS: REMITTANCE AND CROSS-BORDER TRANSFERS

Given the cross-border nature of remittance services, the following additional provisions apply:

  • FATF Recommendation 16 Compliance (Travel Rule): QR Pay Africa will collect and transmit required originator and beneficiary information for electronic fund transfers, in compliance with the FATF Travel Rule and its local implementations across operating corridors.
  • Beneficiary Data Minimization: Beneficiary Personal Data will not be retained beyond the period necessary for regulatory compliance and fraud prevention purposes, subject to AML retention requirements.
  • Corridor-Specific Compliance: QR Pay Africa will apply the data protection requirements of both the sending and receiving jurisdiction for each remittance corridor, applying the higher standard where they conflict.
  • Foreign Exchange Data: Currency conversion data linked to identified individuals is treated as financial Personal Data and subject to all protections under this DPA.
  • Beneficiary Privacy: QR Pay Africa will not share beneficiary information with third parties beyond what is required for transaction completion, regulatory compliance, or fraud prevention.

 

18. SPECIFIC PROVISIONS: BILL PAYMENTS

The following additional provisions apply to bill payment services:

  • Bill Reference Data: Bill reference numbers, utility account identifiers, and associated Personal Data will be processed only for the purpose of presenting and settling the relevant bill.
  • Biller Data Sharing: Personal Data will be shared with billers, utilities, and government agencies only to the extent required to effect payment and obtain confirmation of settlement.
  • Payment History: Bill payment history is treated as financial Personal Data and subject to the retention and security requirements set out in this DPA.
  • Third-Party Biller Processors: Where bill aggregation platforms or biller API gateways process Personal Data on behalf of QR Pay Africa, they are engaged as Sub-Processors subject to Schedule B of this DPA.

 

19. LIMITATION OF LIABILITY

  • QR Pay Africa's aggregate liability under this DPA shall be subject to the limitation of liability provisions set forth in the main Agreement.
  • QR Pay Africa shall not be liable for indirect, consequential, special, or punitive damages arising from data protection claims, to the maximum extent permitted by applicable law.
  • Each Party shall be liable for fines, penalties, and claims arising from its own non-compliance with applicable data protection law as an independent controller.
  • In cases of joint liability (e.g., shared systems or joint controllership), the Parties agree to allocate liability proportionally based on each Party's degree of fault, as determined by the competent supervisory authority or court.
  • The Client remains solely responsible for any fines, penalties, or claims arising from the Client's failure to establish a lawful basis for Processing or to provide required notices to Data Subjects.

 

20. TERMINATION

  • Upon termination or expiry of the Agreement, QR Pay Africa shall, at the Client's election, delete or return Personal Data (in a commonly used, machine-readable format) within 60 days of termination, and certify such deletion in writing.
  • Notwithstanding the above, QR Pay Africa may retain Personal Data for as long as required by AML/CFT law, financial services regulation, tax law, card scheme rules, or for the purposes of legal defence or compliance, as set out in Section 12.
  • All provisions of this DPA that by their nature should survive termination (including Sections 10 (Security), 11 (Breach Notification), 12 (Retention), 19 (Liability)) shall survive termination of the Agreement.

 

21. GOVERNING LAW AND DISPUTE RESOLUTION

This DPA shall be governed by the governing law specified in the main Agreement, subject to the following overrides:

  • Data protection matters specifically governed by mandatory national law (e.g., POPIA for South African Data Subjects; NDPA for Nigerian Data Subjects; CCPA for California residents) shall be interpreted in accordance with those laws, regardless of the governing law of the Agreement.
  • Disputes between the Parties relating to this DPA shall first be subject to good-faith negotiation, followed by mediation, and then formal dispute resolution as set out in the main Agreement.
  • Nothing in this DPA prevents either Party from reporting a data protection matter to the competent supervisory authority or Data Protection Authority in any jurisdiction.

 

22. ORDER OF PRECEDENCE

In the event of any conflict or inconsistency between this DPA and the main Agreement, this DPA shall prevail with respect to data protection and privacy matters. In the event of conflict between this DPA and Schedule A (Applicable Laws), the more protective standard shall apply.

 

SCHEDULE A

APPLICABLE DATA PROTECTION LAWS

A.1  Africa

  • Kenya: Data Protection Act, 2019; Data Protection (General) Regulations, 2021; Data Protection (Complaints Handling Procedure and Enforcement) Regulations, 2021
  • Nigeria: Nigeria Data Protection Act (NDPA), 2023; Nigeria Data Protection Regulation (NDPR), 2019; NDPR Implementation Framework 2020
  • South Africa: Protection of Personal Information Act (POPIA), No. 4 of 2013 (effective July 2021); POPIA Regulations, 2018
  • Ghana: Data Protection Act, 2012 (Act 843); pending amendments under review as of 2025
  • Tanzania: Personal Data Protection Act (PDPA), 2022
  • Uganda: Data Protection and Privacy Act, 2019; Data Protection and Privacy Regulations, 2021
  • Rwanda: Law No. 058/2021 on Protection of Personal Data and Privacy; ICT Law
  • Egypt: Personal Data Protection Law No. 151 of 2020; Executive Regulations
  • Botswana: Data Protection Act, 2024 (effective January 2025)
  • Mauritius: Data Protection Act, 2017
  • Senegal: Law No. 2008-12 on Personal Data Protection (under revision)
  • Regional: African Union Convention on Cyber Security and Personal Data Protection (Malabo Convention, 2014); ECOWAS Supplementary Act on Personal Data Protection, 2010

 

A.2  Asia

  • Singapore: Personal Data Protection Act (PDPA), 2012; PDPA (Amendment) Act, 2020; Personal Data Protection (Amendment) Act, 2024 (phased implementation 2025)
  • India: Digital Personal Data Protection (DPDP) Act, 2023; Draft DPDP Rules, 2025; Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (applicable until DPDP Act enters force)
  • China: Personal Information Protection Law (PIPL), 2021; Data Security Law (DSL), 2021; Cybersecurity Law, 2017; Measures for Security Assessment of Cross-Border Data Transfer, 2022
  • Indonesia: Personal Data Protection Law (PDPL), No. 27 of 2022 (effective 2024)
  • Malaysia: Personal Data Protection Act (PDPA), 2010; Personal Data Protection (Amendment) Act, 2024
  • Thailand: Personal Data Protection Act (PDPA), B.E. 2562 (2019) (enforced June 2022)
  • Philippines: Data Privacy Act of 2012 (Republic Act No. 10173); Implementing Rules and Regulations; NPC Circulars
  • Vietnam: Decree on Personal Data Protection No. 13/2023/ND-CP; pending Personal Data Protection Law (PDPL), expected 2026
  • Japan: Act on the Protection of Personal Information (APPI), 2003 (major 2022 amendments)
  • South Korea: Personal Information Protection Act (PIPA), 2011 (2023 amendments); Credit Information Use and Protection Act
  • Hong Kong SAR: Personal Data (Privacy) Ordinance (PDPO), Cap. 486 (2021 amendments)

 

A.3  United States

  • Federal: Gramm-Leach-Bliley Act (GLBA) & FTC Safeguards Rule (16 C.F.R. Part 314), as amended 2023; Bank Secrecy Act (BSA) & FinCEN Regulations (31 C.F.R. Chapter X); Fair Credit Reporting Act (FCRA), 15 U.S.C. § 1681 et seq.; Children's Online Privacy Protection Act (COPPA)
  • California: California Consumer Privacy Act (CCPA) / California Privacy Rights Act (CPRA); CPPA Regulations (2023, 2025); California Opt Me Out Act
  • Other State Laws (effective as of 2025-2026): Virginia VCDPA; Colorado CPA; Connecticut CTDPA (amended 2025); Texas TDPSA; Oregon OCPA; New Jersey NJDPA; Minnesota MCDPA; Delaware DPDPA; Maryland MODPA; Nebraska NDPA; New Hampshire NHPA; Iowa ICDPA; Indiana ICDPA; Tennessee TIPA; Montana MCDPA (amended 2025); Rhode Island DPDPA
  • Financial Regulatory: State money transmission and payment service licensing data requirements; FinCEN Customer Due Diligence Rule; FinCEN Travel Rule for electronic funds transfers

 

A.4  International / Cross-Cutting

  • EU General Data Protection Regulation (GDPR), Regulation (EU) 2016/679 — applicable where processing involves EU residents
  • UK GDPR and Data Protection Act, 2018 — applicable where processing involves UK residents
  • FATF Recommendations 10 and 16 (KYC and Payment Transparency)
  • ISO/IEC 27001 Information Security Management Standard
  • PCI DSS (Payment Card Industry Data Security Standard) — applicable to card data processing

 

SCHEDULE B

APPROVED SUB-PROCESSOR CATEGORIES

The Client provides general written authorization for QR Pay Africa to engage Sub-Processors in the following categories. A specific list of named Sub-Processors is available on request and published on QR Pay Africa's privacy policy page.

 

CategoryDescriptionProcessing Location(s)
Cloud InfrastructureHosting, compute, database, and storage services for QR Pay Africa platformAfrica, EU, US, Asia (region-dependent)
Payment Network PartnersMobile money operators, card networks, real-time payment railsAfrica, Asia (corridor-specific)
Correspondent BanksCross-border settlement, forex conversion, correspondent bankingGlobal (corridor-specific)
KYC / Identity VerificationBiometric verification, document OCR, liveness detection, watchlist screeningAfrica, Asia, Global
Fraud & AML MonitoringTransaction monitoring, fraud scoring, sanctions screening, SAR automationAfrica, Global (cloud-based)
Bill Aggregation PlatformsBiller connectivity, presentment, settlement confirmationAfrica (market-specific)
QR InfrastructureQR code generation, scanning SDKs, merchant QR managementAfrica, Asia
Customer Support PlatformsHelpdesk, ticketing, and CRM tools for customer and merchant supportAfrica, remote
Regulatory TechnologyCompliance reporting, audit trail management, DPA toolsAfrica, Global
Communications ProvidersSMS OTP, email, push notifications for transaction confirmation and authenticationGlobal

 

 

EXECUTION

By executing the Agreement or integrating with QR Pay Africa APIs, the Client agrees to this Data Protection Addendum in its entirety, including Schedule A (Applicable Laws) and Schedule B (Approved Sub-Processors).

For avoidance of doubt, API integration constitutes electronic execution of this DPA.

 

QR Pay Africa Limited — Data Protection Addendum v2.0 — May 2026

This document is confidential and legally binding. All queries: dpo@qrpayafrica.com