1. Scope and Controller
SIFMIS is operated for the Social Investment Fund to administer social investment programmes, beneficiary applications, implementing partner delivery, field verification, support delivery, loan application routing, monitoring, reporting, and related public services.
For the purposes of this policy, "personal data" means information relating to an identified or identifiable person. "Sensitive personal data" may include identity records, financial information, vulnerability indicators, biometric or identity document references, health or disability information where collected for eligibility, and other protected records.
2. Applicable Ghana Legal Framework
SIFMIS is designed to be operated in accordance with Ghanaian law and recognised public-sector data governance standards, including:
Where SIFMIS works with banks, financial institutions, implementing partners, government agencies, or donor-funded programmes, additional contractual, regulatory, audit, and public financial management obligations may apply.
3. Information We Collect
Beneficiaries and applicants
- Account details such as name, phone number, email address, login credentials, and verification records.
- Identity and eligibility information including Ghana Card details, date of birth, sex, location, district, region, household or group profile, business profile, and vulnerability or programme eligibility details.
- Application records, uploaded documents, declarations, support requests, loan application details, application decisions, and status history.
Implementing partners and field users
- Organisation profiles, registration information, contact details, assigned modules, staff accounts, role permissions, attendance records, field reports, evidence uploads, and performance records.
Financial institutions
- Institution profiles, routing details, contact officers, loan review actions, status updates, and communications related to applicant financing workflows.
Technical information
- Device, browser, IP address, access logs, audit logs, session information, timestamps, error records, and security event logs.
4. How We Use Information
SIFMIS processes information for public service delivery, programme administration, and legitimate operational purposes, including to:
- Create and manage beneficiary, partner, financial institution, and staff accounts.
- Assess programme eligibility, process applications, manage field registration, verify records, and prevent duplicate or fraudulent applications.
- Route loan applications to participating financial institutions and track outcomes.
- Assign modules, record attendance, monitor support delivery, upload evidence, and manage field reports.
- Send notifications, provide helpdesk support, improve services, troubleshoot issues, and maintain audit trails.
- Produce aggregated reports for monitoring, evaluation, planning, compliance, donor reporting, and public accountability.
5. Information Sharing and Disclosure
SIFMIS may share relevant data only where necessary, authorised, and proportionate. Recipients may include:
- Authorised SIF staff and system administrators.
- Approved implementing partners assigned to deliver a programme, module, field activity, verification, or support package.
- Participating financial institutions where an applicant requests or is routed for loan assessment.
- Government ministries, departments, agencies, regulators, auditors, and oversight bodies where required by law or public accountability obligations.
- Technical service providers who host, maintain, secure, or support SIFMIS under confidentiality and data protection obligations.
SIFMIS does not sell personal data. Data shared for reporting should be anonymised or aggregated where individual identification is not necessary.
6. Data Security
SIFMIS applies administrative, technical, and organisational safeguards to protect information against unauthorised access, loss, misuse, alteration, or disclosure. These controls may include role-based access, authentication controls, audit trails, encrypted transport, secure file storage, least-privilege access, backups, monitoring, and incident response procedures.
Users must keep their login details confidential, use only authorised accounts, and report suspected compromise or incorrect data promptly.
7. Retention and Disposal
SIFMIS keeps personal data only for as long as needed for programme delivery, statutory compliance, audit, dispute resolution, financial accountability, reporting, and archival obligations. Retention periods may vary by record type, funding agreement, regulatory requirement, and public-sector recordkeeping policy.
When data is no longer required, SIFMIS should delete, anonymise, archive, or securely dispose of it in accordance with approved retention rules.
8. Your Rights and Choices
Subject to the Data Protection Act, 2012 (Act 843) and applicable programme rules, data subjects may request access to their personal data, correction of inaccurate records, information about processing, restriction or objection where applicable, and review of concerns about unlawful processing.
Some information may be required to determine eligibility, process applications, fulfil legal obligations, prevent fraud, or maintain audit records. If required information is not provided, SIFMIS may be unable to process an application or provide a requested service.
9. Cookies and Analytics
SIFMIS may use essential cookies or similar technologies to maintain secure sessions, remember user interactions, prevent fraud, and improve site reliability. Analytics should be configured to minimise unnecessary personal data collection where used.
10. Children's and Vulnerable Persons' Data
Some programmes may involve vulnerable persons, dependants, youth, or household members. SIFMIS will process such information only where relevant to programme eligibility, safeguarding, public service delivery, or legal obligations, and with appropriate care and access restrictions.
11. Policy Updates
This policy may be updated to reflect changes in SIFMIS services, Ghanaian law, programme requirements, security practices, or data protection guidance. The effective date will be revised when material changes are made.
12. Contact and Complaints
Questions, corrections, access requests, or privacy complaints may be submitted through the official SIF contact channels.