Terms of Reference (ToR) Consultancy Service for Compliance with Data Protection Law
Background:
Rwanda Climate Change and Development Network (RCCDN) is a national member-driven civil society network focusing on environment, climate change and related development challenges. It is a network composed of 76-member organisations working throughout the entire Rwandan territory. RCCDN’s objectives ensure effective networking and communication among members to collectively identify their priority needs and be empowered to take a stand, positioning for sustainable development amidst climate change challenges. It is legally registered with Rwanda Governance Board (RGB) with registration certificate no. 618/RGB/NGO/LP/04/2020.
RCCDN plays a pivotal role in climate change research, advocacy, and the implementation of community-based climate resilience programs. As part of its mandate, RCCDN collects, processes, and manages a variety of data, including personal, sensitive, and environmental data related to beneficiaries, projects, and stakeholders.
On 15 October 2021, law no Nº 058/2021 of 13/10/2021 relating to protecting personal data and privacy was published in the Official Gazette of the Republic of Rwanda. As such, RCCDN aims to comply with Data Protection and Privacy. It is in this regard that Rwanda Climate Change and Development Network (RCCDN) seeks to hire a consultant to analyze the new data protection and privacy law, assess current practices, and recommend actions to ensure full compliance.
Objectives
The main objectives of this consultancy are as follows:
To develop a comprehensive Data Management Policythat aligns with the Rwandan Data Protection Law and international best practices, which will ensure RCCDN handles data in a secure, transparent, and legally compliant manner.
To design and deliver trainingfor RCCDN staff to build their understanding of data protection principles and ensure they are well-equipped to implement the new policy, ensuring compliance with the Rwandan Data Protection Law.
Scope of work
Development of Data Management Policy
- Review of Current Data Management Practices
- Perform a Gap Analysis
- Draft a comprehensive Data Management Policy that incorporates the following components: Data Governance; Data Protection Principles; Data Storage and Security; Data Retention and Disposal; Data Subject Rights; Data Sharing and Third-Party Agreements; Data Breach Management and Compliance and Monitoring:
- Present the draft policy to RCCDN for review and feedback, incorporating any necessary revisions, and finalize the document.
Staff Training on Data Protection Compliance
- Training Needs Assessment:
Conduct an assessment to understand RCCDN staff's current level of knowledge on data protection and identify areas of focus for the training program.
Development of Training Modules:
Develop customized training materials and modules, which should include:
- An introduction to the Rwandan Data Protection Law and its application to RCCDN’s operations.
- Practical guidance on data subject rights, such as consent, access, correction, and the right to be forgotten.
- Roles and responsibilities of RCCDN staff in ensuring data security and compliance with the law.
- Guidelines on secure data handling, storage, and sharing.
- Case studies or scenarios specific to RCCDN’s work in climate change and development.
Training Delivery:
- Deliver training sessions to different groups within RCCDN, including field staff, technical teams, and senior management, through interactive workshops, presentations, and practical demonstrations. Training should include both theoretical knowledge and practical skills.
Post-Training Support:
- Provide post-training support through follow-up sessions, additional resources, or clarification of questions as necessary to ensure proper implementation of the data management practices.
Reporting and Documentation
Comprehensive Final Report:
Submit a final report detailing the consultancy process, including:
- A summary of findings from the data management review.
- The finalized Data Management Policy.
- A summary of the training sessions, including participant feedback and assessments.
- Any recommendations for further steps RCCDN should take to strengthen its data protection practices.
- Support RCCDN in applying for recognized data protection (Data Controller and Data Processor) certification from the relevant authority
Deliverables:
- The consultant will deliver the following:
Inception Report:
- A report outlining the methodology, work plan, and timeline for the consultancy.
Draft Data Management Policy:
- A first draft of the Data Management Policy for RCCDN’s review and feedback.
Final Data Management Policy:
- A finalized, comprehensive Data Management Policy, based on the feedback from RCCDN.
Training Materials:
- Customized training materials and modules designed for RCCDN’s staff.
Training Reports:
- Reports summarizing the training sessions, including participant engagement, feedback, and assessments.
Final Consultancy Report:
- A report documenting the entire consultancy, including the process, results, and any recommendations for continuous improvement.
Duration of the Consultancy:
- The consultancy is expected to be completed within one month, starting from the date of contract signature
Consultant Qualifications:
- Experience in data protection law compliance, policy development, and training.
- Demonstrate knowledge and solid experience in working with Non-governmental organisations through provisions of other consultancy services such as audit, training and policy development
- Bachelor’s degree in business management (any field of specialization such as Law, accounting, finance and Commerce)
- Strong communication and training skills, with experience in delivering workshops and seminars.
Reporting:
- The consultant will report directly to the communications Officer and will be required to submit progress, draft policy and final report upon completion of the consultancy.
Application Process:
- Interested consultants who meet the required criteria shall submit their sealed technical and financial bids in different envelopes addressed to the Coordinator of RCCDN and submitted to the organization Secretariat offices, located in Muyange cell, Kagarama sector in Kicukiro district not later than November 15th, 2024. For any inquiries, please contact telephone number 0788303172
Selection process:
- Because of the high technical requirements of this assignment, technical offers will be evaluated at 80% and financial bids at 20%. RCCDN strongly advises consultants to come up with robust and comprehensive technical offers.
Confidentiality:
- The consultant shall maintain strict confidentiality on all data and materials shared during the consultancy and after the consultancy periods.