READING LIST
Module V: Data Protection Impact Assessment
Primary Kenyan Legal Framework
The Data Protection Act, 2019: This is the primary law in Kenya governing data
protection. You should focus specifically on Section 31, which mandates DPIAs for
processing activities likely to result in "high risk" to data subjects.
The Data Protection (General) Regulations 2021: These regulations provide the
specific criteria and situations (such as large-scale processing or automated
decision-making) where a DPIA is required.
Guidance from the Office of the Data Protection Commissioner (ODPC): Official
guidance issued by the Kenyan regulator to help organizations navigate their legal
obligations and demonstrate accountability. See here - [Link]
content/uploads/2024/02/ODPC-Guidance-Note-on-Data-Protection-Impact-
[Link]
International and Comparative Frameworks
General Data Protection Regulation (EU GDPR): A key international standard that
informs many of the compliance obligations found in Kenyan law.
African Union Convention on Cyber Security and Personal Data Protection: A
regional framework focused on harmonizing data protection and cyber security
across Africa.
Additional Material
CIPIT, Simplified Data Protection Impact Assessment - [Link]
content/uploads/2021/05/[Link]
CIPIT, Kenya High Court’s Worldcoin Determination: Upholding Consent, Accountability
and Data Sovereignty in Biometric Data Processing - [Link]/kenya-high-
courts-worldcoin-determination-upholding-consent-accountability-and-data-
sovereignty-in-biometric-data processing
ODPC, Complaint No. 1394 of 2023 -
[Link]
[Link]
Dr. Mugambi Laibuta, Data Protection Impact Assessments -
[Link]
KICTANet, What is a Data Protection Impact Assessment -
[Link]