0% found this document useful (0 votes)
2 views3 pages

Module 6 Outline

This module provides an overview of Technical and Organisational Measures (TOMs) crucial for data security and compliance in Kenya, covering legal foundations, technical and organizational safeguards, and incident response strategies. Participants will learn to analyze legal frameworks, implement data protection principles, and manage third-party relationships effectively. The module also addresses emerging issues and concludes with key takeaways and future considerations for TOMs in Kenya.

Uploaded by

lelmettom
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
2 views3 pages

Module 6 Outline

This module provides an overview of Technical and Organisational Measures (TOMs) crucial for data security and compliance in Kenya, covering legal foundations, technical and organizational safeguards, and incident response strategies. Participants will learn to analyze legal frameworks, implement data protection principles, and manage third-party relationships effectively. The module also addresses emerging issues and concludes with key takeaways and future considerations for TOMs in Kenya.

Uploaded by

lelmettom
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Module VI: Technical and Organisational

Measures
Module Overview
This module introduces participants to the Technical and Organisational Measures (TOMs)
framework, which is essential for ensuring data security and regulatory compliance in Kenya.
The module is divided into three main parts. In part I, participants will examine the legal basis
for TOMs and explore established legal standards for proactive integration of data protection
by design and privacy by default into organisational systems. Part II of the module will
introduce participants to specific technical safeguards alongside organisational safeguards.
Participants will also be introduced to the standards for third-party and vendor management,
gaining insights into the law that establishes safeguards for managing complex relationships
among data processing actors. Despite the security measures, personal data breaches can still
occur. Part III of the module will cover incident response and breach notification requirements.
Finally, there will be a highlight of emerging issues in TOMs generally, as well as a general
conclusion for the module.

Learning objectives
By the end of this module, participants will be able to:
[Link] the legal basis for implementing technical and organisational measures under the Kenyan Data
Protection Act and regulations made under it.
[Link] how clarifications and or changes in the regulatory landscape through recent caselaw, best
practice, emerging laws, Guidelines, and Codes are impacting standards for TOMs in Kenya.
[Link] principles of data protection by design and privacy by default in the development of new
products or internal processes.
[Link] and select appropriate technical and organisational safeguards to mitigate identified data risks
within organizational settings.
[Link] and navigate a third-party and vendor management framework to ensure compliance.
[Link] a robust incident response plan for detecting, handling and learning from possible data breach
scenarios.
Page 1 of 3
Module topics and outline

Topic Outline

Introduction
Learning objectives
Introduction
An overview of the module

Constitution of Kenya, 2010


Legal basis for technical and Data Protection Act, 2019 (sections 25, 26, 29, 41, and 42)
organisational measures. Data Protection (General) Regulations, 2021 (Parts IV, V, and
VI)

Definition of data protection by design and by default


Scope
Data protection by design and Appropriateness
privacy by default.
Temporal considerations
Enforcement lessons from caselaw

Definition of technical safeguards


Technical safeguards under section 41(4) of DPA
Technical safeguards linked to data protection principles
Technical safeguards Technical safeguards linked to CIA (triad) requirements
Additional technical safeguards in the emerging ODPC
Guidelines and Codes
Enforcement lessons from caselaw

Definition of organizational safeguards


Building a privacy culture institutionally
Risk management and DPIA
Training, awareness, and capacity building
Organisational safeguards Best practice of organizational measures
Additional organizational safeguards in the emerging
Draft/Final ODPC Guidelines and Codes between 2022 and
2026
Enforcement lessons from caselaw

Page 2 of 3
Recap of the definition of key actors
Chain of command and influence on the standards of management of the
relationships
Due diligence on data processors
Third-party and Contracting with data processors
vendor management. Alignment of contractual engagement with third parties/sub-
processors/employees
Routine and non-routine data sharing with joint controllers, processors, and
third parties
Enforcement lessons from caselaw

Definition of personal data breach


Rationale of managing data breaches
Planning data breach management
Incident response Handling data breaches
and breach Reporting data breaches (Communication and notification obligations and
notification. processes)
Learning from data breaches
Best practice on data breach management
Enforcement lessons from caselaw

Emerging technologies and their impact on TOM standards


Emerging issues on
TOM in Kenya

Summary of key takeaways on topics 2-8


Key takeaways

Key conclusions on the future of TOMs in Kenya


Conclusion

Page 3 of 3

You might also like