Module IV: Technical and Organisational
Compliance
Module Overview
In this module unit, we shall explore the organisational measures necessary for data handlers to
meet their compliance obligations under the Data Protection Act, 2019 and its Regulations.
Participants will engage with core principles and statutory requirements for organisational
compliance and practical aspects of data protection operationalisation, providing a well-
rounded and informed approach to compliance that can translate in real-world case scenarios.
Module learning outcomes
On completion of this unit, module participants will be able to:
[Link] the legal requirements on data controllers and processors to implement technical
and organisational measures in their processing activities;
[Link] governance measures necessary to achieve effective data protection compliance
within an organisation; and
[Link] and mitigate risks arising from data processing activities, including cross-border
transfers, third-party engagements, and data breaches.
Module Outline
Rights of data subjects
Compliance obligations under the Kenyan data Compliance categories and roles in Kenya:
protection regime Data controllers, Data processors
Accountability principle
Page 1 of 2
Legal requirements for registration
Thresholds and criteria for mandatory registration
Registration of data controllers and data
Registration process & filing
processors
Renewals
Consequences of non-registration
Institutional data protection governance
frameworks
Data mapping, Records of processing activities
(ROPA) and lifecycle management
Organisational measures and governance The Data Protection Officer (DPO)
Employee data protection awareness and capacity
building
Third party risk management
Data processing agreements
Data protection policies, privacy statements,
cookie policies
Standard operating procedures (SOPs)
Data retention schedules
Standard compliance documentation and
Data breach policies
processes
Data subject rights handling mechanisms
Data subject requests (correction, deletion,
objection)
Response timelines and management
Legal requirements for cross-border transfers
Assessing adequacy
Cross border data transfers
Controller vs processor obligations
Reporting to the ODPC
Organisational challenges for data protection
compliance
Compliance challenges and strategies
Best practice compliance strategies
Sector-specific compliance
Page 2 of 2