0% found this document useful (0 votes)
3 views15 pages

Module I - Introduction To Data Protection

This module provides an introduction to data protection, emphasizing its importance in Kenya and outlining its core principles. It covers key terminologies, the legal framework established by the Data Protection Act of 2019, and real-life applications of data protection principles. The module concludes with a case study illustrating the consequences of non-compliance with data protection regulations.

Uploaded by

Enock Chesire
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PPTX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
3 views15 pages

Module I - Introduction To Data Protection

This module provides an introduction to data protection, emphasizing its importance in Kenya and outlining its core principles. It covers key terminologies, the legal framework established by the Data Protection Act of 2019, and real-life applications of data protection principles. The module concludes with a case study illustrating the consequences of non-compliance with data protection regulations.

Uploaded by

Enock Chesire
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PPTX, PDF, TXT or read online on Scribd

Module I:

Introduction to Data
Protection
Ms. Josephine Kaaniru
Research Associate
Module Overview &
Learning Outcomes
Why this Module Matters
This module lays the conceptual foundation for the course. By the end, you will
understand what data protection means, why it matters in Kenya, and how its core
principles apply in everyday organisational life

Module Outline:

 What is data protection?


 Key terminologies
 Why data protection matters in Kenya
 The eight data protection principles
 Real-life application: scenarios and ODPC enforcement
What is Data Protection?
 Data protection is the legal and ethical framework governing how personal data is
collected, used, processed, stored and shared.

 Data refers to recorded or processed information, including information that is processed


automatically by equipment, intended for such automated processing, held in a filing
system or accessible record, or held by a public entity in any other form (DPA, section 2)

 Personal data - any information relating to an identified or identifiable natural person

 Sensitive personal data - a special category (health, race, biometrics, religion, etc.)
requiring extra protection under the DPA 2019
What is Data Protection?
Distinction between data protection, data privacy and data security

 Data protection - rules governing how personal data is handled throughout its
lifecycle

 Data privacy - the right of individuals to control information about themselves

 Data security - the technical and organisational measures that protect data from
unauthorised access or loss
Key Data Protection
Terminologies
 Data processor - processes personal data on behalf of a controller
Data controller - determines the purpose and means of processing personal data

 Data subject - the identified or identifiable natural person the data is about

 Processing - any operation on personal data, collection, storage, use, disclosure or


deletion
 Consent - any manifestation of express, unequivocal, free, specific and informed
indication of the data subject's wishes by a statement or by a clear affirmative action,
signifying agreement to the processing of personal data relating to the data subject;
DPA s 2

 Data breach - unauthorised access, disclosure, alteration or destruction of personal


data
Why Data Protection Matters in
Kenya

 Constitutional grounding - Article 31 of the Constitution of Kenya, 2010 guarantees the


right to privacy; the data protection laws operationalise this right
 Legislative response - the Data Protection Act, 2019 (DPA) and its regulations give effect
to that constitutional right to privacy
 Protection of data subject rights - data misuse leads to privacy breaches, discrimination,
fraud, surveillance among other harms.
Data Protection Principles
Section 25 of the Data Protection Act, 2019 sets out the principles that
govern all lawful processing of personal data.

 Privacy-respecting - processed in accordance with the data subject's right to


privacy

 Lawful, fair and transparent - processed on a valid legal basis and openly

 Purpose limitation - collected for specified, legitimate purposes and not used
beyond them

 Data minimisation - adequate and relevant, but not excessive for the stated
purpose
Data Protection Principles

 Justified - particularly where family or private affairs are concerned

 Accuracy - kept up to date; inaccurate data corrected or erased without delay

 Storage limitation - retained only as long as necessary to fulfil the stated purpose

 Transfer-safe - only moved outside Kenya where adequate safeguards exist or


consent is given
Scenario 1: Application of Data
Protection Principles
An HR department onboarding a new employee collects a wide range of personal data.
How do the principles apply at each step?

 Data collected - full name, ID number, KRA PIN, bank account details, next of kin
 Lawful basis - contractual necessity and, for medical data, explicit consent
 Purpose limitation - payroll data must not be repurposed for marketing
 Data minimisation - collect only what the employment relationship requires
 Storage limitation - define retention periods; delete data when no longer necessary;
e.g., when contract ends
Scenario 2: Application of Data
Protection Principles
A mobile lending platform collects transaction data, phone contacts and device
information. Where do data protection obligations arise?

 Collection - must disclose to users what data is collected and why (transparency
principle); privacy policies
 Consent - accessing phone contacts requires valid, informed consent
 Commercial use - using customer data to market third-party products without
consent violates the data protection Act
 Cross-border transfers — data sent to servers outside Kenya requires safeguards
under the DPA
Case Study: ODPC Complaint No. 1951
of 2024
Waweru v Platinum Credit Limited
 Samuel Kamau Waweru filed a complaint after receiving an unsolicited call from a
Platinum Credit sales agent promoting loan products, despite never having been a
customer or giving consent. The agent had been given an Excel sheet of names, ID
numbers, phone numbers and vehicle details by her team leader.
 Platinum Credit denied any link to the agent, but ODPC investigations established
she worked for the company.
 The ODPC found the company had unlawfully processed the complainant's
personal data for commercial purposes without consent, violating Sections 30 and
37 of the DPA and Regulation 15.
 Platinum Credit was ordered to pay KES 400,000 in compensation.
Conclusion
Key takeaways

 Data protection is a framework for building trust and protecting the rights of
individuals; Kenya's framework is grounded in Article 31 of the Constitution and
given effect by the Data Protection Act, 2019 and its regulations.

 The eight principles in Section 25 of the DPA govern all lawful processing -
controllers must be able to demonstrate compliance.

 Refer to the course glossary for definitions of all terms introduced in this module.
Thank You!
Email: cipit@[Link]
Website: [Link]

You might also like