Module I - Introduction To Data Protection
Module I - Introduction To Data Protection
Introduction to Data
Protection
Ms. Josephine Kaaniru
Research Associate
Module Overview &
Learning Outcomes
Why this Module Matters
This module lays the conceptual foundation for the course. By the end, you will
understand what data protection means, why it matters in Kenya, and how its core
principles apply in everyday organisational life
Module Outline:
Sensitive personal data - a special category (health, race, biometrics, religion, etc.)
requiring extra protection under the DPA 2019
What is Data Protection?
Distinction between data protection, data privacy and data security
Data protection - rules governing how personal data is handled throughout its
lifecycle
Data security - the technical and organisational measures that protect data from
unauthorised access or loss
Key Data Protection
Terminologies
Data processor - processes personal data on behalf of a controller
Data controller - determines the purpose and means of processing personal data
Data subject - the identified or identifiable natural person the data is about
Lawful, fair and transparent - processed on a valid legal basis and openly
Purpose limitation - collected for specified, legitimate purposes and not used
beyond them
Data minimisation - adequate and relevant, but not excessive for the stated
purpose
Data Protection Principles
Storage limitation - retained only as long as necessary to fulfil the stated purpose
Data collected - full name, ID number, KRA PIN, bank account details, next of kin
Lawful basis - contractual necessity and, for medical data, explicit consent
Purpose limitation - payroll data must not be repurposed for marketing
Data minimisation - collect only what the employment relationship requires
Storage limitation - define retention periods; delete data when no longer necessary;
e.g., when contract ends
Scenario 2: Application of Data
Protection Principles
A mobile lending platform collects transaction data, phone contacts and device
information. Where do data protection obligations arise?
Collection - must disclose to users what data is collected and why (transparency
principle); privacy policies
Consent - accessing phone contacts requires valid, informed consent
Commercial use - using customer data to market third-party products without
consent violates the data protection Act
Cross-border transfers — data sent to servers outside Kenya requires safeguards
under the DPA
Case Study: ODPC Complaint No. 1951
of 2024
Waweru v Platinum Credit Limited
Samuel Kamau Waweru filed a complaint after receiving an unsolicited call from a
Platinum Credit sales agent promoting loan products, despite never having been a
customer or giving consent. The agent had been given an Excel sheet of names, ID
numbers, phone numbers and vehicle details by her team leader.
Platinum Credit denied any link to the agent, but ODPC investigations established
she worked for the company.
The ODPC found the company had unlawfully processed the complainant's
personal data for commercial purposes without consent, violating Sections 30 and
37 of the DPA and Regulation 15.
Platinum Credit was ordered to pay KES 400,000 in compensation.
Conclusion
Key takeaways
Data protection is a framework for building trust and protecting the rights of
individuals; Kenya's framework is grounded in Article 31 of the Constitution and
given effect by the Data Protection Act, 2019 and its regulations.
The eight principles in Section 25 of the DPA govern all lawful processing -
controllers must be able to demonstrate compliance.
Refer to the course glossary for definitions of all terms introduced in this module.
Thank You!
Email: cipit@[Link]
Website: [Link]