Act No: CAP. 411C
Act Title: DATA PROTECTION
SUBSIDIARY LEGISLATION
Arrangement of Sections
THE DATA PROTECTION (CIVIL REGISTRATION) REGULATIONS

ARRANGEMENT OF SECTIONS

PART I – PRELIMINARY

1.

Citation.

2.

Interpretation.

3.

Scope of the Regulations.

PART II – DATA PROTECTION PRINCIPLES

4.

Lawful processing of personal data.

5.

Privacy in processing personal data.

6.

Consent.

7.

Manner of giving consent.

8.

Collection of personal data.

9.

Limitation in processing of personal data.

PART III – RIGHTS OF A DATA SUBJECT

10.

Access to personal data.

11.

Rectification of personal data.

12.

Objection to processing of personal data.

13.

Data portability request.

14.

Exercise of data subject rights by others.

15.

Processing of Personal data relating to a child.

PART IV – OBLIGATION OF THE CIVIL REGISTRATION ENTITY

16.

Duty to notify.

17.

Retention of personal data.

18.

Notification of breach of personal data.

19.

Data protection impact assessment.

20.

Responsibilities of Data Protection Officer.

21.

Sharing of personal information with public agencies.

22.

Automated individual decision making.

23.

Internal complaints handling procedure.

PART V – SECURITY SAFEGUARDS

24.

Data protection by design or default.

25.

Security safeguards of personal data.

26.

Database security.

27.

Monitoring by the Data Commissioner.

28.

Data security procedure.

29.

Database systems and a risk assessment.

30.

Physical protection and secure surroundings.

31.

Data security in manpower management.

32.

Access permission management.

33.

Monitoring and documenting access.

34.

Documentation of security incidents.

35.

Network security.

36.

Periodical audits.

37.

Data backup and restoration.

38.

Transfer of personal data outside Kenya.

PART VII – GENERAL PROVISIONS

39.

Reports to the Data Commissioner.

40.

Outsourcing.

SCHEDULES

FIRST SCHEDULE [r.9 (2), (r.11(2), r.12] —

REQUEST FOR RESTRICTION OR OBJECTION TO THE PROCESSING OF PERSONAL DATA

SECOND SCHEDULE [r. 19(1)] —

DATA PROTECTION IMPACT ASSESSMENT

THE DATA PROTECTION (COMPLAINTS HANDLING PROCEDURE AND ENFORCEMENT) REGULATIONS

ARRANGEMENT OF SECTIONS

PART I – PRELIMINARY

1.

Citation

2.

Interpretation

3.

Object and purpose of the Regulations

PART II – PROCEDURE FOR LODGING, ADMISSION AND RESPONSE TO COMPLAINTS

4.

Lodging of a complaint

5.

Register of complaints

6.

Admission of complaint

7.

Discontinuation of a complaint

8.

Withdrawal of a complaint

9.

Joint consideration of complaints

10.

Language

11.

Notification of a complaint to the respondent

12.

Joinder of parties

13.

Investigations of a complaint

14.

Outcome of investigation

15.

Negotiation, mediation or conciliation

PART III – ENFORCEMENT PROVISIONS

16.

Issuance of enforcement notice

17.

Service of an enforcement notice

18.

Review of enforcement notice

19.

Appeals against enforcement notice

20.

Issuance of penalty notice

21.

Enforcement of penalty notice

SCHEDULES

SCHEDULE [r. 4(2)(a)] —

FORMS

THE DATA PROTECTION (GENERAL) REGULATIONS

ARRANGEMENT OF SECTIONS

PART I – PRELIMINARY

1.

Citation

2.

Interpretation

3.

Exemption

PART II – ENABLING THE RIGHTS OF A DATA SUBJECT

4.

Processing on the basis of consent

5.

Lawful basis for processing

6.

Mode of collection of personal data

7.

Restriction to processing

8.

Objection to processing

9.

Data access request

10.

Rectification of personal data

11.

Data portability request

12.

Right of erasure

13.

Exercise of rights by others

PART III – RESTRICTIONS ON THE COMMERCIAL USE OF PERSONAL DATA

14.

Interpretation of commercial purposes

15.

Permitted commercial use of personal data

16.

Features of an opt out message

17.

Mechanisms to comply with opt out requirement

18.

Request for restriction of further direct marketing

PART IV – OBLIGATIONS OF DATA CONTROLLERS AND DATA PROCESSORS

19.

Retention of personal data

20.

Requests to deal anonymously or pseudonymously

21.

Sharing of personal data

22.

Automated individual decision making

23.

Data protection policy

24.

Contract between data controller and data processor

25.

Obligations of a data processor

26.

Requirement for specified processing to be done in Kenya

PART V – ELEMENTS TO IMPLEMENT DATA PROTECTION BY DESIGN OR BY DEFAULT

27.

Data protection by design or default

28.

Elements of data protection by design or default

29.

Elements for principle of lawfulness

30.

Elements for principle of transparency

31.

Elements for principle of purpose limitation

32.

Elements for principle of integrity, confidentiality and availability

33.

Elements for principle of data minimization

34.

Elements for principle of accuracy

35.

Elements for principle of storage limitation

36.

Elements for principle of fairness

PART VI – NOTIFICATION OF PERSONAL DATA BREACHES

37.

Categories of notifiable data breach

38.

Notification to Data Commissioner

PART VII – TRANSFER OF PERSONAL DATA OUTSIDE KENYA

39.

Interpretation of the Part VII

40.

General principles for transfers of personal data out of the country

41.

Transfers on the basis of appropriate safeguards

42.

Deeming of appropriate safeguards

43.

Binding corporate rules

44.

Transfers on the basis of an adequacy decision

45.

Transfers on the basis of necessity

46.

Transfer on basis of consent

47.

Subsequent transfers

48.

Provisions for the agreement to cross boarder transfer

PART VIII – DATA PROTECTION IMPACT ASSESSMENT

49.

Processing activities requiring data protection impact assessment

50.

Conduct of data protection impact assessment

51.

Prior consultation

52.

Consideration of the data protection impact assessment report

53.

Audit of compliance with Assessment Report

PART IX – PROVISIONS ON EXEMPTIONS UNDER THE ACT

54.

Exemption for national security

55.

Exemptions for public interest

56.

Permitted general situation

57.

Permitted health situation

PART X – GENERAL PROVISIONS

58.

Complaints against data controller and data processor

SCHEDULES

FIRST SCHEDULE [r. 7(2), (r. 8(2)] —

REQUEST FOR RESTRICTION OR OBJECTION TO THE PROCESSING OF PERSONAL DATA

SECOND SCHEDULE [r. 37(1), (3)] —

NOTIFIABLE DATA BREACH

THIRD SCHEDULE [r. 50(1)] —

DATA PROTECTION IMPACT ASSESSMENT TEMPLATE

THE DATA PROTECTION (REGISTRATION OF DATA CONTROLLERS AND DATA PROCESSORS) REGULATIONS

ARRANGEMENT OF REGULATIONS

1.

Citation and commencement

2.

Interpretation

3.

Scope of Regulations

4.

Requirements for registration

5.

Application for registration

6.

Payment of registration fees by specified public bodies

7.

Processing of an application for registration

8.

Approval and issuance of certificate of registration

9.

Duration of certificate of registration

10.

Refusal of registration

11.

Renewal of registration

12.

Refusal of renewal.

13.

Exemption from mandatory registration

14.

Register

15.

Change of particulars

16.

Cancellation or variation of registration

17.

Electronic registration

18.

Offences

SCHEDULES

FIRST SCHEDULE [r. 5(1)(a)] —

REGISTRATION FORM FOR DATA CONTROLLERS AND DATA PROCESSORS

SECOND SCHEDULE [r. 5(2)(b)] —

Fees charged by office

THIRD SCHEDULE [r. 13(1)(3)] —

THRESHOLDS FOR MANADATOTY REGISTRATION