The Data Protection (General) Regulations
The Regulations may be cited as the Data Protection (General) Regulations.
AI-assisted research synopsis — verify against the official legal text below.
- Jurisdiction
- Kenya
- Instrument
- Notice
- Citation
- Legal Notice 263 of 2021
- Version
- Undated source snapshot
- Language
- en
Citation provenance: source:ke:kenyalaw · schema StatuteEnrichmentPublicV1.
Source attribution: Source: Kenya Law
Statute overview
About this statute
The Regulations may be cited as the Data Protection (General) Regulations. Defines the terms 'Act', 'Data Commissioner', and 'Office'. Civil registration entities specified under the Data Protection (Civil Registration) Regulations (L.N. 196/2020) are exempt from these Regulations. Allows a data subject to request rectification of personal data; requires controllers/processors to rectify within 14 days if necessary and to notify refusals in writing within 7 days. Data subjects may request portability of their personal data; controllers/processors must port data within 30 days upon payment of prescribed fees and notify the data subject within seven days if they decline; fees must be reasonable and not exceed actual cost.
Search within this statute
Search all stored provisions in this version.
Legal text
Provisions of The Data Protection (General) Regulations
Showing 58 of 58
Part I
PRELIMINARY
- 1
PRELIMINARY - 1. Citation
AI-assisted research summary: The Regulations may be cited as the Data Protection (General) Regulations.
Section 1. Citation Section These Regulations may be cited as the Data Protection (General) Regulations. - 2
PRELIMINARY - 2. Interpretation
AI-assisted research summary: Defines the terms 'Act', 'Data Commissioner', and 'Office'.
Section 2. Interpretation Section In these Regulations, unless the context otherwise requires— Act means the Data Protection Act (Cap 411C); Data Commissioner means the person appointed as such pursuant to section 6 of the Act; and Office has the meaning assigned to it under the Act.Referenced legislation
- Data Protection Act (Cap 411C); (unresolved)
- 3
PRELIMINARY - 3. Exemption
AI-assisted research summary: Civil registration entities specified under the Data Protection (Civil Registration) Regulations (L.N. 196/2020) are exempt from these Regulations.
Section 3. Exemption Section These Regulations shall not apply to civil registration entities specified under the Data Protection (Civil Registration) Regulations (L.N. 196/2020).Referenced legislation
- Data Protection (Civil Registration) Regulations (L.N. 196/2020). (unresolved)
Part II
ENABLING THE RIGHTS OF A DATA SUBJECT
- 10
ENABLING THE RIGHTS OF A DATA SUBJECT - 10. Rectification of personal data
AI-assisted research summary: Allows a data subject to request rectification of personal data; requires controllers/processors to rectify within 14 days if necessary and to notify refusals in writing within 7 days.
Section 10. Rectification of personal data Section 10(1) Pursuant to section 40 of the Act, a data subject may request a data controller or data processor to rectify their personal data, which is untrue, inaccurate, outdated, incomplete or misleading. Section 10(2) A request for rectification may be made in Form DPG 3 set out in the First Schedule. Section 10(3) An application for rectification of personal data may be supported by such documents as may be relevant to the rectification sought. Section 10(4) A data controller or data processor shall within fourteen days of the request, rectify an entry of personal data in the database where the data controller or data processor is satisfied that a rectification is necessary. Section 10(5) Where a request for rectification is declined, a data controller or data processor shall, in writing, notify a data subject of that refusal within seven days and shall provide reasons for refusal. Section 10(6) A request for rectification shall made free of charge. - 11
ENABLING THE RIGHTS OF A DATA SUBJECT - 11. Data portability request
AI-assisted research summary: Data subjects may request portability of their personal data; controllers/processors must port data within 30 days upon payment of prescribed fees and notify the data subject within seven days if they decline; fees must be reasonable and not exceed actual cost.
Section 11. Data portability request Section 11(1) Pursuant to section 38 of the Act, a data subject may apply to port or copy their personal data from one data controller or data processor to another. Section 11(2) A request for data portability may be made in Form DPG 4set out in the First Schedule. Section 11(3) A data controller or data processor shall within thirty days of the request and upon payment of the prescribed fees port personal data to the data subject’s choice of recipient. Section 11(4) Where fee is charged under subregulation (2), the fee shall be reasonable and not exceed the cost incurred to actualize the request. Section 11(5) A data controller or data processor who receives personal data that has been ported shall, with respect to such data, comply with the requirement of the Act and these Regulations. Section 11(6) Where a data controller or data processor declines the portability request, a data controller or data processor shall, within seven days, notify the data subject of the decline and the reasons for such decline in writing. Section 11(7) The exercise of the right to data portability by a data subject shall not negate the rights of a data subject provided under the Act. - 12
ENABLING THE RIGHTS OF A DATA SUBJECT - 12. Right of erasure
AI-assisted research summary: Gives data subjects the right to request erasure of personal data in specified circumstances, allows a data subject to request erasure in Form DPG5, requires controllers or processors to respond within fourteen days, and lists exceptions where the right does not apply.
Section 12. Right of erasure Section 12(1)(a) the personal data is no longer necessary for the purpose which it was collected; Section 12(1)(b) the data subject withdraws their consent that was the lawful basis for retaining the personal data; Section 12(1)(c) the data subject objects to the processing of their data and there is no overriding legitimate interest to continue the processing; Section 12(1)(d) the processing of personal data is for direct marketing purposes and the individual objects to that processing; Section 12(1)(e) the processing of personal data is unlawful including in breach of the lawfulness requirement; or Section 12(1)(f) the erasure is necessary to comply with a legal obligation. Section 12(2) A data subject may request for erasure of their personal data held by a data controller or data processor in Form DPG5 set out in the First Schedule. Section 12(3) A data controller or data processor shall respond to a request for erasure under subregulation (2) within fourteen days of the request. Section 12(4)(a) to exercise the right of freedom of expression and information; Section 12(4)(b) to comply with a legal obligation; Section 12(4)(c) for the performance of a task carried out in the public interest or in the exercise of official authority; Section 12(4)(d) for archiving purposes in the public interest, scientific research, historical research or statistical purposes where erasure is likely to render impossible or seriously impair the achievement of that processing; or Section 12(4)(e) for the establishment, exercise or defence of a legal claim. Section 12(5) A request for erasure shall be free of charge. - 13
ENABLING THE RIGHTS OF A DATA SUBJECT - 13. Exercise of rights by others
AI-assisted research summary: When a person duly authorised by a data subject seeks to exercise rights on their behalf, the data controller or data processor must act in the data subject's best interests.
Section 13. Exercise of rights by others Section 13(1) Subject to section 27 of the Act, where a person duly authorised by a data subject seeks to exercise the rights on their behalf, the data controller or data processor shall act in the best interests of the data subject. Section 13(2)(a) a person exercising the right is appropriately identified; Section 13(2)(b) profiling of a child that is related to direct marketing is prohibited; and Section 13(2)(c) the parent or guardian is informed of the inherent risks in processing and the safeguards put in place. Section 13(3) Where a data controller or a data processor is uncertain as to the existence of a relationship between the duly authorised person and the data subject, the data controller or data processor may restrict the request of exercising a right on behalf of the data subject until evidence to the contrary is adduced. - 4
ENABLING THE RIGHTS OF A DATA SUBJECT - 4. Processing on the basis of consent
AI-assisted research summary: If a data subject withdraws consent to any part of processing, the data controller or data processor must restrict that part of the processing (subject to section 34 of the Act).
Section 4. Processing on the basis of consent Section 4(1)(a) the identity of the data controller or data processor; Section 4(1)(b) the purpose of each of the processing operations for which consent is sought; Section 4(1)(c) the type of personal data that is collected and used; Section 4(1)(d) information about the use of the personal data for automated decision-making, where relevant; Section 4(1)(e) the possible risks of data transfers due to absence of an adequacy decision or appropriate safeguards; Section 4(1)(f) whether the personal data processed shall be shared with third parties; Section 4(1)(g) the right to withdraw consent; and Section 4(1)(h) the implications of providing, withholding or withdrawing consent. Section 4(2) The information under subregulation (1) may be presented to the data subject through a written notice, oral statement, audio or video message. Section 4(3)(a) data subject has capacity to give consent; Section 4(3)(b) data subject voluntarily gives consent; and Section 4(3)(c) consent is specific to the purpose of processing. Section 4(4)(a) it is presumed on the basis that the data subject did not object to a proposal to processing of their personal data in a particular manner; Section 4(4)(b) it is presented as a non-negotiable part of the terms and conditions for processing; Section 4(4)(c) the data subject is unable to refuse or withdraw their consent without detriment; Section 4(4)(d) the data controller or data processor merges several purposes for processing without seeking specific consent for each purpose; or Section 4(4)(e) the intention of the data subject is ambiguous. Section 4(5) Where the data subject withdraws consent to any part of the processing, the data controller or data processor shall restrict the part of the processing in respect of which consent is withdrawn, subject to section 34 of the Act. - 5
ENABLING THE RIGHTS OF A DATA SUBJECT - 5. Lawful basis for processing
AI-assisted research summary: A data controller or data processor may process personal data without the data subject's consent when the processing is necessary for any reason set out in section 30(1)(b) of the Act.
Section 5. Lawful basis for processing Section 5(1) A data controller or data processor may process data without consent of a data subject if the processing is necessary for any reason set out in section 30(1) (b) of the Act. Section 5(2) Processing under subregulation (1) shall only rely on one legal basis for processing at a time, which shall be established before the processing. Section 5(3)(a) distinguish between the legal bases being used; and Section 5(3)(b) respond to any data subject rights requests. - 6
ENABLING THE RIGHTS OF A DATA SUBJECT - 6. Mode of collection of personal data
AI-assisted research summary: Data controllers and processors must inform individuals when personal data is collected indirectly (within fourteen days), must ensure any new purpose for data is compatible with the original purpose, and must seek fresh consent where a new purpose is incompatible.
Section 6. Mode of collection of personal data Section 6(1)(a) any person other than the data subject; Section 6(1)(b) publications or databases; Section 6(1)(c) surveillance cameras, where an individual is identifiable or reasonably identifiable; Section 6(1)(d) information associated with web browsing; or Section 6(1)(e) biometric technology, including voice or facial recognition. Section 6(2)(a) ensure that processing is limited to personal data which the data subject has permitted the data controller or data processor to collect; Section 6(2)(b) undertake steps to ensure that personal data is accurate, not in excessive and up to date; Section 6(2)(c) undertake processes to secure personal data; and Section 6(2)(d) comply with the lawful processing principles set out under Part IV of the Act. Section 6(3) Where a data controller or data processor collects personal data indirectly, the data controller or data processor shall within fourteen days inform the data subject of the collection. Section 6(4) Where a data controller or data processor intends to use personal data for a new purpose, the data controller or data processor shall ensure that the new purpose is compatible with the initial purpose for which the personal data was collected. Section 6(5) Where the new purpose is not compatible with the initial purpose, a data controller or data processor shall seek fresh consent from the data subject in accordance with regulation 4. - 7
ENABLING THE RIGHTS OF A DATA SUBJECT - 7. Restriction to processing
AI-assisted research summary: Sets when a data subject can request restriction of processing, how to make the request, duties on controllers/processors to implement and record a restriction and to notify third parties, allows controllers/processors to decline manifestly unfounded or excessive requests, requires written notification with reasons within 14 days when declining under section 34(2), and prohibits processing restricted data except for storage.
Section 7. Restriction to processing Section 7(1)(a) the data subject contests the accuracy of their personal data; Section 7(1)(b) the personal data has been unlawfully processed and the data subject opposes the erasure and requests restriction instead; Section 7(1)(c) the data subject no longer needs their personal data but the data controller or data processor requires the personal data to be kept in order to establish, exercise or defend a legal claim; or Section 7(1)(d) a data subject has objected to the processing of their personal data under regulation 8 and a data controller or data processor is considering legitimate grounds that override those of the data subject. Section 7(2) A request for restriction to processing of personal data on any of the grounds provided under section 34 of the Act may be made in Form DPG 1 set out in the First Schedule. Section 7(3)(a) admit and implement the request; Section 7(3)(b) indicate on the data controller or data processors system that the processing of the personal data has been restricted; and Section 7(3)(c) notify any relevant third party of the restriction where personal data, subject to such restriction, may have been shared. Section 7(4)(a) temporarily moving the personal data to another processing system; Section 7(4)(b) making the personal data unavailable to third parties; or Section 7(4)(c) temporarily removing published data specific to the data subject from its website or other public medium in its control. Section 7(5) A data controller or data processor may decline to comply with a request for restriction in processing, where such request is manifestly unfounded or excessive. Section 7(6) Where a data controller or data processor declines a request on any of the grounds provided under section 34(2) of the Act, the data controller or data processor shall within fourteen days of the refusal, notify the data subject of the refusal, in writing, and shall provide the reasons for the decision. Section 7(7) A data controller or data processor shall not process personal data that has been restricted, except to store the personal data, in accordance with section 34(2)(a) of the Act. - 8
ENABLING THE RIGHTS OF A DATA SUBJECT - 8. Objection to processing
AI-assisted research summary: Data subjects may request that controllers or processors stop processing some or all of their personal data; controllers/processors must comply free of charge within fourteen days. The right is absolute for direct marketing, and objections for that purpose mean the data must not be processed for direct marketing.
Section 8. Objection to processing Section 8(1) Pursuant to section 36 of the Act, a data subject may request a data controller or data processor not to process all or part of their personal data, for a specified purpose or in a specified manner. Section 8(2) A request to object the processing may be made in Form DPG 1 set out in the First schedule. Section 8(3) A data controller or data processor shall, without charging any fee, comply with a request for objection under subregulation (2) within fourteen days of the request. Section 8(4) The right to object to processing applies as an absolute right where the processing is for direct marketing purposes which includes profiling to the extent that it is related to such direct marketing. Section 8(5) Where the data subject objects to processing for direct marketing purposes, the personal data shall not be processed for such purposes. Section 8(6)(a) the reasons for declining the request for objection; and Section 8(6)(b) the right to lodge a complaint to the Data Commissioner where dissatisfied. Section 8(7)(a) the reasons for declining the request for objection; and Section 8(7)(b) the right to lodge a complaint to the Data Commissioner where dissatisfied. - 9
ENABLING THE RIGHTS OF A DATA SUBJECT - 9. Data access request
AI-assisted research summary: Section 9 lets a data subject request access to their personal data (using Form DPG 2) and requires data controllers/processors to comply and provide access, copies or mechanisms to view data, with compliance within seven days.
Section 9. Data access request Section 9(1)(a) the purposes of the processing; Section 9(1)(b) the categories of personal data concerned; Section 9(1)(c) the recipients or categories of recipient to whom the personal data have been or will be disclosed, including recipients in other countries or territories; Section 9(1)(d) where possible, the envisaged period for which the personal data may be stored, or, if not possible, the criteria used to determine that period; and Section 9(1)(e) where the personal data is not collected from the data subject, any available information as to the source of collection. Section 9(2) A data subject may request to access their personal data in Form DPG 2 set out in the First Schedule. Section 9(3)(a) on request, provide access to a data subject of their personal data in its possession; Section 9(3)(b) put in place mechanisms to enable a data subject to proactively access or examine their personal data; or Section 9(3)(c) provide the data subject with a copy of their personal data. Section 9(4) A data controller or a data processor shall comply with a request by a data subject to access their personal data within seven days of the of the request. Section 9(5) Where the data subject makes the request by electronic means, and unless otherwise requested by the data subject, the information shall be provided in a commonly used electronic form. Section 9(6) Compliance with a request for access to personal data shall be free of charge.
Part III
RESTRICTIONS ON THE COMMERCIAL USE OF PERSONAL DATA
- 14
RESTRICTIONS ON THE COMMERCIAL USE OF PERSONAL DATA - 14. Interpretation of commercial purposes
AI-assisted research summary: A data controller or processor is treated as using personal data for commercial purposes when personal data is used to advance commercial or economic interests, for example to induce purchases or enable transactions.
Section 14. Interpretation of commercial purposes Section 14(1) For the purposes of section 37(1) of the Act, a data controller or data processor shall be considered to use personal data for commercial purposes where personal data of a data subject is used to advance commercial or economic interests, including inducing another person to buy, rent, lease, join, subscribe to, provide or exchange products, property, information or services, or enabling or effecting, directly or indirectly, a commercial transaction. Section 14(2)(a) sending a catalogue through any medium addressed to a data subject; Section 14(2)(b) displaying an advertisement on an online media site where a data subject is logged on using their personal data; or Section 14(2)(c) sending an electronic message to a data subject about a sale, or other advertising material relating to a sale, using personal data provided by a data subject. Section 14(3) Marketing is not direct where personal data is not used or disclosed to identify or target particular recipients. - 15
RESTRICTIONS ON THE COMMERCIAL USE OF PERSONAL DATA - 15. Permitted commercial use of personal data
AI-assisted research summary: Section 15 permits commercial use of personal data for direct marketing only in specified circumstances (collection from the data subject, notification that direct marketing is a purpose, consent, absence of an opt-out request) and requires controllers/processors to provide an opt-out mechanism; it prohibits transmission for direct marketing unless contact particulars for opting out are indicated and criminalises commercial use without consent with fines or imprisonment.
Section 15. Permitted commercial use of personal data Section 15(1)(a) the data controller or data processor has collected the personal data from the data subject; Section 15(1)(b) a data subject is notified that direct marketing is one of the purposes for which personal data is collected; Section 15(1)(c) the data subject has consented to the use or disclosure of the personal data for the purpose of direct marketing; Section 15(1)(d) the data controller or data processor provides a simplified opt out mechanism for the data subject to request not to receive direct marketing communications; or Section 15(1)(e) the data subject has not made an opt out request. Section 15(2) A data controller or data processor shall not transmit, for the purposes of direct marketing, messages by any means unless the data controller or data processor indicates particulars to which a data subject may send a request to restrict such communications without incurring charges. Section 15(3)(a) where the identity of the person on whose behalf the communication has been sent has been disguised or concealed; Section 15(3)(b) where a valid address to which the recipient of the communication may send a request that such communications cease has not been provided; or Section 15(3)(c) where there is use of automated calling systems without human intervention. Section 15(4) A data controller or data processor who uses personal data for commercial purposes without the consent of the data subject commits an offence and is liable, on conviction, to a fine not exceeding twenty thousand shillings or to a term of imprisonment not exceeding six months, or to both fine and imprisonment. - 16
RESTRICTIONS ON THE COMMERCIAL USE OF PERSONAL DATA - 16. Features of an opt out message
AI-assisted research summary: Section 16(1) lists required features of an opt‑out message (clear explanation, minimal effort process, direct accessible channel, free or nominal cost, accessible to persons with a disability). Section 16(2) prohibits a data controller or data processor from using or disclosing a data subject's personal data for direct marketing if the data subject has opted out and in accordance with the data subject's request.
Section 16. Features of an opt out message Section 16(1)(a) have a visible, clear and easily understood explanation of how to opt out; Section 16(1)(b) include a process for opting out that requires minimal time and effort; Section 16(1)(c) provide a direct and accessible communication channel; Section 16(1)(d) be free of charge or where necessary involve a nominal cost to a data subject; and Section 16(1)(e) be accessible to persons with a disability. Section 16(2) Where a data subject has opted out, a data controller or data processor shall not use or disclose their personal data for the purpose of direct marketing, in accordance with the data subject’s request. - 17
RESTRICTIONS ON THE COMMERCIAL USE OF PERSONAL DATA - 17. Mechanisms to comply with opt out requirement
AI-assisted research summary: Data controllers and data processors must include clear opt-out statements and mechanisms in direct marketing communications, and must provide an option to opt out of all future direct marketing; they may use preference-setting opt-out mechanisms.
Section 17. Mechanisms to comply with opt out requirement Section 17(1) In communicating with a data subject on direct marketing, a data controller or data processor shall include a statement which is prominently displayed, or otherwise draws the attention of the data subject to the fact that the data subject may make an opt out request. Section 17(2)(a) clearly indicate, in each direct marketing message, that a data subject may opt out of receiving future messages by replying with a single word instruction in the subject line; Section 17(2)(b) ensure that a link is prominently located in the email, which takes a data subject to a subscription control centre; Section 17(2)(c) clearly indicate that a data subject may opt out of future direct marketing by replying to a direct marketing text message with a single word instruction; Section 17(2)(d) inform the recipient of a direct marketing phone call that they can verbally opt out from any future calls; and Section 17(2)(e) include instructions on how to opt out from future direct marketing, in each message. Section 17(3) A data controller or a data processor may use an opt out mechanism that provides a data subject with the opportunity to indicate their direct marketing communication preferences, including the extent to which they wish to opt out. Section 17(4) Despite subregulation (3), a data controller or data processor shall provide a data subject with an option to opt out of all future direct marketing communications as one of outlined preferences. - 18
RESTRICTIONS ON THE COMMERCIAL USE OF PERSONAL DATA - 18. Request for restriction of further direct marketing
AI-assisted research summary: Data subjects may ask controllers or processors to restrict disclosure or use of their personal data for direct marketing; controllers/processors must comply within seven days.
Section 18. Request for restriction of further direct marketing Section 18(1) A data subject may request a data controller or data processor to restrict use or disclosure of their personal data, to a third party, for the purpose of facilitating direct marketing. Section 18(2) No fee shall be charged to a data subject for making or giving effect to a request under this Part. Section 18(3) A data controller or data processor shall restrict use or disclosure of personal data for the purpose of facilitating direct marketing by a third party within seven days of the request.
Part IV
OBLIGATIONS OF DATA CONTROLLERS AND DATA PROCESSORS
- 19
OBLIGATIONS OF DATA CONTROLLERS AND DATA PROCESSORS - 19. Retention of personal data
AI-assisted research summary: Data controllers and data processors must retain personal data only as long as reasonably necessary for the purpose and must establish time limits for periodic review of retained data for law enforcement purposes.
Section 19. Retention of personal data Section 19(1) Pursuant to section 39 of the Act, a data controller or data processor shall retain personal data processed for a lawful purpose, for as long as may be reasonably necessary for the purpose for which the personal data is processed. Section 19(2)(a) establish personal data retention schedule with appropriate time limits for the periodic review of the need for the continued storage of personal data that is no longer necessary or where the retention period is reached; and Section 19(2)(b) erase, delete anonymise or pseudonymise personal data upon the lapse of the purpose for which the personal data was collected. Section 19(3)(a) purpose for retention; Section 19(3)(b) the retention period; Section 19(3)(c) provision for periodic audit of the personal data retained; and Section 19(3)(d) actions to be taken after the audit of the personal data retained. Section 19(4)(a) review records with a view of identifying personal data that no longer requires to be retained and permanently delete the personal data; Section 19(4)(b) ensure the retained data is accurate and up-to-date; Section 19(4)(c) specify the purpose for retention of personal data; Section 19(4)(d) ensure that the personal data security measures are adequate; and Section 19(4)(e) identify the best cause of action where personal data retention period lapses. Section 19(5) A data controller or data processor shall establish appropriate time limits for the periodic review of the need for the continued storage of personal data for any of the law enforcement purposes. Section 19(6) The personal data storage limitation period and data retention schedule outlined under paragraph (2)(a) may be included as part of the policy envisaged in regulation 23. - 20
OBLIGATIONS OF DATA CONTROLLERS AND DATA PROCESSORS - 20. Requests to deal anonymously or pseudonymously
AI-assisted research summary: Data controllers or data processors may agree to requests to deal anonymously or pseudonymously if satisfied the request is for any reason listed in subsection (1) and it is in the data subject's best interests.
Section 20. Requests to deal anonymously or pseudonymously Section 20(1)(a) not to be identified; Section 20(1)(b) to avoid subsequent contact such as direct marketing from an entity or third parties; Section 20(1)(c) to enhance their privacy on the whereabouts of a data subject; Section 20(1)(d) to access services such as counselling or health services without it becoming known to others; Section 20(1)(e) to express views in a public arena without being personally identified; or Section 20(1)(f) to minimise the risk of identity fraud. Section 20(2) A data controller or data processor may accede to the request where satisfied that the request is based on any of the reasons specified under subregulation (1) and where the request is in the best interests of the data subject. - 21
OBLIGATIONS OF DATA CONTROLLERS AND DATA PROCESSORS - 21. Sharing of personal data
AI-assisted research summary: Data controllers and processors may share personal data on request (subject to section 25); controllers/processors must determine the purpose and means of sharing; routine sharing between controllers requires agreements; internal sharing within an organisation is not considered data sharing; sharing must specify purpose, retention duration and safeguards.
Section 21. Sharing of personal data Section 21(1) Subject to section 25 of the Act, a data controller or data processor may share or exchange personal data collected, upon request, by another data controller, data processor, third party or a data subject. Section 21(2) A data controller or data processor shall determine the purpose and means of sharing personal data from one data controller or data processor to another. Section 21(3)(a) providing personal data to a third party by whatever means by the data controller or data processor; Section 21(3)(b) receiving personal data from a data controller or data processor as joint participant in a data sharing arrangement; Section 21(3)(c) exchanging or transmission of personal data; Section 21(3)(d) providing third party with access to personal data on the data controller’s information systems; Section 21(3)(e) separate or joint initiatives by data controllers or data processors to pool personal data making the data available to each other or a third-party subject to entering into an agreement, as may be applicable; or Section 21(3)(f) routine data sharing between data controllers on a regular or pre-planned basis. Section 21(4) In carrying out any routine data sharing as contemplated under paragraph (3)(f), a data controller shall enter into agreements prior to data sharing. Section 21(5) For the avoidance of doubt, the sharing of data within the organizational structures of a data controller or data processor is not considered as a data sharing. Section 21(6)(a) the purpose for which personal data is required; Section 21(6)(b) the duration for which personal data shall be retained; and Section 21(6)(c) proof of the safeguards put in place to secure personal data from unlawful disclosure. - 22
OBLIGATIONS OF DATA CONTROLLERS AND DATA PROCESSORS - 22. Automated individual decision making
AI-assisted research summary: When processing involves automated individual decision-making, data subjects must be informed and provided protections including transparency about logic, fairness, error prevention, and the ability to obtain human intervention.
Section 22. Automated individual decision making Section 22(1) In this regulation— “an automated individual decision-making” means a decision made by automated means without any human involvement. Section 22(2)(a) inform a data subject when engaging in processing based on automated individual decision making; Section 22(2)(b) provide meaningful information about the logic involved; Section 22(2)(c) specific transparency and fairness requirements are in place; Section 22(2)(c)(i) specific transparency and fairness requirements are in place; Section 22(2)(c)(ii) rights for a data subject to oppose profiling and specifically profiling for marketing are present; and Section 22(2)(c)(iii) where conditions specified under section 31 of the Act arise, a data protection impact assessment is carried out; Section 22(2)(d) explain the significance and envisaged consequences of the processing; Section 22(2)(e) ensure the prevention of errors; Section 22(2)(f) use appropriate mathematical or statistical procedures; Section 22(2)(g) put appropriate technical and organisational measures in place to correct inaccuracies and minimise the risk of errors; Section 22(2)(h) process personal data in a way that eliminates discriminatory effects and bias; and Section 22(2)(i) ensure that a data subject can obtain human intervention and express their point of view. - 23
OBLIGATIONS OF DATA CONTROLLERS AND DATA PROCESSORS - 23. Data protection policy
AI-assisted research summary: A data controller or data processor must develop, publish and regularly update a policy describing how they handle personal data and what that policy contains.
Section 23. Data protection policy Section 23(1) A data controller or data processor shall develop, publish and regularly update a policy reflecting their personal data handling practices. Section 23(2)(a) the nature of personal data collected and held; Section 23(2)(b) how a data subject may access their personal data and exercise their rights in respect to that personal data; Section 23(2)(c) complaints handling mechanisms; Section 23(2)(d) lawful purpose for processing personal data; Section 23(2)(e) obligations or requirements where personal data is to be transferred outside the country, to third parties, or other data controllers or data processors located outside Kenya and where possible, specify such recipients; Section 23(2)(f) the retention period and schedule contemplated under regulation 19; and Section 23(2)(g) the collection of personal data from children, and the criteria to be applied. - 24
OBLIGATIONS OF DATA CONTROLLERS AND DATA PROCESSORS - 24. Contract between data controller and data processor
AI-assisted research summary: A data controller must engage a data processor through a written contract; data processors must obtain confidentiality commitments from third parties they allow to process personal data; the contract may include auditing and inspection provisions by the data controller.
Section 24. Contract between data controller and data processor Section 24(1) Subject to section 42(2)(b) of the Act, a data controller shall engage a data processor, through a written contract. Section 24(2)(a) the subject matter of the processing; Section 24(2)(a)(i) the subject matter of the processing; Section 24(2)(a)(ii) the duration of the processing; Section 24(2)(a)(iii) the nature and purpose of the processing; Section 24(2)(a)(iv) the type of personal data being processed; Section 24(2)(a)(v) the categories of data subjects; and Section 24(2)(a)(vi) the obligations and rights of the data controller; Section 24(2)(b) instructions of the data controller; Section 24(2)(c) duty on the data processors to obtain a commitment of confidentiality from any person or entity that the data processors allows to process the personal data; Section 24(2)(d) security measures subjecting the data processor to appropriate technical and organizational measures in relation to keeping personal data secure; Section 24(2)(e) provision stipulating that all personal data must be permanently deleted or returned on termination or lapse of the agreement, as decided by the data controller; and Section 24(2)(f) auditing and inspection provisions by the data controller. - 25
OBLIGATIONS OF DATA CONTROLLERS AND DATA PROCESSORS - 25. Obligations of a data processor
AI-assisted research summary: Data processors must not engage third parties without prior authorisation from the data controller; if authorised they must contract with the third party, include required particulars, and remain liable for the third party's compliance.
Section 25. Obligations of a data processor Section 25(1) A data processor shall not engage the services of a third party without the prior authorisation of the data controller. Section 25(2) Where authorisation is given, the data processor shall enter into a contract with the third party. Section 25(3) The contract contemplated under subregulation (1) shall include such particulars as provided for under subregulation 24(2). Section 25(4) A data processor shall remain liable to the data controller for the compliance of any third party that they engage. - 26
OBLIGATIONS OF DATA CONTROLLERS AND DATA PROCESSORS - 26. Requirement for specified processing to be done in Kenya
AI-assisted research summary: Requires specified processing to be done in Kenya: process such personal data through a server and data centre located in Kenya; or store at least one serving copy of the concerned personal data in a data centre located in Kenya.
Section 26. Requirement for specified processing to be done in Kenya Section 26(1)(a) process such personal data through a server and data centre located in Kenya; or Section 26(1)(b) store at least one serving copy of the concerned personal datain a data centre located in Kenya. Section 26(2)(a) administering of the civil registration and legal identity management systems; Section 26(2)(b) facilitating the conduct of elections for the representation of the people under the Constitution; Section 26(2)(c) overseeing any system for administering public finances by any state organ; Section 26(2)(d) running any system designated as a protected computer system in terms of section 20 of the Computer Misuse and Cybercrime Act (Cap. 79C); Section 26(2)(e) offering any form of early childhood education and basic education under the Basic Education Act (Cap. 211); or Section 26(2)(f) provision of primary or secondary health care for a data subject in the country. Section 26(3)(a) has been notified that personal data outside Kenya has been breached or its services have been used to violate the Act and has not taken measures to stop or handle the violation; and Section 26(3)(b) cooperating to investigate and handle such violations; or Section 26(3)(b)(i) cooperating to investigate and handle such violations; or Section 26(3)(b)(ii) neutralising and disabling the effect of cyber security protection measures.Referenced legislation
- Basic Education Act (Cap. 211); (unresolved)
- Constitution (unresolved)
- Computer Misuse and Cybercrime Act (Cap. 79C); (unresolved)
Part IX
PROVISIONS ON EXEMPTIONS UNDER THE ACT
- 54
PROVISIONS ON EXEMPTIONS UNDER THE ACT - 54. Exemption for national security
AI-assisted research summary: National security processing by specified organs counts as processing for national security; controllers/processors seeking exemption must apply to the Cabinet Secretary, who may issue or revoke exemption certificates.
Section 54. Exemption for national security Section 54(1) For the purposes of section 51(2)(b) of the Act, the processing of personal data by a national security organ referred to in Article 239(1) of the Constitution in furtherance of their mandate constitutes a processing for national security. Section 54(2) Despite subregulation (1), a data controller or data processor who processes personal data for national security and wishes to be exempt on that ground shall apply to the Cabinet Secretary for an exemption. Section 54(3) The Cabinet Secretary shall, upon being satisfied that the grounds supporting the application are sufficient, issue a certificate of exemption. Section 54(4) The Cabinet Secretary may revoke a certificate of exemption issued, at any time, where the grounds on which the certificate was issued no longer apply. - 55
PROVISIONS ON EXEMPTIONS UNDER THE ACT - 55. Exemptions for public interest
AI-assisted research summary: Exemptions for public interest
Section 55. Exemptions for public interest Section permitted general situation; or - 56
PROVISIONS ON EXEMPTIONS UNDER THE ACT - 56. Permitted general situation
AI-assisted research summary: Permitted general situation lessening or preventing a serious threat to the life, health or safety of any data subject, or to public health or safety
Section 56. Permitted general situation Section lessening or preventing a serious threat to the life, health or safety of any data subject, or to public health or safety; - 57
PROVISIONS ON EXEMPTIONS UNDER THE ACT - 57. Permitted health situation
AI-assisted research summary: Section 57 lists permitted situations for collecting, using or disclosing health information and conditions under which disclosure is allowed.
Section 57. Permitted health situation Section 57(1)(a) the collection of health information to provide a health service; Section 57(1)(b) the collection, use, or disclosure of health data is for health research and related purposes; Section 57(1)(c) the use or disclosure of genetic information where necessary and obtained in course of providing a health service; Section 57(1)(d) the disclosure of health information for a secondary purpose to a responsible person for a data subject. Section 57(2)(a) they provide a health service to the data subject; Section 57(2)(b) the recipient of the personal data is a responsible person for the data subject; Section 57(2)(c) a data subject is either physically or legally incapable of giving consent to the disclosure, or physically cannot communicate consent to the disclosure; Section 57(2)(d) the disclosure is necessary to provide appropriate care or treatment of a data subject, or the disclosure is made for compassionate reasons; Section 57(2)(e) the disclosure is not contrary to any wish expressed by the data subject before the data subject became unable to give or communicate consent of which the carer is aware or of which the carer could reasonably be expected to be aware; and Section 57(2)(f) the disclosure is limited to the extent reasonable and necessary to provide appropriate care or treatment of the individual or to fulfil the purpose of making a disclosure for compassionate reasons.
Part V
ELEMENTS TO IMPLEMENT DATA PROTECTION BY DESIGN OR BY DEFAULT
- 27
ELEMENTS TO IMPLEMENT DATA PROTECTION BY DESIGN OR BY DEFAULT - 27. Data protection by design or default
AI-assisted research summary: Data protection mechanisms must be embedded in processing.
Section 27. Data protection by design or default Section establish the data protection mechanisms set out under the Act and these Regulations are embedded in the processing; and - 28
ELEMENTS TO IMPLEMENT DATA PROTECTION BY DESIGN OR BY DEFAULT - 28. Elements of data protection by design or default
AI-assisted research summary: Requires elements for the protection of personal data by design or by default to implement the data protection principles in section 25.
Section 28. Elements of data protection by design or default Section The elements for the protection of personal data by design or by default that are necessary to implement the data protection principles outlined under section 25 of the Act are as set out in this Part. - 29
ELEMENTS TO IMPLEMENT DATA PROTECTION BY DESIGN OR BY DEFAULT - 29. Elements for principle of lawfulness
AI-assisted research summary: Processing of personal data must have an appropriate legal basis or legitimate interests clearly connected to the specific purpose of processing.
Section 29. Elements for principle of lawfulness Section appropriate legal basis or legitimate interests clearly connected to the specific purpose of processing; - 30
ELEMENTS TO IMPLEMENT DATA PROTECTION BY DESIGN OR BY DEFAULT - 30. Elements for principle of transparency
AI-assisted research summary: Use clear, simple and plain language to communicate with a data subject so they can make decisions about processing their personal data.
Section 30. Elements for principle of transparency Section the use of clear, simple and plain language to communicate with a data subject to enable a data subject to make decisions on the processing of their personal data; - 31
ELEMENTS TO IMPLEMENT DATA PROTECTION BY DESIGN OR BY DEFAULT - 31. Elements for principle of purpose limitation
AI-assisted research summary: Specify the purpose for each processing of personal data.
Section 31. Elements for principle of purpose limitation Section specifying the purpose for each processing of personal data; - 32
ELEMENTS TO IMPLEMENT DATA PROTECTION BY DESIGN OR BY DEFAULT - 32. Elements for principle of integrity, confidentiality and availability
AI-assisted research summary: Requires having an operative means to manage policies and procedures for information security.
Section 32. Elements for principle of integrity, confidentiality and availability Section having an operative means of managing policies and procedures for information security; - 33
ELEMENTS TO IMPLEMENT DATA PROTECTION BY DESIGN OR BY DEFAULT - 33. Elements for principle of data minimization
AI-assisted research summary: Encourage avoiding processing personal data altogether when possible for the relevant purpose.
Section 33. Elements for principle of data minimization Section avoiding the processing of personal data altogether when this is possible for the relevant purpose; - 34
ELEMENTS TO IMPLEMENT DATA PROTECTION BY DESIGN OR BY DEFAULT - 34. Elements for principle of accuracy
AI-assisted research summary: Requires that data sources be reliable with respect to data accuracy.
Section 34. Elements for principle of accuracy Section ensuring data sources are reliable in terms of data accuracy; - 35
ELEMENTS TO IMPLEMENT DATA PROTECTION BY DESIGN OR BY DEFAULT - 35. Elements for principle of storage limitation
AI-assisted research summary: Requires having clear internal procedures for deletion and destruction.
Section 35. Elements for principle of storage limitation Section having clear internal procedures for deletion and destruction; - 36
ELEMENTS TO IMPLEMENT DATA PROTECTION BY DESIGN OR BY DEFAULT - 36. Elements for principle of fairness
AI-assisted research summary: Data subjects are entitled to the highest degree of autonomy regarding control of their personal data.
Section 36. Elements for principle of fairness Section granting the data subjects the highest degree of autonomy with respect to control over their personal data;
Part VI
NOTIFICATION OF PERSONAL DATA BREACHES
- 37
NOTIFICATION OF PERSONAL DATA BREACHES - 37. Categories of notifiable data breach
AI-assisted research summary: Lists categories of personal data that, when breached, are treated as notifiable data breaches: (a) the data subject’s full name or identification number together with personal data/classes in the Second Schedule; (b) the data subject’s account identifier; and (b)(ii) any password, security code, access code, response to a security question, biometric data or other data used to allow access to the individual’s account. It also states what constitutes non-notifiable data (publicly available data or data disclosed as required/permitted by written law) and that a breach of the listed personal data amounts to a notifiable data breach under section 43 of the Act.
Section 37. Categories of notifiable data breach Section 37(1)(a) the data subject’s full name or identification number and any of the personal data or classes of personal data relating to the data subject set out in the Second Schedule; or Section 37(1)(b) the data subject’s account identifier, such as an account name or number; and Section 37(1)(b)(i) the data subject’s account identifier, such as an account name or number; and Section 37(1)(b)(ii) any password, security code, access code, response to a security question, biometric data or other data that is used or required to allow access to or use of the individual’s account. Section 37(2) A breach of any personal data envisaged under subregulation (1) amounts to notifiable data breach under section 43 of the Act. Section 37(3)(a) any personal data that is publicly available; or Section 37(3)(b) any personal data that is disclosed to the extent that is required or permitted under any written law. Section 37(4) The personal data referred to in sub-paragraph (3)(a) shall not be publicly available solely because of any data breach. - 38
NOTIFICATION OF PERSONAL DATA BREACHES - 38. Notification to Data Commissioner
AI-assisted research summary: Section 38. Notification to Data Commissioner Section 38(1)(a) the date on which and the circumstances in which the data controller or data processor first became aware that the data breach had occurred; Section 38(1)(b) a chronological
Section 38. Notification to Data Commissioner Section 38(1)(a) the date on which and the circumstances in which the data controller or data processor first became aware that the data breach had occurred; Section 38(1)(b) a chronological account of the steps taken by the data controller or data processor after the data controller or data processor became aware that the data breach had occurred, including the data controller or data processor’s assessment that the data breach is a notifiable data breach; Section 38(1)(c) details on how the notifiable data breach occurred, where applicable; Section 38(1)(d) the number of data subjects or other persons affected by the notifiable data breach; Section 38(1)(e) the personal data or classes of personal data affected by the notifiable data breach; Section 38(1)(f) the potential harm to the affected data subjects as a result of the notifiable data breach; Section 38(1)(g) eliminate or mitigate any potential harm to any affected data subject or other person as a result of the notifiable data breach; or Section 38(1)(g)(i) eliminate or mitigate any potential harm to any affected data subject or other person as a result of the notifiable data breach; or Section 38(1)(g)(ii) address or remedy any failure or shortcoming that the data controller or data processor believes to have caused, or enabled or facilitated the occurrence of, the notifiable data breach; Section 38(1)(h) the affected individuals or the public that the notifiable data breach has occurred and how an affected data subject may eliminate or mitigate any potential harm as a result of the notifiable data breach; or Section 38(1)(i) contact information of an authorized representative of the data controller or data processor. Section 38(2) Where the data controller intends not to communicate a notifiable data breach to a data subject affected by such breach, under the conditions set out in section 43(1)(b) of the Act, the notification to the Data Commissioner under subregulation (1) shall additionally specify the grounds for not notifying the affected data subject.
Part VII
TRANSFER OF PERSONAL DATA OUTSIDE KENYA
- 39
TRANSFER OF PERSONAL DATA OUTSIDE KENYA - 39. Interpretation of the Part VII
AI-assisted research summary: Defines “data in transit” as personal data passing through Kenya en route to a foreign country or territory, not accessed, used or disclosed in Kenya except to effect the transportation.
Section 39. Interpretation of the Part VII Section “data in transit” means personal data transferred through Kenya in the course of onward transportation to a country or territory outside Kenya, without the personal data being accessed or used by, or disclosed to, any entity while in Kenya, except for the purpose of such transportation; - 40
TRANSFER OF PERSONAL DATA OUTSIDE KENYA - 40. General principles for transfers of personal data out of the country
AI-assisted research summary: Sets out general principles for transfers of personal data out of the country and requires appropriate data protection safeguards.
Section 40. General principles for transfers of personal data out of the country Section appropriate data protection safeguards; - 41
TRANSFER OF PERSONAL DATA OUTSIDE KENYA - 41. Transfers on the basis of appropriate safeguards
AI-assisted research summary: Transfers of personal data outside Kenya are allowed on the basis of appropriate safeguards, including where a data controller assesses the circumstances and concludes appropriate safeguards exist; transfers must be documented and documentation provided to the Commissioner on request, including date/time, recipient, justification and description of data transferred.
Section 41. Transfers on the basis of appropriate safeguards Section 41(1)(a) a legal instrument containing appropriate safeguards for the protection of personal data binding the intended recipient that is essentially equivalent to the protection under the Act and these Regulations; or Section 41(1)(b) the data controller, having assessed all the circumstances surrounding transfers of that type of personal data to another country or relevant international organisation, concludes that appropriate safeguards exist to protect the data. Section 41(2)(a) the transfer shall be documented; Section 41(2)(b) the documentation shall be provided to the Commissioner on request; and Section 41(2)(c) the date and time of the transfer; Section 41(2)(c)(i) the date and time of the transfer; Section 41(2)(c)(ii) the name of the recipient; Section 41(2)(c)(iii) the justification for the transfer; and Section 41(2)(c)(iv) a description of the personal data transferred. - 42
TRANSFER OF PERSONAL DATA OUTSIDE KENYA - 42. Deeming of appropriate safeguards
AI-assisted research summary: Deeming of appropriate safeguards Section ratified the African Union Convention on Cyber Security and Personal Data Protection
Section 42. Deeming of appropriate safeguards Section ratified the African Union Convention on Cyber Security and Personal Data Protection;Referenced legislation
- African Union Convention on Cyber Security and Personal Data Protection (unresolved)
- 43
TRANSFER OF PERSONAL DATA OUTSIDE KENYA - 43. Binding corporate rules
AI-assisted research summary: Binding corporate rules are legally binding, apply to and are enforced by every member of the group (including employees); they grant data subjects enforceable rights and must meet the requirements listed in subregulation (2).
Section 43. Binding corporate rules Section 43(1)(a) are legally binding and apply to and are enforced by every member concerned of the group of undertakings, or group of enterprises engaged in a joint economic activity, including their employees; Section 43(1)(b) expressly confer enforceable rights on data subjects with regard to the processing of their personal data; and Section 43(1)(c) fulfil the requirements laid down in subregulation (2). Section 43(2)(a) the structure and contact details of the group of undertakings, or group of enterprises engaged in a joint economic activity and of each of its members; Section 43(2)(b) the data transfers or set of transfers, including the categories of personal data, the type of processing and its purposes, the type of data subjects affected and the identification of another country or countries in question; Section 43(2)(c) their legally binding nature, both internally and externally; Section 43(2)(d) the application of the general data protection principles; Section 43(2)(e) the rights of data subjects in regard to processing and the means to exercise those rights; Section 43(2)(f) the complaint procedures; and Section 43(2)(g) the mechanisms within the group of undertakings, or group of enterprises engaged in a joint economic activity for ensuring the verification of compliance with the binding corporate rules. - 44
TRANSFER OF PERSONAL DATA OUTSIDE KENYA - 44. Transfers on the basis of an adequacy decision
AI-assisted research summary: Transfers of personal data are on the basis that the other country/territory/specified sector or the international organization ensures an adequate level of protection; the Data Commissioner may publish a list of such countries, territories, sectors and organisations on its website.
Section 44. Transfers on the basis of an adequacy decision Section 44(1)(a) the other country or a territory or one or more specified sectors within that other country, or Section 44(1)(b) the international organization, ensures an adequate level of protection of personal data. Section 44(2) The Data Commissioner may publish on its website a list of the countries, territories and specified sectors within that other country and relevant international organisation for which the Data Commissioner has made a decision that an adequate level of protection is ensured. - 45
TRANSFER OF PERSONAL DATA OUTSIDE KENYA - 45. Transfers on the basis of necessity
AI-assisted research summary: Personal data may be transferred to another country or territory if the transfer is necessary for purposes outlined under section 48(c); the transfer must be strictly necessary in a specific case and there must be no fundamental rights and freedoms that override the public interest; the section does not affect international agreements on judicial or police co-operation.
Section 45. Transfers on the basis of necessity Section 45(1) Personal data may be transferred to another country or territory on the basis of necessity is such a transfer is necessary for any of the purpose outlined under section 48(c) of the Act. Section 45(2)(a) that the transfer is strictly necessary in a specific case outlined under section 48(c) of the Act; Section 45(2)(b) there are no fundamental rights and freedoms of the data subject concerned that override the public interest necessitating the transfer. Section 45(3) This section does not affect the operation of any international agreement in force between Kenya and other countries in the field of judicial co-operation in criminal matters and police co-operation. - 46
TRANSFER OF PERSONAL DATA OUTSIDE KENYA - 46. Transfer on basis of consent
AI-assisted research summary: A data controller or processor must seek consent from a data subject before transferring sensitive personal data.
Section 46. Transfer on basis of consent Section 46(1)(a) has explicitly consented to the proposed transfer; and Section 46(1)(b) has been informed of the possible risks of such transfers. Section 46(2) Without limiting the generality of subregulation (1), a data controller or processor must seek consent from a data subject for the transfer of sensitive personal data, in accordance with section 49 of the Act. - 47
TRANSFER OF PERSONAL DATA OUTSIDE KENYA - 47. Subsequent transfers
AI-assisted research summary: The entity effecting a permitted transfer must make the transfer conditional on no further transfer without authorization; a competent authority may authorize further transfers only where necessary for law enforcement.
Section 47. Subsequent transfers Section 47(1) Where personal data is transferred in accordance with this Part, the entity effecting the transfer shall make it a condition of the transfer, that the data is not to be further transferred to another country or territory without the authorisation of the transferring entity or another competent authority. Section 47(2) A competent authority may give an authorisation under subregulation (1) only where the further transfer is necessary for a law enforcement purpose. - 48
TRANSFER OF PERSONAL DATA OUTSIDE KENYA - 48. Provisions for the agreement to cross boarder transfer
AI-assisted research summary: The transferring entity is entitled to unlimited access to verify that the recipient has a robust information system for storing personal data.
Section 48. Provisions for the agreement to cross boarder transfer Section unlimited access by the transferring entity to ascertain the existence of a robust information system of the recipient for storing the personal data; and
Part VIII
DATA PROTECTION IMPACT ASSESSMENT
- 49
DATA PROTECTION IMPACT ASSESSMENT - 49. Processing activities requiring data protection impact assessment
AI-assisted research summary: Data processors and data controllers must conduct a data protection impact assessment before processing activities listed in subregulation (1).
Section 49. Processing activities requiring data protection impact assessment Section 49(1)(a) automated decision making with legal or similar significant effect that includes the use of profiling or algorithmic means or use of sensitive personal data as an element to determine access to services or that results in legal or similarly significant effects; Section 49(1)(b) use of personal data on a large-scale for a purpose other than that for which the data was initially collected; Section 49(1)(c) processing biometric or genetic data; Section 49(1)(d) where there is a change in any aspect of the processing that may result in higher risk to data subjects; Section 49(1)(e) processing sensitive personal data or data relating to children or vulnerable groups; Section 49(1)(f) combining, linking or cross-referencing separate datasets where the data sets are combined from different sources and where processing is carried out for different purposes; Section 49(1)(g) large scale processing of personal data; Section 49(1)(h) a systematic monitoring of a publicly accessible area on a large scale; Section 49(1)(i) innovative use or application of new technological or organizational solutions; or Section 49(1)(j) where the processing prevents a data subject from exercising a right. Section 49(2) A data processor or data controller shall, prior to processing data under subregulation (1) conduct a data protection impact assessment. - 50
DATA PROTECTION IMPACT ASSESSMENT - 50. Conduct of data protection impact assessment
AI-assisted research summary: Data controllers or processors may use the Third Schedule template to conduct a data protection impact assessment; the Data Commissioner may vary the assessment format by guidance notes despite subregulation (1).
Section 50. Conduct of data protection impact assessment Section 50(1) Where a data protection impact assessment is required, a data controller or data processor may conduct the assessment through a template set out in the Third Schedule. Section 50(2) Despite subregulation (1), a format of the data protection impact assessment may be varied by the Data Commissioner through guidance notes as may be issued from time to time. - 51
DATA PROTECTION IMPACT ASSESSMENT - 51. Prior consultation
AI-assisted research summary: When required, a data controller or processor must consult the Data Commissioner on the data protection impact assessment within sixty days of receiving the impact statement report.
Section 51. Prior consultation Section 51(1) In accordance with section 31(3) of the Act, where a data controller or a data processor is required to consult the Data Commissioner on the data protection impact assessment prior to processing, such consultations shall be done within sixty days from the date of the receipt of the impact statement report. Section 51(2)(a) the data protection impact assessment prepared under section 31(1) of the Act; and Section 51(2)(b) where applicable, the respective responsibilities of the data controller or data processors involved in the processing. Section 51(3) Where the Data Commissioner considers that the intended processing is likely to infringe on the Act or these Regulations, the Data Commissioner may issue such advice to the data controller or the data processor, in writing. - 52
DATA PROTECTION IMPACT ASSESSMENT - 52. Consideration of the data protection impact assessment report
AI-assisted research summary: Section 52 permits controllers and processors to consult the Office, allows the Data Commissioner to make recommendations, permits processing to start if no communication occurs within sixty days (and the report is deemed approved), and permits publication of the assessment report on a controller's or processor's website.
Section 52. Consideration of the data protection impact assessment report Section 52(1) In conducting a data protection impact assessment, a data controller or a data processor may consult the Office for advice on whether risks identified and mitigation measures suggested are viable in the outlined circumstances. Section 52(2) In reviewing the data protection impact assessment report, the Data Commissioner may make any recommendations to be incorporated prior to commencing the processing operations. Section 52(3) Where a data controller or data processor, upon submitting the data protection impact assessment report to the Data Commissioner, does not receive any communication within sixty days of submission, may commence processing operations and the assessment report shall be taken to have been approved. Section 52(4) A data controller or data processor may publish on its website the data protection impact assessment Report. - 53
DATA PROTECTION IMPACT ASSESSMENT - 53. Audit of compliance with Assessment Report
AI-assisted research summary: The Data Commissioner may carry out periodic audits to monitor compliance with the Assessment Report and recommendations.
Section 53. Audit of compliance with Assessment Report Section Pursuant to section 23 of the Act, the Data Commissioner may carry out periodic audits to monitor compliance with the Assessment Report and any recommendations that may have been provided by the Data Commissioner.
Part X
GENERAL PROVISIONS
- 58
GENERAL PROVISIONS - 58. Complaints against data controller and data processor
AI-assisted research summary: A person aggrieved may lodge a complaint with the Data Commissioner about a decision by a data controller or data processor or about non-compliance.
Section 58. Complaints against data controller and data processor Section A person aggrieved by a decision of a data controller or a data processor under this Regulation or non-compliance with any provision may lodge a complaint with the Data Commissioner in accordance with the Act and regulations on complaints handling made thereunder.
Provision text is displayed from LexChat’s stored statute record. Use the official source links to verify amendments, commencement, and current legal force.
Ask AI about this statute
The Data Protection (General) Regulations
Sign in to ask AI about this statute
Sign in to start authenticated, citation-grounded statute research.
Sign in