The 3rd Town Hall between the Office of the Data Protection Commissioner (ODPC) and the Data Privacy and Governance Society of Kenya (DPGSK) brought together data protection professionals, regulators, legal practitioners, and stakeholders to discuss emerging regulatory, compliance, and operational issues affecting Kenya’s data protection landscape.
The session was opened by the Society, which highlighted its role in bringing together professionals from government, private sector, academia, civil society, and universities to promote dialogue with the regulator. The Data Commissioner emphasized that these quarterly engagements provide an important platform for collaboration, transparency, and continuous improvement of data protection practice in Kenya.
Key Highlights
1. Data Protection Officer (DPO) Guidance Notes
The ODPC confirmed that the DPO Guidance Notes have completed public participation, stakeholder comments have been incorporated, and senior management has approved the document. The guidance was expected to be published within approximately two weeks after branding and formatting.
2. East African Community (EAC) Data Protection Framework
The Commissioner provided an update on regional harmonization efforts, noting that the EAC Technical Working Group has agreed on key data protection principles. Although a regional legislative framework is still under development, the agreed principles are expected to guide future harmonization of privacy laws across East Africa.
3. Election Preparedness
With national elections approaching, the ODPC outlined its preparedness by:
- Conducting risk assessments.
- Participating in multi-agency election coordination structures.
- Reviewing existing election guidance.
- Preparing for an anticipated increase in complaints, particularly involving political parties and misuse of personal data.
4. Complaint Handling and the 90-Day Timeline
Significant discussion focused on the statutory 90-day complaint resolution period.
The Commissioner explained that:
- The ODPC currently follows the interpretation that the 90 days begin after a complaint is admitted for investigation.
- The office continues to face capacity constraints due to increasing complaint volumes.
- Legal practitioners were requested to avoid sending repeated status inquiries during the statutory period, as responding to numerous follow-up requests diverts resources from investigations.
- The ODPC committed to improving communication by publishing expected timelines and complaint status guidance on its website.
5. Assessment of Damages
Participants discussed recent court decisions concerning compensation for privacy violations. The Commissioner acknowledged the need for clearer principles on assessing damages and invited the Society to contribute proposals on developing more consistent and predictable approaches.
6. National Data Governance Policy
The Commissioner addressed concerns surrounding government data sharing and commercialization. While acknowledging public concerns, she noted that the policy remains in draft form and that the ODPC continues to evaluate appropriate safeguards for lawful, transparent, and accountable public sector data sharing.
7. Cross-Border Data Transfers
Several updates were provided:
- Feedback from public participation has informed revisions to the draft Cross-Border Data Transfer Guidance Notes.
- ODPC clarified that not every international transfer requires prior approval from the Commissioner.
- Greater clarity will be provided in the final guidance to distinguish transfers requiring regulatory involvement.
- Stakeholders will have an additional opportunity to review the draft before publication.
8. Standard Contractual Clauses (SCCs)
The Commissioner confirmed that the ODPC is developing Kenya’s own model contractual framework for international transfers. Although it may not be titled “Standard Contractual Clauses” due to legislative wording, draft provisions are already under discussion.
9. EU Adequacy Decision
The Commissioner confirmed that Kenya continues discussions with the European Union regarding an adequacy decision. Achieving adequacy would significantly improve international data flows and support sectors such as business process outsourcing and digital services.
10. Compliance Regulations
The draft compliance regulations have been finalized by the technical committee and submitted to the Ministry for further processing. These regulations are expected to provide greater clarity on compliance audits and practitioner competence.
11. Data Protection Impact Assessments (DPIAs)
The ODPC acknowledged concerns regarding DPIA review timelines and encouraged organizations to:
- Submit DPIAs early during project planning.
- Use the official ODPC template.
- Clearly indicate project implementation timelines where urgent reviews are required.
The Commissioner emphasized that incomplete submissions contribute significantly to processing delays.
12. Complaint Admissibility
The Commissioner clarified that:
- Complaints must first be raised with the relevant data controller where applicable.
- Matters outside the ODPC’s mandate (such as fraud) may be declined.
- Following a determination, dissatisfied parties should pursue available legal remedies rather than repeatedly submitting the same complaint.
The Society proposed a joint Continuing Professional Development (CPD) session with the Law Society of Kenya to improve practitioners’ understanding of complaint procedures.
13. Audits and Transparency
Participants discussed whether ODPC audit reports should be made public.
The Commissioner explained that:
- Publishing detailed audit reports could expose organizations to cybersecurity risks.
- Audit reports are intended as management tools to improve compliance rather than to publicly shame organizations.
- Annual reports already disclose completed audits in summary form.
14. Data Controller and Processor Liability
The Commissioner confirmed that where investigations establish that a processor—not the controller—caused a breach, the processor may bear responsibility. Controllers were encouraged to maintain comprehensive contracts, audit records, and evidence demonstrating appropriate oversight.
15. Humanitarian Organizations
The Commissioner noted ongoing collaboration with the International Committee of the Red Cross (ICRC) to provide specialized privacy training for humanitarian organizations, recognizing the unique data protection challenges in that sector.
16. Digital Money Lenders
ODPC reported a noticeable decline in complaints against digital lenders following collaboration with the Central Bank of Kenya. Licensing requirements now incorporate data protection registration, strengthening compliance across the sector.
17. Registration Enforcement
The Deputy Data Commissioner confirmed that the ODPC has intensified enforcement against organizations that are legally required to register but have failed to do so. Enforcement includes notices, opportunities to comply, and penalties where necessary.
18. Common Compliance Challenges
The ODPC announced plans to publish regular summaries of common audit findings, complaint trends, and emerging compliance risks to help organizations proactively strengthen their privacy programs.
Closing Remarks
The Data Commissioner reaffirmed the ODPC’s commitment to stakeholder engagement, describing the Society as an important partner in strengthening Kenya’s privacy ecosystem. She welcomed both supportive and challenging questions, emphasizing that such discussions help improve regulatory practice while providing the industry with greater certainty.
The session concluded with confirmation that the ODPC and the Data Privacy and Governance Society of Kenya will continue holding quarterly town halls under a formal cooperation framework, ensuring ongoing dialogue between regulators and data protection professionals. The Society also committed to preparing and sharing a summary of the discussions and agreed follow-up actions with members.