No. 24 of 2019 Data Protection [Subsidiary] 23. Data protection policy (1) A data controller or data processor shall develop, publish and regularly update a policy reflecting their personal data handling practices. (2) A policy under sub-regulation (1) may include— (a) the nature of personal data collected and held; (b) how a data subject may access their personal data and exercise their rights in respect to that personal data; (c) complaints handling mechanisms; (d) lawful purpose for processing personal data; (e) obligations or requirements where personal data is to be transferred outside the country, to third parties, or other data controllers or data processors located outside Kenya and where possible, specify such recipients; (f) the retention period and schedule contemplated under regulation 19; and (g) the collection of personal data from children, and the criteria to be applied. 24. Contract between data controller and data processor (1) Subject to section 42(2)(b) of the Act, a data controller shall engage a data processor, through a written contract. (2) The contract envisaged under sub-regulation (1) shall include the following particulars— (a) processing details including— (i) the subject matter of the processing; (ii) the duration of the processing; (iii) the nature and purpose of the processing; (iv) the type of personal data being processed; (v) the categories of data subjects; and (vi) the obligations and rights of the data controller; (b) instructions of the data controller; (c) duty on the data processors to obtain a commitment of confidentiality from any person or entity that the data processors allows to process the personal data; (d) security measures subjecting the data processor to appropriate technical and organizational measures in relation to keeping personal data secure; (e) provision stipulating that all personal data must be permanently deleted or returned on termination or lapse of the agreement, as decided by the data controller; and (f) auditing and inspection provisions by the data controller. 25. Obligations of a data processor (1) A data processor shall not engage the services of a third party without the prior authorisation of the data controller. (2) Where authorisation is given, the data processor shall enter into a contract with the third party. (3) The contract contemplated under sub-regulation (1) shall include such particulars as provided for under sub-regulation 24(2). (4) A data processor shall remain liable to the data controller for the compliance of any third party that they engage. 28

Select target paragraph3