No. 24 of 2019
Data Protection
[Subsidiary]
23. Data protection policy
(1) A data controller or data processor shall develop, publish and regularly update a
policy reflecting their personal data handling practices.
(2) A policy under sub-regulation (1) may include—
(a)
the nature of personal data collected and held;
(b)
how a data subject may access their personal data and exercise their rights
in respect to that personal data;
(c)
complaints handling mechanisms;
(d)
lawful purpose for processing personal data;
(e)
obligations or requirements where personal data is to be transferred outside
the country, to third parties, or other data controllers or data processors
located outside Kenya and where possible, specify such recipients;
(f)
the retention period and schedule contemplated under regulation 19; and
(g)
the collection of personal data from children, and the criteria to be applied.
24. Contract between data controller and data processor
(1) Subject to section 42(2)(b) of the Act, a data controller shall engage a data processor,
through a written contract.
(2) The contract envisaged under sub-regulation (1) shall include the following
particulars—
(a)
processing details including—
(i)
the subject matter of the processing;
(ii)
the duration of the processing;
(iii)
the nature and purpose of the processing;
(iv)
the type of personal data being processed;
(v)
the categories of data subjects; and
(vi)
the obligations and rights of the data controller;
(b)
instructions of the data controller;
(c)
duty on the data processors to obtain a commitment of confidentiality from any
person or entity that the data processors allows to process the personal data;
(d)
security measures subjecting the data processor to appropriate technical and
organizational measures in relation to keeping personal data secure;
(e)
provision stipulating that all personal data must be permanently deleted or
returned on termination or lapse of the agreement, as decided by the data
controller; and
(f)
auditing and inspection provisions by the data controller.
25. Obligations of a data processor
(1) A data processor shall not engage the services of a third party without the prior
authorisation of the data controller.
(2) Where authorisation is given, the data processor shall enter into a contract with the
third party.
(3) The contract contemplated under sub-regulation (1) shall include such particulars
as provided for under sub-regulation 24(2).
(4) A data processor shall remain liable to the data controller for the compliance of any
third party that they engage.
28