Data Protection
No. 24 of 2019
[Subsidiary]
(d)
the number of data subjects or other persons affected by the notifiable data
breach;
(e)
the personal data or classes of personal data affected by the notifiable data
breach;
(f)
the potential harm to the affected data subjects as a result of the notifiable
data breach;
(g)
information on any action by the data controller or data processor, whether
taken before or to be taken after the data controller or data processor notifies
the Data Commissioner of the occurrence of the notifiable data breach to—
(i)
eliminate or mitigate any potential harm to any affected data subject
or other person as a result of the notifiable data breach; or
(ii)
address or remedy any failure or shortcoming that the data controller
or data processor believes to have caused, or enabled or facilitated
the occurrence of, the notifiable data breach;
(h)
the affected individuals or the public that the notifiable data breach has
occurred and how an affected data subject may eliminate or mitigate any
potential harm as a result of the notifiable data breach; or
(i)
contact information of an authorized representative of the data controller or
data processor.
(2) Where the data controller intends not to communicate a notifiable data breach to a
data subject affected by such breach, under the conditions set out in section 43(1) (b) of
the Act, the notification to the Data Commissioner under sub-regulation (1) shall additionally
specify the grounds for not notifying the affected data subject.
PART VII – TRANSFER OF PERSONAL DATA OUTSIDE KENYA
39. Interpretation of the Part VII
In this Part, unless the context otherwise requires —
(a) “data in transit” means personal data transferred through Kenya in the course of
onward transportation to a country or territory outside Kenya, without the personal
data being accessed or used by, or disclosed to, any entity while in Kenya, except
for the purpose of such transportation;
(b) “recipient” means an entity that receives in a country or territory outside Kenya the
personal data transferred to the recipient by or on behalf of the transferring entity,
but does not include an entity that receives the personal data solely as a network
service provider or carrier;
(c) “transferring entity” means an entity that transfers personal data from Kenya to
a country or a territory outside Kenya but does not include an entity dealing with
data in transit; and
(d) “relevant international organisation” means an international organisation that
carries out functions for any of the law enforcement purposes.
40. General principles for transfers of personal data out of the country
A data controller or data processor who is a transferring entity shall before transferring
personal data out of Kenya ascertain that the transfer is based on—
(a)
appropriate data protection safeguards;
(b)
an adequacy decision made by the Data Commissioner;
(c)
transfer as a necessity; or
(d)
consent of the data subject.
41. Transfers on the basis of appropriate safeguards
(1) A transfer of personal data to a another country or a relevant international
organisation is based on the existence of appropriate safeguards where—
33