Data Protection
No. 24 of 2019
[Subsidiary]
26. Requirement for specified processing to be done in Kenya
(1) Pursuant to section 50 of the Act, a data controller or data processor who processes
personal data for the purposeof strategic interest of the state outlined under sub-regulation
(2) shall —
(a)
process such personal data through a server and data centre located in
Kenya; or
(b)
store at least one serving copy of the concerned personal datain a data centre
located in Kenya.
(2) The purpose contemplated under sub-regulation (1) includes the processing of
personal data for the purpose of—
(a)
administering of the civil registration and legal identity management systems;
(b)
facilitating the conduct of elections for the representation of the people under
the Constitution;
(c)
overseeing any system for administering public finances by any state organ;
(d)
running any system designated as a protected computer system in terms of
section 20 of the Computer Misuse and Cybercrime Act (No. 5 of 2018);
(e)
offering any form of early childhood education and basic education under the
Basic Education Act (No. 14 of 2013); or
(f)
provision of primary or secondary health care for a data subject in the country.
(3) Despite (2), the Cabinet Secretary may require a data controller who processes
personal data outside Kenya to comply with sub-regulation (1), where the data controller—
(a)
has been notified that personal data outside Kenya has been breached or its
services have been used to violate the Act and has not taken measures to
stop or handle the violation; and
(b)
resists, obstructs or fails to comply with requests of the Data Commissioner
or any other relevant authority in—
(i)
cooperating to investigate and handle such violations; or
(ii)
neutralising and disabling the effect of cyber security protection
measures.
PART V – ELEMENTS TO IMPLEMENT DATA
PROTECTION BY DESIGN OR BY DEFAULT
27. A data controller or data processor shall in processing of personal data —
(a)
establish the data protection mechanisms set out under the Act and these
Regulations are embedded in the processing; and
(b)
design technical and organisational measures to safeguard and implement
the data protection principles.
28. Elements of data protection by design or default
The elements for the protection of personal data by design or by default that are
necessary to implement the data protection principles outlined under section 25 of the Act
are as set out in this Part.
29. Elements for principle of lawfulness
The elements necessary to implement the principle of lawfulness include—
(a)
appropriate legal basis or legitimate interests clearly connected to the specific
purpose of processing;
(b)
processing that is necessary for the purpose;
(c)
the data subject being granted the highest degree of autonomy possible with
respect to control over their personal data;
29