Data Protection No. 24 of 2019 [Subsidiary] 26. Requirement for specified processing to be done in Kenya (1) Pursuant to section 50 of the Act, a data controller or data processor who processes personal data for the purposeof strategic interest of the state outlined under sub-regulation (2) shall — (a) process such personal data through a server and data centre located in Kenya; or (b) store at least one serving copy of the concerned personal datain a data centre located in Kenya. (2) The purpose contemplated under sub-regulation (1) includes the processing of personal data for the purpose of— (a) administering of the civil registration and legal identity management systems; (b) facilitating the conduct of elections for the representation of the people under the Constitution; (c) overseeing any system for administering public finances by any state organ; (d) running any system designated as a protected computer system in terms of section 20 of the Computer Misuse and Cybercrime Act (No. 5 of 2018); (e) offering any form of early childhood education and basic education under the Basic Education Act (No. 14 of 2013); or (f) provision of primary or secondary health care for a data subject in the country. (3) Despite (2), the Cabinet Secretary may require a data controller who processes personal data outside Kenya to comply with sub-regulation (1), where the data controller— (a) has been notified that personal data outside Kenya has been breached or its services have been used to violate the Act and has not taken measures to stop or handle the violation; and (b) resists, obstructs or fails to comply with requests of the Data Commissioner or any other relevant authority in— (i) cooperating to investigate and handle such violations; or (ii) neutralising and disabling the effect of cyber security protection measures. PART V – ELEMENTS TO IMPLEMENT DATA PROTECTION BY DESIGN OR BY DEFAULT 27. A data controller or data processor shall in processing of personal data — (a) establish the data protection mechanisms set out under the Act and these Regulations are embedded in the processing; and (b) design technical and organisational measures to safeguard and implement the data protection principles. 28. Elements of data protection by design or default The elements for the protection of personal data by design or by default that are necessary to implement the data protection principles outlined under section 25 of the Act are as set out in this Part. 29. Elements for principle of lawfulness The elements necessary to implement the principle of lawfulness include— (a) appropriate legal basis or legitimate interests clearly connected to the specific purpose of processing; (b) processing that is necessary for the purpose; (c) the data subject being granted the highest degree of autonomy possible with respect to control over their personal data; 29

Select target paragraph3