On 22 December 2023, the Office of the Data Protection Commissioner (ODPC) adopted the "Guidance Note for the Communication Sector" to assist service providers in the telecommunications, broadcasting, and postal services in Kenya to comply with the Data Protection Act, 2019. The guidance outlines principles for processing personal data in the communication sector, including lawful, fair, and transparent processing. It emphasizes that service providers must process personal data based on a lawful basis such as consent, contractual necessity, or compliance with legal obligations. The guidance also covers the rights of data subjects, including access to personal data, rectification, and erasure, as well as the need to implement data protection by design and by default. The guidance specifies the obligations of service providers to register with the ODPC, notify data breaches, and ensure compliance with data protection regulations when engaging with data processors. Furthermore, it encourages adherence to international best practices, including those for information security management.
Original source