The number of data protection laws in Africa has more than doubled in the last decade, and a third of these laws were passed in just the last five years. Kenya, Uganda, and Tanzania have each adopted data protection legislative frameworks modelled on the European Union’s General Data Protection Regulation (GDPR) and have each set up regulatory authorities to drive compliance and enforcement.
Understanding the specific data protection frameworks in Kenya, Uganda, and Tanzania is critical to ensuring compliance and minimising risks in East Africa.
This article summarises the key aspects of the data protection laws in these three countries, focusing on compliance requirements, regulatory authorities, and cross-border data transfer guidelines.
Kenya’s Constitution ensures every citizen’s right to privacy. This encompasses the protection of personal information and communications from unauthorised access or exposure. The Kenyan Data Protection Act, 2019 (DPA) further solidifies this right by laying out explicit rules on handling personal data. Kenya’s data protection framework is primarily governed by the DPA), a comprehensive law that sets out the rules for collecting, processing, and storing personal data. The DPA shares several similarities with the GDPR, emphasising accountability, data minimisation, and transparency.
The DPA defines “processing” to include a range of activities, from collection to erasure. Data controllers and processors must register and follow strict guidelines when processing personal data. The DPA also mandates Data Protection Impact Assessments (DPIAs) for activities that pose a high risk to individual rights. DPIAs must be submitted to the ODPC 60 days before starting a high-risk processing activity.
The DPA allows data controllers and processors to appoint a Data Protection Officers (DPO), but this is not a strict legal requirement. Appointing a DPO is considered good practice for organisations handling personal data. The DPO is responsible for ensuring that data controllers and processors comply with data protection laws, implement appropriate security measures, and maintain the integrity of personal data. A DPO can be a member of staff with other roles in the organisation, indicating flexibility in the appointment process.
Transferring personal data outside Kenya requires additional safeguards, including consent from data subjects for transfer of sensitive personal data and approval from the ODPC for civil registration data. Despite the comprehensive framework, challenges remain, such as building capacity for compliance and addressing gaps in enforcement against foreign entities.
Tanzania’s data protection framework is derived from its Constitution and the Tanzanian Personal Data Protection Act, 2022 (PDPA), supported by the Data Protection and Privacy Regulations, 2021 (the DPP Regulations).
The PDPA requires data controllers and processors to appoint a DPO to oversee compliance with the Act where an organisation’s processing operations require regular and systematic monitoring of data subjects on a large scale or where the organisation’s core activities involve the processing of sensitive personal data. The DPO ensures that appropriate technical and organisational measures are in place to safeguard personal data. The PDPA mandates DPIAs when processing operations are likely to pose a high risk to data subjects’ rights and freedoms.
To comply with Tanzania’s requirements before transferring data across borders, organisations need to follow the procedures outlined by the PDPA and the DPP Regulations.
Organisations should identify whether their intended data transfer involves personal data or sensitive personal data. Additionally, they should determine whether the recipient country provides adequate data protection measures equivalent to those required by the PDPA.
Organisations must ensure also that the receiving country has adequate data protection safeguards in place. These safeguards must meet or exceed the level of protection required by the PDPA. If the receiving country does not meet this requirement, additional measures may be needed to ensure the security and privacy of the data.
If the receiving country lacks adequate data protection measures, organisations may need to obtain explicit consent from the data subject(s) before transferring personal data. It is essential that the data subjects are fully informed of the risks and purpose of the transfer.
For cross-border transfers, organisations must apply to the PDPC for a permit to transfer personal data. Applications must include the following details in the application:
To support the application, organisations must also provide proof that the receiving country has adequate data protection measures. This could include:
The PDPA provides for exceptions to the transfer of personal data to countries without adequate protection. These exceptions include:
The PDPC reviews the application within 14 days of receipt. They may accept or reject the application based on the information provided and their assessment of data protection safeguards. If accepted, the PDPC will issue a permit for the transfer, which may include certain conditions such as:
If the PDPC rejects the application, the organisation will receive written notification with the reasons for rejection. Common reasons for rejection include inadequate data protection in the receiving country, risks to national security, or failure to meet the DPP Regulations’ requirements. Organisations should address these issues before reapplying.
Challenges include jurisdictional clarity, where there’s debate about whether cases should be brought before the PDPC or the High Court of Tanzania.
Uganda’s data protection laws are rooted in its Constitution and governed by the Ugandan Data Protection and Privacy Act, 2019 (DPPA).
The DPPA requires data controllers and processors to designate a Data Protection Officer (DPO) in certain situations. The DPO must ensure compliance with the DPPA’s data protection requirements, implementing appropriate measures to prevent unauthorised access, loss, or damage to personal data. However, the Uganda framework does not specifically prescribe a requirement for DPIAs.
For data processors or controllers based in Uganda who process or store personal data outside the country, the DPPA imposes additional requirements. Data transfers are allowed if the receiving country has equivalent or greater protection, or if the data subject consents. The PDPO can impose fines or imprisonment for non-compliance, with penalties for offences such as unlawfully obtaining or disclosing personal data.
Compliance with data protection laws in Kenya, Uganda, and Tanzania is essential for investors in East Africa. Legal teams should focus on understanding each country’s unique requirements, and ensuring proper registrations are made in each. Cross-border data transfers require careful consideration of compliance with each jurisdiction’s regulations.
By adhering to the principles and requirements outlined in each country’s data protection framework, foreign investors can mitigate risks and foster a culture of responsible data handling in the region. Legal teams should remain informed about updates to these laws and engage with the respective regulatory authorities to ensure ongoing compliance and business success in East Africa.
--
Read the original publication at ALN