- notify the Data Commissioner without delay, within seventy-two (72) hours of becoming aware of such breach; and
- communicate to the data subject in writing within a reasonably practical period, unless the identity of the data subject cannot be established.
- description of the nature of the data breach;
- description of the measures that the data controller or data processor intends to take or has taken to address the data breach;
- recommendation on the measures to be taken by the data subject to mitigate the adverse effects of the security compromise;
- where applicable, the identity of the unauthorized person who may have accessed or acquired the personal data; and
- the name and contact details of the data protection officer where applicable or other contact point from whom more information could be obtained.
Related blogs & news
What you need to know about the Data Protection Act, 2019
For a long time, Kenya has lacked a comprehensive personal data protection legislation which has been quite necessary in this age of digital use and access. This has exposed citizens to the risk of their personal data being misused. ...
The Data Protection Act: A Series
The Data Protection Act, No. 24 of 2019 (the DPA) was enacted into law on 11 November 2019 through Gazette Supplement Number 181. The provisions of the DPA gives life to Article 31 (c) and (d) of the Constitution of Kenya which guarantees the right to privacy including the right of a person not to have information relating to their family or private affairs unnecessarily required or revealed and the right not to have the privacy of their communications infringed....
Data Subject - What you need to know
The Data Protection Act, No. 24 of 2019 (the DPA), introduced various concepts and principles aimed at bringing to life the right to privacy enshrined under our Constitution. ...
Data Security Today
Technology has so strongly been synced to our everyday lives and as a result, data security is both personal and a corporate consideration. Personal computer and mobile phone users are faced with concerns on the accessibility of their devices and the data contained in the same way that businesses are concerned with customer data....
Data Protection in M&A What You Need to Know
Any context requiring or necessitating the use of personal data requires taking steps to comply with the Data Protection Act, 2019 (the Act), including where personal data is to be shared or processed within a transactional context. ...
Share this blogLinkedIn Twitter Facebook Print