By Joseph Githaiga
NAIROBI, Kenya, May 5 – Data protection has become a pivotal conversation for organizations in their compliance journey.
Furthermore, the emphasis on compliance has been reinforced by recent regulatory sanctions imposed by the Office of the Data Protection Commissioner, which has increased the urgency for organisations to be compliant with Kenyan data protection laws.
One of the salient features in the Data Protection Act, 2019 (the” DPA”), as well as the Data Protection (General) Regulations, 2021 (the “Regulations”), is that data processors and data controllers need to have internal mechanisms that enable data subjects to exercise their rights.
In the recent Proximus case, the Court of Justice of the European Union (CJEU) decided that a data controller is required to take reasonable steps to inform data processors of a data subject’s requests, and in this case, the request was concerning the right to erasure.
In a progressively interconnected world, organisations have often resorted to sharing data subjects’ personal data either with joint controllers or data processors.
If this is the case, such organisations must have in place internal procedures to inform other joint data controllers and data processors with which they have shared personal data, that they have received a request from a data subject.
This could be a data subject request relating to accessing, rectifying, erasing, restricting processing, objecting to processing or to porting of personal data.
This emphasizes the cooperative relationship that data controllers need to have with their joint data controllers and data processors.
The Proximus case brought to light significant legal aspects relating to data subject rights.
These include: in cases where several data controllers rely on the single consent of the data subject, it is sufficient for the data subject to withdraw such consent by contacting any one of the joint data controllers. Arguably, this would also apply to the other rights exercisable by data subjects.
It is also important that joint data controllers enter into an agreement setting out their respective responsibilities to comply with the DPA and the Regulations. The main aspects of the agreement must communicate how data subjects would go about exercising their rights.
Notably, data processors only process personal data on behalf of the data controller. Consequently, organisations that are data controllers are required to take reasonable steps to inform joint data controllers and data processors of the relevant data subject request(s).
A data subject may request a data controller or data processor to comply with a request with respect to being informed about the use of their personal data, being granted access to their personal data, objecting to the processing of all or part of their personal data, rectifying false or misleading data or deletion of the same or copying and porting of their personal data from one data controller or data processor to another.
The data subjects can exercise their rights themselves through the means availed by the data controllers. A guardian or someone with parental authority can exercise these rights on behalf of a minor.
Further, where the data subject has a mental or other disability, a guardian or administrator may make the requests on their behalf.
Organisations should invest in appropriate internal procedures and policies to facilitate communication of the exercise of data subject rights to joint controllers and data processors, within a reasonable time.
Moreover, organisations need to maintain proper inventories of the personal data held as well as the corresponding joint controllers and data processors that hold the personal data.
Furthermore, the internal procedures should allow timely and effective processing of these data subject right requests.
This involves training of the mandated personnel in vital issues such as the criteria for allowing or objecting to the data subject rights requests as well as ensuring that the responses are reverted within the statutory timelines.
Herbert Njoroge, Lavelyne Nusu and Jade Makory contributed to this article. The authors are Legal Business Solutions Advisors with PwC
