The Data Landscape
I got immersed a little bit in data matters this week.
I found myself paying attention to two incidences which on a normal day, I would have ignored and or suffered through, as usual.
I walked into two buildings and finally paid attention to the security protocals at play.
In both buildings, security could not let me through without first confiscating my passport / national identity documents and logging in my details in a large book (not intended for that purpose) filled with numerous other names.
The particulars recorded included:
- full names
- Identification number
- Phone number
- signature
- Time of entry and time of exit
One building retained by passport (this was one of the reasons I was triggered - it had not happened to me in a while). The other building obtained a record of my car number plate through scanners at the gate, the guard at the main entrance used a handheld device to record my temperature before being let through and getting my details recorded as was done in teh first building.
I am not sure where all the information that was taken from me now resides.
I do recall that one time I spent a long time in a building with similar security protocals and by the time I was leaving the officeIi was visiting on the 8th floor, one of the guards manning that floor had already left for the day. What intrigued and concerned me, was the fact that he left a book similar to the one used on the ground floor and which was filled with peoples details, on his chair on that floor.
What trouble me about these incidences is that fact that this is a very common security measure here and the practice is still very much at play with absolutely no change or variation in methodology / approach and notwithstanding the new data protection laws in place.
I am not sure that businesses are taking the issue of data privacy seriously. Some do not think it applies to them. One client thought they could outsource it - I smiled in responce.
I dare say that we have a rather laissez faire attitude to data privacy and the laws and regulations that govern them in Kenya and that, was the inspiration behind my latest blog.
My other blog https://gumzogalore.blogspot.com/ will continue to document my musings on all things business and climate change.
In this blog, I intend to document my thoughts on data and privacy matters generally.
I spent most of my professional life in compliance and therefore notwithstanding my current professional orientation, I still find myself dabbling in compliance matters often.
So I will use this blog as a repository of case law / decisions / real life scenarios grounded on privacy and I look forward to populating it with content that will bring to life real life situations where data privacy issues have come up, disputes recorded and resolved in the hope that they will make this issue real and offer insight on the areas that businesses need to correct.
I therefore hope, my dear readers, that we can learn from my blog, review our approaches to data privacy and compliance so that we can normalise doing the right thing.
Lets Go!
So, we have a Data Protection Act. The Act is very closely modeled around the GDPR and came into effect on November 25, 2019. The legislation whose main purpose is to protect the privacy rights of data subjects is therefore still pretty new.
The administrative structures necessary to operationalize the law have been set up. The first Data Commissioner was appointed in November 2020 and the office is resourced in the areas that matter.
The application of the law is still at its infancy and the scenarios
attracting interventions by the commissioner not yet tested to a large
extent in our country. There is therefore very little jurisprudence in Kenya on matters data
protection. What will be interesting is how the Data Commissioner will handle
complaints and disputes that will set precedents on such matters and how those decisons will be received.
We live in a global village and I therefore reckon that based on the happenings in other parts of the world, the law behind the legislation will start getting very rich in due course of time.
One of my objectives for this blog, is to document data privacy cases and the decisions arrived at, so that we can start enriching our data base of knowledge of data privacy, challenge our assumptions about what the law means and therefore anticipate what the jurisprudence would look like based on what other jurisdictions are doing.
I will not go into hard legislation (my law firm can do that on their page). Here, we chit chat :)
Some of the interesting issues that we will review based on decisions so far taken will revolve around:
- cookies
- data breaches
- automated decision making
- the use of temperature scanners
- medical records (from the most unlikely source - you need to watch out for this one)
- marketing
- eCommerce sites
- CCTV (I told you this would be fun)
- deletion requests (and ignoring them!)
- not storing quality information
- anonymization
- Safeguard measures or the lack thereof
- etc
So lets start this journey together and see how many ways you can get caught out by this new law and lets grow our understanding together.
Comments
Post a Comment