Data Privacy by Design - The Problem & Promise of the DPA,19

 
In early September of this year the headlines screamed various versions of "Facebook doesn't know where your data is, what it's engineers are doing with it." https://www.huffpost.com/entry/facebook-user-data_n_6318ff67e4b046aa0230a14e

We clutched at our pearls in shock and horror. How could they?
 
But is Facebook's experience unique to them? 

I do not think so.

As you interact more intimately with the Kenyan Data Protection Act, 2019, you realise that this problem is not unique to Facebook.

Many organisations do not know where their data is, or what it's constituents are doing with it.

DPA,19 and Privacy by Design
A major challenge with the DPA, 19 is that the government mandated a legislation without factoring the technical part, implemented by software and hardware engineers, as part of its transition.
 
There are resource implications of placing data protection and privacy at the centre of design. 

Time, cost and technical expertise has to be factored into creating compliant systems.
 
DPA,19 has significant positive implications. It is intended to change how organisations interact with personal data both operationally and strategically - how and why they collect it, its quality, what they do with it or how they monetise it. 

It however has far reaching legal, technical and administrative implications. 

For an organisation to correctly implement the legislation, they have to go beyond the administrative and legal aspects of the legislation, and make real technical investments in systems and processes that collect, control and manage data.

Not doing this will mean that compliance system is compromised at a very basic level.

From client work, installing a compliant (technical) system is the bedrock of compliance. This was the catalyst behind MZIZI Africa on-boarding a systems architect as part of its consulting team. 

The DPO/legal, CISO and CDO roles have never been more closely aligned.
 
Transition pain points
The implications of the lack of or inadequate transition mechanisms of the DPA,19 means that the initial periods of implementing the DPA,19 is risk based, and probably chaotic.

Organisations will prioritise meeting their legal obligations first, followed by adaptation. 
 
40 organisations recently received enforcement notices under the DPA19 from the Office of the Data Protection Commissioner. Some of these organisations may not be prepared for the levels of scrutiny that follow such notices for various reasons.

Organisations have been operating various  software / platforms for years. They depend on such platforms to manage their business, their clients, financial systems, marketing activities, employee lifecycles etc.

Some of the platforms were not designed with data privacy and protection as part of the system architecture. 

Now imagine what a mature organisation that has been operating with multiple legacy systems, developed by multiple partners, has to go through, to truly embed the requirements of the DPA,19 into their operations. 

The volume of non compliant tech is massive.

A section of the DPA,19 that is bound to raise a good number of disputes is the data access request.

Consider this example:
Imagine that an employee separated from his employer. The employer has archived the employees HR files / information acirding to its retential guidelines.  The employee has now commenced legal proceedings against the organisation disputingthe manner of his dismissal and has made a subject access request to include meeting minutes and correspondences.

The organisation possibly has the employees personal data sitting:
- on other employees phones,
- in corporate WhatsApp groups, 
- email threads,
- personal computers (BYOD),
- individual servers,
- retention rooms (manual),
- even personal emails.
- meeting notes.

Consider this even as you remember that access requests can and will be weaponised. 

To deal with these matters correctly, busineses will have to change their data achitecture so that it accomodates new legal requirements such as the DPA,19. This has time and cost implications.

In the meantime, it can be argued that the Huduma Number Case set the stage for retroactive application of the law. The government was ordered to undertake an impact assessment of a planned rollout of a mass registration system in respect of a 2018 legal pronouncement, that preceded the DPA,19. It can therefore be argued that the law against retroactive application of the law does not apply to the DPA,19.

Its one thing to legislate and quite another to embed privacy into already designed and built frameworks and restrictive architectures such as those found in legacy systems - that's putting the horse before the cart.

Systems architects and / system engineers define the architecture of a computer or networking system in order to fulfil or achieve certain requirements anx purposes including privacy.

Imagine being asked to provide evidence of data privacy by design in respect of your Accounting / Payroll / CRM software. You quickly realise how ill prepared you are to comply with this law - you haven't even touched on transfer requirements or underlying processor contracts.

One cannot legislate in a vacuum.

They drafters of this law may have approached this issue as a legal problem only, therefore creating other problems on the technical side that need time to resolve.

The ODPCs approach to non compliance will become clearer in time. In the meantime, an appeal from its decisions lie in the high Court.

Data privacy is first and foremost a technical problem.

Ultimately organisations have to adopt approaches that ensures compliance and that means putting data privacy and data protection issues at the design phase of any system, service, product or process and then throughout the lifecycle.

It is the right thing to do. Once the systems are put in place to handle data correctly, the strategic opportunities manifest.

Conclusion
So, before you snigger at Facebook, just know they are not alone. 

 

Many organisations do not know where their data is and the step-by-step process of integrating privacy into systems to ensure compliance will lay bare the true cost of compliance.

 

Connect: linktr.ee/mzizi_africa


Comments

Popular posts from this blog

10 Compliance Movies & Lessons

Data Privacy Risks of Recycled Phone Numbers

The Persons with Disabilities Bill, 2023