Posts

Showing posts with the label compliance

Data Privacy Risks of Recycled Phone Numbers

Image
The Kenyan government launched the Gava Mkononi app this week. Against this backdrop, there are genuine concerns about steps being taken to safeguard citizen data.  Today, we review the risks associated with recycled phone numbers. Gava Mkononi and eCitizen The Kenya government has prioritised mobile phones in their digital services ambition to scale up access to government services from the current 400 to 5,000 by the end of the year. To that end, it is facilitating citizens' access to low-priced mobile phones through a local manufacturer and a leading telco. The Gava  M kononi service is an extension of the country’s eCitizen platform. The eCitizen platform uses SMS-based authentication where a single-use passcode (OTP) is sent to the subscriber's phone through a text message. Negative effects of recycled numbers More than ever, phone numbers are tied to people’s identities.  They are used to link online accounts (social media accounts, ridesharing apps, mo...

Trends in ethics and compliance

Ethics and compliance officers have to perpetually scope the environment to draw out emerging trends impacting organizations. as a result your ethics and compliance program cannot remain static and it must evolve with those emerging trends. We have identified a non-exhaustive list of 5 trends in ethics and compliance impacting business: – 1. The rise of Sustainability / ESG / Climate change reporting Sustainability reporting continues to evolve. In the past, ESG reporting was left to corporate HQ, investor relations and communications teams of regulated entities. That has changed.  With changes in legislation and ongoing litigation around ESG / Climate change matters, the risk profile of organizations on the issue has also evolved.   The Central Bank of Kenya issued guidelines to regulated entities to report on climate change matters base don the TCFD framework.    That framework has since been adopted with modifications by the International Sustainability Standards ...

Data Breach Guide

A data breach occurs when an incident exposes protected information such as personal data. The breach may involve loss or theft of a customer or employee list, an unencrypted hard drive, lost thumb drive, exposed attendee list, which may be containing names, credit card numbers, national identification/passport numbers, personal images or videos, personal health information, emails, NHIF or NSSF numbers. A data breach may be intentional or accidental. A threat actor may hack your data bases or an employee may accidentally expose that information. The concern about cyber attacks is widespread, which can have a crippling impact on businesses, but the main cause of breaches remains non-cyber incidents and human error. The stakes are high if you suffer a data breach. Hundreds of data reaches have been reported around the world. In 2019, Techweez reported a Safaricom Ltd data breach perpetrated by an employee who downloaded and offered a third party personal data affecting 11.5m customers. ...

Cultivating Ethical Cultures through Technology: The Case for a Policy Management System

Image
  Digitizing policy management can help an organisation achieve culture change through accountability. A digital system provides a centralized, automated, and transparent approach to policy and procedures management that is very supportive of accountability frameworks.  Here are some ways to achieve accountability using a digital policy management system: 1. Centralized policy management : A digital system allows an organization to store all its policies and procedures in a single, central location.  This ensures that all employees have access to the most up-to-date policies and procedures, reducing the risk of non-compliance due to outdated or inaccessible policies. 2. Automated policy updates and notifications : A digital policy management system can automatically update policies and procedures and notify employees when changes are made.  This ensures that employees are always aware of changes to policies and procedures, reducing the risk of non-complianc...

Three Things to Consider when Setting Up Data Compliance

Image
This article seeks to highlight three items that we consider to be important when it comes to #data compliance. It is based on the work that we are doing to support organisations implement or strengthen data compliance systems.  1. Apply the age-old #compliance frameworks when implementing data compliance.  The framework is tried and tested and provides a useful implementation framework that covers: - policies and procedures (including code of conduct and #ethics ), - effective #communication (hotline), - training, - compliance office (outsourced or in-house), - #audit and monitoring, - consequence/accountability management, and - third party transactions. You will note that registration with the Office of the Data Protection Commissioner (ODPC) is not listed as an element on its own. Registration is a necessary but not sufficient aspect of compliance. In fact, we consider registration, particularly the declarations made in that process, as exposing  organisations ...

Greenwashing and Fraud

This week an important claim was made against JBS was filed with the SEC. Mighty Earth, a small activist group, filed a whistleblower complaint against JBS with the US Securities & Exchange Commission (SEC) over JBS's USD2.3 billion Sustainability Linked bond.   For context, JBS is the world’s largest meat processor with operations in over 20 countries.   In 2021 JBS issued green bonds to investors.The bonds were linked to to the company's sustainability goal, to wit achieve net zero by 2040.    The problem is that, in setting the benchmark environmental goal, JBS never included its Scope 3 emissions. In fact, the Second Party Opinion issued in respect of the securities concluded that the bonds “were not material to the whole corporate value chain as the KPI does not include Scope 3 emission...”  The kicker here is that for JBS, Scope 3 emissions are responsible for an estimated 97% of the company’s footprint and therefore the non inclusion of Scope 3 in the...

Data Privacy by Design - The Problem & Promise of the DPA,19

  In early September of this year the headlines screamed various versions of "Facebook doesn't know where your data is, what it's engineers are doing with it." https://www.huffpost.com/entry/facebook-user-data_n_6318ff67e4b046aa0230a14e We clutched at our pearls in shock and horror. How could they?   But is Facebook's experience unique to them?  I do not think so. As you interact more intimately with the Kenyan Data Protection Act, 2019, you realise that this problem is not unique to Facebook. Many organisations do not know where their data is, or what it's constituents are doing with it. DPA,19 and Privacy by Design A major challenge with the DPA, 19 is that the government mandated a legislation without factoring the technical part, implemented by software and hardware engineers, as part of its transition.   There are resource implications of placing data protection and privacy at the centre of design.  Time, cost and technical expertise has to be factored in...