Kenya
DPA KE
Data Protection Act 2019
要点
Kenya's Data Protection Act is closely modeled on the GDPR. Consent is one lawful basis and must be express, unequivocal, free, specific and informed, with stricter conditions for sensitive data and direct marketing.
地域
Kenya
施行状況
In force since 2019
分類
アジア・アフリカ
遵守が必要な事業者
Data controllers and processors established in Kenya, and those abroad that process personal data of data subjects in Kenya.
制裁
Penalties up to KES 5 million or, for undertakings, up to 1% of annual turnover, whichever is lower.
主な義務
- Obtain express, free and specific consent where it is the basis
- Provide notice of purpose and rights before collection
- Honor access, rectification, erasure and objection rights
- Register as a data controller or processor where required
- Notify the commissioner and affected people of breaches
ConsentX で DPA KE に対応する方法
- 1
サイトをスキャンする
無料スキャンでサイト上のすべての Cookie とトラッカーを検出し、DPA KE の下で何に同意が必要かを正確に把握します。
- 2
地域を判定する同意バナーを表示する
ConsentX のバナーを設置します。訪問者の地域を検出し、DPA KE が求める同意の体験を自動的に表示します。
- 3
同意まではトラッカーをブロックする
訪問者が同意するまで、必須でない Cookie とトラッカーをブロックしたままにし、同意前には何も発火しないようにします。
- 4
改ざん検知可能な証跡を記録する
すべての選択は改ざん検知可能な同意レシートとして保存され、DPA KE の監査で提示できます。
- 5
データ主体の請求に期限内に対応する
SLA タイマー付きの DSAR ワークフローを使い、開示、削除、オプトアウトの請求に法定期限内に回答します。