I&M Bank House, 5th Floor, 2nd Ngong Avenue, Upper Hill, Nairobi, Kenya

Data Protection Advisory

Data Protection Advisory

At Barizi Data Privacy Services, we go beyond answering questions. We’re your trusted advisor, providing practical solutions tailored to your organization’s unique data privacy needs. Our expertise spans critical areas like cross-border data transfers, Data Protection Impact Assessments (DPIAs), and data subject management.

1. Cross-Border Data Transfers

At Barizi Data Privacy Services, we understand the complexities of cross-border data transfers under Kenyan data protection regulations. We can assist you in navigating this process to be more compliant and secure by:
  • Assessing transfer mechanisms :We’ll help you identify the most appropriate transfer mechanism for your specific scenario, considering factors like adequacy decisions, standard contractual clauses, or binding corporate rules.
  • Transfer impact assessments:We can guide you in conducting a transfer impact assessment to evaluate the risks associated with transferring data to a specific recipient country.
  • Documentation and approvals:We’ll assist with preparing the necessary documentation and obtaining any required approvals from the Kenyan authorities, ensuring your cross-border data transfers comply with Kenyan law.

2. Data Protection Impact Assessment

Section 31 of the Data Protection Act, 2019 mandates that a DPIA shall be carried out where the processing of data shall result in a high risk to the rights and freedoms of a data subject, by virtue of its nature, scope, context, and purposes.

We help you navigate Data Protection Impact Assessments (DPIAs). We advise on the process, prepare the documentation, and submit it to the ODPC.

3. Data Subject Management

Data subjects are the individuals, who are the subject of personal data. The Data Protection Act affords data subjects the right to access personal data and supplementary information, the right to have inaccurate personal data rectified, or completed if it is incomplete, the right to erasure in certain circumstances, the right to object to processing personal information and the right to obtain their data in a machine-readable format.

Where Data subjects wish to enforce their rights, organizations should be prepared to manage these requests.

At Barizi Data Privacy Services we   help   you to manage and respond to data subject access request through our Data Subject Access Requests (SAR) quality assurance services.  We prepare documentation suitable to each request and provide expert advice based on the organization’s policies.

We are here to help you.

Become a client today discuss the background of your organization and requirements.