The Kenyan ICT industry has endorsed the recently enacted data protection law, calling it a critical framework to prevent data commercialization and misuse without proper oversight. Signed by President Uhuru Kenyatta in November 2019, the legislation establishes safeguards requiring approval from both the data commissioner and subjects before data can be used.
Robert Nyamu, a partner at EY East Africa, noted the law's significance despite Kenya lagging behind nations like South Africa, which had already implemented its General Data Protection Regulation. "This law is good for the country even though we are having it five years after countries such as South Africa has implemented their GDPR," Nyamu stated during the CIO100 Awards and IT Symposium in Naivasha.
Industry leaders emphasized the need for swift implementation of supporting regulations, urging the government to engage stakeholders to ensure compliance. Louis Otieno, former Microsoft4Africa executive, highlighted the law's potential to build trust between businesses and data subjects but stressed the importance of self-regulation for data holders.
Participants also raised concerns about digital economy taxation, warning that excessive levies could stifle innovation. Otieno compared Kenya's challenges to India's success in creating an enabling environment for ICT investment. "Policies in Africa or lack of it has made doing business difficult compared to the rest of the world," he said.
The sector criticized punitive provisions in the social media regulation bill, including licensing fees for bloggers and taxation of platform administrators. Nyamu argued such measures hinder business ecosystems, citing Uganda's 3-million-user drop after similar social media taxes. "Communication Authority should remove the clause on the social media regulation bill that requires bloggers to pay fees to acquire a license to operate," he said.
Tech industry players push for changes in data rules