Section 43 of the Kenya DPA establishes the Personal Data Breach Notification framework. (1) Section 43(1) Personal Data Breach Definition: (a) Breach of security leading to accidental or unlawful (i) destruction; (ii) loss; (iii) alteration; (iv) unauthorised disclosure; (v) access to personal data; (b) Covers all data states - at rest + in transit + in use; (c) Covers both technical (cyber) + human (insider + negligence) + physical (theft + loss); (d) Covers controller + processor breaches. (2) Section 43(2) ODPC Notification: (a) Notification required to ODPC without undue delay; (b) Where feasible within 72 HOURS of becoming aware; (c) If delayed beyond 72 hours - reasons must accompany notification; (d) Phased notification allowed if full information not available; (e) Ongoing updates as investigation progresses. (3) Section 43(3) Notification Information Required: (a) Nature of the breach (i) categories of affected data subjects + approximate numbers; (ii) categories of personal data records + approximate numbers; (b) DPO contact details; (c) Likely consequences of the breach; (d) Measures taken or proposed to address the breach + mitigate possible adverse effects. (4) Section 43(4) Notification to Affected Subjects: (a) Where breach likely to result in HIGH RISK to data subject rights and freedoms; (b) Without undue delay; (c) In clear and plain English and Kiswahili language; (d) Information - nature of breach + DPO contact + consequences + measures; (e) Exemptions - if controller implemented appropriate technical/organisational measures rendering data unintelligible (e.g. encryption); if controller subsequently mitigated risk; if would involve disproportionate effort + public communication instead; (f) ODPC may require notification if not done. (5) Section 43(5) Processor Obligations: (a) Processor must notify controller WITHOUT UNDUE DELAY of breach; (b) Controller then has 72-hour ODPC SLA; (c) Section 42 processor contract should specify breach notification mechanism; (d) Sub-processor flow-down. (6) Documentation Requirement per Section 43(6): (a) ALL BREACHES documented regardless of notification threshold; (b) Facts + effects + remedial action; (c) Enables ODPC compliance verification; (d) Supports trend analysis + organisational learning. (7) Risk Assessment per Section 43: (a) Likelihood + severity assessment; (b) Factors include - type of breach + nature/sensitivity/volume of data + ease of identification + severity of consequences + special characteristics of subjects (children/vulnerable) + special characteristics of controller; (c) ENISA + EDPB methodology + emerging Kenya guidance; (d) Privacy Risk Score frameworks. (8) Cross-Border Breach Notification: (a) If affected data subjects in multiple jurisdictions - notify each Supervisory Authority; (b) ODPC liaison with foreign DPAs; (c) African Union + EAC coordination; (d) International cooperation via Convention 108+. (9) Breach Response Lifecycle: (a) Detection - SIEM + DLP + EDR + insider threat + user reports; (b) Containment - isolation + access revocation + system shutdown + business continuity; (c) Assessment - scope + impact + risk classification; (d) Notification - ODPC + subjects + others; (e) Eradication - root cause + fix + patches; (f) Recovery - restore + monitor; (g) Lessons learned - post-mortem + report + improvement. (10) Sector-Specific Notification: (a) Banking + Central Bank of Kenya; (b) Telecom + Communications Authority of Kenya; (c) Health + Ministry of Health; (d) Cybersecurity + National KE-CIRT/CC. (11) Penalties for Notification Failures: (a) Section 63 administrative penalties up to KES 5M or 1% turnover; (b) ODPC escalation; (c) Civil compensation per Section 65; (d) Reputational damage + customer churn; (e) Potential class action under Civil Procedure Code. Coordinates with EU GDPR Articles 33 + 34 + UK DPA 2018 + Convention 108+ + EDPB Guidelines + ENISA Methodology + ISO/IEC 27035 + NIST SP 800-61 + Kenya Section 42 Processor + Section 29 Privacy Notice + Section 41 Security + Central Bank of Kenya + Communications Authority of Kenya + Ministry of Health + National KE-CIRT/CC + African Union Convention on Cyber Security and Personal Data. Kenya DPA Breach Notification + Section 43 applies.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.