LOADING

Type to search

Explainer

What Is the Role of a Data Protection Officer? Understanding Their Duties and Responsibilities 

Share
A Data Protection Officer advises organisations, monitors compliance, trains staff and helps protect personal data while ensuring privacy laws are followed.

As organisations collect increasing amounts of personal information, the role of a Data Protection Officer has become increasingly important.

Businesses, government agencies, hospitals, schools and other institutions routinely handle names, phone numbers, identification details, financial records and other personal information.

As a result, they need clear policies and effective systems to protect this data from misuse, loss or unauthorised access.

A Data Protection Officer (DPO) helps an organisation meet these responsibilities, the officer provides guidance on data protection requirements, monitors compliance and promotes responsible handling of personal information.

In Kenya, the role operates within the framework of the Data Protection Act, 2019, which regulates the processing of personal data and provides for the rights of data subjects.

Who Is a Data Protection Officer?

A Data Protection Officer is a professional who helps an organisation comply with data protection laws and its privacy obligations, the officer advises management and employees on how to collect, process, store and share personal information in accordance with the law.

In addition, the DPO can serve as a contact point for data protection matters. Under Section 24 of Kenya’s Data Protection Act, a data controller or data processor may designate or appoint a DPO.

The law sets out circumstances in which the role applies, including where processing is carried out by a public or private body, where core activities require regular and systematic monitoring of data subjects, or where core activities involve processing sensitive categories of personal data.

The person appointed must have relevant academic or professional qualifications, which may include knowledge and technical skills in data protection. A DPO may also perform other duties, provided they do not create a conflict of interest.

Main Duties of a DPO

A DPO handles several responsibilities aimed at helping an organisation comply with data protection requirements. These include:

  • Advising management, employees and other relevant staff on data processing requirements under the Data Protection Act and other applicable laws.
  • Checking whether the organisation complies with its data protection obligations and identifying areas that require improvement.
  • Helping build staff capacity by creating awareness and supporting training for employees involved in data processing.
  • Providing advice when the organisation carries out a Data Protection Impact Assessment (DPIA) to identify and address potential privacy risks.
  • Cooperating with the Office of the Data Protection Commissioner (ODPC) and other relevant authorities on data protection matters.

The Act also requires a data controller or processor to publish the DPO’s contact details on its website and communicate them to the Data Commissioner.

Also Read: OPINION: Why Kenya’s Data Protection Act is the New Gold Standard for SMEs

When Does an Organisation Need a DPO?

The appointment of a DPO depends on the organisation and the nature of its data-processing activities.

Section 24 of Kenya’s Data Protection Act specifically provides for DPO designation or appointment where processing is carried out by a public or private body, subject to the statutory exception for courts acting in their judicial capacity.

It also covers organisations whose core activities involve regular and systematic monitoring of data subjects or processing sensitive categories of personal data.

This means organisations should consider their legal obligations based on the nature, scope and purpose of the personal data they process.

For example, institutions handling sensitive information about patients, employees, customers or other individuals need strong systems for managing privacy risks.

Appointing an appropriately qualified DPO can help such organisations maintain proper oversight of their data-processing activities.

Why a DPO is Important

A DPO helps an organisation identify and address privacy risks before they develop into serious compliance problems.

By advising employees, reviewing data-processing practices and supporting privacy assessments, the officer helps build data protection into everyday operations.

The role also promotes transparency, as individuals whose information an organisation processes need clear channels for raising data protection concerns, while organisations need systems for responding appropriately to those concerns.

However, the DPO does not replace the organisation’s own responsibilities under the law. Instead, the officer provides advice, supports compliance and works with relevant authorities while the data controller or processor remains responsible for meeting its legal obligations.

Also Read: SHA, SHIF and PHCF Explained: Why Your SHA Cover May Not Be Accepted at Every Hospital

How a DPO Protect Personal Data

A DPO helps put data protection requirements into practice by examining how an organisation collects, uses, stores and shares personal information.

The officer can advise on whether processing complies with legal requirements and whether appropriate safeguards are in place.

The DPO can also guide the organisation through a Data Protection Impact Assessment where required and help address potential risks associated with proposed data-processing activities.

In addition, the officer works with relevant authorities on data protection matters and supports staff involved in processing personal information.

As organisations increasingly rely on digital systems and collect more personal information, the Data Protection Officer plays an important role in strengthening privacy and accountability.

Follow our WhatsApp channel for instant news updates.

A Data Protection Officer advises organisations, monitors compliance, trains staff and helps protect personal data while ensuring privacy laws are followed.

Photo of a Data Commissioner Immaculate Kassait, MBS, during a two-day Data Protection Impact Assessment (DPIA) training for 120 Data Protection Officers in Nairobi, held on April 24–25, 2024. PHOTO/ ODPC

Tags: