of the Huduma Card and led the instant judicial review application for orders of certiorari, mandamus and
prohibition all aimed at the rollout of Huduma Card.
The interested party led a preliminary objection to the eect that there existed an alternative remedy in
sections 56 and 64 of the Data Protection Act, 2019 and regulations 23(5) and (6) of the Data Protection (Civil
Registration) Regulations, 2020 available to the applicants. The interested party’s position was that parties
ought to have exhausted the available mechanisms for resolution of the instant dispute before invoking judicial
review proceedings.
Issues
i.
Whether the Data Protection Act applied retrospectively to such an extent or to such a time as to cover
any action that could be deemed to aect the right to privacy.
ii.
Whether there was a presumption against retrospective legislation in that ousted vested rights and
imposed new obligations and duties.
iii.
Whether retrospective application of section 31 of the Data Protection Act that imposed a new duty
to carry out a data protection impact assessment that was not there before and during the collection
of personal data under NIIMS was unfair.
iv.
Whether retrospective application of section 31 of the Data Protection Act imposed a new duty to
carry out a data protection impact assessment that was a violation of the right to privacy.
v.
What was the eect of the collection and processing of personal data without there being a legal
framework for the protection of the right to privacy?
vi.
Whether the collection and processing of personal data under the National Integrated Identity
Management System were subject to the Data Protection Act.
vii.
Whether a judicial review court could entertain a judicial review application where an applicant led
a judicial review application before exhausting statutory dispute resolution mechanisms.
Relevant provisions of the Law
Data Protection Act, No 24 2019
Section 31 - Data protection impact assessment
(1). Where a processing operation is likely to result in high risk to the rights and freedoms of a data subject, by
virtue of its nature, scope, context and purposes, a data controller or data processor shall, prior to the processing,
carry out a data protection impact assessment.
(2) A data protection impact assessment shall include the following—
1.
a systematic description of the envisaged processing operations and the purposes of the processing, including,
where applicable, the legitimate interest pursued by the data controller or data processor;
2.
an assessment of the necessity and proportionality of the processing operations in relation to the purposes;
3.
an assessment of the risks to the rights and freedoms of data subjects;
4.
the measures envisaged to address the risks and the safeguards, security measures and mechanisms to
ensure the protection of personal data and to demonstrate compliance with this Act, taking into account
the rights, and legitimate interests of data subjects and other persons concerned.
(3) The data controller or data processor shall consult the Data Commissioner prior to the processing if a data
protection impact assessment prepared under this section indicates that the processing of the data would result in
a high risk to the rights and freedoms of a data subject.
(4) For the purposes of this section, a "data protection impact assessment" means an assessment of the impact of the
envisaged processing operations on the protection of personal data.
(5) The data impact assessment reports shall be submitted sixty days prior to the processing of data.
(6) The Data Commissioner shall set out guidelines for carrying out an impact assessment under this section.
kenyalaw.org/caselaw/cases/view/220495/
3