9.
10.
11.
12.
13.
14.
15.
16.
17.
exemption from the internal mechanisms but only after the applicant moved the court and sought for
such exemption.
The reasons given by the applicant for sidestepping the internal dispute resolution mechanisms put
in place could only have been considered in the context of the application for exemption; it was not
open to the applicants, or any of them, to decide unilaterally that the 2nd applicant needed not comply
with section 56 of the Data Protection Act and section 9(2) of the Fair Administrative Action Act but
instead directly invoked the jurisdiction of the instant court to determine his complaint.
The interested party appeared to approbate and reprobate the provisions of the Data Protection
Act (the Act). On one hand, the interested party was approving that the Act was retrospective but,
on the other hand, the interested party said it was not and that it only applied from the date of
commencement. The interested party could not do that. She was bound to elect and pursue either of
the two alternatives; it was either the Act applied retrospectively or it did not.
The applicants could not be held to account on compliance with sections 56 and 64 of the Act and
the Regulations made thereunder would betray her stance against the retrospective application of the
Act. It could not be the case, the Act was not severable or was not severable to such an extent that
only certain provisions that were favourable to the interested party’s case were retrospective but those
against it were not.
Courts viewed the rule of retroactive application of statutes as a guide in interpretation of statutes.
However, Parliament could pass a statute to apply to a past time. The principle of retroactive
application of the law meant that the courts, in the exercise of their function of interpreting the law
in cases which came before them, viewed themselves as bound by the rule of construction that no
law was to be given an operation from a time prior to its enactment unless Parliament had expressly
provided that it was to have such an or unless the words of the Act could have no meaning except by
the application to this past time.
Legislation could be retrospective in its application and such an intention had to be either apparent
from the statute in question or could be implied, as a matter of necessity. From the preamble of the
Data Protection Act, it was created to give eect to the right to privacy guaranteed under part (c) and
(d) of article 31 of the Constitution. Section 3 of the Act, on the object and purpose of the Act, shed
more light on how the right to privacy was to be protected.
From a reading of the preamble to the Data Protection Act together with section 3 thereof on the Act’s
object and purpose, the Act was intended to be retrospective to such an extent or to such a time as to
cover any action taken by the State or any other entity or person that could be deemed to aect, in one
way or the other, the right to privacy under article 31(c) and (d) of the Constitution.
The need to protect the constitutional right to privacy did not arise from the enactment of the Data
Protection Act; the right accrued from the Constitution. The obligation to protect the individual
rights under article 31 of the Constitution was not a new obligation or duty imposed on the State when
the Data Protection Act came into force.
The amendments introduced in section 9 of the Registration of Persons Act and the events that
followed pursuant to those amendments, more particularly the nationwide collection of personal and
biometric data in March 2019, would in some way impact on the right to privacy under article 31
of the Constitution. It was because of such likely impact that section 3 of the Data Protection Act
stated that the Act was intended to regulate the processing of such personal data; that the processing
of the personal data of a data subject was guided by certain principles whose import was to protect an
individual’s right to privacy; that the Act was intended to protect the individual’s personal data and,
that the Act was also intended to provide data subjects with rights and remedies whenever their right
to privacy was infringed.
Owing to the likely impact of the amendments to section 9 of the Registration of Persons Act and the
exercise of collection and processing of personal data on the individual’s right to privacy, it would have
kenyalaw.org/caselaw/cases/view/220495/
5