Legal Intelligence · Privacy & Data Protection

Privacy & Data Protectionlegal & regulatory updates

Briefly tracks privacy & data protection developments — court rulings, legislation, gazette notices, and regulatory updates — from courts and regulators. 11 updates tracked in the past 30 days, last updated 15 Jul.

Get Privacy & Data Protection updates in your inbox
Legal News
Namibia
Legal News

Vishing Scams: CRAN, MTC, and BoN Sound Alarm in Namibia

The Communications Regulatory Authority of Namibia (CRAN), in conjunction with Mobile Telecommunications Company (MTC) and the Bank of Namibia (BoN), has issued a critical warning to the public regarding a significant increase in 'vishing' scams. This surge in voice phishing incidents, where scammers use phone calls to trick individuals into divulging sensitive personal or financial information or transferring funds, persists despite the mandatory SIM registration requirements implemented to enhance accountability and traceability. The authorities are urging heightened vigilance, indicating that existing preventative measures are not fully deterring these sophisticated fraudulent activities, which often exploit human vulnerabilities rather than technical loopholes. This development carries substantial legal significance for practitioners, businesses, and the public alike. For legal professionals, it underscores the persistent and evolving threat of cybercrime and financial fraud, necessitating a proactive approach to client advisory on cybersecurity and consumer protection. Businesses, particularly those in the financial services and telecommunications sectors, face increased reputational risk, potential financial losses, and heightened regulatory scrutiny concerning their customer protection frameworks. The prevalence of these scams also highlights the potential for litigation arising from customer losses, data breaches, or alleged failures in fraud prevention systems, placing a greater onus on companies to demonstrate robust security measures and incident response capabilities. Legally, this issue touches upon several key Namibian statutes and regulatory frameworks. The Communications Act 8 of 2009 establishes CRAN and governs telecommunications, including the SIM registration mandate, which was intended to curb anonymity in communication. The Banking Institutions Act 2 of 1998, overseen by the BoN, regulates financial institutions and mandates measures to combat financial crime and protect consumers. Furthermore, the Prevention of Organised Crime Act 29 of 2004 (POCA) is relevant, as vishing scams often form part of broader organised criminal activities involving money laundering. While Namibia is still developing comprehensive data protection legislation, the principles of data privacy and security are implicitly relevant. Key parties involved are CRAN, MTC, BoN, and the general Namibian public who are the targets of these scams, alongside the anonymous perpetrators. Practitioners should advise clients, especially financial institutions, telecommunication providers, and any business handling sensitive customer data, to review and strengthen their cybersecurity protocols, employee training on fraud awareness, and customer education initiatives. Implementing robust multi-factor authentication, clear communication channels for reporting suspicious activity, and comprehensive incident response plans are crucial. Attorneys should also prepare for potential litigation related to customer losses, data breaches, or regulatory non-compliance, emphasizing the need for businesses to demonstrate due diligence in protecting their customers from evolving fraud tactics. Monitoring the ongoing legislative developments in data protection will also be vital.

13 Jul
Ghana
Legal News

e-Crime Bureau Chair Warns of Ghana's Digital Fraud Vulnerability

The recent statement by Dr. Albert Antwi-Boasiako, Founder and Executive Chair of E-Crime Bureau, highlighting social engineering as Ghana's most significant vulnerability in the fight against digital fraud, underscores a critical and evolving threat landscape for individuals, businesses, and the national economy. Dr. Antwi-Boasiako's observation points to a sophisticated shift in cybercriminal tactics, moving beyond purely technical exploits to leverage human psychology – trust, fear, ignorance, and online habits – to illicitly obtain money or personal information. This development is not merely a technical challenge but a profound legal and regulatory one, demanding a multi-faceted response that integrates robust legal frameworks with public awareness and corporate governance. The increasing prevalence of such schemes necessitates a re-evaluation of existing cybersecurity strategies and a heightened focus on the human element as the primary line of defense. From a legal perspective, this development carries significant implications for practitioners across various sectors. The legal context for combating digital fraud in Ghana is primarily anchored in the Cybersecurity Act, 2020 (Act 1038), which establishes the Cybersecurity Authority and provides a comprehensive framework for cybersecurity governance, protection of critical information infrastructure, and incident response. Complementing this are the Electronic Transactions Act, 2008 (Act 772), governing the security of electronic transactions, and the Data Protection Act, 2012 (Act 843), which is crucial for safeguarding personal information frequently targeted by social engineering attacks. Financial institutions, key parties in this fight, are also subject to stringent regulations from the Bank of Ghana (BoG) and the Securities and Exchange Commission (SEC) regarding customer data protection and fraud prevention. Criminal offences related to fraud, identity theft, and unauthorized access under the Criminal Offences Act, 1960 (Act 29) also provide avenues for prosecution. The E-Crime Bureau, the Cybersecurity Authority, the Ghana Police Service, and the Attorney-General's Department are key institutional players in addressing these challenges. For legal practitioners, the takeaway is clear: proactive and preventative measures are paramount. Attorneys should advise corporate clients on the urgent need to enhance internal cybersecurity protocols, particularly through comprehensive employee training programs designed to identify and resist social engineering tactics. Businesses must review and update their incident response plans, ensuring clear data breach notification procedures are in place, compliant with Act 843. Furthermore, contractual agreements with third-party service providers handling sensitive data should be scrutinized for robust data security clauses and liability provisions. Financial institutions, in particular, face heightened regulatory scrutiny and potential liability for customer losses resulting from social engineering; they must intensify customer awareness campaigns and strengthen internal controls. The rising tide of digital fraud, particularly through social engineering, signals an increased likelihood of litigation related to data breaches, financial losses, and regulatory non-compliance, making robust legal counsel in this area indispensable.

10 Jul
Kenya
Legal News

East African Community Endorses Harmonised Framework for Cross-Border Data Transfers

The East African Community (EAC) is making significant strides towards establishing a Single Digital Market through the development of a harmonised framework for cross-border data transfers. This initiative is designed to streamline the flow of data across partner states, substantially reduce compliance costs for businesses, and accelerate the broader agenda of digital integration within the EAC bloc. This move signifies a concerted effort by the regional body to foster a more cohesive and efficient digital economy, addressing the fragmented regulatory landscape that currently characterises data governance in East Africa. The legal significance of this harmonised framework cannot be overstated for practitioners and businesses operating within or looking to enter the EAC market. It promises to simplify the complexities associated with data protection compliance, which currently varies significantly across member states. For businesses engaged in e-commerce, digital services, cloud computing, and other data-intensive operations, this framework will be a game-changer, potentially unlocking new opportunities for growth and innovation by reducing legal and operational friction. It also signals a maturing approach to digital governance, moving towards a more unified and predictable regulatory environment that will enhance investor confidence and facilitate regional trade in digital goods and services. In Kenya, the Data Protection Act, 2019, currently governs data processing and cross-border transfers, requiring specific safeguards and conditions. Other EAC partner states, such as Uganda with its Data Protection and Privacy Act, also have their own national legislation. The harmonised framework will likely take the form of a regional protocol, model law, or binding directive, aiming to reconcile these national laws or establish a common standard for data transfers that supersedes or complements existing national provisions. This aligns with the EAC Treaty's objectives of economic integration and the establishment of a common market. Key parties involved include the EAC Secretariat, the individual EAC Partner States (Kenya, Uganda, Tanzania, Rwanda, Burundi, South Sudan, DRC, Somalia), national data protection authorities like Kenya's Office of the Data Protection Commissioner, and a multitude of businesses and legal professionals navigating the digital economy. Practitioners advising clients with operations or customers across the EAC must closely monitor the finalisation and implementation of this harmonised framework. It will necessitate a thorough review and potential overhaul of existing data transfer agreements, privacy policies, and internal compliance strategies to ensure alignment with the new regional standards. Understanding the interplay between the new EAC framework and existing national data protection laws will be crucial for providing accurate and effective legal advice. Businesses should proactively engage with legal counsel to assess the impact on their data processing activities, consent mechanisms, and data breach notification protocols, preparing for a more integrated yet potentially more stringent regional compliance landscape. This development also presents a significant opportunity for legal tech specialists and those advising on digital transformation.

9 Jul
Kenya
Legal News

Social Health Authority (SHA) Requires Fingerprint Verification for Minors in Kenya

The Social Health Authority (SHA) has officially implemented a biometric fingerprint identification system for registered child dependants aged between seven and seventeen, marking a significant shift in the administration of Kenya’s public health insurance. This move is primarily designed to enhance beneficiary verification and mitigate the persistent issue of fraudulent claims that plagued the predecessor National Hospital Insurance Fund (NHIF). By integrating biometric data for minors, the SHA aims to ensure that medical services are strictly accessed by legitimate beneficiaries, thereby safeguarding the financial integrity of the Social Health Insurance Fund (SHIF). This development follows the transition mandated by the Social Health Insurance Act of 2023, which seeks to provide a more robust framework for Universal Health Coverage in Kenya. From a legal perspective, this initiative intersects significantly with the Data Protection Act of 2019, which classifies the biometric data of minors as sensitive personal data requiring heightened levels of protection. Practitioners should note that the SHA, as a data controller, must demonstrate strict adherence to the principles of data minimization and purpose limitation, ensuring that the collection of fingerprints from children is both necessary and proportionate to the goal of fraud prevention. The involvement of the Office of the Data Protection Commissioner (ODPC) will be crucial in monitoring whether the SHA has conducted a Data Protection Impact Assessment (DPIA) to address the inherent risks of processing such sensitive information. Furthermore, the move reflects the broader regulatory trend in Kenya toward digital identity integration, aligning with the government’s "Digital Superhighway" agenda. For legal professionals and healthcare providers, the takeaway is twofold: first, there is a heightened compliance burden regarding the handling of minor-related data within the healthcare ecosystem. Attorneys representing healthcare facilities must ensure their clients’ internal systems are compatible with SHA’s biometric requirements while remaining compliant with privacy laws. Second, the transition from NHIF to SHA continues to be a fertile ground for administrative law challenges, particularly concerning the inclusivity of the registration process and the protection of constitutional rights to health and privacy. Practitioners should monitor for any potential class-action litigation or constitutional petitions that may arise if the biometric requirement inadvertently excludes vulnerable children from accessing essential medical services due to technical or registration hurdles.

8 Jul

Privacy & Data Protection coverage by jurisdiction

Other topics