With the enactment of the Data Protection Act in 2019, organisations -- big or small – are expected to, among other things, register as data processors or controllers and instal technology to prevent theft of personal information.
But a report released last week by the consultancy firm EY Kenya shows low levels of compliance among non-governmental organisations, small and medium enterprises (SMEs) and savings and credit cooperative societies (saccos).