Strict data compliance is no longer just a nice-to-have for organisations

Have you ever received a promotional text message and wondered how the company that sent it got your contact details? Or maybe you’re casually browsing social media and you see your face, or even worse, your child’s, being used in a marketing campaign without your consent.

Play Video

Over the past decade, our increasing reliance on technology for daily tasks has resulted in an increase in the digital footprints left by web users. This has escalated the risk of personal data being misused.

In an era where a single data breach can cost offenders millions in fines and reputational damage, strict data compliance is no longer a nice to have for organisations. It is a legal requirement, crucial for building trust and achieving long-term success in today’s hyper vigilant world.

According to market research, customers are 77 percent more likely to stay loyal to or purchase from brands that are transparent about how their data is collected and used, than those which are not.

As the world marks the Global Data Privacy Week, an annual event held from January 26 to raise awareness about data risks, organisations that handle sensitive customer data such as financial details, addresses, biometrics and health records, must be at the forefront in promoting best data practices.

For instance, clearly disclosing to clients why their data is being collected and how it will be used, by replacing complex language with clear privacy notices, can help to build a foundation of trust that is essential for customer retention.

In addition, companies should commit to collect only the necessary personal information from customers, maintain the data they need for specific regulatory retention periods and have clear protocols for the eventual disposal of outdated information.

Data minimisation and digital shredding can reduce the risk of data breaches by limiting the amount of sensitive information stored and ensuring data doesn’t linger indefinitely.

Companies should only share personal information with third parties who demonstrate equivalent data privacy standards or are subject to similar local and international laws, such as the Kenya Data Protection Act (2019).

Data Protection Officers, whom companies appoint to act as internal watchdogs and direct links to regulatory bodies, must be empowered to operate independently and be involved in key business decisions.

Leave a Reply

Your email address will not be published. Required fields are marked *