Hard truths.

News

MPs question Energy State Department over failure to meet data protection rules

The Public Accounts Committee grilled the State Department for Energy after an Auditor-General audit flagged gaps in compliance with Kenya’s Data Protection Act, 2019, including failure to appoint a Data Protec...

By
3 min read
The State Department for Energy Principal Secretary Alex Wachira appears before the Parliament's Public Accounts Committee in parliament on 29th July,2026. PHOTO/DAVID BOGONKO NYOKANG’I

Ignoring key data protection requirements has landed the State Department for Energy in the spotlight after Parliament questioned why it has yet to comply with laws meant to safeguard the personal information of Kenyans. MPs warned that the failures exposed by the Auditor-General could leave sensitive government records at risk and called for immediate action to address the gaps.

The concerns emerged when Principal Secretary Alex Wachira appeared before the Public Accounts Committee to respond to audit queries contained in the Auditor-General's Report for the 2023/2024 financial year. The session, chaired by Butere MP Tindi Mwale, also brought together senior officials from agencies under the State Department.

A major issue raised by the Auditor-General was the department's failure to appoint a Data Protection Officer as required under Section 24 of the Data Protection Act, 2019. The audit also established that the department had not registered as either a data controller or a data processor with the Office of the Data Protection Commissioner, despite both being mandatory under the law.

Committee members questioned how a government department that routinely handles confidential information belonging to the public had failed to comply with legal requirements that have existed for years.

Lawmakers said the continued failure to comply with the law exposes sensitive government records to unnecessary risks and raises concerns about the protection of personal information collected from Kenyans.

They warned that any breach involving such information could result in serious legal and administrative consequences for the government.

"What is so difficult in complying with the law? The data protection requirements have been in force since 2019," posed the Committee Chairperson.

The remarks reflected the Committee's dissatisfaction with what members described as a prolonged failure by the department to meet legal obligations that apply across public institutions.

In response, Principal Secretary Wachira admitted that the process of complying with the law was still ongoing.

"We are in the process of designating officers to serve as the Data Controller and Data Processor. We are also registering the State Department as a Data Controller and Data Processor in line with the requirements of the Data Protection Act," he said.

The Committee also examined another governance issue highlighted in the audit after it emerged that some officers had been using personal email accounts to conduct official government business even though official government email addresses were available.

According to the Auditor-General's report, the practice goes against the Head of the Public Service Circular issued on June 14, 2022, which bars public officers from using personal email addresses for official communication because of the security and accountability risks associated with them.

MPs questioned why some officers continued to ignore official communication channels, warning that the practice weakens record keeping, reduces accountability and increases exposure to cyber security threats.

Wachira told the Committee that management had since issued official government email accounts to staff in line with government policy.

The Committee, however, directed the Principal Secretary to urgently ensure the department fully complies with all provisions of the Data Protection Act and submit documentary evidence confirming that the corrective measures have been put in place.

The hearing adds to increasing pressure on accounting officers to address governance concerns repeatedly raised by the Auditor-General, with Parliament insisting that compliance with data protection laws is a legal requirement that every public institution must observe.

More from NewsBrowse the section
Continue to the next story →