The Ethics of Data Protection: Beyond Compliance for Revenue Authorities
Written by Globis Mandela
ETHICS OF DATA PROTECTION
Introduction
With many groundbreaking technological developments, our data has become a precious commodity and hence, there is a great need to regulate who has access to our information. For many taxpayers, the notion that the revenue authority may have unimpeded access to their private information should the Finance Bill 2025 be enacted remains a cause of concern.
Background
To say that this is KRA’s first attempt to access taxpayer’s information would be a stretch. In 2020, a case was instituted against the Revenue Authority, questioning the constitutionality of Sections, 57, 58, 59 and 99 of the Tax Procedures Act (TPA) 2015. However, this case was ruled in favor of the Revenue Authority. The court found that Section 59 was constitutional as it was upon KRA to also ensure that confidentiality of the information provided was maintained as per Section 6 of the TPA. Additionally, the right to not incriminate oneself that was set out in Shapiro¹ cannot be used to absolve oneself of a crime nor can it be used to make oneself immune to a duty imposed on all other citizens.
Drawing focus on the Finance Act of 2023 that introduced Section 59A of the TPA, it provided that the Commissioner may establish a data management and reporting system for the submission of electronic documents including detailed transactional data relating to those documents. However, the documents to be submitted would not include trade secrets; and private or personal data held on behalf of customers or collected during business² . To this extent, we can affirm that this section was compliant with Article 31 of the Constitution which guarantees the protection of our privacy.
Current Provision
The right to privacy is therefore an integral concept in a democratic society and it is enshrined in Article 31 of our Constitution. That said, this is not an absolute right and can be limited according to the standards set out in Article 24 so long as the limitation is within the bounds of existing law and it is done in a manner which is not arbitrary. KRA is currently allowed to have access to our information as highlighted above for the purposes of ensuring compliance with tax obligations. tax obligations³.
The Data Protection Act guarantees the rights of data subjects to be informed of the use to which their personal data is to be put and to object to the processing of their data⁴. However, sensitive data may still be collected for the enforcement of a law which imposes a pecuniary penalty⁵, which may perhaps be the angle that KRA may use to justify the deletion of Section 59A 1(b) of the TPA.
Conclusion
Notwithstanding the current provisions, the possibility of doing away with Section 59A 1(b) seems to conflict with our data protection rights. While KRA may be bound to keep personal data and trade secrets confidential by law should they have access to it, the general confidence of the public in government authorities to not interfere with or use sensitive data inappropriately withers day by day.
¹ Shapiro v. United States, 335 U.S. 1, 92 L. Ed. 1787, 68 S. Ct. 1375, reh'g denied, 335 U.S. 836, 93 L. Ed. 388, 69 S. Ct. 9 (1948)
² Section 59A 1(b) Tax Procedures Act 2015.
³ Section 4, Tax Procedures Act 2015.
⁴ Section 26, Data Protection Act 2019.
⁵ Section 28, Data Protection Act 2019.