Regional Data Protection and Cybersecurity Symposium for Humanitarian Actors
- Date: 9th September 2026
- Location: Gemsuites Hotel, Riverside Lane, off Riverside Drive, Nairobi, Kenya
- Time: 8:00 am – 6:00 pm
- Format: Hybrid (In-person and virtual participation)
Médecins Sans Frontières / Doctors Without Borders (MSF) Eastern Africa is organising the Regional Data Protection and Cybersecurity Symposium for Humanitarian Actors in Nairobi, Kenya, on 9th September 2026 under the theme “From Practice to Impact: Securing Humanitarian Data in a Digital-First Era, Protecting People by Protecting Data.”
From Practice to Impact: Symposium Overview
The 2026 symposium seeks to move beyond basic policy implementation toward evaluating real-world effectiveness, cyber resilience, and measurable accountability in humanitarian contexts. As operations digitize, protecting data remains inseparable from protecting human dignity.
It brings together regional humanitarian actors, technical experts, policymakers, and data protection stakeholders to share operational lessons, address evolving AI-powered cyber threats, and advance ethical, secure data practices aligned with frameworks like the Kenya Data Protection Act.
Ultimately, the symposium aims to strengthen sector-wide collaboration, bridge the gap between headquarters policies and field realities, and promote responsible data governance that safeguards the dignity and rights of affected populations.
Objectives, Tracks & Outcomes
The symposium seeks to achieve the following core objectives:
- Foster Collaboration: Build stronger partnerships between NGOs, donors, governments, and technical experts in the region.
- Advance Accountability and Trust: Promote transparent and responsible data use in line with humanitarian principles and legal frameworks such as the Kenya Data Protection Act among other national and regional data protection and cybersecurity frameworks.
- Evaluate Impact: Explore how data protection and cybersecurity practices are improving outcomes for patients and beneficiaries.
- Strengthen Cyber Resilience: Discuss emerging cybersecurity threats affecting humanitarian operations and share mitigation strategies.
- Drive Innovation: Showcase practical tools, approaches, and technologies that enhance data protection in low-resource and emergency settings.
Humanitarian organizations are among the most affected institutions in the digital threat landscape, yet among the least resourced to defend themselves. State-sponsored attacks, ransomware campaigns, insider threats amplified by high staff turnover, and social engineering directed at field staff all pose serious risks.
This theme moves beyond awareness-raising to examine what adequate cybersecurity actually looks like in a mobile health clinic, a refugee registration center, or a disease surveillance program.
Data protection in humanitarian settings is not only a compliance obligation. It is a site of active advocacy. Legal frameworks across the region were drafted primarily with commercial and governmental data processing in mind.
Equally important is applying the principle of témoignage to digital rights: bearing witness to the data-related harms experienced by affected populations and translating that witness into evidence that shapes policy.
Dignity, trust, and duty of care are not abstract humanitarian values. They are operationalized in every interaction with a beneficiary, and data protection belongs squarely in that frame.
To collect intimate personal information from individuals in profound vulnerability, and then store it carelessly, share it without consent, or retain it without purpose, is to treat the person behind the data as a resource rather than a rights-holder.
Organizations may have sophisticated data protection frameworks at headquarters level, yet in the field, data is collected on personal phones, stored on unencrypted USB drives, shared via WhatsApp, and retained indefinitely with no disposal plan.
Closing this gap requires purpose-built tools that work in low-resource environments: IT solutions that function without reliable literacy or connectivity, and data minimization embedded at the collection design stage.
Sustainable capacity cannot be built through a single training workshop or the appointment of a Data Protection Officer without authority or resources. It requires a systemic approach operating at three levels simultaneously.
At the organizational level, it means embedding data protection into program design rather than appending it as an afterthought and creating feedback loops between field experience and policy development.
Compliance systems do not create cultures. What changes data practices at the level of daily operational decisions is a shared set of values and expectations that shape behavior even when no one is watching.
Effective training is contextual, applied, and continuous. Leadership is the most underestimated dimension: culture follows what senior managers model, not what policies prescribe.
The symposium anticipates delivering the following outcomes across the sector:
- Clear documentation of practical case studies demonstrating impact at project level.
- Strengthened regional network of data protection and cybersecurity practitioners.
- Increased awareness of emerging cyber threats and mitigation strategies.
- Development of sector-informed recommendations and guidance notes on responsible data use.
- Recognition and publication of a winning student essay on data protection guidelines for the humanitarian sector.
- Enhanced collaboration between advocacy, operations, and data protection teams.
As humanitarian organizations continue to digitize their operations, protecting personal data is inseparable from protecting the dignity, safety, and rights of affected populations. This symposium will serve as a critical platform to move the sector forward from implementing systems to ensure they truly work, withstand threats, and uphold trust.