Rolland Kaya General Director MSF Eastern Africa 

2nd Regional Data Protection and Cybersecurity Symposium for Humanitarian Actors

  • Date: 9th September 2026
  • Location:Nairobi, Kenya
  • Time: 8:00 am – 6:00 pm
  • Format: Hybrid (In-person and virtual participation)

Médecins Sans Frontières / Doctors Without Borders (MSF) Eastern Africa is organising the 2nd Regional Data Protection and Cybersecurity Symposium for Humanitarian Actors in Nairobi, Kenya, on 9th September 2026 under the theme “From Practice to Impact: Securing Humanitarian Data in a Digital-First Era, Protecting People by Protecting Data.”

John Riaga standing at a podium addressing attendees at the Regional Data Protection and Cybersecurity Symposium for Humanitarian Actors.

From Practice to Impact: Symposium Overview

Image removed.
“Moving beyond basic policy toward evaluating real-world cyber resilience and beneficiary protection.”
Securing humanitarian data in a digital-first era — where protecting data is protecting people.

The 2026 symposium seeks to move beyond basic policy implementation toward evaluating real-world effectiveness, cyber resilience, and measurable accountability in humanitarian contexts. As operations digitize, protecting data remains inseparable from protecting human dignity.

It brings together regional humanitarian actors, technical experts, policymakers, and data protection stakeholders to share operational lessons, address evolving AI-powered cyber threats, and advance ethical, secure data practices aligned with frameworks like the Kenya Data Protection Act.

Ultimately, the symposium aims to strengthen sector-wide collaboration, bridge the gap between headquarters policies and field realities, and promote responsible data governance that safeguards the dignity and rights of affected populations.

Image removed.

Philip Kisaka

Chief Privacy Officer, DPO 360 Africa Limited

Leading privacy strategy across Africa. 7+ years in GDPR & African frameworks. Advisor to Mastercard Foundation, Telkom Malawi, AUDA-NEPAD. Advocate, CIPP/E.

Image removed.

Zoya Naidoo

Information Officer, MSF Southern Africa

Information governance & data protection since 2018. CIPM, expert in records management & policy. Pursuing Masters in Critical Diversity Studies.

Image removed.

Sophie Orr

Keynote Speaker

Head of Institutional Readiness, Crisis Response and Learning at ICRC. Oversees Ethics, Risk & Compliance, Data Protection & Evaluation. 20+ years in protection & management, ex-Regional Director Americas.

Image removed.

Dr. Laibuta Mugambi

Advocate, CIPM, PhD Law (Wits)

Advocate, CIPM, PhD Law (Wits). President, Data Privacy & Governance Society of Kenya. Expert on AI governance & privacy by design.

Image removed.

Chris Asembo

Regional Technical Referent – IT

IT professional with MSF France, supporting humanitarian operations across Kenya, South Sudan, Somalia, Uganda, Malawi and Sudan. 17+ years in ICT, cybersecurity and data protection.

Image removed.

Susan M. Maswili

Digital Transformation Leader, People in Need

Senior Software Engineer, 10+ years in humanitarian tech. Women In Tech Ambassador & Chair, NetHope Africa Chapter.

Image removed.

Karisa Mwanyale

Senior ICT Leader, MSF Belgium

Senior ICT Leader at MSF Belgium leading cloud operations, governance & security across Azure. Expert in cloud security and safeguarding data in conflict zones.

Image removed.

Hakima Masud

Humanitarian Affairs Manager, MSF Switzerland

Humanitarian Affairs Manager with MSF Switzerland in Kenya. 13+ years in public health, emergency response, advocacy, and community engagement.

Image removed.

Kimberly Lobry

Data Protection Officer, MSF France

Data Protection Officer for MSF France, Epicentre, and Fondation MSF. Launched the Kenya Data Protection project in 2022.

Image removed.

Annette Opiyo

Humanitarian Affairs Manager, MSF Kenya

Human rights and global health advocate. Humanitarian Affairs Manager at MSF Kenya, leading advocacy on non-communicable diseases and SRHR policy.

Image removed.

Janet Maranga

Data Protection & Cybersecurity Professional

Data Protection and Cybersecurity professional with 11+ years of experience. Leads Data Protection for MSF Eastern Africa.

Image removed.

Esther Kago

Advocate, High Court of Kenya

Advocate of the High Court of Kenya with 7+ years' experience. Works in MSF Eastern Africa's Data Protection Unit.

Philip Kisaka is the Chief Privacy Officer at DPO 360 Africa Limited, where he leads privacy strategy and regulatory compliance initiatives across Africa and internationally.

With more than seven years of experience in data protection and technology law, he has developed deep expertise in applying the GDPR and African data protection frameworks to complex organizational environments, supporting institutions such as the Mastercard Foundation, Telkom Networks Malawi, AUDA-NEPAD, and the Office of the Data Commissioner Zambia.

Philip is an Advocate of the High Court of Kenya, holds a Bachelor of Laws from the University of Nairobi and a Master's in Information Technology and Intellectual Property Law from the University of East Anglia, and is a Certified Information Privacy Professional Europe (CIPP/E).

He serves as Vice Secretary of the Data Privacy and Governance Society of Kenya and is the official Event Moderator for the East Africa Data Governance Conference.

Outside of work, Philip is an avid golfer, always looking for a good excuse to be out on the course.

I have served as the Information Officer for Médecins Sans Frontières (MSF) Southern Africa since 2018, supporting the organisation's information governance, data protection, knowledge management, and organisational information systems. My role focuses on ensuring that information is managed securely, ethically, and efficiently to strengthen humanitarian operations and support evidence-based decision-making.

Over the course of my career, I have developed extensive experience in information management, governance, and organisational development. I have led initiatives to strengthen data protection frameworks, develop policies aligned with international privacy standards, and improve information management practices across diverse teams. My expertise includes data privacy, records management, information governance, stakeholder engagement, and driving organisational change within complex humanitarian settings. I hold the Certified Information Privacy Manager (CIPM) qualification, and have further enhanced my expertise through a range of professional workshops and courses in information governance, privacy, and organisational development.

Outside of work, I enjoy running, playing padel, and hiking, activities that help me maintain balance and resilience. I am also currently pursuing a Master's degree in Critical Diversity Studies, reflecting my commitment to continuous learning and my interest in equity, inclusion, and social justice.

Sophie Orr is the Head of Institutional Readiness, Crisis Response and Learning at the International Committee of the Red Cross (ICRC). In this role, as well as supervising the organization's efforts on business continuity, Ms. Orr also oversees the work of the Ethics, Risk and Compliance Office, of the Data Protection Office and of the Evaluation Office.

Ms. Orr has worked for and represented the ICRC for over 20 years, primarily in the fields of protection and general management in often complex contexts, as well as at headquarters. Prior to her current role, Ms. Orr served as the ICRC's Regional Director for the Americas (covering ICRC operations in North, Central, and South America), where she guided the organization's strategic response and contributed to humanitarian diplomacy efforts at various levels.

Before joining the humanitarian sector, Ms Orr had a first career as a journalist and foreign affairs producer with the UK's Channel 4 News and the BBC.

Dr Mugambi Laibuta is an Advocate of the High Court of Kenya, Certified Information Privacy Manager (CIPM), technology compliance professional, legislative drafter and leading expert in data protection, digital rights and artificial intelligence governance. He holds a PhD in Law from the University of the Witwatersrand, where his research examined the adequacy of Kenya's data protection framework.

He is President of the Data Privacy and Governance Society of Kenya and a lecturer at the Kenya School of Law. He has advised governments, judiciaries, development partners and public institutions across Africa on data protection, digital transformation, AI policy and compliance, legislative reform and responsible technology governance.

His work focuses on translating complex legal and ethical principles into practical safeguards for institutions adopting emerging technologies. He is particularly interested in privacy by design, accountable AI, cybersecurity governance and protecting dignity, equality and fundamental rights in increasingly data-driven humanitarian and public service environments.

Chris Asembo is an IT professional with Médecins Sans Frontières France, supporting humanitarian operations across Kenya, South Sudan, Somalia, Uganda, Malawi and Sudan.

With over 17 years of experience, Chris has held senior positions in both corporate organizations and NGOs, most recently at Action Against Hunger and at MSF, where he serves as Regional Technical Referent – IT. His expertise spans ICT service and infrastructure management, cybersecurity and data protection, risk management, process automation, Policy formulation, internal system audits, and quality management systems. His work focuses on aligning People, processes and Technology to strengthen operational resilience, protect information, support data-driven decision-making and enable effective service delivery in complex environments.

Chris describes himself as someone who brings people and technology together to solve problems and deliver practical, sustainable solutions. Beyond his professional work, he is passionate about mentoring young people in technology, volunteering, and supporting community initiatives, reflecting his belief that technology should ultimately serve people and create positive impact.

Susan M. Maswili is a Digital Transformation Leader and Senior Software Engineer with over 10 years of experience designing and implementing digital solutions across the humanitarian and development sectors. She currently works within the Digital Unit at People in Need, where she contributes to technology-driven innovation and the development of secure, scalable and practical digital solutions.

Susan's expertise spans software engineering, digital transformation, data systems, technology innovation, and the design of solutions that respond to the realities of complex and resource-constrained environments. She is particularly passionate about responsible technology, cybersecurity, data protection, and ensuring that digital systems are designed with people, privacy, security, and accessibility at their core.

Beyond her professional role, Susan is a Women In Tech Ambassador and Chair of the NetHope Africa Chapter, where she supports collaboration and digital innovation across the humanitarian technology community. She is passionate about using technology to create inclusive opportunities and strengthen communities, particularly for women and young people.

Susan believes technology is most powerful when it is secure, inclusive, and designed to serve people with dignity.

Karisa Mwanyale is a Senior ICT Leader at Médecins Sans Frontières (MSF) Belgium, where he leads cloud operations, governance, and security across the organization's Azure infrastructure, drawing on deep expertise in Azure architecture and cloud security. Working at the intersection of humanitarian aid and technology, he brings a first-hand perspective on the unique cybersecurity and data protection challenges facing organizations that operate in conflict zones and fragile settings where protecting sensitive patient and operational data can be a matter of life and death. He joins today's panel to share insights on securing digital infrastructure and safeguarding data integrity within the humanitarian sector.

Hakima Masud is the Humanitarian Affairs Manager with Médecins Sans Frontières (MSF) Switzerland in Kenya. With a background in nursing and disaster management, and currently pursuing a Master of Public Health, she has over 13 years of experience spanning public health, emergency response, advocacy, community engagement and programme management.

In her current role, she leads context analysis, advocacy, stakeholder engagement, and the documentation and analysis of operational and community-based evidence in support of MSF operations in Kenya. Her work draws on information from health programmes, patients and communities to inform dialogue and advocacy on issues affecting access to healthcare and people's wellbeing.

Hakima previously held programme management and coordination roles with MSF and the Kenya Red Cross Society. At the heart of her work is a commitment to dignity, equity and meaningful engagement with communities, ensuring that people's experiences are heard and reflected in the decisions that affect them.

Kimberly Lobry serves as the Data Protection Officer for MSF France, Epicentre, and the Fondation MSF. She began her career with the French data protection authority before working as a consultant for clients across both the private and public sectors.

Since joining MSF in 2019, she has deployed to several operational missions in Africa and the Middle East, gaining firsthand experience in aligning data protection practices with field activities and operational constraints. In 2022, backed by sponsorship from MSF East Africa and in collaboration with Alex, DPO for MSF Switzerland, she helped launch the Kenya Data Protection project.

Guided by the principle that protecting data means protecting people, she focuses on making data protection accessible, intuitive, and practical.

Annete A. Opiyo is a human rights and global health advocate with extensive experience across humanitarian and development contexts. She currently serves as Humanitarian Affairs Manager at Médecins Sans Frontières (MSF) Kenya, leading advocacy on non-communicable diseases, including diabetes, hypertension, and sickle cell disease, with a focus on strengthening health systems, reducing out-of-pocket expenditure, and improving access to affordable, quality medicines.

She also advances sexual and reproductive health and rights (SRHR) policy, centring the needs and voices of vulnerable and marginalised populations. Annete holds an LLM in Human Rights, specialising in Sexual and Reproductive Rights, from the Centre for Human Rights, University of Pretoria, an LLB from Kenyatta University, and a Postgraduate Diploma in Law from the Kenya School of Law.

She is passionate about health equity, human rights, patient-led advocacy, and building more responsive, patient-centred health systems. Outside work, she enjoys travelling, discovering new places, and spending time with family and friends.

Janet Maranga is a Data Protection and Cybersecurity professional with over 11 years of experience in data protection, cybersecurity governance, privacy, and information risk management. She holds CIPP/E, CIPM and CISA certifications and an MSc in Computer Science from the University of Nairobi.

Janet leads Data Protection for MSF Eastern Africa and supports regional operations in strengthening responsible data practices, cybersecurity resilience, and digital risk management. She is passionate about translating privacy and cybersecurity principles into practical, sustainable solutions that protect people, data, and humanitarian operations.

Esther Kago is an Advocate of the High Court of Kenya with over 7 years' experience and a Certified Public Accountant (Kenya). She holds a Certified Information Privacy Professional/Europe (CIPP/E) and a DPO Certification for Humanitarian Action from Maastricht University.

She has worked in Médecins Sans Frontières Eastern Africa's Data Protection Unit for almost four years. In that time, she has grown the Data Protection Privacy Champions Programme from pilot to maturity stage and contributed to the implementation of data protection across 15 country programmes and 37 field projects, including Kenya, South Sudan, Tanzania, Eswatini, and the International Privacy Coordination Office.

She has trained over 200 participants during her time with the unit, reviewed more than 30 contracts, and conducted countless Data Protection Impact Assessments. She has also contributed to the development of frameworks such the Data Protection and Knowledge Management Frameworks. Esther has co-created a handbook on data protection as well as a playbook on starting and growing a privacy champions programme within the MSF Movement.

Objectives, Tracks & Outcomes

8:00 AM – 6:00 PM 2 Plenary & Panel Blocks Full-Day Programme
Morning
  • 8:00 AM8:30 AM

    Arrival, Registration

    Front Desk Team

  • 8:30 AM8:35 AM

    Welcome Remarks

    Zoya Naidoo / Philip Kisaka

  • 8:35 AM8:45 AM

    Access & Security Briefing

    Bashir Maalim

  • 8:45 AM8:55 AM

    Health Briefing

    Zipporah Wachira

  • 9:00 AM9:15 AM

    Opening Remarks

    Rolland Kaya General Director — MSF East Africa

  • 9:20 AM9:50 AM
    Keynote

    Keynote Address

    Sophie Orr Head of Institutional Readiness, Crisis Response and Learning — ICRC

  • 9:50 AM10:00 AM

    Group Photo

    All — Philip Kisaka

  • 10:00 AM10:30 AM

    Tea Break & Visit to Sponsor Booths

  • 10:35 AM11:45 AM
    Plenary Session 1

    AI, Data Protection and Emerging Technologies

    Dr. Laibuta Mugambi President, Data Privacy & Governance Society of Kenya

  • 11:45 AM11:55 AM

    Icebreaker

    Zoya Naidoo

  • 11:55 AM1:00 PM
    Panel Session 1

    Cybersecurity in humanitarian contexts: threats, trends, and response

    ModeratorJanet Maranga

    PanelistsEmmanuel Karisa, Susan Maswili, Chris Asembo

  • 1:00 PM2:00 PM

    Lunch Break

Afternoon
  • 2:00 PM2:10 PM
    Spotlight

    MSF at a Glance

    MSF

  • 2:20 PM3:30 PM
    Panel Discussion 2

    Advocacy & Data Protection in humanitarian action

    ModeratorEsther Kago

    PanelistsKimberly Lobry, Annette Opiyo, Hakima Masud

  • 3:45 PM4:00 PM

    Wrap-Up & Symposium Way Forward

    Eunice Obala

  • 4:00 PM4:05 PM

    Symposium Evaluation

    Tolbert Ayuaya

  • 4:05 PM4:15 PM

    Closing Remarks & Vote of Thanks

    Tolbert Ayuaya

  • 4:15 PM6:00 PM

    Coffee, Networking & Departure

    All Guests

The symposium seeks to achieve the following core objectives:

  • Foster Collaboration: Build stronger partnerships between NGOs, donors, governments, and technical experts in the region.
  • Advance Accountability and Trust: Promote transparent and responsible data use in line with humanitarian principles and legal frameworks such as the Kenya Data Protection Act among other national and regional data protection and cybersecurity frameworks.
  • Evaluate Impact: Explore how data protection and cybersecurity practices are improving outcomes for patients and beneficiaries.
  • Strengthen Cyber Resilience: Discuss emerging cybersecurity threats affecting humanitarian operations and share mitigation strategies.
  • Drive Innovation: Showcase practical tools, approaches, and technologies that enhance data protection in low-resource and emergency settings.
Cybersecurity in humanitarian contexts: threats, trends, and response

Humanitarian organizations are among the most affected institutions in the digital threat landscape, yet among the least resourced to defend themselves. State-sponsored attacks, ransomware campaigns, insider threats amplified by high staff turnover, and social engineering directed at field staff all pose serious risks.

This theme moves beyond awareness-raising to examine what adequate cybersecurity actually looks like in a mobile health clinic, a refugee registration center, or a disease surveillance program.

Advocacy and Data Protection in humanitarian action

Data protection in humanitarian settings is not only a compliance obligation. It is a site of active advocacy. Legal frameworks across the region were drafted primarily with commercial and governmental data processing in mind.

Equally important is applying the principle of témoignage to digital rights: bearing witness to the data-related harms experienced by affected populations and translating that witness into evidence that shapes policy.

Data protection as a humanitarian imperative: dignity, trust, and duty of care

Dignity, trust, and duty of care are not abstract humanitarian values. They are operationalized in every interaction with a beneficiary, and data protection belongs squarely in that frame.

To collect intimate personal information from individuals in profound vulnerability, and then store it carelessly, share it without consent, or retain it without purpose, is to treat the person behind the data as a resource rather than a rights-holder.

Operationalizing data protection in field projects

Organizations may have sophisticated data protection frameworks at headquarters level, yet in the field, data is collected on personal phones, stored on unencrypted USB drives, shared via WhatsApp, and retained indefinitely with no disposal plan.

Closing this gap requires purpose-built tools that work in low-resource environments: IT solutions that function without reliable literacy or connectivity, and data minimization embedded at the collection design stage.

Building sustainable data protection capacity

Sustainable capacity cannot be built through a single training workshop or the appointment of a Data Protection Officer without authority or resources. It requires a systemic approach operating at three levels simultaneously.

At the organizational level, it means embedding data protection into program design rather than appending it as an afterthought and creating feedback loops between field experience and policy development.

Building a culture of data protection

Compliance systems do not create cultures. What changes data practices at the level of daily operational decisions is a shared set of values and expectations that shape behavior even when no one is watching.

Effective training is contextual, applied, and continuous. Leadership is the most underestimated dimension: culture follows what senior managers model, not what policies prescribe.

The symposium anticipates delivering the following outcomes across the sector:

  • Strengthened regional network of data protection and cybersecurity practitioners.
  • Increased awareness of emerging cyber threats and mitigation strategies.
  • Development of sector-informed recommendations and guidance notes on responsible data use.
  • Enhanced collaboration between advocacy, operations, and data protection teams.
us06web.zoom.us

As humanitarian organizations continue to digitize their operations, protecting personal data is inseparable from protecting the dignity, safety, and rights of affected populations. This symposium will serve as a critical platform to move the sector forward from implementing systems to ensure they truly work, withstand threats, and uphold trust. 

REGISTER NOW
Regional Data Protection and Cybersecurity Symposium for Humanitarian Actors