• Cancellation right – A consumer should be granted the right to cancel a contract for certain types of goods and services, without reason and within a specified time period. • Payment fraud – A consumer should be granted certain protections from liability for fraudulent payments made in the consumer’s name, unless the vendor or payment service provider can prove that the consumer has been grossly negligent in the operation of the payment mechanism. • Performance obligations – The vendor should be obliged to perform the contract within a minimum specified period of time or be liable to fully refund the consumer. In addition, existing rules governing the content and techniques used to advertise and market goods and services should be reviewed and amended to take into account innovative online mechanisms, such as ‘pop-ups’, that may fall outside the current regime. The Task Force recommends the following: 2.5 • That the EAC Secretariat and Partner States give due consideration to consumer protection issues in cyberspace within a broader consumer protection framework, at both a national and regional level. • That reforms should encompass information requirements, cancellation rights, payment fraud and performance obligations. • That the EAC Secretariat and Partner States initiate programmes to raise consumer awareness about the benefits and risks of transacting in cyberspace, including such things as labelling schemes. • That the EAC Secretariat and Partner States give further consideration to the regional and national implications of electronic money or digital cash and the need to develop an appropriate regulatory framework (R.18). Data Protection and Privacy For the purposes of the Framework, ‘data protection’ is used here to describe those obligations placed upon those entities that process information about living individuals, generally referred to as ‘personal data’. A data protection regime will also grant certain rights upon individual data subjects. The application of data protection rules may be limited only to private sector entities or public bodies. A sectoral regulatory response may be appropriate to address specific uses and abuses of personal data, whether driven by domestic or foreign concerns, such as the financial services sector. In terms of the entity responsible for the processing, the following minimum obligations represent international best practice in the area: 17

Select target paragraph3