Compliance

Getting ready for the Kenya Data Protection Act: a practical checklist

Getting ready for the Kenya Data Protection Act: a practical checklist

The Kenya Data Protection Act, 2019 moved data protection from a “nice to have” to a legal obligation. If your organisation collects or processes personal data — customer records, staff files, patient information — the Act applies to you, and the Office of the Data Protection Commissioner (ODPC) is increasingly active in enforcing it. The good news: getting compliant is mostly a matter of doing a set of sensible things in order.

Who the Act applies to

The Act covers any data controller or processor handling the personal data of people in Kenya. That is a broad net — it includes SMEs, NGOs, schools, clinics, and startups, not just large enterprises. If you hold a spreadsheet of customers or an HR system full of staff details, you are in scope.

A practical readiness checklist

You do not need to solve everything at once. Work through these steps in order and you will cover the essentials most organisations are missing.

1. Know what data you hold

You cannot protect — or account for — data you have not mapped. Build a simple record of what personal data you collect, where it lives, why you have it, and who can access it. This single exercise usually reveals the biggest risks on its own.

2. Establish a lawful basis

For each type of processing, be clear on why you are allowed to do it — consent, a contract, a legal obligation, or a legitimate interest. Consent, where you rely on it, must be freely given and specific, not buried in fine print.

3. Update your privacy notice

People have a right to know how their data is used. A clear, honest privacy notice — in plain language — is both a legal requirement and a trust builder.

4. Respect data subject rights

Individuals can ask to access, correct, or delete their data. Put a simple process in place so these requests are handled within the timelines the Act sets, rather than scrambling when the first one arrives.

5. Secure the data

  • Encrypt sensitive data in transit and at rest.
  • Apply least-privilege access so staff only see what they need.
  • Keep audit logs so you can detect and investigate misuse.
  • Have a breach response plan — the Act requires notifying the ODPC of serious breaches.

6. Consider registration

Depending on your size and the nature of your processing, you may be required to register with the ODPC as a data controller or processor. Check where your organisation falls rather than assuming you are exempt.

A note on scope: compliance is a programme, not a one-off project. Regulations and your own data holdings both change — build in a periodic review so you stay current.

Turning the checklist into a plan

Most organisations know they should do this; the hard part is knowing where they stand and what to prioritise. A structured gap assessment maps your current state against the Act and gives you a phased, budget-aware roadmap. See how our compliance and gap analysis works, or talk to us about where to start.

This article is general guidance, not legal advice. For obligations specific to your organisation, consult a qualified data-protection professional.

← Back to all insights
Start the conversation

Ready to understand your real exposure?

Every engagement starts with a scoping conversation — no obligation, no sales pitch. Just a clear-eyed look at where you stand.

Scroll to Top