Compliance

The Kenya Data Protection Act in Practice: What Compliance Actually Requires

The Act has been in force for years and enforcement is active. Here is what it requires in operational terms, rather than legal summary.

Reviewing data protection documentation

Most organisations we assess have heard of the Data Protection Act and have done something about it — usually a privacy policy on the website. That is the smallest part of what the Act asks for, and rarely the part a regulator examines first.

Know what you hold

Everything else depends on this. You need a record of the personal data you process: what it is, why you have it, the lawful basis, where it lives, who can reach it, who you share it with, and how long you keep it.

Building this is tedious and almost always reveals surprises — data collected for a purpose that ended years ago, copies in systems nobody remembered, spreadsheets of customer records on individual laptops. You cannot protect or delete what you have not mapped.

Have a lawful basis, and be able to name it

Consent is one basis among several, and often the weakest choice because it can be withdrawn. Contractual necessity, legal obligation and legitimate interests frequently fit better. The requirement is that you can state which basis applies to each processing activity and justify it — not that you obtained consent for everything.

If you rely on consent

It must be freely given, specific, informed and unambiguous. Pre-ticked boxes do not qualify. Bundling consent into terms and conditions does not qualify. Withdrawal must be as easy as giving it was.

Be able to answer a data subject

Individuals can ask what you hold about them, request correction, request deletion, object to processing, and ask for their data in a portable form. You need a process that can meet the statutory deadline — which means knowing where data lives before the request arrives, not starting the search afterwards.

Run one internally as a test. Organisations consistently discover the response would take weeks rather than days.

Registration and the Data Protection Officer

Many data controllers and processors must register with the Office of the Data Protection Commissioner. Certain organisations must designate a Data Protection Officer. Whether these apply to you depends on your size and the nature of your processing — confirm your position rather than assuming you are exempt.

Breach notification runs on a short clock

Breaches meeting the threshold must be reported to the Commissioner within the statutory period, and affected individuals notified where the risk is high. That deadline is short, and it starts when you become aware — not when the investigation concludes.

This is the obligation most often missed, because it requires an incident response process that includes a legal and regulatory track running in parallel with the technical one. If your plan does not name who assesses notifiability and who files, it will be improvised during the worst week of your year.

Transfers outside Kenya

Moving personal data across borders carries conditions. If you use cloud services hosted elsewhere — and almost everyone does — this applies to you. Know where your processors store data and what safeguards are in place.

Appropriate technical and organisational measures

The Act requires security proportionate to the risk, without prescribing controls. In practice that means access control, encryption of sensitive data at rest and in transit, logging and monitoring, tested backups, vendor due diligence, staff training, and documented evidence that you considered the risks and acted on them.

The documentation matters as much as the controls. Demonstrating compliance is itself an obligation, and a regulator will ask what you did and when.