WhitepaperThe Kenya Data Protection Act: An Engineering Checklist
What the Data Protection Act, 2019 actually asks engineering and security teams to build — translated out of legal language and into controls, logs and retention rules.
Policy administration, claims and the broker network — assessed as one connected estate, because that is how an attacker reaching policyholder data experiences it.

Keeping policyholder data where it belongs.
Insurers hold an unusually rich concentration of personal data: identity documents, financial information, vehicle and property detail, and in medical lines, health records that the Data Protection Act treats as a sensitive category with heightened obligations. The value of that data to an attacker is independent of your premium income, which is why smaller insurers are targeted as readily as large ones.
The estate is also unusually distributed. Policy administration, claims handling, broker and agent portals, aggregator integrations, assessors, garages, medical providers and payment partners all touch the same records, frequently through interfaces built years apart to different standards. Assessing any one component in isolation misses the paths that run between them.
Our insurance work maps those paths first, then concentrates testing where policyholder data and claims authorisation are reachable — including the broker and partner access that sits outside your own control environment.
Portals issued to intermediaries extend access to policyholder data to organisations whose security you do not run. Shared logins, no multi-factor authentication and no per-account anomaly baseline are the common findings.
Where the same interface permits both claims lookup and claims adjustment, used by a broad group, the fraud path is internal and looks like ordinary work. Dual authorisation above a threshold and append-only logging change the picture.
Medical insurance brings health records into scope, which the Act treats as sensitive personal data. Retention, access control and the onward flow to providers and third-party administrators all need to withstand specific scrutiny.
Long-lived core systems often predate the controls now expected around them — weak authentication, unencrypted interfaces, no meaningful audit trail. Compensating controls and segmentation are usually more realistic than replacement.
Business email compromise against finance and client-facing teams redirects premium and claims payments without touching your systems. The control that stops it is procedural: out-of-band verification on a number held on file beforehand.
Quote and bind integrations hand data to partners at volume. Credentials scoped wider than the use case, no rate limiting and no per-partner traffic baseline are the pattern we find most often.
The sequence below is what a insurance engagement looks like in practice — shaped by what your environment can and cannot tolerate.
Talk to our Insurance teamWe produce the data map the Act effectively requires — every system holding personal data, its lawful basis, its retention rule, and the downstream parties it flows to. It is the foundation for everything that follows.
Broker, agent, assessor and provider access is tested as its own trust boundary, with recommendations you can actually impose through your intermediary agreements rather than through your own infrastructure.
We review operational entitlements against what each role genuinely needs, and design the approval and logging changes that make internal fraud detectable without slowing legitimate claims handling.
Findings land mapped to the Data Protection Act, its subsidiary regulations and ISO/IEC 27001:2022, with the records a regulator or a reinsurer’s due diligence would ask to see.
Each of these is a published instrument you can read. We map findings to them directly, so an assessment feeds your audit and supervisory cycle instead of sitting beside it.
WhitepaperWhat the Data Protection Act, 2019 actually asks engineering and security teams to build — translated out of legal language and into controls, logs and retention rules.
Threat AdvisoryThe mailbox-rule and supplier-impersonation patterns we keep finding in finance departments, with the detection logic and the four controls that stop them.