Practical Data Protection Compliance for Kenyan Organisations
The Data Protection Act, 2019 gives effect to the right to privacy in Article 31 of the Constitution. It applies to any organisation that processes the personal data of people in Kenya, including organisations based outside the country, and it is enforced by the Office of the Data Protection Commissioner (ODPC).
Enforcement is now routine. The ODPC can impose administrative fines of up to KES 5 million or 1% of annual turnover, issues enforcement notices and compensation orders, and has determined hundreds of complaints. Organisations must also report a personal data breach to the ODPC within 72 hours of becoming aware of it.
We help organisations build compliance that holds up in practice, from registration and policies through to contracts, training and breach response. When a complaint or enforcement action arises, our litigation team represents clients before the ODPC and the courts.
How We Can Help
ODPC Registration
Confirming whether your organisation must register under the 2021 Registration Regulations, and registering you as a data controller or processor. Some sectors, including financial services and health, must register regardless of size.
Compliance Audits
Reviewing how your organisation collects, stores, shares and deletes personal data, and giving you a prioritised plan to close the gaps.
Data Protection Impact Assessments
Carrying out the impact assessments the Act requires before high-risk processing, such as large-scale monitoring or use of sensitive personal data.
Policies, Notices & Contracts
Drafting privacy notices, consent mechanisms, data processing and data sharing agreements, and safeguards for transferring data outside Kenya.
Breach Response
Guiding you through the first 72 hours after a breach: containing it, notifying the ODPC, and telling affected people what they need to know.
ODPC Complaints & Disputes
Responding to complaints, enforcement notices and penalty notices, and challenging ODPC decisions before the High Court.
Why Choose Us for Data Protection & Privacy
Advisers Who Also Litigate
We handle ODPC complaints and appeals, so our compliance advice reflects how the regulator actually decides cases.
Proportionate to Your Size
A SACCO, a clinic and a technology platform have very different risks. We scale the work to what your organisation genuinely needs.
Sector Experience
We work with financial services, insurance, co-operative, health and non-profit organisations, all of which handle sensitive personal data.
Ongoing Support
Beyond a one-off audit, we can act as your external data protection adviser, supporting your Data Protection Officer and answering questions as they arise.
Need Help With Data Protection Compliance?
Speak to our team about your matter. We respond to enquiries within one working day.