Mumbi Gikonyo & Co. Advocates

Data Protection Compliance for businesses

In Data Protection Compliance for businesses, Businesses that process personal data have a mandatory duty to comply with the data protection laws in the country. Compliance is based on the sensitivity of data collected, not on the size of the company/business.

Kenya’s data protection framework is anchored in the Data Protection Act, 2019 (DPA), enforced by the Office of the Data Protection Commissioner (ODPC). Both large and small businesses that process personal data must consider the following:

1. Registration with the ODPC

2. Lawful basis for processing

3. Data subject rights

4. Data minimization and purpose limitation

5. Security safeguards

6. Data breach notification

7. Third-party and cross-border transfers

8. Data Protection Impact Assessments (DPIAs)

9. Appointing a Data Protection Officer (DPO)

Required for public bodies and businesses engaged in high-risk or large-scale processing; smaller businesses may still benefit from designating a compliance lead.

Data Protection Compliance for businesses

Disclaimer: This article is for information purposes only. For formal legal advice and support kindly contact us on admin@mgcadvocates.com, +254701093254 or physically visit our office at Muchane Plaza, Kikuyu

Exit mobile version