In Data Protection Compliance for businesses, Businesses that process personal data have a mandatory duty to comply with the data protection laws in the country. Compliance is based on the sensitivity of data collected, not on the size of the company/business.
Kenya’s data protection framework is anchored in the Data Protection Act, 2019 (DPA), enforced by the Office of the Data Protection Commissioner (ODPC). Both large and small businesses that process personal data must consider the following:
1. Registration with the ODPC
- Entities that qualify as “data controllers” or “data processors” (based on revenue, volume of data processed, or nature of the business, e.g., health, financial services) must register annually with the ODPC. Even smaller businesses should check applicable thresholds, as many categories now require registration regardless of size.
2. Lawful basis for processing
- Ensure personal data is collected and processed based on consent, contractual necessity, legal obligation, or legitimate interest, and that data subjects are informed clearly (via privacy notices).
3. Data subject rights
- Implement processes to handle rights requests such as access, correction, deletion, objection to processing, and data portability.
4. Data minimization and purpose limitation
- Collect only data necessary for a specified purpose and avoid repurposing without fresh consent.
5. Security safeguards
- Apply technical and organizational measures (encryption, access controls, staff training) to protect data from breaches, loss, or unauthorized access.
6. Data breach notification
- Establish protocols to notify the ODPC and affected data subjects within 72 hours of a breach, where feasible.
7. Third-party and cross-border transfers
- Vet vendors/processors handling data on your behalf via data processing agreements, and ensure adequate safeguards for any data transferred outside Kenya.
8. Data Protection Impact Assessments (DPIAs)
- Conduct DPIAs for high-risk processing activities, such as large-scale profiling or sensitive data handling.
9. Appointing a Data Protection Officer (DPO)
Required for public bodies and businesses engaged in high-risk or large-scale processing; smaller businesses may still benefit from designating a compliance lead.
