Why this matters for your IT systems
Kenya’s Data Protection Act, 2019 governs how organisations collect, store, use and share personal data. It created the Office of the Data Protection Commissioner (ODPC), which registers data controllers and processors, handles complaints and can impose penalties. Most obligations in the Act are met — or missed — in your IT systems and processes.
This checklist is a practical starting point, not legal advice. Confirm your specific obligations with a qualified advisor and the ODPC’s current guidance.
1. Know your data and register
- Map what personal data you hold, where it lives (servers, cloud, laptops, phones, paper), who can access it and why.
- Check whether you must register with the ODPC as a data controller or processor under the registration regulations, and renew on time.
- Record the lawful basis for each processing activity — consent, contract, legal obligation or another basis permitted by the Act.
2. Build the principles into your systems
- Purpose limitation and minimisation: collect only what you need for a stated purpose.
- Accuracy: make it easy to correct records.
- Storage limitation: set retention periods and delete or anonymise data when they expire.
- Security: apply appropriate technical and organisational measures — access control, encryption, logging and backups.
3. Support data-subject rights
Individuals have rights to be informed, to access their data, to object to processing, and to have inaccurate data corrected or deleted. Your systems should let you find, export, correct and erase a person’s data within a reasonable time — which is only possible if your data is well organised.
4. Assess high-risk processing
Where processing is likely to result in high risk to individuals — for example large-scale processing of sensitive data or new technologies — carry out a Data Protection Impact Assessment (DPIA) before you start, and keep it on file.
5. Be ready for a breach
- The Act requires you to notify the Data Commissioner within 72 hours of becoming aware of a breach that poses a real risk of harm, and to inform affected people where appropriate.
- Have an incident-response plan, named responsibilities and pre-drafted notices.
- Keep logs that let you establish what happened, which data was affected and when.
6. Control cross-border transfers and third parties
- Personal data may only leave Kenya with appropriate safeguards; check where your cloud and SaaS providers store and back up data.
- Put data-processing terms in contracts with every vendor that handles personal data on your behalf.
7. The technical controls that make compliance real
- Identity and access management with multi-factor authentication and least-privilege access.
- Encryption of data at rest and in transit; managed, encrypted devices.
- Centralised logging and monitoring, with alerts for suspicious activity.
- Tested backups and disaster recovery.
- Regular security audits and vulnerability assessments aligned to ISO/IEC 27001.
Getting help
Technology Abreast carries out independent security and risk audits, designs privacy-by-design controls and provides ISO 27001-based security management — helping you close the gap between what the law requires and what your systems actually do.

