Data Protection Act Compliance for Kenyan Businesses: A Founder's Checklist
The Kenya Data Protection Act isn't just a developer concern — it's a business risk with real penalties attached. Here's what a founder or business owner, not a software engineer, actually needs to know and do to reduce exposure.

Table of ContentsExpand
Kenyan businesses that collect personal data — customer names, phone numbers, ID numbers, payment details — are data controllers or processors under the Data Protection Act (2019) and are expected to register with the Office of the Data Protection Commissioner, have a lawful basis for collecting data, tell people what you do with their data, secure it appropriately, and be able to respond if someone asks what data you hold on them. The starting checklist: register with the ODPC, write down what personal data you actually collect and why, review your third-party tools (payment processors, marketing platforms, chat tools) for how they handle that data, and have a plan for what you'd do if there were a breach.
- 01.If your business collects customer names, phone numbers, ID numbers, or payment information, the Data Protection Act likely applies to you — registration with the ODPC is a real, checkable requirement.
- 02.Non-compliance carries real penalties, not just reputational risk — know your exposure before a customer complaint or audit forces the question.
- 03.Most businesses don't need a full-time compliance officer to get the basics right: a data inventory, a written privacy notice, and a breach-response plan cover the core ground.
- 04.Third-party tools (WhatsApp Business, payment gateways, email marketing platforms) are part of your compliance surface — you're responsible for how they handle data on your behalf.
- 05.This is the founder-facing version of the conversation — for the engineering-level implementation checklist, see the companion technical post.
What the Act Actually Requires
Strip away the legal language and the Kenya Data Protection Act (2019) asks for a handful of concrete things from any business collecting personal data:
- Register with the Office of the Data Protection Commissioner (ODPC) if you're a data controller or processor above the exemption thresholds.
- Have a lawful basis for collecting data — consent, contract necessity, or legal obligation, not just "we've always done it this way."
- Tell people what data you collect and why, in a privacy notice they can actually find and read.
- Secure the data appropriately for its sensitivity — this doesn't mean enterprise-grade infrastructure for a five-person business, it means proportionate, reasonable controls.
- Be able to respond if a customer asks what data you hold on them, or asks you to delete it.
Real Penalties, Real Risk
This isn't a paperwork exercise with no teeth. The ODPC has issued penalties for non-compliance, and the reputational cost of a data-handling failure — a leaked customer list, a payment breach — tends to be worse than the regulatory one for a small business that depends on trust to get repeat customers.
The Starting Checklist
- Register with the ODPC if you haven't already — this is a straightforward administrative step, not a technical one.
- Write down what personal data you actually collect. Most founders are surprised by the list once it's on paper: names, phone numbers, delivery addresses, ID numbers for verification, payment details, sometimes health or location data.
- Review your third-party tools. WhatsApp Business, your payment gateway, your email marketing platform, your booking system — each one is part of your compliance surface. You're responsible for how they handle data collected through your business.
- Write a plain-language privacy notice and make sure customers can actually find it.
- Have a breach-response plan, even a simple one: who gets notified, what gets checked first, how customers are informed if their data is affected.
When to Bring in Outside Help
The checklist above covers most small businesses' starting exposure without needing outside consulting. Bring in help when you're handling sensitive categories of data at real scale, integrating several systems that all touch customer data, or responding to an actual incident where getting the response right matters for both regulatory and customer-trust reasons.
The technical companion
This piece is deliberately non-technical. For the engineering-level implementation — how a development team translates these obligations into actual code-level controls — see Data Protection Act Compliance: A Developer's Checklist. For a structured review of where your business currently stands, see Data Protection services or reach out via Nazline Mwita's site.
Frequently Asked Questions
Bring This Resilience to Your Enterprise Stack
Harrison Ndeke and Nazline Mwita conduct a comprehensive 48-hour diagnostic audit of your n8n workflows, Next.js web application speed, and cybersecurity perimeter.