Module IX: Data Protection in Practice
Module Overview
Module IX translates the legal architecture studied in earlier modules into applied, operational
frameworks for data controllers, processors, legal practitioners, and governance professionals.
The module is grounded in the Data Protection Act, Cap 411C (DPA) and its 2021 subsidiary
regulations, supplemented by current Office of the Data Protection Commissioner (ODPC)
enforcement data, and sector-specific guidelines issued by the ODPC.
Participants will leave with an understanding of how to build and sustain a compliant data
protection programme within a Kenyan organisational context, how to respond to data subject
requests and breaches, how to manage third-party risk, and how enforcement trends should
shape legal advisory and compliance strategy.
Learning Objectives
By the end of this module, participants will be able to:
[Link] and maintain a data inventory and Records of Processing Activities (RoPA) in
compliance with the DPA and the Regulations under the DPA.
[Link], implement and review the full organisational documentation suite: data protection
policies, privacy notices, processor contracts, data sharing agreements, and consent
records.
[Link] on the appointment, governance, and independence of a Data Protection Officer
(DPO) and identify common pitfalls in DPO practice.
[Link] the ODPC registration framework, including registration tiers, renewal
obligations, and common errors in registration submissions.
[Link] data subject rights requests end-to-end, from receipt and identity verification
through to documented response within the prescribed statutory timelines.
Page 1 of 17
[Link] and execute a breach notification workflow compliant with the 72-hour ODPC
notification requirement.
[Link] and negotiate data processor contracts and apply a tiered vendor risk
management framework.
[Link] a continuous compliance programme including an annual compliance calendar,
internal audit cycle, and DPIA refresh schedule.
[Link] ODPC enforcement decisions and extract compliance lessons, with reference to
2025 regulatory shifts identified in DPGSK's determinations analysis.
[Link] the ODPC’s sector-specific guidelines and understand their enforcement weight.
[Link] on the intersection of the DPA with other laws, including the Constitution of Kenya
2010, the Computer Misuse and Cybercrimes Act, the Employment Act, banking and health
legislation and identify dual-regulatory obligations.
[Link] and address the principal institutional, organisational, and capacity challenges
facing data protection compliance in the Kenyan context.
COURSE STRUCTURE
Topic 1: Data mapping, data inventory and records of processing activities
1.1. Why Data Mapping is the Foundation of Compliance
Data controllers cannot protect what they do not know they hold; mapping enables every
downstream compliance activity.
Retention schedules, DPIA triggers, and ODPC registration depend on an accurate, current
data inventory.
The data protection policy (mandatory) shall describe 'the nature of personal data collected
and held’ only achievable after mapping.
ODPC registration requires a description of categories of personal data being processed
and the purposes thereof.
Page 2 of 17
1.2. Building a Data Inventory and Records of Processing Activities (RoPA)
Mandatory RoPA elements:
Name and contact details of the data controller and/or processor.
Purpose(s) of processing one legal basis at a time, established before processing
commences.
Categories of data subjects and personal data types, including sensitive categories.
Recipients or categories of recipients, including cross-border transfer destinations.
Retention periods and the approved retention schedule.
Description of information flows: collection, storage, use, transfer, and deletion.
Four-step data mapping methodology:
[Link] identification: systems, processes, and departments.
[Link] flow interviews: what data is collected, from whom, why, and where it goes.
[Link]: personal data, sensitive personal data, children's data.
[Link] flagging: identification of DPIA triggers.
Topic 2: Data protection policies, privacy notices and organisational
documentation
2.1. The Data Protection Policy
Mandatory policy content under the DPA:
The nature of personal data collected and held.
How data subjects may access their data and exercise their rights.
Complaints handling mechanisms.
Lawful purposes for processing personal data.
Obligations where personal data is transferred outside Kenya.
Data retention period and schedule.
Provisions on collection of children's data and the applicable criteria.
Best practice: Policies should be version-controlled, dated, reviewed annually, and easily
accessible to data subjects.
Page 3 of 17
2.2 Privacy Notices: Transparency Obligations
Prior to consent-based processing: inform data subject of identity, purpose, data type,
third-party sharing, transfer risks, and right to withdraw.
Elements of compliant transparency: clear and plain language; easily accessible; machine-
readable; tailored for vulnerable groups and children.
Where data is collected indirectly: notify the data subject within 14 days.
2.3 The Essential Organisational Documentation Suite
Data controller–processor contract: mandatory written contract for every processor
engagement.
Data retention schedule: linked to the RoPA and reviewed periodically.
Data sharing agreements: required before routine data sharing between organisations.
Consent records and withdrawal logs.
Incident response plan and breach register.
Topic 3: Appointment and governance of the data protection officer
3.1 Legal Basis and Mandatory Appointment Contexts
Large-scale processing of personal data, including sensitive personal data.
Public authorities or bodies (other than courts acting in a judicial capacity).
Regular and systematic monitoring of data subjects on a large scale.
3.2 Core DPO Responsibilities
Advising on compliance with the DPA 2019 and subsidiary regulations.
Monitoring internal compliance: policies, training, and audits.
Serving as the primary contact point for the ODPC and for data subjects.
Advising on and monitoring Data Protection Impact Assessments (DPIAs).
Independence principle: the DPO should not receive instructions regarding the exercise of
their tasks from any person within the organisation.
Page 4 of 17
3.2 Core DPO Responsibilities
Written appointment instrument defining role, scope, reporting line, and resources.
Access to senior management and the board: the DPO shall be able to escalate to the
highest level.
No conflict of interest: the DPO cannot simultaneously hold a role that determines the
purposes or means of processing.
Contact details of the DPO shall be published and communicated to the ODPC.
Shared DPO arrangements are permissible for groups of undertakings.
3.4 Practical Compliance Challenges in Kenya
Acute capacity gap: many organisations lack qualified DPOs.
Outsourced DPO arrangements are permissible but require clear written terms of
engagement.
Liability point: the data controller or processor remains legally liable; the DPO is an advisor,
not a guarantor.
Common failure: DPOs appointed as a formality with no authority, no resources, and no
board reporting line.
Topic 4: ODPC registration: legal framework and organisational approaches
4.1 Statutory Basis and Who Shall Register
DPA: mandatory registration; no processing lawful without registration if required.
ODPC issues a Certificate of Registration valid for two years (renewable).
Applicable to all data controllers and processors in Kenya.
Foreign entities targeting Kenyan data subjects are subject to registration.
Sectors where registration is always required: health, financial services, government.
Page 5 of 17
4.2 Registration Tiers
Tier 1: Individual / Sole Proprietors.
Tier 2: SMEs and Non-Profit Organisations.
Tier 3: Large organisations and listed entities.
Tier 4: Critical infrastructure and government agencies.
Each tier carries different fees, obligations, and renewal cycles.
4.3 How Organisations Have Approached Registration
Proactive approach: large corporates, banks, telcos, and multinationals, self-assessed
obligations, appointed DPOs, mapped processing activities, and registered ahead of
enforcement.
Reactive approach: mid-tier firms registered only after receiving ODPC compliance notices
or following peer pressure; minimal internal preparation; checkbox compliance.
Non-compliant approach: many SMEs, NGOs, and informal sector entities remain
unregistered citing resource constraints, lack of awareness, or misunderstanding of
applicable thresholds.
4.4 Common Errors in Registration Practice
Incorrect classification of organisational role as controller versus processor.
Under-declaration of processing purposes.
Appointing DPOs without technical or legal capacity.
Certificates lapsing without renewal.
Topic 5: Handling requests by data subjects
5.1 The Data Subject Rights Framework
Right of Access: confirm processing and obtain a copy of personal data.
Right to Rectification: correct inaccurate or incomplete data without undue delay.
Right to Erasure: the 'right to be forgotten'; applies where no lawful basis for continued
processing.
Page 6 of 17
Right to Object: object to processing; absolute right to halt direct marketing processing
immediately.
Right to Data Portability: receive data in structured, machine-readable format; right to
transfer to another controller.
Right Not to Be Subject to Automated Decisions: challenge significant decisions made
solely by automated means.
5.2 Recommended DSR Handling Workflow
Five-stage workflow: (1) Receive request → (2) Verify identity → (3) Assess request → (4)
Respond → (5) Record and archive.
5.3 Statutory Response Timelines (Summary Table)
Right / Request Type Timeline Key Notes
Access to Personal Data 7 days Free of charge; copy or access provided
Rectification of Data 14 days Refusal: notify within 7 days with reasons
Applies where data no longer necessary, consent
Erasure (Right to be Forgotten) 14 days
withdrawn, etc.
Restriction of Processing 14 days Implement or notify refusal with reasons
Objection to Processing 14 days Absolute right for direct marketing
Data Portability 30 days May attract a reasonable fee
Notification of Refusal 7 days of refusal Written reasons required
Indirect Collection Notification 14 days Inform data subject when data collected indirectly
Direct Marketing Restriction (3rd
7 days Controller should stop sharing for marketing
Party)
Complaint Response (ODPC) 21 days Respondent shall file written response
Page 7 of 17
5.4 Practical Challenges in DSR Management
Identity verification: risk of disclosing data to imposters; absence of standardised
verification procedures.
Manifestly unfounded requests: difficult to invoke the exception without appearing
evasive.
Erasure versus retention conflicts: legal hold obligations (tax, AML) conflict with erasure
requests; no clear ODPC guidance.
Backlogs and resourcing: the timelines are challenging to meet with complex requests and
understaffed teams.
Data mapping deficits: inability to locate all data held on a data subject due to fragmented
systems.
Portability format disputes: 'machine-readable' standard unclear; interoperability issues
across sectors.
Topic 6: Managing data breaches
6.1 The Breach Notification Framework
Statutory workflow: Breach occurs → Detect and assess → Notify ODPC (within 72 hours) →
Notify data subjects (without undue delay) → Document and remediate (ongoing).
6.2 ODPC Notification Requirements
The notification to the ODPC should include:
Date and circumstances of first becoming aware of the breach.
Chronological account of steps taken after awareness, including an assessment of
notifiability.
Categories and approximate number of data subjects affected.
Categories and approximate volumes of personal data records involved.
Description of likely consequences of the breach.
Description of measures taken or proposed to address the breach and mitigate adverse
effects.
Page 8 of 17
6.3 High-Risk Data Categories in Breach Triage
Categories requiring heightened breach response: authentication and security credentials;
health and medical data; biometric data; children's and vulnerable persons' data; financial and
banking information; highly sensitive personal circumstances (e.g., domestic abuse, mental
health).
6.4 Breach Management Pitfalls
No internal Incident Response Plan (IRP) in most SMEs.
Delayed detection: breaches discovered weeks or months after occurrence.
Conflating IT security incidents with personal data breaches.
Failure to notify because the breach is perceived as 'minor'.
No breach register maintained.
Notifying data subjects before risk assessment is complete; causes disproportionate alarm.
Topic 7: Third party processing and vendor risk management
7.1 The Mandatory Processor Contract
Every processor engagement shall be governed by a written contract. Mandatory particulars:
Subject matter, duration, nature and purpose of processing.
Type of personal data and categories of data subjects.
Obligations and rights of the data controller.
Data processing instructions: the processor should act only on documented controller
instructions.
Confidentiality obligation binding all persons authorised to process.
Appropriate technical and organisational security measures.
Data deletion or return on termination: as directed by the controller.
Audit and inspection rights exercisable by the controller.
Sub-processor engagement requires prior controller authorisation; the processor remains
liable for sub-processor compliance.
Page 9 of 17
7.2 Tiered Vendor Risk Management Framework
Tier 1 (High Risk): Access to large volumes of sensitive or personal data; comprehensive
due diligence and annual audit rights required.
Tier 2 (Medium Risk): Incidental or limited data access; standard contractual safeguards
required.
Tier 3 (Low Risk): Anonymised data or no personal data access; basic contractual
acknowledgement required.
7.3 Cross-Border Vendor Considerations
Confirm lawful transfer basis before onboarding a foreign processor: adequacy decision,
appropriate safeguards (BCRs, contractual clauses), necessity, or consent.
Document all transfers: date, recipient name, justification, and data description.
Subsequent transfers restricted: the recipient cannot further transfer data without prior
authorisation.
Preferred long-term safeguard: Ratification of the AU Malabo Convention or bilateral data
protection agreements.
Topic 8: Monitoring, audits and continuous compliance
8.1 ODPC Audit Powers
The ODPC may conduct periodic audits of data controllers and processors.
Audits may be triggered by complaint, risk-based selection, sector review, or post-breach
inspection.
The ODPC may audit compliance with DPIA assessment reports and any recommendations
issued.
8.2 Internal Data Retention Audit Obligations
Periodic retention audits should:
Identify data no longer requiring retention and permanently delete it.
Verify accuracy and currency of retained data.
Confirm that the purpose for continued retention remains valid.
Assess the adequacy of current security measures.
Determine the appropriate course of action where a retention period has lapsed.
Page 10 of 17
8.3 Sample Annual Compliance Calendar
Q1: Annual data mapping review and RoPA update; renewal of registration (if due in the
period).
Q2: Data protection policy and privacy notice review and update; staff data protection
training refresh.
Q3: Internal audit of processor contracts and identification of gaps; DPIA review; reassess
existing DPIAs for changed risk profiles.
Q4: Data breach and incident response simulation exercise; retention schedule audit and
data purge; board/senior management data protection report.
8.4 Continuous Compliance Programme Pillars
A sustainable compliance programme rests on six pillars:
[Link] training,
[Link] reviews,
[Link] updates,
[Link] reassessment,
[Link] refresh cycles, and
[Link] simulation drills.
Topic 9: Lessons from ODPC decisions and enforcement actions
Source: DPGSK Analysis of 2025 ODPC Determinations.
9.1 The Complaints Pipeline: From Lodging to Determination
Lodging: Any aggrieved person may lodge a complaint orally, electronically, or by other
means. Free of charge; anonymous complaints are permissible.
Admission: ODPC undertakes preliminary review; may admit, refer to another body, or
decline.
Notification to Respondent: 21 days to respond, provide evidence, or propose resolution.
Investigation: ODPC may issue summons, examine persons, require documents, enter
premises (on court warrant).
Page 11 of 17
Determination: Written decision stating the nature of the complaint, facts found, decision,
reasons, and remedies.
Available remedies: enforcement notice, penalty notice, dismissal, prosecution
recommendation, compensation order. ADR (negotiation, mediation, conciliation) is available,
agreements are binding and enforceable as ODPC determinations.
9.2 ODPC Enforcement Powers and Tools
Enforcement Notice: direct compliance within a specified period; failure constitutes a
criminal offence.
Penalty Notice: administrative fines up to KES 5 million or 1% of annual turnover
(whichever is lower).
Assessment Notice: compel submission to an audit of data processing operations.
Information Notice: require provision of specified information within a set time.
Stop Processing Order: temporary or permanent halt on processing activities causing harm.
Criminal Prosecution: offences for obstruction, unlawful processing, and unauthorised
disclosure.
9.3 2025 ODPC Determinations: Key Statistics (DPGSK Analysis)
96 cases determined in 2025.
83% resulted in an award for damages.
Average compensation award: KES 324,000.
Highest single award: KES 1.5 million.
Top complaint categories: Data Subject Rights Violations (61 cases); Consent Failures (53
cases); Unlawful Processing (21 cases).
Top sectors: Finance/Credit (40% of cases, 34 awards); Digital Media/Marketing (6 awards,
fines up to KES 1.5M).
Page 12 of 17
9.4 Seven Key Regulatory Shifts from 2025 Enforcement
Key Regulatory Shift Summary and Leading Cases
No implied/oral consent; burden of proof on controller. (Jagermeister
Express Consent Required
SE; Platinum Credit)
Fresh consent required for any material change in processing.
Consent is Dynamic
(Bohemian Flowers Ltd)
Absolute Right to Object to Direct Controller shall cease immediately upon objection. KES 900K penalty.
Marketing (Philip Bolo v Platinum Credit)
Data controllers liable for agents/processors. DPAs and active
Controller Liable for Agent Actions
oversight mandatory. (Samuel Waweru; Philip Bolo)
Cross-Border Regulatory First formal EA cooperation: ODPC engaged Uganda's PDPO. (Aaditi
Cooperation Rajput v DTB Kenya and DTB Uganda)
Prosecution of Directors for ODPC recommended criminal prosecution under s.72 DPA for
Obstruction obstruction. (Zuku Fibre; RocketPesa; Sportspesa)
Compensation Directly to Monetary orders now paid to complainants, not state. High Court
Complainants adoption required for execution.
⚠ Practitioner Note: To enforce an ODPC award, complainants shall apply to the High Court to adopt
the determination as a court order.
Page 13 of 17
Topic 10: ODPC sector-specific guidelines
Source: ODPC, [Link]/guidelines-2/
Guideline / Document Details
Provides minimum data protection standards for government institutions
Guidance Notes for Public
processing personal data. It emphasizes lawful, transparent processing and
Sector
accountability in handling citizen data within public service delivery.
Tailors data protection obligations for micro, small, and medium enterprises. It
Guidance Notes on
simplifies compliance requirements while ensuring adherence to core principles
Processing by MSMEs
such as lawful processing and security.
Clarifies how data protection law applies to journalism and media activities. It
Guidance Notes for
balances the right to privacy with freedom of expression and public interest
Journalistic Purpose
reporting.
Guidance Notes – Provides rules for processing personal data in research contexts. It emphasizes
Processing for Research safeguards such as anonymisation and ethical handling of data while supporting
Purpose innovation and knowledge creation.
Governs the use of personal data in elections, including voter data and political
Guidance Note for Electoral
campaigning. It ensures that electoral actors process data lawfully and respect
Purposes
voter privacy rights.
Guidance Note on
Explains who must register with the ODPC and outlines applicable thresholds and
Registration of Data
categories. It also sets out obligations tied to registration, including maintaining
Controllers and Data
accurate records and compliance.
Processors
Guidance Note on Data Provides a structured approach for identifying and mitigating risks in high-risk data
Protection Impact processing activities. It requires organizations to assess impacts on data subjects
Assessment (DPIA) before implementing systems or projects.
Sets out how valid consent should be obtained, recorded, and withdrawn. It
Guidance Note on Consent emphasizes that consent must be informed, specific, freely given, and
demonstrable.
Alternative Dispute Provides mechanisms for resolving data protection disputes outside formal
Resolution (ADR) litigation. It promotes efficient, cost-effective resolution while safeguarding data
Framework / Guidelines subject rights.
Guidance Notes for Addresses how personal data may be processed in audio-visual and recorded media
Processing on Publications publications. It ensures compliance while accommodating media production and
of Recorded Media dissemination practices.
Provides enhanced safeguards for processing children’s personal data. It requires
Guidance Notes for
parental consent, limits profiling, and emphasizes protection due to children’s
Processing Children’s Data
vulnerability.
Page 14 of 17
Regulates the processing of biometric data such as fingerprints and facial
Guidance Notes on
recognition data. It requires heightened safeguards due to the sensitive and
Biometric Data
immutable nature of such data.
Guidance Notes on
Allows processing of personal data for research, statistics, or historical use under
Historical and Statistical
strict safeguards. It promotes anonymisation and limits re-identification risks.
Purposes
Sets out procedures for lodging, handling, and resolving complaints before the
ODPC Complaints
ODPC. It ensures transparency, fairness, and consistency in enforcement
Management Manual
processes.
Guidance Note for Digital Provides sector-specific rules for digital lenders handling personal and financial
Credit Providers data. It addresses risks such as over-collection, profiling, and unlawful data sharing.
Establishes strict requirements for handling sensitive health data. It emphasizes
Guidance Note on the
confidentiality, security, and compliance with both data protection and health
Processing of Health Data
sector standards.
Provides guidance on processing student and staff data within educational
Guidance Note for the
institutions. It highlights protection of minors and responsible handling of academic
Education Sector
records.
Guidance Note for the Addresses telecom and digital communication service providers. It focuses on
Communication Sector lawful processing, data security, and protection of subscriber information.
Sets out requirements for sharing personal data between entities. It ensures that
Data Sharing Code data sharing is lawful, secure, and subject to appropriate safeguards and
agreements.
Topic 11: Impact of the DPA on other laws and professional obligations
11.1 Key Legal Intersections
Constitution of Kenya 2010 (Art. 31): The constitutional right to privacy is the root of the
DPA. Where the DPA falls short, the constitutional right may be invoked directly.
Evidence Act (Cap. 80): Personal data obtained unlawfully may be excluded as evidence;
digital evidence collection shall comply with DPA lawful basis requirements.
Computer Misuse and Cybercrimes Act 2018: Overlapping offences: CMCA addresses
criminal liability, DPA addresses regulatory compliance. Practitioners shall navigate both
regimes simultaneously.
Page 15 of 17
Employment Act: Employee monitoring (CCTV, email surveillance, biometrics) is now
regulated; employers shall disclose, justify, and limit monitoring. Biometric attendance
systems require a DPIA.
Banking Act and CBK Prudential Guidelines: Credit reference reporting shall comply with
DPA accuracy and consent requirements. Cross-border transfers to parent companies
require an adequacy assessment.
Health Laws (Health Act, Mental Health Act): Patient health data is a sensitive category
requiring explicit consent. Ethics board approval does not replace DPA compliance.
Telemedicine platforms shall comply fully.
11.2 Sector-Specific Professional Obligations
Advocates and Legal Practitioners:
Client files constitute personal data: obligations on retention, security, and access.
Disclosure to third parties requires a lawful basis beyond mere client request.
LSK members are functionally data controllers for all client personal data.
Healthcare Practitioners:
Patients hold data subject rights over their health records.
Sharing with insurers, researchers, or employers requires specific consent.
Mandatory disease reporting versus DPA obligations: public interest lawful basis applies.
Financial Sector Practitioners:
AML/KYC data collection is dual regulated under CBK and DPA.
Automated lending decisions trigger the right not to be subject to automated decisions.
Fraud investigations: legitimate interests test applies.
HR and Employment Practitioners:
Pre-employment screening: proportionality of data collected is scrutinised.
Performance management records are subject to employee access rights.
Whistleblowing channels: anonymisation obligations apply.
Page 16 of 17
Topic 12: Data protection challenges in practice
12.1 Institutional Challenges
Absence of an accredited DPO certification programme.
Limited inter-agency coordination among the CAK, CBK, NHIF, and other regulators.
12.2 Organisational Challenges
Data mapping and inventory absent in most organisations.
Legacy systems not designed with privacy by design.
DPOs lacking seniority, budget, or direct board access.
Vendor and third-party management gaps: processor agreements lacking or inadequate.
Cross-border data transfer controls not implemented.
12.3 Legal and Interpretive Challenges
Ambiguity in 'consent' where services are not truly voluntary.
The legitimate interests balancing test: no ODPC guidance published.
Conflict between DPA erasure rights and statutory retention obligations.
Children's data: 'guardian consent' mechanism remains unclear.
Definition of 'sensitive data' relative to sector-specific data categories.
12.4 Awareness and Capacity Challenges
Low public awareness of data rights among Kenyan citizens.
Legal practitioners not trained in data protection advisory work.
DPOs hired without requisite legal and technical skills.
SME sector largely unaware of registration and compliance obligations.
Academic curriculum lags behind legislative and regulatory developments.
Page 17 of 17