Skip to content
  • Open now replies within the hour
Book a consultationBook a call
Book a free 30-min discovery call

Nairobi EAT · Mon–Fri 08:00–18:00

Navigating the Kenya Data Protection Act

What the Data Protection Act, 2019 means for analytics and AI projects, and the practical steps to stay compliant.

SIGMA BROOKS Team 2 min read

Data and AI projects in Kenya run on personal data: customer records, transactions, health information, survey responses. The Data Protection Act, 2019 sets the rules for collecting and using that data, and the Office of the Data Protection Commissioner (ODPC) enforces them.

This article is a practical overview for project teams. It is not legal advice; for decisions about your organisation, speak to your data protection officer or legal adviser.

Know your role

The Act distinguishes data controllers, who decide why and how personal data is used, from data processors, who handle data on a controller's behalf. Many organisations are controllers for their own customers and processors for partners. Registration with the ODPC is required for many controllers and processors, so check whether it applies to you.

Have a lawful basis for every use

Consent is one basis, but not the only one. Others include performing a contract, meeting a legal obligation and legitimate interests. Document which basis applies to each use of personal data in your project, especially when data collected for one purpose is reused for analytics.

Collect less, keep it shorter

Two principles save a lot of trouble in analytics projects:

  • Data minimisation: only use the fields you actually need.
  • Retention limits: delete or anonymise data when you no longer need it.

Pseudonymising data before it reaches analysts and models is often the simplest way to reduce risk.

Assess high-risk processing first

Processing that is likely to result in high risk to people, such as large-scale profiling or automated decisions about credit, generally calls for a data protection impact assessment before you start. Treat it as a design tool rather than paperwork; it surfaces issues while they are still cheap to fix.

Respect people's rights

People can ask what you hold about them, ask for corrections, object to some processing and ask for their data to be deleted. Systems should make these requests straightforward to answer.

Plan for incidents

If personal data is breached, the Commissioner must be notified within the timelines the Act sets, which are short. Know in advance who decides, who notifies and how you will contact affected people.

How we build it in

Every SIGMA BROOKS engagement includes a data protection checklist at the scoping stage, pseudonymisation by default in analytics environments and documentation your compliance team can review. Getting this right early is what lets projects move quickly later.

Turn your data into your next advantage.

Book a free 30-minute consultation and let’s explore how data, AI and automation can create real value for your organisation.

  • Strategic discussion
  • Practical recommendations
  • No obligation

30minute
consultation
Free

Book a free consultation
Book a call WhatsApp