Specialist Services
Data Protection & ODPC Compliance in Kenya
Practical compliance with Kenya's Data Protection Act 2019 — from ODPC registration to breach response.
The ODPC can issue enforcement notices and administrative fines for non-compliance. A compliance review now costs far less than responding to a complaint or breach investigation.
Do any of these situations sound familiar?
You collect customer, patient, student or employee data and are unsure whether your organisation must register with the ODPC.
You have suffered, or suspect, a personal data breach and need to decide quickly what must be reported and to whom.
Your contracts with vendors, cloud providers or group companies do not address how personal data is handled or transferred.
You're not alone. Our advocates deal with these exact situations every week. Speak to us today →
Our Data Protection & ODPC Compliance Practice
The Data Protection Act 2019 places clear obligations on organisations in Kenya that collect or use personal data — from banks, hospitals and schools to SMEs, NGOs and online businesses. The Office of the Data Protection Commissioner (ODPC) enforces these obligations, and non-compliance can lead to enforcement notices, administrative fines and reputational damage.
We help organisations understand which of their activities are covered, register with the ODPC as data controllers or data processors where required, and build a practical compliance framework: privacy notices, data processing agreements with vendors, lawful-basis and consent mechanisms, retention rules, data protection impact assessments for high-risk processing, and internal policies that staff can follow.
When something goes wrong, timing matters. We advise on personal data breach response — including notification to the ODPC and, where required, to affected data subjects — and represent organisations in complaints and investigations before the ODPC. We also advise on cross-border transfers of personal data and on data protection terms in commercial contracts.
How We Work With You
Initial Consultation
We listen, understand your matter, assess urgency and give you a clear view of your legal options.
Strategy & Planning
We build a defined legal strategy with milestones, timelines and a transparent cost estimate.
Expert Execution
Our senior advocates handle all filings, negotiations, documentation and court appearances.
Resolution & Follow-Up
We secure the outcome, ensure it's properly documented and follow up on implementation.
How We Can Help
ODPC Registration
Assessment of registration obligations and registration as a data controller or processor.
Compliance Audits & Gap Analysis
Review of current data practices against the Data Protection Act 2019 and its Regulations.
Privacy Notices & Policies
Privacy notices, internal data protection policies, consent and retention frameworks.
Data Processing Agreements
Contract terms with vendors, cloud providers and group companies, including cross-border transfers.
Data Protection Impact Assessments
DPIAs for high-risk processing such as sensitive data or systematic monitoring.
Breach Response & ODPC Proceedings
Breach notification, complaints and investigations before the ODPC.
Why Clients Choose WTT Lichuma Advocates LLP
EBS Presidential Honour — Senior Partner
Led by Mrs. Winfred Osimbo Lichuma, EBS — over three decades of experience and former Chairperson of the National Gender and Equality Commission.
International & Regional Reach
We undertake domestic, regional and international assignments — bringing world-class legal standards to every matter.
Dedicated Legal Team
Advocates of the High Court of Kenya assigned to your matter from instruction to conclusion.
Plain-Language Communication
We explain your legal position clearly at every stage. No jargon. Just clear, actionable guidance.
Frequently Asked Questions
Common questions our clients ask about data protection & odpc compliance in Kenya.
Data controllers and data processors must register with the ODPC unless they fall within the exemptions in the Data Protection (Registration of Data Controllers and Data Processors) Regulations 2021, which consider factors such as annual turnover, number of employees and the nature of the processing. Organisations in certain sectors listed in the Regulations — including health, education and financial services — must register regardless of size. We assess whether registration applies and handle the application.
Under the Data Protection Act 2019, a data controller must notify the ODPC of a breach that creates a real risk of harm to data subjects without delay, and within 72 hours of becoming aware of it. Affected data subjects must also be informed where there is a real risk of harm, and a data processor must notify the controller promptly. We help organisations prepare a breach response plan in advance.
A data protection impact assessment (DPIA) is required where processing is likely to result in a high risk to the rights and freedoms of data subjects — for example, large-scale processing of sensitive personal data or systematic monitoring. It identifies the risks and the measures that will address them, and in some cases must be submitted to the ODPC before processing begins.
Yes, but only where the conditions in the Data Protection Act 2019 are met — for example, where there is proof of appropriate safeguards for the protection of the data, or another lawful basis for the transfer applies. Organisations that use overseas cloud services or group companies should document the basis for each transfer.
Have a question not covered here? Ask one of our advocates →
Who We Serve
Related Practice Areas
Take the Next Step
Ready to Resolve Your Data Protection & ODPC Compliance Matter?
Speak with our advocates in Karen, Nairobi or Kakamega. Request a consultation and we will respond the same business day.
Tana House, Karen Shopping Centre, Karen, Along Lang'ata Road, 3rd Floor, Room 309 | Regulated Advocates | Commissioners for Oaths & Notaries Public
