Keega & Company Advocates
services/data protection & compliance

data protection and compliance in kenya — turn the odpc from a risk into your competitive advantage

The ODPC has issued over 1,000 penalties, a significant jump from the roughly 100 issued in the previous two years. Enforcement is active, expanding, and sector-agnostic. We handle registration, DPIAs, policy drafting, outsourced DPO services, and breach response.

Keega & Company Advocates
team members
Hero Magic Pattern Dot

Data Protection is a Business Imperative

Share
facebook
whatsapp
linkedin
instagram

Last updated: 1 June 2025

Kenya’s Office of the Data Protection Commissioner is no longer a theoretical compliance risk. The ODPC is issuing enforcement notices, conducting audits, and awarding compensation to data subjects whose rights have been violated. In cases involving Oppo, Regus, and Whitepath, the Commissioner ordered penalties the maximum KES 5,000,000 for various data protection violations. The message was clear: treating data protection as optional paperwork is no longer an option. The ODPC has since issued over 1,000 penalties of varying amounts for non-compliance, and is actively considering raising the ceiling on fines further. For your business, this is both a legal obligation and a strategic opportunity. Companies that get data protection right do not just avoid fines. They build the kind of trust with clients, partners, and employees that becomes a genuine commercial differentiator, particularly in sectors where data is the product. At Keega and Company Advocates, we understand the law deeply and practically, and we know how to make compliance achievable rather than theoretical.

ODPC Registration and Ongoing Compliance

Every organisation that processes personal data in Kenya is required to register with the Office of the Data Protection Commissioner as a data controller, a data processor, or both. Failure to register can result in fines of up to KES 5 million or 1% of annual turnover, whichever is higher.

We handle the entire registration process. That means determining whether your organisation qualifies as a data controller, data processor, or both, preparing and submitting your ODPC registration application, drafting or reviewing your data processing records, and advising on your ongoing obligations including breach notification timelines. For international organisations operating in Kenya, we also advise on cross-border data transfer requirements and the adequacy framework under the Data Protection Act 2019.

Registration is the starting point, not the finish line. We stay with you through the compliance cycle.

Data Protection Impact Assessments

Before undertaking high-risk data processing activities, organisations are required to conduct a Data Protection Impact Assessment and, in certain cases, notify the ODPC before proceeding. High-risk activities include processing sensitive personal data at scale, introducing surveillance or monitoring systems, and implementing automated decision-making processes that affect individuals.

We conduct comprehensive DPIAs across all sectors, with particular depth in healthcare, fintech, edtech, and digital platforms. Our assessments identify actual risks rather than theoretical ones, and every recommendation we make is practical and implementable within your existing operations, not a compliance checklist that sits in a drawer.

Data Protection Officer Services

Not every organisation is required to appoint a Data Protection Officer, but those that are must designate someone with genuine expertise, independence, and the legal knowledge to do the role properly. Most organisations do not have that capacity sitting internally, and appointing the wrong person creates more risk than it resolves.

We offer outsourced DPO services on a retained basis, acting as your organisation’s DPO with the independence, expertise, and regulatory standing the law requires. Your outsourced DPO will maintain your compliance calendar, advise your team on day-to-day data protection queries, liaise with the ODPC on your behalf, and manage breach notification procedures when they arise.

Policy Drafting and Staff Training

Data protection compliance is not just about legal documents. It is about operational culture. A privacy policy that nobody reads, or a data retention policy that nobody follows, offers no real protection when the ODPC comes knocking.

We draft privacy policies that are legally compliant and written to be understood, data processing agreements for vendor relationships, incident management policies, data retention and deletion policies, and access control procedures. We also design and deliver staff training programmes tailored to your sector and your team’s level of technical knowledge. Our training is built for genuine understanding, not box-ticking, because the weakest point in most data protection frameworks is not the policy document. It is the person who never read it.

Data Breach Response

When a personal data breach occurs, you have 72 hours to notify the ODPC if the breach poses a risk to data subjects’ rights and freedoms. How you respond in those 72 hours will shape both your legal liability and your reputational outcome.

We provide rapid-response data breach support from the moment you discover an incident. That means breach assessment and risk classification, notification drafting for the ODPC and affected data subjects, coordination with your technical team on containment and remediation, representation before the ODPC in any subsequent investigation, and post-breach legal analysis to close the gaps that allowed the breach to happen in the first place.

Seventy-two hours moves fast. We help you use them well.

Our Integrated Data Protection Services

We offer end-to-end solutions tailored to your specific industry and risk profile.

Data Handler Registration
We will handle your full ODPC registration process, ensuring accurate classification, documentation, and submission. We make compliance seamless and secure your official registration certificate.
Virtual Data Protection Officer (vDPO) Service
Our Virtual Data Protection Officer (vDPO) service offers ongoing expert oversight of your compliance program. We manage data subject requests, handle data breaches, and serve as your direct liaison with the ODPC.
Data Protection Training
We offer tailored training and practical internal policies that equip your team to confidently manage data and respond to incidents, making them your first line of defence.
Data Protection Impact Assessments (DPIAs)
We perform mandatory DPIAs to identify and address privacy risks early, preventing costly redesigns and ensuring regulatory compliance.
Vendor & Contract Management
We assess your third-party vendors and craft strong Data Processing and Information Sharing Agreements that clearly outline roles, responsibilities, and liabilities.
Breach Response & Litigation Support
Our 24/7 breach response service ensures timely ODPC notifications within 72 hours, manages all communications, and protects you from potential regulatory actions or claims.

Our Process

legal guidance in 3 simple steps

We simplify the process so you can focus on what matters most

01

Get in Touch
Reach out for a free, no-obligation consultation. We’ll listen to your story and understand your needs.

02

Get Your Strategy
Our attorneys will craft a clear, personalized legal plan so you know exactly what to expect.

03

Case Resolved
We handle the hard work, while you get peace of mind and the outcome you deserve.

Customer testimonials

Hear our Clients' Stories

Reliable Legal Partner for Startups
"Keega was the strategic partner we did not know we needed. They handled the entire legal stack, incorporation, trademark, and regulatory compliance, all with a founder's mindset. They freed us up to focus on product and growth. More than just counsel, they were the catalyst that got us from idea to investor-ready."
Davis Thoyah Ngoa  | CEO, Swypt
Streamlined Data Protection Compliance
"What seemed like a daunting regulatory hurdle became a streamlined process. Their approach to our data protection training and policies gave us a robust, audit-ready framework in no time. A truly invaluable partner for any healthcare provider."
Dr. Nancy Nyaga  | CEO, Blossom Out Consultants
Strategic Legal Partner
"They do not just draft and review our contracts. They protect our business model. The firm's work on our MSAs and licensing agreements is strategic. They spot risks we miss and strengthen our commercial position. They have directly contributed to us closing better, more profitable deals."
Lewis Kori  | Co-Founder, inflection studio

Frequently asked questions

Our team is here to answer any questions you might have!

If your business collects, stores, uses, or shares any personal data, including names, email addresses, phone numbers, financial data, health information, or any other information that can identify an individual, you are almost certainly required to register with the ODPC as a data controller, a data processor, or both. The threshold is low and the scope is broad. Non-registration is itself a compliance breach, not just a technicality. We can determine your registration obligations quickly in an initial consultation.

Related Services

Data protection compliance does not have to be overwhelming.

With the right legal partner it becomes a structured, manageable process and, done well, a genuine source of competitive strength. Talk to our data protection team today. Call us on +254 713 451 503, or book a consultation online. All enquiries are handled in strict confidence.