An employee’s laptop is stolen from a parked car. It holds a spreadsheet of client names, phone numbers and identity card copies. What happens next is governed by Kenya’s data breach notification rules, and the first hours matter. What counts as a personal data breach in Kenya? A breach is wider than a hack. It … Read more
Vendors, clients and regulators all ask whether your organisation is a data controller or a data processor. The answer shapes who must register, who answers complaints and how your contracts should be drafted, and the two roles are often confused. What is the difference between a controller and a processor? A data controller decides why … Read more
Fingerprints, facial images and voice recordings identify a person as nothing else can, and Kenyan law treats them accordingly. Biometric data falls within the sensitive category under the Data Protection Act 2019, and organisations that collect it, from schools running attendance systems to fintechs verifying customers, must meet a higher standard than for ordinary records. … Read more
If your organisation keeps a customer list, runs a payroll or sends a newsletter, Kenyan data protection law already applies to you. One of the first questions organisations ask is whether formal registration with the Office of the Data Protection Commissioner is required before personal data may lawfully be processed. Who must register with the … Read more
Your privacy, your choice. We use a few anonymous cookies to understand which pages help visitors most (e.g. counting views of a legal guide) and to remember your preferences. No advertising trackers, no third-party cookies, no personal profiles, in line with the Kenya Data Protection Act, 2019. Read our Cookie Policy and Privacy Notice.