Data Protection Advocates in Nairobi, Kenya

Data protection law in Kenya is governed by the Data Protection Act, 2019, which safeguards personal privacy rights, regulates how public and private organisations collect and process personal data, and establishes the Office of the Data Protection Commissioner (ODPC) for enforcement. The Act gives effect to the constitutional right to privacy under Article 31 of the Constitution of Kenya. At Ondieki & Matoke Company Advocates, we help businesses register, comply, and respond correctly when something goes wrong and we help individuals understand and exercise their rights over their own data.

Data Protection Law

Core Principles for Handling Data

  • Lawful & Transparent Processing — Data must be gathered fairly, with valid consent that is express, unequivocal, free, specific, and informed.
  • Purpose Limitation — Information may only be collected for specific, clearly stated purposes.
  • Data Minimisation — Only the data actually necessary for the stated purpose should be collected.
  • Accuracy & Storage Limits — Records must be accurate and kept no longer than necessary for their purpose.
  • Security Safeguards — Proper technical and organisational measures must protect data from unauthorised access or breaches.

Rights of Data Subjects

  • Right to Access — The right to know what personal data an organisation holds about you.
  • Right to Correction — The right to request correction of inaccurate or outdated personal details.
  • Right to Deletion — The right to request erasure of personal data once it’s no longer needed for its original purpose.
  • Right to Object — The right to stop specific uses of your personal data, such as direct marketing.

Key Concepts Worth Understanding

  • Personal Data — Any information relating to an identified or identifiable natural person — a broader category than most people expect, covering far more than just names and ID numbers.
  • Sensitive Personal Data — A category subject to heightened protection, including health status, ethnic origin, religious belief, genetic and biometric data, property details, marital status, and family details such as children’s or spouses’ names.
  • Data Controller vs Data Processor — A data controller determines the purpose and means of processing personal data; a data processor processes it on the controller’s behalf. This distinction matters, since obligations under the Act differ depending on which role your organisation plays.
  • Personal Data Breach — A security breach leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.
Data Protection Law services

Business & Organisational Duties

  • Mandatory Registration — Most data controllers and processors must register with the ODPC before processing personal data.
  • Data Breach Reporting — Serious security breaches must be reported to the ODPC promptly, and in many cases, to the affected individuals as well.
  • Cross-Border Transfer Limits — Transferring personal data outside Kenya requires proof of adequate safeguards in the receiving jurisdiction, or the data subject’s explicit consent.
  • Penalties — Non-compliance can result in administrative fines of up to KES 5 million or 1% of annual turnover, alongside potential criminal sanctions in serious cases.

Private client Law

What to Expect — Our Process

  • Initial consultation — you share what data your organisation handles and your compliance question or incident.
  • Assessment — we assess your registration status, data handling practices, and any immediate exposure.
  • Compliance build-out or breach response we develop the policies you need, or manage an active incident’s notification requirements.
  • ODPC engagement — where needed, we manage registration, notifications, or responses to ODPC inquiries.
  • Ongoing support — we remain available as your data practices and obligations evolve.

Call now for a Free Consultation