Call/ WhatsApp us: 0710942629 / 0736677646 Email: omaadvocates@gmail.com
Data Protection Advocates in Nairobi, Kenya
Data protection law in Kenya is governed by the Data Protection Act, 2019, which safeguards personal privacy rights, regulates how public and private organisations collect and process personal data, and establishes the Office of the Data Protection Commissioner (ODPC) for enforcement. The Act gives effect to the constitutional right to privacy under Article 31 of the Constitution of Kenya. At Ondieki & Matoke Company Advocates, we help businesses register, comply, and respond correctly when something goes wrong and we help individuals understand and exercise their rights over their own data.
The Legal Framework
The Data Protection Act’s stated purpose is to regulate the processing of personal data, ensure that processing follows the Act’s core principles, protect individual privacy, establish the legal and institutional mechanisms needed to do so, and give data subjects real rights and remedies where their data is mishandled.
- Who the Act Applies To — The Act applies to any data controller or processor established or ordinarily resident in Kenya who processes personal data and, importantly, it also applies to controllers and processors based outside Kenya if they process the personal data of individuals located in Kenya. A foreign company serving Kenyan customers online is not automatically outside the Act’s reach.

Core Principles for Handling Data
- Lawful & Transparent Processing — Data must be gathered fairly, with valid consent that is express, unequivocal, free, specific, and informed.
- Purpose Limitation — Information may only be collected for specific, clearly stated purposes.
- Data Minimisation — Only the data actually necessary for the stated purpose should be collected.
- Accuracy & Storage Limits — Records must be accurate and kept no longer than necessary for their purpose.
- Security Safeguards — Proper technical and organisational measures must protect data from unauthorised access or breaches.
Rights of Data Subjects
- Right to Access — The right to know what personal data an organisation holds about you.
- Right to Correction — The right to request correction of inaccurate or outdated personal details.
- Right to Deletion — The right to request erasure of personal data once it’s no longer needed for its original purpose.
- Right to Object — The right to stop specific uses of your personal data, such as direct marketing.
Key Concepts Worth Understanding
- Personal Data — Any information relating to an identified or identifiable natural person — a broader category than most people expect, covering far more than just names and ID numbers.
- Sensitive Personal Data — A category subject to heightened protection, including health status, ethnic origin, religious belief, genetic and biometric data, property details, marital status, and family details such as children’s or spouses’ names.
- Data Controller vs Data Processor — A data controller determines the purpose and means of processing personal data; a data processor processes it on the controller’s behalf. This distinction matters, since obligations under the Act differ depending on which role your organisation plays.
- Personal Data Breach — A security breach leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.
Our Data Protection Services
- ODPC Registration Assistance — Assessing whether registration is required for your organisation and managing the application with the ODPC.
- Compliance Audits & Policy Drafting — Reviewing data handling practices and drafting privacy policies, data protection impact assessments, and internal compliance frameworks.
- Data Breach Response — Guiding your organisation through breach notification obligations to the ODPC and affected individuals, and managing the legal exposure that follows.
- Cross-Border Data Transfer Advisory — Advising on the safeguards required to lawfully transfer personal data outside Kenya.
- Data Subject Rights Advisory — Helping organisations respond correctly to access, correction, deletion, and objection requests from data subjects.
- ODPC Representation — Representing clients in ODPC investigations, inquiries, and enforcement proceedings.

Business & Organisational Duties
- Mandatory Registration — Most data controllers and processors must register with the ODPC before processing personal data.
- Data Breach Reporting — Serious security breaches must be reported to the ODPC promptly, and in many cases, to the affected individuals as well.
- Cross-Border Transfer Limits — Transferring personal data outside Kenya requires proof of adequate safeguards in the receiving jurisdiction, or the data subject’s explicit consent.
- Penalties — Non-compliance can result in administrative fines of up to KES 5 million or 1% of annual turnover, alongside potential criminal sanctions in serious cases.
Why Ondieki & Matoke Company Advocates
- Direct access to your advocate throughout not a call centre or a junior clerk.
- Practical compliance advice that fits how your business actually operates, not generic templates.
- Calm, clear guidance during a breach, when speed and accuracy both matter.
- A transparent process and fee structure, explained clearly before work begins.

What to Expect — Our Process
- Initial consultation — you share what data your organisation handles and your compliance question or incident.
- Assessment — we assess your registration status, data handling practices, and any immediate exposure.
- Compliance build-out or breach response we develop the policies you need, or manage an active incident’s notification requirements.
- ODPC engagement — where needed, we manage registration, notifications, or responses to ODPC inquiries.
- Ongoing support — we remain available as your data practices and obligations evolve.
Frequently Asked Questions
Most data controllers and processors are required to register with the Office of the Data Protection Commissioner before processing personal data, though the specific requirement depends on the scale and nature of your data processing activities. It’s worth confirming your registration status early rather than assuming you’re exempt.
Administrative fines can reach up to KES 5 million or 1% of annual turnover, whichever applies, alongside potential criminal sanctions in serious cases. Beyond the direct penalty, non-compliance also carries real reputational and business risk once a breach becomes public.
A Data Protection Impact Assessment is a structured review of how a particular data processing activity could affect individuals’ privacy, typically carried out before launching a new product, system, or process that involves significant personal data processing. It helps identify and address privacy risks before they become compliance problems.
Yes, but only where you can demonstrate adequate safeguards exist in the receiving country, or where the data subject has given explicit consent to the transfer. This is a common compliance gap for businesses using cloud services or software hosted outside Kenya, so it’s worth reviewing specifically.
Sensitive personal data includes information revealing race, health status, ethnic origin, religious or other beliefs, genetic and biometric data, property details, marital status, and family details such as the names of a person’s children, parents, or spouse. This category receives heightened protection under the Act, with stricter requirements around lawful processing.
Call now for a Free Consultation
Contact
0710942629 / 0736677646 / omaadvocates@gmail.com / info@omaadvocates.co.ke
Office
A.C.K. Garden Annex, 1st Ngong Avenue, Ground Floor, Suite 04, Upper Hill, Nairobi, Kenya
Open Hours
Monday-Saturday 8 am – 5pm
Weekends on Appointments only.
