Insights / Compliance
Kenya's Data Protection Act: what your website has to do
Devaltech · · 6 min read
If your website has a contact form, a newsletter box, a booking page or a checkout, it collects personal data, and Kenya's Data Protection Act, 2019 applies to what you do with it. A name and a phone number are enough. Most small businesses have never read the Act, and most websites in Kenya do not follow it. This is not legal advice, but it is where to start.
Do you have to register?
The Office of the Data Protection Commissioner (ODPC) requires organisations that process personal data to register. There is an exemption, and it is narrow: you are exempt only if your annual turnover is below KES 5 million and you employ fewer than ten people. Miss either condition and you register. Some activities are never exempt, including telecoms and processing genetic data, and public bodies, charities and religious entities register regardless of size.
For a micro or small business the one-time registration fee published by the ODPC is KES 4,000. It is cheap enough that a business near the threshold should simply register and stop wondering.
Being exempt from registering does not exempt you from the Act. It only exempts you from the form.
What the website itself has to do
Four things show up on almost every Kenyan site. First, a privacy policy that says in plain words what you collect, why, how long you keep it, who else receives it, and how someone asks for their data to be corrected or deleted. Second, a reason for collecting each field: if the form asks for a postal address you never use, remove the field. Third, honest handling of third parties. Google Analytics, a mailing platform and a payment gateway all receive visitor data, and the policy should name them. Fourth, a way to act on requests, which can be as simple as a monitored email address.
Get a free 12-point audit within 48 hours.
Where sites get it wrong
The common failures are boring. A policy copied from a foreign site that mentions the wrong law. A newsletter box that signs people up without asking. Tracking scripts that load before anyone has agreed to anything. Contact form submissions that sit in a shared inbox forever. Customer lists exported to a spreadsheet and emailed around. None of these needs a lawyer to fix. They need someone to look.
If a breach does happen, the Act expects the Data Commissioner to be told quickly, within 72 hours in the guidance most firms cite. That is an argument for knowing where your data lives before something goes wrong, not after.
What to do this month
List every place your site collects personal data. Check each against what your privacy policy says. Remove fields you do not need. Decide whether you need to register, and if you are unsure, check the ODPC's published guidance or ask a Kenyan data protection lawyer.