Who this is for
Any business processing personal data of Kenyan residents is in scope for the KDPA — that includes most SaaS products, e-commerce platforms, fintechs, and NGOs operating in Kenya, regardless of where the company is incorporated. This toolkit is for founders who need a plain-language starting point and developers who need to translate legal obligations into concrete system behavior.
What's in the toolkit
- Data minimization & lawful basis — what data you actually need to collect, and the lawful basis for collecting it.
- Consent architecture — how consent should be captured, recorded, and withdrawable.
- Encryption & access control — baseline expectations for data at rest and in transit.
- Breach readiness — what a breach-response plan needs to cover before you need one.
- ODPC registration — when registration as a data controller/processor applies, and how to approach it.
How to use it
Download the checklist, go through it honestly against your actual current systems (not your intended future state), and treat every unchecked item as a prioritization signal rather than an immediate fire drill. Items touching payment data, health data, or children's data should be prioritized first.
Go deeper
For the full developer-facing breakdown of KDPA obligations mapped to code-level controls, see the field note KDPA Developer Checklist. For a scoped compliance engagement — gap assessments, data processing registers, DPIAs, breach-response planning, and vendor/DPA review — see Data Protection Consulting.