Who this is for

Any business processing personal data of Kenyan residents is in scope for the KDPA — that includes most SaaS products, e-commerce platforms, fintechs, and NGOs operating in Kenya, regardless of where the company is incorporated. This toolkit is for founders who need a plain-language starting point and developers who need to translate legal obligations into concrete system behavior.

What's in the toolkit

How to use it

Download the checklist, go through it honestly against your actual current systems (not your intended future state), and treat every unchecked item as a prioritization signal rather than an immediate fire drill. Items touching payment data, health data, or children's data should be prioritized first.

Go deeper

For the full developer-facing breakdown of KDPA obligations mapped to code-level controls, see the field note KDPA Developer Checklist. For a scoped compliance engagement — gap assessments, data processing registers, DPIAs, breach-response planning, and vendor/DPA review — see Data Protection Consulting.

← Back to all Resources