The Kenya Data Protection Act (KDPA) applies the moment your business collects a name, an email address, a phone number, or an ID number from a Kenyan resident. Most businesses discover their gaps only when a client's procurement team asks for a compliance attestation, or after something has already gone wrong.

This service treats KDPA compliance as an engineering and process problem, not a paperwork exercise — obligations get mapped to the specific systems and data flows that create them, and to a concrete owner.

Who this is for

What the engagement covers

DeliverableWhat It Establishes
KDPA Gap AssessmentWhere current practice falls short of statutory obligations, ranked by exposure.
Data Processing RegisterWhat personal data is collected, why, where it's stored, and who can access it.
DPIA (Section 31)A formal Data Protection Impact Assessment for higher-risk processing activities.
Breach-Response PlanWho does what within the statutory notification window if a breach is suspected.
Vendor & DPA ReviewWhether third-party processors (SaaS tools, AI vendors, payment providers) carry adequate data processing agreements.

How this differs from a security assessment

A Web & API Security Assessment tests whether your systems can be broken into. Data protection consulting asks a different question: even with systems working exactly as designed, is the personal data inside them being collected, stored, and shared lawfully? The two engagements are complementary — a security assessment often surfaces the technical findings this consulting engagement translates into statutory obligations.

Evidence and method

The regulatory-to-code translation approach behind this service is documented publicly in the KDPA Developer Checklist.

How engagements start: the 48-Hour Secure Digital Workflow Assessment

Most clients begin with the 48-Hour Secure Digital Workflow Assessment, delivered jointly with HarLyn Digital Partners, which flags KDPA exposure alongside technical findings before scoping a full compliance engagement.

START HERE

Engagements begin with a fixed-scope scoping call. Clear decisions before code, and no obligation to proceed to follow-on build work.

Request a Scoping Call →

Related: Web & API Security Assessment · Security Audits · All services