The Kenya Data Protection Act (KDPA) applies the moment your business collects a name, an email address, a phone number, or an ID number from a Kenyan resident. Most businesses discover their gaps only when a client's procurement team asks for a compliance attestation, or after something has already gone wrong.
This service treats KDPA compliance as an engineering and process problem, not a paperwork exercise — obligations get mapped to the specific systems and data flows that create them, and to a concrete owner.
Who this is for
- Businesses and NGOs collecting personal data of Kenyan residents through a website, app, or CRM.
- Teams being asked for a KDPA compliance attestation by an enterprise client, bank, or donor.
- Organisations that have never formally registered as a data controller/processor with the ODPC.
- Anyone unsure whether their current vendor stack (analytics, email, payments, AI tools) creates exposure.
What the engagement covers
| Deliverable | What It Establishes |
|---|---|
| KDPA Gap Assessment | Where current practice falls short of statutory obligations, ranked by exposure. |
| Data Processing Register | What personal data is collected, why, where it's stored, and who can access it. |
| DPIA (Section 31) | A formal Data Protection Impact Assessment for higher-risk processing activities. |
| Breach-Response Plan | Who does what within the statutory notification window if a breach is suspected. |
| Vendor & DPA Review | Whether third-party processors (SaaS tools, AI vendors, payment providers) carry adequate data processing agreements. |
How this differs from a security assessment
A Web & API Security Assessment tests whether your systems can be broken into. Data protection consulting asks a different question: even with systems working exactly as designed, is the personal data inside them being collected, stored, and shared lawfully? The two engagements are complementary — a security assessment often surfaces the technical findings this consulting engagement translates into statutory obligations.
Evidence and method
The regulatory-to-code translation approach behind this service is documented publicly in the KDPA Developer Checklist.
How engagements start: the 48-Hour Secure Digital Workflow Assessment
Most clients begin with the 48-Hour Secure Digital Workflow Assessment, delivered jointly with HarLyn Digital Partners, which flags KDPA exposure alongside technical findings before scoping a full compliance engagement.
Engagements begin with a fixed-scope scoping call. Clear decisions before code, and no obligation to proceed to follow-on build work.
Request a Scoping Call →Related: Web & API Security Assessment · Security Audits · All services