Skip to content
Security & Compliance

Kenya Data Protection Act: What Website Owners Must Do

10 min read

On this page
  1. What counts as personal data on a website
  2. Do you need to register with the ODPC?
  3. Forms, consent and lawful basis
  4. Privacy notices and cookies
  5. Data retention and deletion requests
  6. Breaches: what to do
  7. Website compliance checklist
  8. Getting it done

For most businesses, Data Protection Act website compliance in Kenya comes down to five jobs: know what personal data your site collects, tell people plainly what you do with it, have a lawful reason for each use, keep it secure and only as long as you need it, and be ready to act if it leaks. Whether you also need to register with the Office of the Data Protection Commissioner (ODPC) depends on rules it publishes, which we point you to below.

This is a practical guide written by web developers, not lawyers. It turns the Data Protection Act, 2019 into website tasks you can tick off. Where the law has details that change or need interpretation, we say so and send you to the source.

What counts as personal data on a website

Under the Act, personal data is any information relating to an identified or identifiable person. On a typical Kenyan business website that covers much more than people expect:

Where on the sitePersonal data collected
Contact and quote formsName, phone, email, sometimes location or company
Checkout and M-Pesa paymentsName, phone number used to pay, delivery address, order history
Booking systemsAppointment times, reasons for visit, sometimes health details
Job application pagesCVs, ID numbers, references, salary history
Newsletter sign-upEmail address, sometimes interests
Analytics and ad pixelsIP address, device identifiers, browsing behaviour
Member or parent portalsLogin details, account records, children's data
Server logsIP addresses and timestamps

Some data is treated as sensitive under the Act and attracts stricter rules. That includes health information, biometric data, and details such as ethnic origin and religious beliefs. A clinic booking form that asks "what is the reason for your visit?" is collecting health data, which raises the bar considerably. Schools and anyone dealing with children should also read the Act's provisions on processing children's data, which require parental consent in most cases.

The first practical task: walk through every form, plugin and third-party script on your site and fill in a table like the one above for your own business. You cannot comply with what you have not listed.

Do you need to register with the ODPC?

The Act requires data controllers (who decide why and how data is processed) and data processors (who process it on someone else's behalf) to register with the ODPC, subject to thresholds and exemptions set out in regulations. In broad terms, the registration regulations look at factors such as annual turnover and number of employees, and they also list certain types of processing that must register regardless of size. Sectors such as health, education and some financial services have commonly appeared on that list.

We are deliberately not quoting thresholds here. They are set in regulations that can be amended, and getting them wrong either way is costly. Instead:

  1. Go to odpc.go.ke and read the current registration guidance and the list of mandatory sectors.
  2. Check the Data Protection Act and its regulations on Kenya Law if you want the primary text.
  3. If you are close to a threshold, run a school, clinic, SACCO or lender, or handle large customer databases, ask a lawyer or contact the ODPC directly.

Registration does not replace the other duties in this article. A business that is exempt from registering still has to handle personal data lawfully.

The Act lists lawful bases for processing personal data. Consent is one; others include performing a contract with the person, complying with a legal obligation and legitimate interests. For a website, it helps to match each form to the basis you are relying on.

Map each form to a purpose

  • Quote request: you need the details to answer the request the person made. Do not quietly add them to a marketing list as well.
  • Online order: you need name, phone and delivery address to fulfil the contract. You probably do not need a date of birth.
  • Newsletter or WhatsApp updates: this is marketing, and consent is the cleanest basis. The Act has specific rules on using personal data for commercial purposes, and an opt-in is the safe default.
  • Job applications: say how long you keep CVs from unsuccessful candidates.

Make consent real

Where you rely on consent, it should be a clear, separate action. In practice that means:

  • An unticked checkbox for marketing, separate from "I accept the terms".
  • Wording that says exactly what they will get: "Send me monthly offers by email" rather than "I agree to communications".
  • A way to withdraw that is as easy as giving consent, such as an unsubscribe link or replying STOP.
  • A record of when and how consent was given. Your form tool or CRM should store the date and the wording shown.

Collect less

Data minimisation is one of the Act's principles, and it is also the cheapest compliance step. Every field you delete from a form is data you no longer need to protect, explain or delete later. ID numbers and dates of birth are the usual suspects on Kenyan forms that do not need them.

Privacy notices and cookies

The Act gives people a right to be informed about how their data is used. On a website, that is the job of a privacy notice (often called a privacy policy) linked from every page footer and from each form.

A useful notice answers, in plain language: who you are and how to contact you; what you collect and from which parts of the site; why, and on what basis; who you share it with (your hosting company, email provider, payment processor, courier, analytics tools); whether it leaves Kenya; how long you keep it; and how people exercise their rights. Our separate guide on writing a privacy policy for a Kenyan website works through each section with example wording.

Cookies and tracking

Analytics tools and advertising pixels such as Google Analytics and the Meta pixel set cookies and collect identifiers. Treat them as part of your data processing:

  • List them in the privacy notice by name.
  • Consider a cookie banner that lets visitors accept or refuse non-essential cookies before they load.
  • Turn off features you do not use, such as advertising data sharing in analytics.

The exact expectations around cookie consent are an area where guidance develops, so check what the ODPC currently publishes rather than copying a European banner wholesale.

Data retention and deletion requests

The Act says personal data should not be kept longer than necessary for its purpose. Websites are bad at this by default: form plugins store every submission forever, and the same data sits in email inboxes, WhatsApp chats and spreadsheets.

Set simple retention rules

DataExample rule (adapt to your business)
Contact form enquiries that did not become customersDelete after 12 months
Customer orders and invoicesKeep for as long as tax and accounting law requires; confirm the period with your accountant
Unsuccessful job applicationsDelete after 6 months unless the candidate agrees to stay on file
Newsletter subscribers who unsubscribeRemove from mailing lists straight away; keep only a suppression record
Server and security logsRotate automatically, typically within weeks or a few months

Then ask your developer to switch on automatic deletion where the software allows it, so the rules happen without anyone remembering.

Handle requests from individuals

People have rights under the Act, including to access the data you hold about them, to correct it and, in many cases, to have it deleted or to object to its use. Name one person who handles these requests, give them an email address that is monitored, and make sure they can actually find a customer's data across the website, CRM and email. If you cannot find it, you cannot delete it.

Breaches: what to do

A personal data breach is any security incident that leads to personal data being lost, exposed or altered without authority. On a website that might be a hacked database, a misconfigured form that emailed submissions to the wrong address, or a former staff member who still has admin access.

The Act requires data controllers to notify the Data Commissioner of certain breaches within a short deadline (the Act refers to 72 hours from becoming aware, where there is a real risk of harm), and in some cases to inform the affected people too. Data processors, such as a web agency or hosting company working for you, must tell the controller promptly. Check the current wording and ODPC breach-reporting process at odpc.go.ke, because the details matter when the clock is running.

A short plan to write down now, before anything happens:

  1. Contain. Change passwords, revoke access, take the affected feature offline if needed.
  2. Record. Note what happened, when you found out, what data and how many people may be affected.
  3. Assess. Decide, with legal advice if needed, whether the breach must be reported.
  4. Notify. Report to the ODPC and inform affected people where required.
  5. Fix and review. Close the hole and update your maintenance routine so it does not recur.

For the technical side of a compromised site, follow our guide on what to do in the first 24 hours after a website hack.

Website compliance checklist

Work through this list with whoever manages your site. None of it requires a large budget; most of it is decisions and configuration.

  • Every form, plugin and tracking script is listed with what personal data it collects.
  • Each form has a stated purpose, and unnecessary fields are removed.
  • Marketing opt-ins are separate, unticked and specific, with consent records stored.
  • A privacy notice is linked in the footer and next to each form, and matches what the site really does.
  • Non-essential cookies and pixels are disclosed, with a way to refuse them.
  • The site runs on HTTPS, admin accounts use strong passwords and two-factor authentication, and software is kept updated.
  • Contracts or terms with your developer, host and other processors cover data protection.
  • Retention periods are set, and old submissions are deleted on schedule.
  • One named person handles data requests and breaches, using a monitored email address.
  • You have checked the ODPC's current registration requirements and recorded your conclusion.
  • Sensitive or children's data has had a closer review, ideally with legal input.

Several of these items are also on our website maintenance runbook, which is a good way to make sure they get checked every quarter rather than once.

Getting it done

Compliance is mostly about knowing your own site and keeping it tidy. If you would like a developer to audit your forms, plugins and tracking, remove what is not needed and set up retention and consent properly, our website support team can do the technical work, and we will tell you plainly where you need a lawyer instead. If you are planning a new site, ask us to build these controls in from the start through our web development service.

FAQ

Questions about this topic

If your website collects information that identifies a person, such as a name, phone number, email or delivery address, the Act applies to how you handle it, whatever your size. Size mainly affects whether you must formally register with the ODPC. The duties to be transparent, collect only what you need and keep it secure apply to everyone.

The Act does not use the word cookie, but analytics and advertising cookies can collect personal data, so you need to tell visitors about them and have a lawful basis for using them. Many businesses use a simple banner that lets visitors accept or refuse non-essential cookies. Check current ODPC guidance at odpc.go.ke for what it expects.

The ODPC can issue enforcement notices and administrative fines, and it has published determinations against Kenyan businesses following complaints. The maximum amounts and the way fines are calculated are set in the Act and its regulations, so read them on kenyalaw.org or odpc.go.ke, and take legal advice if you receive a complaint or notice.

Many Kenyan websites run on servers abroad. The Act has specific rules on transferring personal data outside Kenya, including safeguards you need to show, and some categories of processing have stricter requirements. If your site handles sensitive data such as health records, ask a lawyer and check ODPC guidance before deciding where it is hosted.

Ready to build something great?

Tell us what you need. We'll come back with a fixed-scope proposal within one business day.

Start a conversation
Chat with us