On this page
A privacy policy for a website in Kenya should describe, in plain words, what personal data your site really collects, why, who you share it with, how long you keep it and how people can exercise their rights under the Data Protection Act, 2019. The safest way to write one is to inventory your own site first and then draft each section from that list, rather than pasting a template from a foreign website.
Here is how to do it in an afternoon, with sample wording you can adapt.
Why copied policies are risky
Scroll to the footer of many Kenyan business websites and you will find a policy lifted from somewhere else. The giveaways are easy to spot: references to "the State of California", a European data protection officer, US dollar thresholds, or promises about tools the site does not use.
That is worse than it looks. A privacy policy is a statement of fact about your practices. If it says you never share data with third parties while your site runs Google Analytics, a Meta pixel and a WhatsApp chat widget, the policy is simply untrue. If someone complains to the Office of the Data Protection Commissioner, your own policy becomes the first piece of evidence against you.
Other problems we often see in copied policies:
- The wrong business name, or the name of the web designer instead of the business.
- No working contact for privacy requests, or an email address on a domain that has expired.
- Promises of "industry-standard encryption" for data that is actually emailed around as spreadsheets.
- No mention of M-Pesa, WhatsApp or SMS, which for most Kenyan businesses are where customer data actually flows.
- A "last updated" date from years before the current website existed.
A short, accurate policy beats a long, impressive, wrong one.
Inventory what your site collects
Before you write a word, open your website in one tab and a blank sheet in another. Go through every page and note:
- Forms: contact, quote, booking, enquiry, job application, newsletter. List each field.
- Payments: M-Pesa (STK push, Paybill, Till), card gateway, cash on delivery. Note which payment provider handles the details.
- Accounts: customer logins, member or parent portals, saved addresses.
- Third-party scripts: analytics, advertising pixels, chat widgets, embedded YouTube or Google Maps, reCAPTCHA.
- Behind the scenes: your hosting company, email service, CRM, courier, SMS provider, accounting software.
- Location of data: whether any of those services store data outside Kenya.
If your developer installed things you do not know about, ask them for a list of every plugin and external service. This inventory is also the starting point for wider compliance, which we cover in what the Data Protection Act means for website owners.
Required sections
Build the policy from the sections below. The wording in quotes is illustrative only; replace the details with your own and have a lawyer review it if your business handles sensitive data such as health, financial or children's records.
1. Who we are
Your registered business name, physical location, and a contact email and phone number for privacy questions.
Using a made-up hardware business as the example:
"This website is operated by Mwangaza Hardware Ltd, Thika Road, Nairobi. For any question about your personal data, email privacy@example.co.ke or call 07XX XXX XXX."
2. What we collect
Group the data by where it comes from, using your inventory. Be specific.
"When you request a quote we collect your name, phone number, email and the products you are interested in. When you order online we also collect your delivery address and the M-Pesa phone number used to pay."
3. Why we use it, and on what basis
For each purpose, say why. Answering an enquiry and delivering an order are needed to do what the customer asked. Marketing should rest on consent.
"We only send offers by SMS, WhatsApp or email if you tick the box asking for them. You can stop them at any time by replying STOP or using the unsubscribe link."
4. Who we share it with
Name categories, and ideally the services: hosting provider, payment processor, courier, email and SMS services, analytics. Say that you do not sell personal data, if that is true.
5. Transfers outside Kenya
If your hosting, email or analytics providers store data abroad, say so and describe the safeguards you rely on. This is an area with specific rules in the Act, so check the current position with the ODPC.
6. How long we keep it
Give real periods, not "as long as necessary".
"Enquiries that do not lead to an order are deleted after 12 months. Order and invoice records are kept for the period required by Kenyan tax law."
7. How we protect it
A short, honest description: HTTPS, restricted staff access, two-factor authentication on admin accounts, regular backups. Avoid absolute promises such as "your data is 100% secure".
8. Your rights
Explain that people can ask to see their data, correct it, have it deleted in many cases and object to marketing, and how to do so. Mention that they can complain to the ODPC at odpc.go.ke.
9. Children
Schools, tuition centres and any site that may collect children's details need a specific section explaining parental consent and how children's data is handled.
10. Changes and date
State the date the policy was last updated and how you will tell people about significant changes.
Cookies and analytics notice
Cookies deserve their own short section or a separate cookie notice. Split them into two groups:
| Type | Examples | What to tell visitors |
|---|---|---|
| Essential | Shopping cart, login session, security tokens | Needed for the site to work; cannot be switched off |
| Analytics | Google Analytics | Helps you understand visits; can be refused |
| Advertising | Meta pixel, Google Ads tags | Used to measure and target ads; can be refused |
| Embedded content | YouTube videos, Google Maps | The third party may set its own cookies |
A consent banner with clear "Accept" and "Reject non-essential" buttons is a sensible default. If you run ads to your site, read our guide on Facebook ads and landing pages for how pixels fit in.
Where to place links and consent
- Footer of every page: "Privacy Policy" next to "Terms" and, for shops, "Returns".
- Under every form: one line, such as "We use these details to reply to your enquiry. See our Privacy Policy."
- At checkout: a link near the place-order button, with any marketing opt-in as a separate, unticked box.
- On account sign-up: a link before the account is created.
- On WhatsApp and SMS opt-ins: a short note and a link, especially if you collect numbers on the website for broadcasts.
Avoid making people tick "I have read the privacy policy" to send a contact form. It adds friction and does not make the policy any more effective.
Keeping it up to date
The policy goes stale the moment someone adds a new plugin. Tie reviews to events, not just the calendar:
- Adding a new form, payment method, chat tool or tracking pixel
- Changing hosting, email or CRM provider
- Launching a mobile app or customer portal
- Any change in ODPC guidance that affects you
- At least once a year regardless
Put the annual review on your website maintenance checklist alongside renewals and security checks, so it actually happens.
Need help matching the policy to the site?
The hard part is usually the inventory, because few owners know every script running on their site. Our support team can list what your site collects and remove what is not needed, so your policy (written or reviewed by your lawyer) describes a tidier site. If you are commissioning a new website, ask us at the start; through our web development service we build forms, consent boxes and cookie controls in from day one.