All articles
Compliance18 February 2026 6 min read

Data Protection for Kenyan SMEs: What the Law Actually Expects From You

You keep customer names, numbers and M-Pesa records — that makes you a data handler under the Data Protection Act, and the ODPC has been issuing real fines. The practical compliance guide, minus the legalese.

Most Kenyan business owners assume data protection law is for banks and telcos. It isn't. If you keep customer names, phone numbers, ID copies or transaction records — in a CRM, a notebook, or a WhatsApp chat — the Data Protection Act (2019) applies to you, and the Office of the Data Protection Commissioner has shown it will fine ordinary businesses, not just corporates.

What the law boils down to

  • Collect only what you need, and tell people why you're collecting it
  • Use it for the purpose you stated — the customer who gave a number for delivery didn't consent to daily promo blasts
  • Keep it secure — locked systems and phones, not customer lists floating between staff handsets
  • Delete it when it's no longer needed
  • If a person asks what you hold on them, or asks you to correct or delete it, you must be able to

Do you need to register with the ODPC?

The ODPC requires data controllers and processors meeting certain thresholds — including turnover and the nature of processing — to register, and businesses in listed sectors must register regardless of size. Registration is done online through the ODPC portal and is not expensive; check the current thresholds on odpc.go.ke or ask a professional, because the categories are updated. The bigger risk isn't the registration fee — it's a complaint from an aggrieved customer landing you in an investigation unprepared.

The afternoon-sized compliance project

  • Map your data: list where customer information lives — systems, phones, notebooks, old spreadsheets
  • Cut the copies: one authoritative place per record; retire the floating Excel sheets and shared handset lists
  • Add a one-paragraph privacy notice to your forms and website saying what you collect and why
  • Lock things: PINs on business phones, passwords on systems, access only for staff who need it
  • Agree a marketing rule: only message people who opted in, and honour every 'stop' immediately

Compliance as a selling point

In a country losing billions to data-fuelled fraud, "we protect your information" is becoming a competitive claim — corporates increasingly demand it from suppliers, and tenders ask for it. The businesses that treat customer data with visible care are quietly winning the clients that matter most. The law is the floor; trust is the prize.

Your customer list is an asset you hold in trust. Guard it like the money it eventually becomes — the law now insists, but the market rewards it more.
A

Antony Mungai

Founder, Steff Cloud — building websites, systems and automation for Kenyan businesses from Nakuru.

Want this working in your business?

Get a free quote today — no obligation, reply within 2 hours.