Data Protection for SMEs in Kenya: A Practical Guide to the Data Protection Act, 2019

Data Protection for SMEs in Kenya: A Practical Guide to the Data Protection Act, 2019

Picture this. A customer walks into your electronics shop in Thika looking for a laptop. Before leaving, they pay through M-Pesa, give you their name, phone number and email address so you can send the electronic receipt and notify them when accessories arrive. A week later, they begin receiving promotional messages from businesses they have never interacted with.

The first question they ask is usually not “Who sold my data?” Instead, they ask a much more damaging question:

“Can I trust this business with my information?”

In today’s digital economy, trust has become one of the most valuable business assets. Whether you run a hardware store, consultancy, online clothing business, school, medical practice, law firm or restaurant, chances are you collect customer information every single day. That information is legally protected.

The Data Protection Act, 2019 introduced a comprehensive legal framework governing how organisations collect, use, store and share personal data. Contrary to popular belief, the law is not only aimed at banks, multinational corporations or technology companies. Small and medium-sized enterprises (SMEs) are equally expected to comply where they process personal data.

The Act is administered by the Office of the Data Protection Commissioner (ODPC), whose role includes enforcing compliance, investigating complaints and promoting responsible data handling across Kenya.

Why should SMEs care?

Waweru Nyambura Advocates

Many business owners assume data protection is a problem for large corporations because they have sophisticated computer systems and millions of customers.

That assumption is dangerous.

If your business stores names, telephone numbers, identification details, email addresses, employment records, CCTV footage, customer payment records or even WhatsApp conversations relating to customers, you are processing personal data.

Personal data is broadly defined under the Data Protection Act as any information relating to an identified or identifiable natural person. The legal definition extends beyond names and ID numbers. It includes photographs, online identifiers, location data and other information capable of identifying someone.

Legal Warning: Compliance with the Data Protection Act is not determined by the size of your business. If your business processes personal data, the law may impose obligations regardless of whether you employ three people or three hundred.

For many SMEs, customer information has quietly become one of their most valuable business assets. Yet it is often managed with very little thought about legal responsibility. Staff members save customer contacts on personal phones, invoices are shared through unsecured messaging platforms, and old employee records remain accessible long after employment has ended.

These practices may appear harmless until something goes wrong.

What exactly is personal data?

The law distinguishes between ordinary personal data and sensitive personal data.

Ordinary personal data includes information such as:

  • Names
  • Telephone numbers
  • Email addresses
  • National ID or passport numbers
  • Residential addresses
  • Vehicle registration details

Sensitive personal data attracts even greater legal protection. This includes information relating to health, biometric identifiers, religious beliefs, race, children’s information and financial details in certain contexts.

Businesses handling sensitive information are expected to apply stronger safeguards because misuse of such information may expose individuals to discrimination, fraud or other serious harm.

The complete legal framework can be found in the Data Protection Act, 2019, published through the Kenya Law website.

The seven principles every SME should understand

The Data Protection Act is built around several principles that guide responsible handling of personal information.

First, businesses should collect data lawfully, fairly and transparently. Customers should know why information is being collected and how it will be used.

Second, data should only be collected for a legitimate purpose. If a customer provides their phone number to receive delivery updates, using that same number for unrelated marketing campaigns may require additional consent.

Third, businesses should collect only the information they genuinely need. Asking for unnecessary personal details simply because a form has space available increases legal risk without adding business value.

Fourth, information should remain accurate and up to date. Incorrect records can create problems not only for customers but also for the business itself.

Fifth, personal data should not be kept indefinitely. Businesses should develop reasonable record retention practices and securely dispose of information that is no longer necessary.

Finally, organisations are expected to implement appropriate security measures that protect information against loss, theft, unauthorised access or accidental disclosure.

These principles closely mirror internationally recognised privacy standards and demonstrate that data protection is fundamentally about accountability rather than paperwork.

Consent is important—but it is not everything

One of the biggest misconceptions is that businesses only need customer consent.

Consent certainly plays an important role. However, the Act recognises several lawful bases for processing personal data depending on the circumstances. In some situations, processing may be necessary to fulfil a contract, comply with a legal obligation or protect legitimate interests recognised by law.

This means compliance cannot simply be reduced to asking customers to tick a checkbox. Businesses should understand why they are collecting information and whether that purpose is legally justified.

data-protection-for-smes-in-kenya Waweru Nyambura Advocates

Practical compliance steps every SME should take

The good news is that compliance is not reserved for businesses with dedicated legal or IT departments. Most SMEs can significantly reduce their legal exposure by adopting simple but deliberate practices.

Start by identifying the personal data your business collects. Many business owners are surprised by how much information they already hold—from customer databases and CCTV recordings to supplier contacts, employee records and WhatsApp business conversations.

Next, ask yourself three simple questions:

  • Why are we collecting this information?
  • Who has access to it?
  • How long should we keep it?

Answering these questions creates the foundation of a practical data protection programme.

Businesses should also review who can access customer information. Not every employee requires unrestricted access to payroll records, customer databases or identification documents. Restricting access based on job responsibilities significantly reduces the risk of accidental disclosure or misuse.

Equally important is staff awareness. Many data breaches occur not because hackers break into systems but because employees unknowingly share confidential information through email, messaging applications or unsecured devices.

Compliance Tip: Data protection is not only an IT responsibility. Every employee who handles customer or employee information forms part of your organisation’s compliance system.

What happens when things go wrong?

Imagine an employee exports your customer contact list before resigning and begins using it to market a competing business. Or perhaps your company laptop containing payroll records is stolen because it was not password protected.

These situations raise more than operational concerns. Depending on the circumstances, they may amount to personal data breaches requiring internal investigation and, where appropriate, notification to the Office of the Data Protection Commissioner.

The ODPC has increasingly demonstrated its willingness to investigate complaints and issue enforcement decisions where organisations fail to meet their obligations. Recent enforcement actions and guidance published by the Commissioner show that compliance is becoming an active regulatory priority rather than a theoretical legal requirement.

Businesses can access regulatory guidance, registration information and published decisions through the Office of the Data Protection Commissioner.

Building customer trust through privacy

Many SMEs view compliance as an expense. In reality, good privacy practices can become a competitive advantage.

Customers are increasingly aware of how their personal information is used. They notice whether businesses explain why information is collected, whether they seek permission before sending promotional messages and whether sensitive documents are handled professionally.

A business that demonstrates respect for customer privacy communicates something much deeper than legal compliance—it signals professionalism, integrity and accountability.

This is particularly important for sectors such as healthcare, education, financial services, legal practice, recruitment, hospitality and e-commerce, where clients routinely disclose highly personal information.

Data protection is also good business

Beyond avoiding legal consequences, proper information management improves business operations. Accurate customer records reduce costly mistakes. Clear retention policies minimise unnecessary storage. Controlled access lowers internal fraud risks, while documented procedures improve consistency as businesses grow.

In other words, the same practices that satisfy legal requirements often make businesses more organised and efficient.

As Kenya’s digital economy continues expanding through online shopping, mobile payments, cloud services and artificial intelligence, responsible data governance will become increasingly important for businesses of every size.

Final thoughts

The Data Protection Act, 2019 is not designed to discourage businesses from collecting information. Rather, it seeks to ensure that organisations handle personal data responsibly, transparently and securely.

For SMEs, compliance begins with recognising that customer information is not merely another business asset—it belongs to real people whose privacy deserves protection.

Whether you operate a neighbourhood retail shop, an online business, a professional practice or a growing enterprise, adopting sound data protection practices today will not only reduce legal risk but also strengthen the trust that every successful business depends upon.

To learn more about your obligations, consult the official resources published by the Office of the Data Protection Commissioner, read the full Data Protection Act, 2019, and follow updates from the Judiciary of Kenya and Kenya Law on emerging decisions that continue to shape privacy law in Kenya.


Comments

Leave a Reply

Your email address will not be published. Required fields are marked *