Introduction
Data privacy has become a critical legal and business issue in Kenya. With the enforcement of the Data Protection Act 2019, organizations that collect, process, or store personal data must comply with strict data protection requirements. Failure to comply can lead to serious consequences including financial penalties of up to KSh 5 million or 1% of annual turnover, reputational damage, and regulatory investigations.
The Office of the Data Protection Commissioner (ODPC) is actively enforcing the Data Protection Act 2019, and many Kenyan businesses are unknowingly violating the law due to poor data governance practices.
In this article, we explore 10 common Data Protection Act 2019 violations Kenyan businesses make and practical steps organizations can take to stay compliant and avoid costly fines.
The 10 common Data Protection Act 2019 violations
1. Collecting Personal Data Without Consent
One of the most common violations of the Data Protection Act 2019 is collecting personal data without obtaining proper consent from individuals.
Many businesses gather customer details such as names, phone numbers, emails, and ID numbers without informing individuals how their data will be used.
How to Avoid This Violation
- Always obtain clear and informed consent before collecting personal data.
- Provide a privacy notice explaining how the data will be used.
- Allow individuals to withdraw consent easily.
Transparent data collection is a key requirement under the Data Protection Act 2019.
2. Failure to Register as a Data Controller or Data Processor
The Data Protection Act 2019 requires many organizations to register with the Office of the Data Protection Commissioner as Data Controllers or Data Processors.
Businesses that process customer data but fail to register risk regulatory penalties.
How to Avoid This Violation
- Determine whether your organization qualifies as a Data Controller or Data Processor.
- Complete the ODPC registration process.
- Maintain updated records of your data processing activities.
3. Lack of a Data Protection Policy
Many Kenyan SMEs collect large amounts of customer and employee data but operate without any formal data protection policy.
This lack of documentation is a serious compliance gap under the Data Protection Act 2019.
How to Avoid This Violation
- Develop a comprehensive Data Protection Policy.
- Define how personal data is collected, stored, processed, and deleted.
- Train employees on data protection responsibilities.
4. Poor Cybersecurity Controls
Weak cybersecurity practices expose organizations to data breaches, which can lead to violations of the Data Protection Act 2019.
Common issues include:
- Weak passwords
- Lack of encryption
- Outdated systems
- Poor access controls
How to Avoid This Violation
- Implement multi-factor authentication
- Encrypt sensitive data
- Conduct regular cybersecurity assessments
- Monitor systems for suspicious activity
Strong cybersecurity is essential for protecting personal data under the Data Protection Act 2019.
5. Failure to Report Data Breaches
The Data Protection Act 2019 requires organizations to report data breaches to the regulator within a specific timeframe.
However, many businesses attempt to hide breaches instead of reporting them.
How to Avoid This Violation
- Establish a data breach response plan
- Immediately investigate suspected incidents
- Notify the Office of the Data Protection Commissioner where required.
Timely breach reporting demonstrates accountability and compliance.
6. Retaining Personal Data Longer Than Necessary
Another common violation of the Data Protection Act 2019 is storing personal data indefinitely.
Organizations often keep outdated customer records, employee data, or transaction information without a clear purpose.
How to Avoid This Violation
- Implement data retention policies
- Define retention periods for different data categories
- Securely delete data that is no longer required.
7. Sharing Personal Data With Third Parties Without Safeguards
Some businesses share personal data with marketing partners, service providers, or vendors without proper contractual safeguards.
This violates the Data Protection Act 2019 requirements for secure data processing.
How to Avoid This Violation
- Sign Data Processing Agreements (DPAs) with vendors
- Ensure third parties comply with the Data Protection Act 2019
- Conduct vendor security assessments.
8. Ignoring Data Subject Rights
The Data Protection Act 2019 gives individuals several rights over their personal data, including: Right to access their data, Right to correction, Right to deletion and Right to object to processing.
Many businesses fail to respond to these requests.
How to Avoid This Violation
- Create a process for handling Data Subject Access Requests (DSARs)
- Respond within the legally required timelines
- Maintain records of all requests.
9. Poor Employee Data Protection Practices
Employees often handle sensitive customer and company data. Without proper training, they may accidentally violate the Data Protection Act 2019.
Examples include: Sending confidential data through unsecured email, Downloading sensitive files to personal devices, and Falling victim to phishing attacks
How to Avoid This Violation
- Conduct regular data protection training
- Implement strict access controls
- Establish clear internal data handling procedures.
10. Failing to Conduct Data Protection Impact Assessments (DPIAs)
Organizations introducing new technologies or large-scale data processing systems may be required to conduct Data Protection Impact Assessments (DPIAs).
Many businesses overlook this requirement under the Data Protection Act 2019.
How to Avoid This Violation
- Perform Data Privacy Impact Assessments (DPIAs) before launching new data processing systems
- Identify and mitigate privacy risks
- Document compliance measures.
How Kenyan Businesses Can Stay Compliant With the Data Protection Act 2019
To avoid fines and legal risks, organizations must adopt a proactive approach to compliance with the Data Protection Act 2019.
Key steps include:
- Registering with the Office of the Data Protection Commissioner
- Conducting data protection audits
- Implementing strong cybersecurity controls
- Training employees on data protection practices
- Developing comprehensive data protection policies
Businesses that prioritize data protection not only avoid penalties but also build trust with customers and partners.
Conclusion
Compliance with the Data Protection Act 2019 is no longer optional for Kenyan businesses. With enforcement by the Office of the Data Protection Commissioner increasing, organizations that ignore data protection requirements risk fines of up to KSh 5 million, regulatory investigations, and severe reputational damage.
The good news is that most Data Protection Act 2019 violations are preventable with the right policies, cybersecurity controls, and employee awareness.
Is your organization compliant with the Data Protection Act 2019?
At Kryplock Cybersecurity, we help Kenyan businesses implement practical data protection and privacy compliance programs including:
- Data Protection Act 2019 compliance assessments
- Data protection policies and procedures
- Data protection training for staff
- Data security audits and risk assessments
Contact us today to protect your organization from costly fines and ensure full compliance with the Data Protection Act 2019.
๐ Location: 2nd Floor, Elysee Plaza (opp. Adams Arcade), Kilimani Road, Kilimani
๐ Phone: +254700693747
๐ง Email: support@kryplockcyberexperts.com
Disclaimer!
All content provided on this blog is for educational and informational purposes only. The goal is to provide defensive insights and promote better Cyber-security practices.

