Data protection · Competition · PBO compliance
Regulatory Compliance, Data Protection and Nonprofit Governance
Kenyan regulators have moved from issuing guidance to issuing penalties. The organisations being fined are not the ones that ignored the rules — they are the ones that assumed a policy document was the same as compliance.
Compliance regimes we advise on
- Data protection compliance
- Data protection audits and impact assessments
- Registration of data controllers and processors
- Cross-border data transfers
- PBO registration and nonprofit compliance
- Setting up an NGO, foundation or trust
- Faith-based and community organisations
and 7 further areas set out below
For several years after the Data Protection Act came into force, the risk of non-compliance in Kenya was largely theoretical. That has changed. The Office of the Data Protection Commissioner has now issued 184 compensation orders, 134 enforcement notices and 20 penalty notices, and the penalties are landing on ordinary organisations: a school fined KES 4.55 million for processing student data without proper consent, a digital lender fined KES 2.975 million for using borrowers' third-party contacts in debt collection.
The pattern is instructive. Neither organisation was doing anything it thought was unusual — one was administering pupil records, the other was chasing arrears the way its competitors did. What they lacked was a defensible basis for the processing and a record demonstrating it. That is what a regulator asks for first, and it is the thing most compliance programmes do not actually produce.
The same shift is visible elsewhere. The Public Benefit Organizations Act, 2013 finally commenced in May 2024 and replaced the NGO Co-ordination Board with a new regulator, changing the registration and reporting position for every nonprofit in the country. We advise on the obligations themselves — what applies to your organisation, what evidence a regulator will want to see, and what to do when one is already asking.
Areas of work
Compliance regimes we advise on
Data protection compliance
Lawful basis, privacy notices, consent, data subject rights, retention and security under the Data Protection Act, 2019 — and the records that demonstrate compliance rather than merely assert it.
ExploreData protection audits and impact assessments
Reviewing what personal data an organisation actually holds, on what basis and where it goes, including data protection impact assessments for higher-risk processing and new products.
Registration of data controllers and processors
Assessing whether registration with the ODPC is required and completing it, together with the appointment of a data protection officer where the organisation's processing calls for one.
Cross-border data transfers
Conditions for transferring personal data outside Kenya, and the contractual and safeguard requirements that apply — a routine issue for any organisation using overseas cloud services.
PBO registration and nonprofit compliance
Registration under the Public Benefit Organizations Act, 2013 with the PBO Regulatory Authority, together with governance, reporting and the position of organisations that did not transition from the repealed NGO regime in time.
Setting up an NGO, foundation or trust
Choosing the right vehicle for a not-for-profit purpose — PBO, company limited by guarantee, or trust — which differ materially in registration route, governance and reporting burden.
Faith-based and community organisations
Registration and governance for churches, faith-based organisations and community groups, including constitutions, trustee arrangements and the holding of property.
Competition law and merger control
Compliance with the Competition Act, 2010: restrictive agreements, abuse of dominance, and notification of mergers to the Competition Authority of Kenya where thresholds are met.
Consumer protection compliance
Terms of sale, advertising claims, pricing transparency and complaint handling, particularly for businesses selling directly to consumers online.
Sector licensing and regulatory approvals
Identifying and obtaining the authorisations a business needs to operate in its sector, and maintaining them — including the reporting calendar that keeps a licence in good standing.
ExploreHealth and pharmaceutical regulation
Compliance for healthcare providers, pharmaceutical businesses and health technology, including practitioner licensing, product registration and patient data obligations.
ExploreEnvironmental and product compliance
Environmental impact assessment and licensing obligations, and product standards and certification requirements for manufactured and imported goods.
Compliance audits and programmes
Building or reviewing a compliance framework: risk assessment, policies people can actually follow, training, monitoring, and escalation that surfaces problems before a regulator does.
Regulatory investigations and enforcement
Responding to information requests, inspections, enforcement notices and penalty proceedings. How the first response is framed materially affects the outcome.
ExploreThe law that applies
The compliance obligations that bite in Kenya
These are the regimes where Kenyan regulators are actively enforcing, and where the gap between having a policy and being able to evidence compliance is most often exposed.
Data Protection Act, 2019
Requires a lawful basis for processing personal data, transparency to data subjects, respect for data subject rights, security measures and conditions on cross-border transfer. Certain controllers and processors must register with the ODPC, and higher-risk processing requires a data protection impact assessment.
Administrative penalties under section 63 are capped at KES 5 million or 1% of annual turnover, whichever is lower. As at 2026 the ODPC had issued 184 compensation orders, 134 enforcement notices and 20 penalty notices.
Public Benefit Organizations Act, 2013
Commenced on 14 May 2024 by Legal Notice 78 of 2024. It repealed the NGO Co-ordination Act and transferred the regulator's functions to the Public Benefit Organizations Regulatory Authority, changing registration, governance and reporting for the whole nonprofit sector.
Organisations registered under the repealed Act were given until 13 May 2025 to transition. That deadline has passed, so organisations that did not transition need specific advice on their current position. Regulations under the Act remained in draft when this page was reviewed.
Competition Act, 2010
Prohibits restrictive trade practices and abuse of a dominant position, and requires mergers and acquisitions meeting the thresholds to be notified to the Competition Authority of Kenya and cleared before completion. It also underpins consumer protection enforcement.
Companies Act, 2015 — ongoing compliance
Annual returns, statutory registers and the beneficial ownership register lodged with the Business Registration Service. Enforcement has tightened, and failure to file can lead to strike-off — which in turn affects banking, financing and tender eligibility.
Environmental Management and Co-ordination Act
Requires environmental impact assessment and licensing for prescribed projects and activities, administered by NEMA. Relevant to construction, manufacturing, energy and any development project, and best addressed before commitments are made rather than after.
Sector statutes and their regulators
Health, pharmaceuticals, education, energy, transport, food and agriculture each have their own licensing statute and regulator. The practical first question for any business is which of these it falls under, because more than one frequently applies.
This page describes the legal framework in general terms and is not legal advice. Legislation and regulator practice change; the position below was reviewed on 26 August 2026. Advice on your own circumstances requires an engagement with the firm.
Who we act for
Who we advise on compliance
Companies handling personal data
Holding customer, employee or user data and needing a defensible basis for it — usually prompted by a client questionnaire, an investor, or a complaint.
NGOs, PBOs and foundations
Registering under the PBO Act, transitioning from the repealed NGO regime, or dealing with governance and reporting obligations to the new regulator.
Faith-based organisations
Formalising registration, governance and property holding arrangements, often for an organisation that has operated informally for years.
Regulated businesses
Holding a sector licence and managing the conditions, reporting and inspections that come with it.
Boards and audit committees
Needing an independent view of whether the organisation's compliance position is genuinely defensible or merely documented.
Organisations under regulatory scrutiny
Facing an information request, an inspection or an enforcement notice and needing the response handled properly from the first letter.
Find out what actually applies to you
Tell us what your organisation does and what data it handles. We will map the regimes that apply, show you where the real exposure sits, and set out what closing it involves.
How we work
How a compliance instruction runs
- 01
Obligation mapping
We establish which regimes actually apply to your organisation and what each requires in practice — not a generic checklist, but the obligations attaching to what you do.
- 02
Gap assessment
A review of the current position against those obligations, prioritised by exposure, so remediation starts where the risk is rather than where the work is easiest.
- 03
Remediation
Policies, notices, contracts, registrations and records — built so they can be evidenced to a regulator, which is a different standard from having them on file.
- 04
Ongoing support and engagement
A compliance calendar, training where it helps, and representation if a regulator raises a query or opens an investigation.
Legal insights
Further reading on compliance & regulatory
- Company LawDoes Your Kenyan Company Actually Need a Company Secretary?The threshold is clearer than most directors think, and the penalty for getting it wrong is not the fine — it is the invalid resolution.
- Company LawDirectors' Duties Under the Kenyan Companies Act: What Boards Get WrongThe Companies Act 2015 codified directors' duties that many Kenyan boards still treat as advisory. Personal liability says otherwise.
Common questions
Questions we are asked most
Related Gracen Law Services
Work that sits alongside compliance & regulatory
Most matters in this area touch at least one of the following. Each links through to the relevant Gracen Law practice or sector page.
- Regulatory & ComplianceDecisions that withstand regulatory and stakeholder scrutiny.
- Corporate LawOwnership, capital, and governance structured for long-term value.
- Banking, Finance, Fintech & SaccosCapital, compliance, and financial innovation structured with confidence.
- Nonprofits, Faith Based Institutions, and Education
- Healthcare and Pharmaceuticals
- Financial Services and Fintech
Request a consultation
Find out what actually applies to you
Tell us what your organisation does and what data it handles. We will map the regimes that apply, show you where the real exposure sits, and set out what closing it involves.
Confidentiality guaranteed. All communications with Gracen Law are protected by legal professional privilege. Your information is never shared with third parties.
Send us a message
We respond within 2 business hours. Fields marked * are required.
Reviewed by the Gracen Law compliance & regulatory team · Last reviewed 26 August 2026