Data protection · Competition · PBO compliance

Regulatory Compliance, Data Protection and Nonprofit Governance

Kenyan regulators have moved from issuing guidance to issuing penalties. The organisations being fined are not the ones that ignored the rules — they are the ones that assumed a policy document was the same as compliance.

Compliance regimes we advise on

  • Data protection compliance
  • Data protection audits and impact assessments
  • Registration of data controllers and processors
  • Cross-border data transfers
  • PBO registration and nonprofit compliance
  • Setting up an NGO, foundation or trust
  • Faith-based and community organisations

and 7 further areas set out below

For several years after the Data Protection Act came into force, the risk of non-compliance in Kenya was largely theoretical. That has changed. The Office of the Data Protection Commissioner has now issued 184 compensation orders, 134 enforcement notices and 20 penalty notices, and the penalties are landing on ordinary organisations: a school fined KES 4.55 million for processing student data without proper consent, a digital lender fined KES 2.975 million for using borrowers' third-party contacts in debt collection.

The pattern is instructive. Neither organisation was doing anything it thought was unusual — one was administering pupil records, the other was chasing arrears the way its competitors did. What they lacked was a defensible basis for the processing and a record demonstrating it. That is what a regulator asks for first, and it is the thing most compliance programmes do not actually produce.

The same shift is visible elsewhere. The Public Benefit Organizations Act, 2013 finally commenced in May 2024 and replaced the NGO Co-ordination Board with a new regulator, changing the registration and reporting position for every nonprofit in the country. We advise on the obligations themselves — what applies to your organisation, what evidence a regulator will want to see, and what to do when one is already asking.

Areas of work

Compliance regimes we advise on

01

Data protection compliance

Lawful basis, privacy notices, consent, data subject rights, retention and security under the Data Protection Act, 2019 — and the records that demonstrate compliance rather than merely assert it.

Explore
02

Data protection audits and impact assessments

Reviewing what personal data an organisation actually holds, on what basis and where it goes, including data protection impact assessments for higher-risk processing and new products.

03

Registration of data controllers and processors

Assessing whether registration with the ODPC is required and completing it, together with the appointment of a data protection officer where the organisation's processing calls for one.

04

Cross-border data transfers

Conditions for transferring personal data outside Kenya, and the contractual and safeguard requirements that apply — a routine issue for any organisation using overseas cloud services.

05

PBO registration and nonprofit compliance

Registration under the Public Benefit Organizations Act, 2013 with the PBO Regulatory Authority, together with governance, reporting and the position of organisations that did not transition from the repealed NGO regime in time.

06

Setting up an NGO, foundation or trust

Choosing the right vehicle for a not-for-profit purpose — PBO, company limited by guarantee, or trust — which differ materially in registration route, governance and reporting burden.

07

Faith-based and community organisations

Registration and governance for churches, faith-based organisations and community groups, including constitutions, trustee arrangements and the holding of property.

08

Competition law and merger control

Compliance with the Competition Act, 2010: restrictive agreements, abuse of dominance, and notification of mergers to the Competition Authority of Kenya where thresholds are met.

09

Consumer protection compliance

Terms of sale, advertising claims, pricing transparency and complaint handling, particularly for businesses selling directly to consumers online.

10

Sector licensing and regulatory approvals

Identifying and obtaining the authorisations a business needs to operate in its sector, and maintaining them — including the reporting calendar that keeps a licence in good standing.

Explore
11

Health and pharmaceutical regulation

Compliance for healthcare providers, pharmaceutical businesses and health technology, including practitioner licensing, product registration and patient data obligations.

Explore
12

Environmental and product compliance

Environmental impact assessment and licensing obligations, and product standards and certification requirements for manufactured and imported goods.

13

Compliance audits and programmes

Building or reviewing a compliance framework: risk assessment, policies people can actually follow, training, monitoring, and escalation that surfaces problems before a regulator does.

14

Regulatory investigations and enforcement

Responding to information requests, inspections, enforcement notices and penalty proceedings. How the first response is framed materially affects the outcome.

Explore
The law that applies

The compliance obligations that bite in Kenya

These are the regimes where Kenyan regulators are actively enforcing, and where the gap between having a policy and being able to evidence compliance is most often exposed.

Data Protection Act, 2019

Requires a lawful basis for processing personal data, transparency to data subjects, respect for data subject rights, security measures and conditions on cross-border transfer. Certain controllers and processors must register with the ODPC, and higher-risk processing requires a data protection impact assessment.

Administrative penalties under section 63 are capped at KES 5 million or 1% of annual turnover, whichever is lower. As at 2026 the ODPC had issued 184 compensation orders, 134 enforcement notices and 20 penalty notices.

Public Benefit Organizations Act, 2013

Commenced on 14 May 2024 by Legal Notice 78 of 2024. It repealed the NGO Co-ordination Act and transferred the regulator's functions to the Public Benefit Organizations Regulatory Authority, changing registration, governance and reporting for the whole nonprofit sector.

Organisations registered under the repealed Act were given until 13 May 2025 to transition. That deadline has passed, so organisations that did not transition need specific advice on their current position. Regulations under the Act remained in draft when this page was reviewed.

Competition Act, 2010

Prohibits restrictive trade practices and abuse of a dominant position, and requires mergers and acquisitions meeting the thresholds to be notified to the Competition Authority of Kenya and cleared before completion. It also underpins consumer protection enforcement.

Companies Act, 2015 — ongoing compliance

Annual returns, statutory registers and the beneficial ownership register lodged with the Business Registration Service. Enforcement has tightened, and failure to file can lead to strike-off — which in turn affects banking, financing and tender eligibility.

Environmental Management and Co-ordination Act

Requires environmental impact assessment and licensing for prescribed projects and activities, administered by NEMA. Relevant to construction, manufacturing, energy and any development project, and best addressed before commitments are made rather than after.

Sector statutes and their regulators

Health, pharmaceuticals, education, energy, transport, food and agriculture each have their own licensing statute and regulator. The practical first question for any business is which of these it falls under, because more than one frequently applies.

This page describes the legal framework in general terms and is not legal advice. Legislation and regulator practice change; the position below was reviewed on 26 August 2026. Advice on your own circumstances requires an engagement with the firm.

Who we act for

Who we advise on compliance

Companies handling personal data

Holding customer, employee or user data and needing a defensible basis for it — usually prompted by a client questionnaire, an investor, or a complaint.

NGOs, PBOs and foundations

Registering under the PBO Act, transitioning from the repealed NGO regime, or dealing with governance and reporting obligations to the new regulator.

Faith-based organisations

Formalising registration, governance and property holding arrangements, often for an organisation that has operated informally for years.

Regulated businesses

Holding a sector licence and managing the conditions, reporting and inspections that come with it.

Boards and audit committees

Needing an independent view of whether the organisation's compliance position is genuinely defensible or merely documented.

Organisations under regulatory scrutiny

Facing an information request, an inspection or an enforcement notice and needing the response handled properly from the first letter.

Find out what actually applies to you

Tell us what your organisation does and what data it handles. We will map the regimes that apply, show you where the real exposure sits, and set out what closing it involves.

How we work

How a compliance instruction runs

  1. 01

    Obligation mapping

    We establish which regimes actually apply to your organisation and what each requires in practice — not a generic checklist, but the obligations attaching to what you do.

  2. 02

    Gap assessment

    A review of the current position against those obligations, prioritised by exposure, so remediation starts where the risk is rather than where the work is easiest.

  3. 03

    Remediation

    Policies, notices, contracts, registrations and records — built so they can be evidenced to a regulator, which is a different standard from having them on file.

  4. 04

    Ongoing support and engagement

    A compliance calendar, training where it helps, and representation if a regulator raises a query or opens an investigation.

Common questions

Questions we are asked most

Request a consultation

Find out what actually applies to you

Tell us what your organisation does and what data it handles. We will map the regimes that apply, show you where the real exposure sits, and set out what closing it involves.

Mon–Fri 8am–6pm · Sat 9am–1pm · urgent matters handled same-day

Confidentiality guaranteed. All communications with Gracen Law are protected by legal professional privilege. Your information is never shared with third parties.

Send us a message

We respond within 2 business hours. Fields marked * are required.

100% confidential · No commitment · Response within 2 business hours

Reviewed by the Gracen Law compliance & regulatory team · Last reviewed 26 August 2026