The Data Protection Act, 2019 is Kenya’s principal legislation governing the processing of personal data. It also established the Office of the Data Protection Commissioner (ODPC) and provides rights and remedies relating to personal data.
The Act applies to processing by entities established or ordinarily resident in Kenya, and can also apply to entities outside Kenya that process personal data relating to people located in Kenya.
This means data protection isn’t only an issue for large corporations.
A Kenyan business with a website can potentially process personal data every day.

What Counts as Personal Data?
Personal data generally refers to information relating to an identified or identifiable person.
Depending on your website, this could include:
- Names
- Email addresses
- Telephone numbers
- Physical addresses
- Identification information
- Account information
- Payment-related information
- Employment information
- Student information
- Customer records
- IP or online identifiers where they relate to an identifiable person
The exact treatment of information depends on the circumstances and applicable law.
How Does a Website Collect Personal Data?
Your website may collect personal data through much more than a traditional contact form.
Common examples include:
Contact Forms
A visitor may provide:
- Name
- Phone number
- Message
Ecommerce Checkout
An online store may collect:
- Customer name
- Delivery address
- Telephone number
- Order information
- Payment-related information
User Accounts
Websites can collect information when customers create accounts or profiles.
Newsletter Forms
Email marketing forms collect contact details for communications.
School Applications
School websites may process information about students, parents and applicants.
NGO Registration Forms
NGO websites may collect information from volunteers, donors and beneficiaries.
The important question is therefore not simply “Do I have a database?”
Instead, ask:
“What personal information does my website collect, why does it collect it, where does it go, and how is it protected?”
The Data Protection Principles Website Owners Should Know
Section 25 of the Act sets out key data protection principles. Personal data should be processed lawfully, fairly and transparently; collected for explicit and legitimate purposes; limited to what is necessary; kept accurate; retained no longer than necessary; and protected appropriately. The Act also addresses transfers outside Kenya.
For a website owner, these principles can be translated into practical questions.
1. Are You Transparent?
Visitors should understand what information you’re collecting and why.
2. Are You Collecting Only What You Need?
Don’t request unnecessary information simply because your form can.
3. Is the Information Accurate?
Businesses should take reasonable steps to keep personal data accurate and up to date.
4. Do You Keep Information Indefinitely?
You should consider how long personal information needs to be retained for the purpose for which it was collected.
5. Is the Information Secure?
Appropriate technical and organisational safeguards should be implemented.
Your Website Should Have a Clear Privacy Notice
One of the most important practical steps for a website owner is having a clear privacy notice or privacy statement.
The ODPC’s 2026 guidance explains that a privacy notice should communicate how personal data is collected, used and protected. It should cover matters including the purpose of collection, data-subject rights, third parties receiving information and relevant safeguards.
Your privacy notice should be easy for visitors to find.
A common approach is to link it from:
- Website footer
- Contact forms
- Registration pages
- Checkout pages
- Newsletter forms
What Should Your Privacy Notice Explain?
Depending on your processing activities, your notice should explain things such as:
What Data You Collect
Tell visitors what categories of information you collect.
Why You Collect It
Explain the purpose.
For example:
“We collect your email address to respond to your enquiry.”
Who May Receive the Information
If personal data is shared with third parties, explain this appropriately.
How You Protect It
Explain the relevant security measures in clear language.
How Long You Keep It
Explain retention practices where applicable.
How People Can Exercise Their Rights
Provide a practical way for users to contact you about their personal data.
What Rights Do Website Users Have?
The Data Protection Act gives data subjects several rights.
According to the Act and ODPC, these include the right:
- To be informed about the use of their personal data
- To access their personal data
- To object to processing
- To have false or misleading information corrected
- To have false or misleading information deleted
This means website owners should have a process for handling legitimate data-subject requests.
For example, if a customer contacts your company asking what personal information you hold about them, you should know where that information is stored and how such requests are handled.
Don’t Collect More Data Than You Need
One common mistake businesses make is asking website visitors for excessive information.
Imagine a basic newsletter form asking for:
- Full name
- Phone number
- ID number
- Date of birth
- Physical address
If the purpose is simply sending a newsletter, many of these fields may be unnecessary.
The principle of data minimisation requires personal data to be adequate, relevant and limited to what is necessary for the purpose.
A better approach is to collect only information you genuinely need.
Don’t Forget Cookies
Modern websites may use cookies and similar technologies for purposes such as:
- Website functionality
- Analytics
- Preferences
- Marketing
- Advertising
The ODPC’s 2026 guidance specifically discusses cookies and states that websites should provide information about cookie use and, where required, obtain consent or enable user choice in accordance with applicable requirements.
Therefore, don’t treat cookies as something completely separate from your website’s privacy strategy.
Review:
- Which cookies your website uses
- Why they’re used
- What information they collect
- Which third parties receive information
- What choices users have
Website Security Is Part of Data Protection
Data protection isn’t only about writing a privacy policy.
Your website also needs appropriate security measures.
Depending on your website, these can include:
SSL/HTTPS
Encrypt communication between the visitor and your website.
Strong Passwords
Use strong administrator and user passwords.
Two-Factor Authentication
Add another layer of authentication where appropriate.
Software Updates
Keep WordPress, plugins, themes and server software updated.
Backups
Maintain appropriate backups so information and systems can be recovered after incidents.
Access Controls
Only give users access to the information and systems they actually need.
Malware Protection
Monitor your website and hosting environment for malicious activity.
The ODPC’s registration guidance specifically identifies technical and organisational safeguards as part of data-protection compliance.
What Happens If Your Website Suffers a Data Breach?
A data breach can involve unauthorised access to or acquisition of personal data.
Under section 43 of the Data Protection Act, where a breach creates a real risk of harm to a data subject, a data controller must notify the Data Commissioner without delay and within 72 hours of becoming aware of the breach. A data processor that becomes aware of a personal-data breach must notify the data controller without delay and, where reasonably practicable, within 48 hours.
This is why website owners should have an incident-response process rather than waiting until something goes wrong.
Your Hosting Provider Matters
Data protection responsibilities aren’t solved simply by choosing a hosting provider.
Your organisation remains responsible for understanding its data-processing activities and obligations.
However, your hosting environment is an important part of your technical security.
When choosing hosting, look for:
- SSL certificates
- Secure server infrastructure
- Regular backups
- Access controls
- Malware protection
- Security monitoring
- Reliable technical support
- Appropriate data-processing arrangements where applicable
For businesses using third-party providers to process personal data, contracts and responsibilities should be considered carefully. Kenya’s Data Protection (General) Regulations include requirements concerning data processors and processing arrangements.
What About Data Stored Outside Kenya?
Don’t automatically assume that using an international service is prohibited.
The Data Protection Act addresses transfers of personal data outside Kenya and requires appropriate safeguards or consent in the circumstances specified by the law.
The issue can become especially important when your website uses:
- International cloud services
- Email marketing platforms
- Analytics platforms
- Payment services
- CRM systems
- External form providers
- Cloud backups
You should understand where personal data is processed and what safeguards apply.
For certain categories of processing, the regulations also contain specific requirements relating to processing or storage in Kenya.
Are Websites Required to Register With the ODPC?
Registration requirements depend on the organisation, the nature of its processing activities and the applicable exemptions or mandatory-registration categories.
The ODPC provides a registration system for data controllers and data processors and asks applicants to provide information about matters such as the categories of personal data processed, purposes, data subjects, transfers and safeguards.
Don’t assume that because your company is small, registration requirements automatically don’t apply.
Review the current ODPC requirements for your specific organisation.
A Practical Website Data Protection Checklist
Use this checklist when reviewing your website:
| Website Area | What to Check |
|---|---|
| Privacy Notice | Is it clear and easy to find? |
| Contact Forms | Are you collecting only necessary information? |
| Newsletter | Is the purpose clearly explained? |
| Cookies | Do you understand which cookies are used? |
| SSL | Is HTTPS enabled? |
| Passwords | Are administrator accounts protected? |
| Updates | Are website components regularly updated? |
| Backups | Can your website and data be restored? |
| Access | Are permissions appropriately restricted? |
| Third Parties | Do you know who receives personal data? |
| Data Retention | Do you know how long information is retained? |
| Breaches | Do you have an incident-response process? |
How Hostnali Can Help
Hostnali provides web hosting infrastructure and related services that form part of the technical environment supporting websites.
For a Kenyan business, hosting is one part of a broader website security and data-protection strategy.
When selecting a hosting plan, consider features such as:
- SSL support
- Backup solutions
- Server security
- Website performance
- Email security
- Technical support
- Scalability
However, hosting alone does not make a website legally compliant. Your organisation must also address its own data-processing practices, policies, procedures and responsibilities.
Frequently Asked Questions
Does the Kenya Data Protection Act apply to websites?
It can. If your website processes personal data, the Act may apply depending on the nature and circumstances of the processing. The Act applies to relevant processing by entities in Kenya and certain processing involving people located in Kenya.
Does my website need a privacy policy?
A clear privacy notice is an important practical measure for explaining how your organisation collects, uses and protects personal data. The ODPC’s guidance specifically addresses privacy notices and the information they should communicate.
Is SSL enough for Data Protection Act compliance?
No. SSL is an important security measure, but data protection involves much more, including lawful and transparent processing, data minimisation, retention, user rights and appropriate organisational and technical safeguards.
What should I do if customer data is hacked?
Treat it as a potential personal-data breach. Assess the incident, contain it, preserve relevant information, and follow the applicable breach-notification requirements. Where the statutory conditions apply, section 43 provides a 72-hour notification requirement for data controllers and a 48-hour processor-to-controller notification timeframe.
Who regulates data protection in Kenya?
The Office of the Data Protection Commissioner (ODPC) is the regulatory office established under the Data Protection Act.
Final Thoughts
The Kenya Data Protection Act is highly relevant to modern websites because websites increasingly collect, store and process personal information.
For Kenyan businesses, compliance should go beyond simply adding a privacy-policy link to the footer.
Start by understanding:
- What personal data your website collects
- Why you collect it
- Who receives it
- Where it is processed or stored
- How long you retain it
- How you protect it
- How users can exercise their rights
- What you will do if a data breach occurs
A secure hosting environment, HTTPS, strong access controls, backups and regular website maintenance can support your technical safeguards—but they are only part of the overall picture.
For the latest regulatory information, consult the Office of the Data Protection Commissioner and the Kenya Law version of the Data Protection Act.