Have any questions:

Contact:+254 715 131275

Mail:info@aimashinani.org

Complying with the Kenya Data Protection Act 2019: A Simple Guide for Small Businesses

In: Cyber Security

Your Small Business Probably Handles More Personal Data Than You Realise

Think about a normal day in a Kenyan business.

A customer sends their name and phone number through WhatsApp.

Another customer pays through M-Pesa.

Someone fills in an online registration form.

Your business keeps an Excel sheet containing customer contacts.

Your CCTV records people entering your premises.

Your website collects information from visitors.

An employee sends you a copy of their ID.

All of this can involve personal data.

And once your business collects or uses personal data, you need to think seriously about how that information is handled.

Kenya’s Data Protection Act, 2019 established rules governing the processing of personal data and strengthened the rights of individuals over their information.

For a small-business owner, the law may initially sound like something designed for banks, hospitals, telecommunications companies or large technology companies.

But data protection isn’t only a big-company issue.

If your business collects information about identifiable people, privacy should be part of how you operate.

This guide breaks the subject down into practical steps.

Note: This article provides general educational information and is not legal advice. Businesses with specific compliance questions should consult the Office of the Data Protection Commissioner (ODPC), applicable regulations, and qualified professional advisers where necessary.


First: What Is Personal Data?

Personal data is information relating to an identified or identifiable person.

In everyday business, this could include information such as:

  • Names
  • Phone numbers
  • Email addresses
  • Identification details
  • Customer addresses
  • Employee information
  • Photographs
  • Location information
  • Financial information
  • Online identifiers

Some types of personal information require particularly careful handling because of their sensitivity.

The important question for your business is:

What information are we collecting that can be connected to a person?

Start there.


Why Should a Small Business Care About Data Protection?

There are several reasons.

1. Customer Trust

Imagine giving a business your phone number to receive an order.

Two weeks later, you start receiving unrelated promotional messages.

You would probably ask:

“Where did they get my number?”

Customers expect businesses to treat their information responsibly.

Privacy therefore isn’t only about compliance.

It is also about trust.


2. Your Business Reputation

A data incident can damage the reputation of a small business quickly.

Customers may forgive a delayed delivery.

They may be less forgiving if their private information is exposed through careless handling.


3. Legal Responsibilities

Kenya has a legal framework governing the processing of personal data.

Businesses should therefore understand which requirements apply to their activities rather than assuming privacy laws are only relevant to large organisations.


4. Cybersecurity

Privacy and cybersecurity are closely connected.

If you collect customer information but don’t secure it properly, attackers, dishonest insiders or unauthorized individuals could potentially access it.

Good data protection practices therefore also strengthen your overall business security.


Step 1: Know What Personal Data Your Business Collects

Before buying expensive software or writing a 50-page privacy policy, do something simpler.

Create a data inventory.

Ask:

What information do we collect?

For example:

  • Customer names
  • Phone numbers
  • Email addresses
  • Employee records
  • Supplier contacts
  • Payment information
  • CCTV footage
  • Website form submissions

Why do we collect it?

For example:

Phone number → delivery coordination

Email → sending an invoice

Employee ID details → employment administration

Where is it stored?

For example:

  • WhatsApp
  • Phone contacts
  • Google Sheets
  • Excel
  • Email
  • Paper files
  • Cloud storage
  • Accounting software
  • CRM system

Who can access it?

This question is critical.

Maybe five employees have access to information that only one person actually needs.

That’s unnecessary risk.


Step 2: Collect Only What You Actually Need

Suppose you are running a small bakery.

A customer wants to order a birthday cake.

Do you need their:

Name? Probably.

Phone number? Probably.

Delivery location? If you’re delivering, yes.

But do you need unrelated personal information simply because your online form allows you to ask for it?

Probably not.

A useful principle is:

Don’t collect personal data simply because you can.

Collect what is reasonably necessary for the legitimate purpose you have identified.

Less unnecessary data can mean less unnecessary risk.


Step 3: Tell People Why You’re Collecting Their Information

Transparency matters.

Customers should not have to guess what you’re going to do with their information.

Suppose someone enters their phone number to receive an order confirmation.

That doesn’t automatically mean they expect to receive promotional messages indefinitely.

When collecting personal information, clearly communicate relevant information about how it will be used.

For a simple business form, this might include an appropriate privacy notice explaining the purpose of collecting the information and how it will be handled.

Your exact requirements will depend on your processing activities, so your privacy notices should be designed around what your business actually does.


Step 4: Don’t Turn Your Customer Database Into a WhatsApp Spamming Machine

This deserves special attention because WhatsApp is extremely important to many Kenyan businesses.

Imagine you have 800 customer phone numbers.

Those customers gave you their numbers while:

  • Making purchases
  • Asking questions
  • Requesting deliveries
  • Registering for an event

You now decide:

“Wacha nitume promotion kwa wote.”

Pause.

Before using personal information for a new marketing purpose, consider whether that use is appropriate and whether you have the necessary legal basis and permissions.

Also give people appropriate ways to stop receiving communications where required.

Good marketing should build relationships.

It shouldn’t make customers regret giving you their phone number.


Step 5: Protect the Data You Keep

You don’t need to be a cybersecurity engineer to improve basic security.

Start with practical controls.

Use strong passwords

Avoid passwords such as:

business123

password123

admin123

Use strong, unique passwords for important accounts.


Enable Multi-Factor Authentication

Where supported, multi-factor authentication can provide an additional layer of account security.

This is especially important for accounts containing customer or business information.


Limit Access

Not every employee needs access to every file.

Ask:

Who actually needs this information to perform their job?

Grant access accordingly.


Secure Business Devices

Phones and laptops containing customer information should be protected.

Use:

  • Screen locks
  • Device updates
  • Secure authentication
  • Appropriate backups
  • Anti-malware/security measures where relevant

And avoid leaving sensitive customer information exposed on shared devices.


Step 6: Be Very Careful With Google Sheets and Excel

Many small businesses manage operations using spreadsheets.

There is nothing inherently wrong with that.

The problem begins when a spreadsheet containing:

Names + phone numbers + ID numbers + payment information

is shared carelessly.

For example:

“Anyone with this link can view.”

Now imagine that link gets forwarded.

You may have unintentionally exposed customer information.

Regularly review:

  • Who can view the file?
  • Who can edit it?
  • Is public-link access enabled?
  • Do former employees still have access?
  • Does everyone with access actually need it?

A five-minute permissions review can prevent major problems.


Step 7: Don’t Keep Personal Data Forever

Small businesses often accumulate data.

Old customer lists.

Former employee documents.

Old registrations.

Old spreadsheets.

Old application forms.

Old CCTV footage.

The question is:

Why are we still keeping this?

Businesses should establish appropriate retention practices based on legal, operational and legitimate business requirements.

If information is no longer required and there is no appropriate reason to retain it, it should be handled according to an appropriate deletion or disposal process.

That includes physical records too.

Throwing sensitive documents into an ordinary open bin may expose personal information.


Step 8: Understand Your Third-Party Tools

Your business probably doesn’t operate alone.

You may use:

  • Cloud storage
  • Email platforms
  • Accounting software
  • Payment systems
  • Marketing platforms
  • Website hosting
  • CRM systems
  • AI tools

These services may process information on behalf of your business.

Before uploading customer information somewhere, ask:

What information am I sharing?

Why am I sharing it?

Does this service actually need the information?

What privacy and security controls does the provider offer?

This becomes particularly important when using AI.


Step 9: Be Careful When Using Customer Data With AI

Imagine you receive a customer complaint.

Instead of summarising the situation, you copy the customer’s entire message into a public AI tool.

The message contains:

Full name

Phone number

Order details

Account information

Home address

You only wanted AI to help write a response.

But you may have shared far more information than was necessary.

A safer approach is to remove or replace unnecessary identifying information before using external AI systems.

For example, instead of:

“Jane Wanjiku, phone number 07XX XXX XXX, living at [full address], purchased…”

Use:

“A customer purchased…”

This is sometimes called data minimisation or sanitisation in practice—removing information that the AI doesn’t need to complete the task.

The rule is simple:

Don’t give an AI system personal information merely because copying and pasting it is convenient.


Step 10: Prepare for Data Incidents Before They Happen

What happens if:

  • An employee loses a company phone?
  • A laptop containing customer records is stolen?
  • Someone accidentally shares a customer database?
  • An account containing personal information is compromised?
  • Information is sent to the wrong person?

Don’t wait for the incident to invent your response plan.

Your business should know:

  1. Who should be informed internally?
  2. How will access be secured?
  3. What information was affected?
  4. Which individuals may be affected?
  5. What records should be preserved?
  6. What legal or regulatory reporting obligations might apply?

Depending on the circumstances, a personal data breach can trigger notification and other obligations.

Businesses should understand these requirements before an incident occurs.


A Simple Data Protection Checklist for Kenyan Small Businesses

Use this as a starting point.

☐ We know what personal data we collect.

☐ We know why we collect it.

☐ We avoid collecting unnecessary personal information.

☐ Customers receive appropriate information about how their data is used.

☐ Access to customer data is limited.

☐ Important accounts use strong passwords.

☐ Multi-factor authentication is enabled where appropriate.

☐ Shared files have appropriate permissions.

☐ Former staff do not retain unnecessary access.

☐ We have appropriate data-retention practices.

☐ We consider privacy before sharing information with third-party tools.

☐ We avoid entering unnecessary personal data into AI tools.

☐ We have a process for handling suspected data breaches.

If several boxes remain unticked, you have identified areas to improve.

That is a useful first step.


Example: A Small Online Shop

Let’s make this practical.

Imagine Amina sells handbags through Instagram and WhatsApp.

Customers send:

  • Names
  • Phone numbers
  • Delivery locations
  • Order details

Amina records everything in a spreadsheet.

As the business grows, she hires two assistants.

Both receive access to the spreadsheet.

One assistant eventually leaves the business.

Six months later, Amina realises the former employee can still access the customer database.

This situation could have been reduced with a simple process:

Employee leaves → account/access review → unnecessary access removed immediately.

Data protection isn’t always about sophisticated technology.

Sometimes it is simply about having good business processes.


Does Every Kenyan Business Need to Register With the ODPC?

This is where businesses should avoid oversimplification.

Kenya’s data protection framework includes registration requirements for data controllers and data processors, alongside applicable regulations and exemptions.

Whether a particular organisation is required to register can depend on factors such as its activities, processing, sector and other applicable criteria.

Don’t rely on a social media post saying:

“Every business must register.”

And don’t assume:

“I’m small, so the law doesn’t concern me.”

Instead, check the current guidance and requirements published by Kenya’s Office of the Data Protection Commissioner (ODPC) and seek professional advice where your situation requires it.


Privacy Should Become Part of Your Business Culture

The strongest privacy policy means little if employees don’t follow it.

Teach your team simple rules:

Don’t share customer information unnecessarily.

Don’t send sensitive files to personal accounts without authorization.

Don’t leave customer records exposed.

Don’t share passwords.

Don’t paste confidential information into random AI tools.

Report mistakes quickly.

Security works better when people know what is expected of them.


Turn Compliance Into a Business Advantage

Many entrepreneurs hear the word compliance and immediately think:

“Another expense.”

But responsible data practices can create business value.

Imagine two companies.

Company A says:

“Just send your ID on WhatsApp.”

Company B explains why the information is required, limits who can access it, protects the records and removes information when it is no longer required.

Which business feels more trustworthy?

As customers become more digitally aware, privacy can become part of professional service.


Where AI Can Help With Data Protection

AI can assist businesses with administrative tasks such as:

  • Creating a first draft of a data inventory
  • Generating staff privacy-awareness questions
  • Creating cybersecurity checklists
  • Identifying questions to ask about business processes
  • Drafting internal procedure outlines
  • Simplifying complex compliance concepts
  • Creating staff training scenarios

However, AI should not be treated as your lawyer or regulator.

Never assume:

“ChatGPT said we’re compliant.”

AI can help you understand questions you should investigate.

Actual compliance requires checking the applicable law, regulations, official guidance and your organisation’s specific circumstances.


A Useful AI Prompt for Small Businesses

Try this:

PROMPT

“Act as a data-protection awareness assistant for a small Kenyan business.

My business is a [TYPE OF BUSINESS].

We collect the following customer information:
[LIST INFORMATION]

We store it using:
[SYSTEMS]

Our employees who access it are:
[ROLES]

Help me create a simple data inventory showing:

  1. The type of personal information collected
  2. Why the business collects it
  3. Where it is stored
  4. Who currently accesses it
  5. Potential privacy/security risks I should investigate
  6. Questions I should verify against Kenya’s Data Protection Act, applicable regulations and ODPC guidance

Do not claim that the business is legally compliant. Clearly identify areas requiring professional or regulatory verification.”

Notice the last instruction.

You are asking AI to help you identify questions, not declare your business compliant.


Start With Your Business, Not the Legal Jargon

If you’re an entrepreneur, don’t allow the size of the Data Protection Act to stop you from improving your privacy practices.

Start with five questions:

What personal information do we collect?

Why do we need it?

Where do we keep it?

Who can access it?

What would happen if it leaked?

Those five questions can reveal a surprising amount about your business.

Then investigate the legal requirements that apply to those activities.


Use the AI Business Compass to Review Your Business

Running a modern business involves more than selling.

You also need to think about:

  • Customer information
  • Digital security
  • Business processes
  • Marketing
  • Financial records
  • AI usage
  • Compliance
  • Operational risks

The AI Mashinani Business Compass is designed to help entrepreneurs examine different areas of their businesses and identify where better systems, digital tools and AI-supported workflows may help.

Start Your Business Compass Assessment

[START THE AI BUSINESS COMPASS]

Use it to identify gaps, prioritise improvements and turn technology into something practical for your business.


Frequently Asked Questions

Does Kenya have a data protection law?

Yes. Kenya enacted the Data Protection Act in 2019 and has established a regulatory framework governing personal data protection.

Does the Data Protection Act affect small businesses?

A business that processes personal data should determine which obligations under Kenya’s data protection framework apply to its activities. Business size alone should not be used as the only basis for deciding whether privacy obligations matter.

Is a customer’s phone number personal data?

A phone number can constitute personal data when it relates to an identified or identifiable individual.

Can I use customer phone numbers for marketing?

Businesses should consider the purpose for which information was collected, the applicable legal basis and relevant direct-marketing/privacy requirements before reusing customer information for marketing.

Can employees access customer information?

Access should be appropriately controlled. Employees should generally only have access to personal information necessary for their authorised responsibilities.

Can I put customer information into ChatGPT or another AI tool?

Businesses should avoid providing unnecessary personal, confidential or sensitive information to public AI tools. Review the service’s applicable privacy, security and data-handling terms and consider whether the information can be anonymised or removed entirely.

What should I do if customer information is leaked?

Act quickly to contain the incident, determine what information was affected, preserve relevant records and assess your obligations under applicable Kenyan data protection requirements. Serious incidents may require professional advice and engagement with the appropriate authorities.


Final Takeaway

Data protection can sound complicated.

But better privacy starts with simple questions.

What are we collecting?

Why are we collecting it?

Who can access it?

How are we protecting it?

When should we delete it?

And increasingly:

Are we sharing it with AI systems unnecessarily?

You don’t need to solve everything in one day.

Start by mapping the personal information your business already holds.

Fix obvious security weaknesses.

Review unnecessary access.

Train your team.

Then work through the legal and regulatory requirements relevant to your organisation.

Because in the digital economy, customer data isn’t simply information sitting in a spreadsheet.

It is information someone trusted your business to handle responsibly.

Leave a Reply

Your email address will not be published. Required fields are marked *