KPLR/TK/001/2026
Compliance Toolkit
A practical, end-to-end framework aligned to the Data Protection Act, 2019 and the ODPC regulatory regime
Thirteen sections taking an organisation from ODPC registration and privacy notices through DPAs, DPIAs, data subject rights, technical & organisational security measures, breach response, cross-border transfers, AI governance and a master compliance checklist — with a curated set of ODPC and High Court determinations.
KPLR/ACAD/001/2026
Course Manual
Kenya DPA 2019 compared with UK/EU GDPR — for legal & compliance practitioners
A practitioner-level course manual walking through the Kenyan and UK/EU frameworks side by side, built for in-house counsel and compliance teams who need working fluency in both regimes.
KPLR/ACAD/002/2026
Companion Workbook
From knowledge to implementation for digital credit providers and fintechs operating in Kenya
A working companion for fintech and digital-lending compliance teams — takes the regulatory framework and turns it into an implementation workbook rather than a reading list.
MPA-DP-001
Template
A comprehensive, adaptable privacy policy aligned to the Data Protection Act, 2019
Twenty-three sections covering data collected, lawful bases, cookies, AI-assisted processing, automated decision-making, cross-border transfers, security, retention, data subject rights, children's data and complaints — ready to adapt and publish.
MPA-WEB-002
Template
A standalone cookie and tracking-technology notice for websites, portals and SaaS platforms
Cookie categories, third-party and analytics cookies, AI-personalisation technologies, browser controls and consent withdrawal — applicable to websites, client portals, web applications and SaaS platforms.
KPLR/CHK/001/2026
Checklist
An executive self-assessment instrument — 20 scored requirements
A board-level self-assessment against twenty core statutory and regulatory benchmarks, with a compliance score band and priority action plan.
KPLR/CHK/002/2026
Checklist
A practical self-assessment guide — 30 scored requirements
Covers privacy notices, cookies, forms, analytics, payment gateways and user accounts on a website against the Data Protection Act, 2019 and applicable Regulations.
KPLR/CHK/003/2026
Checklist
A practical screening & assessment guide — 24 scored requirements
Screens for when a Data Protection Impact Assessment is required under section 31 and the General Regulations, 2021, and walks through the assessment itself.
KPLR/CHK/004/2026
Checklist
A practical vendor & governance assessment guide — 26 scored requirements
Data protection, AI governance and cybersecurity due diligence to embed before signing a contract for an AI-enabled tool or service.
KPLR/CHK/005/2026
Checklist
An incident readiness & response guide — 24 scored requirements
Readiness against the 72-hour ODPC notification duty in section 43, incident response roles, and data subject notification content.
KPLR/CHK/006/2026
Checklist
A practical data mapping & governance guide — 26 scored requirements
Maintaining an accurate record of processing activities and surfacing unknown or unauthorised data flows, in line with section 41.
The full Compliance Toolkit above already covers registration, notices, DPAs, DPIAs, security, breach response, cross-border transfers and AI governance end to end. If you need a template or checklist that isn't listed above, our team can prepare it directly for your organisation ahead of general release.