Muchangi Patrick & Associates Advocates logo Muchangi Patrick & Associates Advocates ← Back to Insights

Practice Note

SACCOs & Cooperatives Series
Nairobi Edition
Regulation, technology & the business of Kenya
Dual Regulation

SASRA and the ODPC: Where SACCO Compliance Overlaps

Being SASRA-compliant on paper doesn't mean a SACCO is covered on data protection — and the reverse is just as true.

Practice Note 7 min read SACCOs & Cooperatives
By Muchangi Patrick, Advocate — Muchangi Patrick & Associates Advocates · Published July 2026

Every deposit-taking SACCO in Kenya already knows it answers to the SACCO Societies Regulatory Authority (SASRA) — licensing, prudential standards, corporate governance, capital adequacy, and increasingly, ICT and cyber-risk expectations. Far fewer boards have mapped how much of that same territory is separately, and independently, regulated by the Office of the Data Protection Commissioner (ODPC) under the Data Protection Act, 2019.

These are two different regulators, with two different mandates, two different enforcement powers, and two different inspection regimes. A SACCO can pass a SASRA on-site inspection and still be fully exposed to an ODPC complaint — because the two regimes ask related but distinct questions.

§1 Two regulators, two different mandates

SASRA licenses and supervises deposit-taking SACCOs under the SACCO Societies Act, 2008 — capital adequacy, liquidity, corporate governance, and increasingly, ICT and operational risk standards. The ODPC's mandate is entirely separate: oversight of how personal data is processed, by any controller or processor in Kenya, under the Data Protection Act, 2019.

A SACCO's SASRA licence says nothing about its ODPC registration status. The two are assessed independently, by different regulators, against different criteria — by design, not by oversight.

The assumption boards make

Because SASRA's supervisory reach already feels thorough — governance reviews, risk-based supervision, periodic inspections — it's easy for a board to assume that being in good standing with SASRA means the SACCO's data handling is also covered. It doesn't. Registration with the ODPC, a documented lawful basis for processing member data, and a published privacy policy are ODPC-specific obligations that SASRA supervision does not test for.

Not sure where your SACCO stands?

Run our free 2-minute ODPC Compliance Self-Assessment to see your registration status and biggest data protection gaps — separate from, and in addition to, your SASRA compliance position.

Take the Self-Assessment →

§2 Where the two regimes actually meet

The overlap isn't in the law itself — it's in the underlying operations. The same systems, files and third-party relationships a SASRA inspector reviews for prudential purposes are, at the same time, personal data processing activities regulated by the ODPC.

Governance & risk registers

SASRA expects documented ICT and operational risk controls; data protection expects its own accountability records and safeguards. Related evidence, separate requirements.

Core banking & member data

The same member and loan files a SASRA inspection reviews for prudential completeness are personal data subject to the Data Protection Act's own principles.

Outsourcing & vendors

SASRA's expectations around outsourced core functions (IT systems, credit reference checks) sit alongside the separate requirement for signed data processing agreements with those same vendors.

Incident reporting

Significant IT or operational incidents may trigger SASRA reporting expectations and, independently, the ODPC's own breach-notification clock.

§3 Where they diverge

Passing a SASRA inspection tells you nothing about whether you're registered with the ODPC.

SASRA supervision does not check whether a SACCO has registered as a data controller, whether it has a documented lawful basis for processing member and guarantor data, or whether it has published a privacy policy — those are ODPC-specific obligations. Equally, the ODPC does not assess capital adequacy, liquidity ratios or governance structure. A SACCO can be a genuine model of data protection practice and still fall short of a prudential requirement, or the reverse. Neither regulator's approval substitutes for the other's.

§4 The governance gap this creates

Most SACCO boards already have a Risk & Audit Committee reporting on SASRA compliance. Far fewer have an equivalent structure asking data-protection-specific questions — and the DPO function, where it exists at all, is often informal or bundled into a compliance officer's already-full plate.

Designated DPO or compliance lead

Named, with data protection explicitly in their mandate — not assumed to sit inside general risk.

Confirmed ODPC registration

Verified independently of SASRA licensing status.

Data inventory / register of processing

Covering member, guarantor and staff data separately from the SASRA risk register.

Vendor agreements reviewed twice

Once for prudential/outsourcing risk, once for data processing terms — the same contract, two different checklists.

Breach response plan

Timed to satisfy both any SASRA incident-reporting expectation and the ODPC's notification clock.

Board reporting that names both regimes

Not folded into a single "compliance" line item that only reflects SASRA status.

§5 Questions every SACCO board should ask

These are governance questions as much as they are compliance questions — and they're the ones a board should be able to answer before a regulator, either one, asks first.

§6 The bottom line

Dual regulation is additive, not either/or. Treating "SASRA compliant" and "data protection compliant" as the same box on the same checklist gives a board a false sense of assurance — because the two regulators are, quite deliberately, asking different questions about the same institution. The SACCOs that get ahead of this are the ones that build governance structures that answer both, separately and explicitly, rather than hoping one covers the other.

Final thought

If your SACCO's compliance reporting has a line for SASRA and nothing separately for the ODPC, that's usually the first gap worth closing — not because it's the biggest risk, but because it's the easiest one to miss entirely.

How this touches your SACCO's compliance posture

SASRA licensing and ODPC registration are two separate boxes to tick — not one. If your board's compliance reporting only has a line for SASRA, that's usually the first gap worth closing.

Muchangi Patrick & Associates Advocates advises SACCO boards, CEOs and compliance teams on data protection governance, ODPC registration and outsourced DPO support that sits alongside — not in place of — your SASRA compliance function.

Talk to us

Muchangi Patrick & Associates Advocates advises SACCOs, fintechs, startups and corporates on data protection compliance across Kenya — from ODPC registration and DPIAs to outsourced DPO services and cross-border data transfer advisory. If the overlap above touches your SACCO, we can help you close the gap.

Book a Consultation → Chat on WhatsApp