Practice Note
Being SASRA-compliant on paper doesn't mean a SACCO is covered on data protection — and the reverse is just as true.
Every deposit-taking SACCO in Kenya already knows it answers to the SACCO Societies Regulatory Authority (SASRA) — licensing, prudential standards, corporate governance, capital adequacy, and increasingly, ICT and cyber-risk expectations. Far fewer boards have mapped how much of that same territory is separately, and independently, regulated by the Office of the Data Protection Commissioner (ODPC) under the Data Protection Act, 2019.
These are two different regulators, with two different mandates, two different enforcement powers, and two different inspection regimes. A SACCO can pass a SASRA on-site inspection and still be fully exposed to an ODPC complaint — because the two regimes ask related but distinct questions.
SASRA licenses and supervises deposit-taking SACCOs under the SACCO Societies Act, 2008 — capital adequacy, liquidity, corporate governance, and increasingly, ICT and operational risk standards. The ODPC's mandate is entirely separate: oversight of how personal data is processed, by any controller or processor in Kenya, under the Data Protection Act, 2019.
A SACCO's SASRA licence says nothing about its ODPC registration status. The two are assessed independently, by different regulators, against different criteria — by design, not by oversight.
Because SASRA's supervisory reach already feels thorough — governance reviews, risk-based supervision, periodic inspections — it's easy for a board to assume that being in good standing with SASRA means the SACCO's data handling is also covered. It doesn't. Registration with the ODPC, a documented lawful basis for processing member data, and a published privacy policy are ODPC-specific obligations that SASRA supervision does not test for.
Run our free 2-minute ODPC Compliance Self-Assessment to see your registration status and biggest data protection gaps — separate from, and in addition to, your SASRA compliance position.
The overlap isn't in the law itself — it's in the underlying operations. The same systems, files and third-party relationships a SASRA inspector reviews for prudential purposes are, at the same time, personal data processing activities regulated by the ODPC.
SASRA expects documented ICT and operational risk controls; data protection expects its own accountability records and safeguards. Related evidence, separate requirements.
The same member and loan files a SASRA inspection reviews for prudential completeness are personal data subject to the Data Protection Act's own principles.
SASRA's expectations around outsourced core functions (IT systems, credit reference checks) sit alongside the separate requirement for signed data processing agreements with those same vendors.
Significant IT or operational incidents may trigger SASRA reporting expectations and, independently, the ODPC's own breach-notification clock.
SASRA supervision does not check whether a SACCO has registered as a data controller, whether it has a documented lawful basis for processing member and guarantor data, or whether it has published a privacy policy — those are ODPC-specific obligations. Equally, the ODPC does not assess capital adequacy, liquidity ratios or governance structure. A SACCO can be a genuine model of data protection practice and still fall short of a prudential requirement, or the reverse. Neither regulator's approval substitutes for the other's.
Most SACCO boards already have a Risk & Audit Committee reporting on SASRA compliance. Far fewer have an equivalent structure asking data-protection-specific questions — and the DPO function, where it exists at all, is often informal or bundled into a compliance officer's already-full plate.
Named, with data protection explicitly in their mandate — not assumed to sit inside general risk.
Verified independently of SASRA licensing status.
Covering member, guarantor and staff data separately from the SASRA risk register.
Once for prudential/outsourcing risk, once for data processing terms — the same contract, two different checklists.
Timed to satisfy both any SASRA incident-reporting expectation and the ODPC's notification clock.
Not folded into a single "compliance" line item that only reflects SASRA status.
These are governance questions as much as they are compliance questions — and they're the ones a board should be able to answer before a regulator, either one, asks first.
Dual regulation is additive, not either/or. Treating "SASRA compliant" and "data protection compliant" as the same box on the same checklist gives a board a false sense of assurance — because the two regulators are, quite deliberately, asking different questions about the same institution. The SACCOs that get ahead of this are the ones that build governance structures that answer both, separately and explicitly, rather than hoping one covers the other.
If your SACCO's compliance reporting has a line for SASRA and nothing separately for the ODPC, that's usually the first gap worth closing — not because it's the biggest risk, but because it's the easiest one to miss entirely.
SASRA licensing and ODPC registration are two separate boxes to tick — not one. If your board's compliance reporting only has a line for SASRA, that's usually the first gap worth closing.
Muchangi Patrick & Associates Advocates advises SACCO boards, CEOs and compliance teams on data protection governance, ODPC registration and outsourced DPO support that sits alongside — not in place of — your SASRA compliance function.
Muchangi Patrick & Associates Advocates advises SACCOs, fintechs, startups and corporates on data protection compliance across Kenya — from ODPC registration and DPIAs to outsourced DPO services and cross-border data transfer advisory. If the overlap above touches your SACCO, we can help you close the gap.