MP Muchangi Patrick& Associates Advocates
Talk to an Expert
Practice Areas Case Digest Knowledge Centre Insights About Contact Talk to an Expert
Home / Solutions / Policy & Procedure Drafting
Regulatory & Compliance

Policy & Procedure Drafting.

Policies should describe how your organisation actually handles data — and give staff a defensible procedure to follow when the law matters.

The service

Turn legal obligations into operational rules.

A policy that simply reproduces statutory language does not create a functioning compliance programme. We draft and review privacy and data-governance documents around the organisation's actual processing activities, responsibilities, systems and risk profile.

Scope matters. The precise legal and regulatory instruments reviewed depend on your sector, processing activities, contractual arrangements and the question you need answered.
01

Documents we can draft or review

Privacy policies and privacy notices for customers, employees, websites and digital products.

Data retention and deletion policies, schedules and operational procedures.

Data subject rights request procedures, escalation routes and response workflows.

Personal data breach response and notification procedures.

Data sharing, disclosure and third-party processing procedures.

Vendor, processor and data-protection contractual provisions and supporting procedures.

Internal data governance, accountability and role-based responsibilities.

02

How we approach drafting

Map the relevant processing activities and identify the legal obligations that the document must address.

Separate mandatory legal requirements from internal choices about risk, governance and business operations.

Draft in language that management and operational teams can actually use.

Align related documents so that privacy notices, contracts, retention rules and internal procedures do not contradict one another.

Identify implementation actions where a policy cannot work without a corresponding process, system control or contractual term.

03

Where this is particularly useful

Organisations preparing for ODPC registration or a compliance review.

Businesses introducing new digital products, CRM systems, HR systems or data-driven processes.

Companies using external processors, cloud services or international vendors.

Organisations responding to a breach, complaint, audit finding or regulatory concern.

Boards and management teams seeking a documented accountability framework.

Legal framework

Grounded in the rules that actually apply.

Depending on scope, drafting is informed by the Kenya Data Protection Act, 2019, the Data Protection (General) Regulations, 2021 and applicable ODPC guidance, together with sector requirements and contractual obligations. Where the GDPR applies, the relevant GDPR transparency, accountability, processor, security and international-transfer requirements are considered.

Questions

Common questions.

Will you use a generic privacy policy template?

Templates can provide a starting structure, but the final document should reflect the organisation's actual processing, purposes, recipients, retention practices and rights mechanisms. We draft to the agreed scope rather than simply supplying boilerplate.

Can you draft procedures as well as policies?

Yes. Procedures are often what make a policy operational — for example, a data subject request workflow or breach escalation procedure.

Can existing policies be reviewed instead of replaced?

Yes. We can conduct a targeted gap review and amend only what needs to change.

Need a clear compliance position?

Tell us what your organisation does, where the relevant data flows, and what decision you need to make. We can scope the legal review around the problem rather than around a generic checklist.