What separates an institution that manages a data breach from one a data breach manages.
Download PDFNo institution can guarantee it will never suffer a data breach. What every institution can control is what happens in the hours immediately afterward — and it is that response, more than the incident itself, that regulators, clients and courts will ultimately judge.
Kenya’s data protection framework expects controllers to notify the Office of the Data Protection Commissioner and affected data subjects without undue delay once a breach is identified — a standard increasingly benchmarked, in practice and in comparable frameworks such as the GDPR, against a 72-hour window. Few institutions have genuinely rehearsed what those hours would look like.
This analysis sets out why the earliest hours of a breach are where governance is tested most severely, and what a Board should have in place long before it needs it.
The technical part of a breach — the vulnerability, the intrusion, the exfiltration — is usually over by the time anyone senior finds out about it.
What happens next is a governance test: how quickly the organisation understands what occurred, decides what it owes to whom, and communicates before the narrative is written for it by someone else.
02Kenya’s data protection regulations require notification of a breach to the regulator and affected individuals without undue delay. Many organisations, in our experience, treat “without undue delay” as licence to deliberate for days.
The safer institutional posture — and the one increasingly expected in practice — treats notification within roughly 72 hours as the working standard, the same benchmark used under the GDPR, rather than the outer limit of what is acceptable.
03Plans fail early, not late. The most common failure is not a lack of technical capability but a lack of clarity about authority: who is allowed to say a breach has occurred, who can authorise notifying the regulator, and who speaks to the press — questions that should never be decided for the first time during an actual incident.
Before an incident, the Board’s role is to ensure a credible plan exists and has been tested. During an incident, the Board’s role is oversight and rapid decision-making, not day-to-day management of the response. After an incident, the Board’s role is to ensure the organisation learns from it — genuinely, not only in the language of a post-incident report nobody revisits.
05Every Board should be able to put the following questions to management, and expect a considered answer:
Do we have a named incident lead with pre-delegated authority to act immediately?
Is legal counsel retained and briefed before an incident, not found during one?
When did we last rehearse our breach response, and what did the rehearsal reveal?
What is our internal threshold for notifying the Board, and has it ever been tested?
Do we have a pre-approved communication template ready to adapt, not draft from scratch?
How would we demonstrate, after the fact, that we notified without undue delay?
A breach tests an institution’s governance more honestly than almost any other event, because it happens on a timeline the institution does not control. The Boards that come through it with their credibility intact are, almost without exception, the ones that rehearsed the hours before they ever needed them.
“If notified of a serious breach at 6 p.m. on a Friday, does your organisation know exactly what happens next?”
If the honest answer is uncertain, a rehearsed breach playbook — tested before it is needed — is the most consequential gap to close.
We help leadership teams understand, govern and continuously improve Digital Trust through structured, evidence-based advisory engagements.
A short monthly briefing from the Kenya Privacy Law Review — new ODPC determinations, guidance notes, and compliance deadlines. No spam, unsubscribe anytime.