Regulatory Review.
A structured legal review of the rules that apply to your organisation, the obligations they create, and the gaps between those obligations and what your business actually does.
Know what the rules require — before the regulator does.
Regulatory exposure rarely comes from one statute in isolation. It sits at the intersection of legislation, regulations, regulator guidance, contracts, internal policies and the way data and technology are actually used. We review that landscape and translate it into a practical compliance position for management.
What we review
Applicable data protection and privacy obligations, including the Data Protection Act and relevant regulations.
Regulatory requirements affecting digital products, customer onboarding, marketing, records, vendors and technology-enabled processing.
Existing policies, procedures, notices, contracts and governance documents against the obligations that actually apply.
Regulatory correspondence, emerging guidance and enforcement themes relevant to the organisation's risk profile.
What you receive
A scoped regulatory obligations matrix identifying the rules and requirements relevant to the engagement.
A gap analysis separating legal requirements, governance weaknesses and operational implementation issues.
Prioritised recommendations, distinguishing urgent remediation from medium-term governance improvements.
Practical drafting or remediation support where the review identifies a document, process or contractual gap.
Typical triggers for a review
Launching a new product, platform, data-driven service or technology.
Entering a new sector, market or regulatory environment.
Changing vendors, processors, cloud infrastructure or data flows.
Preparing for an audit, board review, regulator engagement or transaction.
Responding to a regulatory development that may change existing compliance assumptions.
Grounded in the rules that actually apply.
The review is scoped to the laws and regulatory instruments that actually apply to the client. Depending on the engagement, this may include the Kenya Data Protection Act, 2019 and subsidiary regulations, ODPC guidance, sector-specific requirements, contractual obligations and other digital-regulatory instruments.
Common questions.
Is this the same as an audit?
Not necessarily. A regulatory review is a legal and compliance assessment of the obligations and gaps within an agreed scope. A broader operational or technical audit can be added where the engagement requires it.
Can you review a specific regulation or regulator requirement?
Yes. A review can be narrowly scoped to a particular regulatory change, notice, sector requirement, product launch or compliance question.
Do you also help implement the recommendations?
Yes. Where agreed, the review can be followed by policy drafting, contract remediation, process changes, training or ongoing compliance support.
Need a clear compliance position?
Tell us what your organisation does, where the relevant data flows, and what decision you need to make. We can scope the legal review around the problem rather than around a generic checklist.