KPLR Academy/Data Protection & GDPR Compliance: A Practical Course Manual
Cover of Data Protection & GDPR Compliance: A Practical Course Manual
KPLR/ACAD/001/2026 Course Manual Data Protection & GDPR
KPLR Academy · Professional Legal Certification Programme

Data Protection & GDPR Compliance: A Practical Course Manual

Kenya DPA 2019 compared with UK/EU GDPR — for legal & compliance practitioners

Author
Patrick Muchangi
Published
July 2026
Format
27 pages · PDF & Online
Version
1.0
Editorial Status
Published
Language
English
Abstract

This manual is the core teaching text of the KPLR Academy's professional legal certification programme in Data Protection & GDPR Compliance. It traces the evolution of privacy law from the 1948 Universal Declaration of Human Rights to Kenya's Data Protection Act, 2019, and works through three practitioner modules — legal definitions and principles, DPIAs and technical safeguards, and the DPO/DSAR/breach-notification framework — comparing the Kenyan regime section-by-section against the UK/EU GDPR throughout.

Who This Manual Is For

Advocates, compliance officers, Data Protection Officers and governance professionals preparing to advise Kenyan organisations — schools, SACCOs, healthcare providers, hospitality venues and corporates — on data protection audits, staff training and retainer compliance work, benchmarked throughout against the UK/EU GDPR for organisations with cross-border exposure.

Day 1 · The Evolutionary Timeline of Privacy Law

The course begins by tracing the legal journey from post-war human rights declarations to enforceable digital data governance, across four phases.

Phase 1 (1948) — The Post-WWII International Foundation

Article 12 of the Universal Declaration of Human Rights protected privacy through a spatial, physical and territorial lens — a negative right shielding the individual's body, home and correspondence from state intrusion. It contained no concept of informational self-determination, since computer networks and digital profiles did not yet exist.

Phase 2 (1980–1995) — The Digital Shift & The European Blueprint

The OECD's 1980 Privacy Guidelines introduced data minimisation and purpose limitation as the baseline vocabulary of modern data protection law. The EU's Data Protection Directive 95/46/EC (1995) then legally defined data controllers and processors for the first time — but, as a directive rather than a regulation, left enforcement fragmented across EU member states, each writing its own national implementing law.

Phase 3 (2016/2018) — The Golden Standard: The EU GDPR

The GDPR, adopted in 2016 and enforceable from May 2018, introduced extraterritorial effect (applying to any organisation processing EU residents' data regardless of location), severe penalties (up to €20 million or 4% of global turnover), enhanced rights (erasure and portability), and the Privacy by Design obligation to build security into systems before launch.

Phase 4 (2010–present) — The Kenyan Constitutional & Statutory Framework

Article 31 of the Constitution of Kenya, 2010 created the constitutional right to privacy, but lacked administrative machinery. Parliament's Data Protection Act, 2019 gave that right operational teeth: establishing the Office of the Data Protection Commissioner (ODPC), translating "information unnecessarily required" (Art. 31(c)) into the statutory principle of data minimisation (s.25), translating "privacy of communications infringed" (Art. 31(d)) into direct-marketing penalties (s.37), and importing a GDPR-style fine mechanism of up to KES 5 million.

Section 2 of the Kenya DPA classifies the actors, data types and roles that every other provision of the Act builds on.

Module 1 · The 8 Core Data Protection Principles

Sections 25 and 30 of the Kenya DPA are mapped throughout the manual against Articles 5 and 6 of the UK GDPR. Each principle carries a practitioner application and an audit red flag:

  1. Lawfulness, Fairness & Transparency (s.25(a) / Art. 5(1)(a)) — a clear privacy notice must accompany any collection; the red flag is tracking or intake with no visible notice.
  2. Purpose Limitation (s.25(b) / Art. 5(1)(b)) — data gathered for one purpose (e.g. appointment reminders) cannot be repurposed for marketing without fresh consent.
  3. Data Minimisation (s.25(c) / Art. 5(1)(c)) — intake forms should collect only what the service strictly requires.
  4. Data Accuracy (s.25(d) / Art. 5(1)(d)) — organisations must provide a functional route for subjects to correct outdated records.
  5. Storage Limitation (s.25(e) + s.39 / Art. 5(1)(e)) — requires an active data retention and secure disposal schedule.
  6. Data Subject Rights Realisation (s.25(f) + s.26 / Arts. 12–23) — an accessible channel (e.g. a dedicated privacy inbox) must exist for subjects to exercise their rights.
  7. International Transfer Restrictions (s.25(g) + ss.48–50 / Arts. 44–50) — cross-border hosting requires verifying the destination's adequacy or filing transfer confirmations with the ODPC.
  8. Data Security & Technical Safeguards (s.25(h) + s.41 / Art. 5(1)(f)) — HTTPS, database access locks and staff training are baseline expectations; the classic red flag is an unencrypted HTTP intake form capturing ID numbers.

Processing is unlawful unless it passes through a mandatory gateway under s.30(1) of the DPA or Article 6(1) GDPR: explicit consent (freely given, specific, informed, unambiguous — pre-ticked boxes are invalid in both regimes); performance of a contract; a legal obligation on the controller; protection of vital interests (strictly life-or-death); performance of a public task; and legitimate interests, which requires a documented Legitimate Interests Assessment balancing the business's interest against the subject's rights.

Module 1 · Compliance Audit Framework & Risk Register

A practical audit walks four recurring exposure points: user intake channels running over unencrypted HTTP; marketing campaigns lacking a functional opt-out; open physical visitor logbooks; and indefinite retention of historical customer profiles — each mapped to its statutory violation and required remediation.

Module 2 · Data Protection Impact Assessments (DPIAs)

Under s.31 DPA and Article 35 UK GDPR, a DPIA is mandatory before processing likely to create high risk to data subjects, triggered by: systematic and extensive automated evaluation or profiling; large-scale processing of special-category data; systematic monitoring of publicly accessible areas (e.g. commercial CCTV); or deployment of new technologies such as AI, drones or biometric tracking. In Kenya, the completed DPIA must go to the ODPC 60 days before launch, and the regulator can issue a stop order; in the UK, the controller screens internally and only escalates to the ICO under Article 36 if residual risk stays high.

A complete DPIA documents: a systemic description of the data flow; a necessity assessment; a risk log of vulnerabilities; and a mitigation matrix of the specific technical defences deployed.

Module 2 · The Mathematical Risk Quantification Protocol

DPOs are taught to quantify risk with the formula R = L × I (Risk = Likelihood × Severity of Impact), each scored 1–5. A worked case study — a hospital registration app transmitting diagnoses over unencrypted HTTP — scores an initial 5×5 = 25 (critical exposure). After forcing TLS, restricting database access via MFA and adding data obfuscation, the residual score falls to 1×2 = 2 (safe range), demonstrating the protocol's use both before and after remediation.

Module 2 · Technical & Organisational Measures (TOMs)

Section 41 DPA and Article 32 UK GDPR require active security controls. Technical safeguards include TLS 1.3 in transit, AES-256 encryption at rest, pseudonymisation, and automated vulnerability scanning. Organisational safeguards include role-based access control (a receptionist should never reach payroll or health records) and clean-desk policies. Every external vendor handling company data — a bulk-SMS platform, a cloud host — must execute a Section 42 Data Processing Agreement before receiving any data.

Module 3 · The DPO Mandate

Section 24 DPA (mirrored by Article 37 UK GDPR) makes DPO designation mandatory for public authorities, and for organisations whose core activities involve large-scale systematic monitoring or large-scale processing of sensitive personal data — in practice, schools, healthcare providers, hospitality venues and financial or micro-lending businesses in Kenya, regardless of size. The DPO must report to the highest level of management and is statutorily protected from dismissal for performing their monitoring duties. Combining the DPO role with CTO, Head of Marketing or CEO is an illegal conflict of interest, since the DPO cannot independently audit systems they themselves designed or manage for growth.

Module 3 · Data Subject Access Requests

Sections 26–27 DPA grant rights of confirmation and access, rectification, erasure and objection to marketing; Kenya allows 21 days to respond, the UK GDPR one calendar month. The corporate intake protocol runs four steps: verify the requester's identity; assess whether the request seeks access, erasure or rectification; redact any third parties' details before releasing extracts; and issue the structured response within the statutory window, free of charge.

Module 3 · The 72-Hour Breach Notification Protocol

A breach is not limited to external hacking — it includes unauthorised internal access, accidental deletion or physical loss of an encrypted device. Section 43(1) DPA and Article 33 UK GDPR require notifying the regulator within 72 hours of becoming aware, unless the leak is unlikely to create risk to individuals; affected subjects must be told without delay where the risk to them is high. Under s.43(2), a processor who discovers a leak must notify the controller immediately. A compliant breach report states the nature of the breach, the DPO's contact details, the realistic risk consequences, and the remediation steps taken.

Module 3 · The Corporate Privacy Register

Under the accountability principle, the DPO maintains three living records: a Record of Processing Activities (ROPA) mapping every data pipeline — HR payroll, marketing, CCTV — to its purpose, access holders, storage location and destruction date; an internal Data Breach Register capturing every incident, including those below the 72-hour regulatory threshold; and a Consent Lifecycle Log recording exactly when and how each data subject's consent (and any subsequent opt-out) was captured.

Course Completion Checklist

Disclaimer: This publication is provided for general informational purposes and does not constitute legal advice. Reading this publication does not create an advocate-client relationship with Muchangi Patrick & Associates Advocates. For advice on a specific matter, please book a consultation.
PM

Patrick Muchangi

Advocate of the High Court of Kenya · Founder, Muchangi Patrick & Associates Advocates

Patrick Muchangi is an Advocate of the High Court of Kenya and founder of Muchangi Patrick & Associates Advocates, a Nairobi practice specialising in data protection, privacy, AI governance and technology law, and editor of the Kenya Privacy Law Review.