Digital compliance for Kenyan schools — admissions portals, biometric attendance, learner photographs and third-party EdTech platforms, and the registration obligation most schools don't know applies to them.
Prepared by Muchangi Patrick & Associates Advocates
Book a Complimentary 10-Minute Digital Trust Gap AnalysisKenyan schools now run most of their operations through digital channels — online admissions, biometric attendance, school management platforms, and websites promoting school life through photographs of learners. Each of these channels collects, stores or displays data belonging to children, who are among the categories of data subject the Data Protection Act 2019 protects most closely.
Fewer schools realise that the Data Protection (Registration of Data Controllers and Data Processors) Regulations, 2021 name “educational institutions” as a sector subject to mandatory registration with the ODPC — regardless of turnover or employee count. The general small-entity exemption (turnover under KES 5 million and fewer than 10 employees) does not apply to schools. Most Kenyan schools that have never registered are not exempt; they are simply unregistered.
This Executive Brief sets out what that means in practice — and the questions every Board of Governors and proprietor should be able to answer about how their school governs the data of the children in its care.
Educational institutions must register with the ODPC regardless of turnover or headcount — the small-entity exemption does not apply.
A single mishandled admissions form or leaked class photo reaches parents faster than any regulator ever could.
Each issue below is examined in full within the Executive Brief, from admission through to the data a school still holds long after a learner has left.
Educational institutions are named as a mandatory registration category under the Data Protection (Registration) Regulations, 2021 — irrespective of the school's size or turnover.
Whether admission forms collect only what is necessary, and whether unsuccessful applicants' data is ever deleted.
Whether there is a distinct, recorded consent step for a child's data — separate from the general terms of enrolment.
Whether publishing images on a website or social media rests on a documented consent or opt-out mechanism.
Necessity and proportionality of biometric attendance data, and data processing agreements with School Management System providers.
Signage, retention and a clear policy distinguishing safeguarding from surveillance, particularly around classrooms.
Download a professionally formatted PDF suitable for Board circulation and executive discussion.
Get the next Executive Brief before it's published.
Board-level SACCO and data-governance briefings, direct to your inbox. No spam, unsubscribe any time.
If this Executive Brief raises governance questions relevant to your organisation, we would be pleased to discuss them with you. Explore current governance priorities, privacy and cybersecurity oversight, Digital Trust maturity, and practical next steps.
Phoenix Digital Trust Assurance is an independent governance methodology developed by Muchangi Patrick & Associates Advocates to assist Boards and executive leadership in strengthening organisational governance across privacy, cybersecurity, information governance, technology governance, artificial intelligence, third-party risk and continuous improvement.
The methodology promotes structured governance oversight rather than reactive compliance.
Muchangi Patrick & Associates Advocates is a Kenyan law firm specialising in Data Protection, Privacy, Digital Governance and Emerging Technology Law.
Through its Knowledge Centre and Phoenix Digital Trust Assurance initiative, the firm publishes practical governance resources designed to assist Boards and executive leadership in navigating the evolving digital economy.
Help us tailor future Executive Briefs to what Boards and executive teams actually need.
Educational Notice. This Executive Brief is published for educational and informational purposes only. It discusses general governance considerations and should not be interpreted as legal advice or an assessment of any particular organisation.
A short monthly briefing from the Kenya Privacy Law Review — new ODPC determinations, guidance notes, and compliance deadlines. No spam, unsubscribe anytime.