A live working session for SACCO directors, CEOs, company secretaries and compliance officers — on the data subject sitting on every loan file that almost nobody treats as one.
Guarantor information is fundamental to SACCO lending. Yet the collection, verification, use, disclosure, and retention of guarantor personal data raise important obligations under Kenya's Data Protection Act, 2019. Drawing on lessons from a real complaint before the Office of the Data Protection Commissioner (ODPC Complaint No. 1966 of 2024), this executive briefing examines how routine lending processes can create unintended legal, regulatory, and governance risks — and the practical measures SACCOs can implement to strengthen compliance.
Companion reading: The Hidden Data Protection Liability in Every SACCO Loan File →
Free cheat sheet: 18 SACCO Data Protection Red Flags →
Most SACCO data protection reviews start and end with the member applying for the loan — the KYC form, the credit check, the disbursement. The guarantor is treated as paperwork: a signature that makes the loan possible, not a person whose ID number, phone number, employer and salary details are now sitting in your files and, in many cases, being shared with credit reference bureaus, employers, or recovery agents.
The ODPC's 2024 enforcement record shows that gap is exactly where regulators are now looking. A lawful basis for processing the borrower's data does not automatically extend to the guarantor's — origination, credit scoring, debt collection and account closure are each treated as needing their own basis. For a SACCO board, that turns "we have consent to lend" from an answer into a question with several parts.
This briefing sets out, in practical terms, what a defensible guarantor data file looks like — and what to fix on Monday morning if yours doesn't.
What ODPC Complaint No. 1966 of 2024 actually found, and why "we have the borrower's consent" wasn't a defence.
Where guarantor data enters your SACCO, where it's stored, and every point it's shared onward — CRBs, employers, recovery agents.
The lawful basis, documentation and consent language a guarantor file needs to withstand an ODPC inquiry.
Bring your SACCO's specific guarantorship process — we'll work through it live where time allows.
The legal status of guarantor personal data under the Data Protection Act, 2019.
Common data protection risks arising during loan processing and guarantor management.
Lessons from recent regulatory enforcement.
Governance measures SACCOs should implement to reduce legal and operational risk.
Practical recommendations for strengthening compliance within lending operations.
Participants will gain practical insights into emerging regulatory expectations and governance considerations affecting the management of guarantor information within SACCO lending operations.

Managing Partner, Muchangi Patrick & Associates Advocates, and Founder of the Kenya Privacy Law Review (KPLR). Patrick advises technology companies, financial institutions and public bodies on data protection, ODPC compliance and technology law in Nairobi.
He publishes the Kenya Privacy Law Review, tracking ODPC determinations and High Court data protection jurisprudence as they're decided, and regularly advises SACCOs and digital lenders on the practical side of Data Protection Act compliance.
Can't make the live session? Register anyway — we'll send the recording and slides to everyone who signs up.
Look out for an email with the Zoom link ahead of 12 August. See you there.
Important Notice. This executive briefing is provided for educational and professional development purposes. It does not constitute legal advice. Participants requiring advice on specific circumstances should seek independent legal counsel.
A short monthly briefing from the Kenya Privacy Law Review — new ODPC determinations, guidance notes, and compliance deadlines. No spam, unsubscribe anytime.