Home / Knowledge Centre / Webinars
KPLR Boardroom Briefings — Session 01

The Guarantor Gap: The Data Protection Risk in Every SACCO Loan File

A live working session for SACCO directors, CEOs, company secretaries and compliance officers — on the data subject sitting on every loan file that almost nobody treats as one.

Wednesday, 12 August 2026 2:00 – 3:00 PM EAT Live via Zoom Hosted by Patrick Muchangi
About the Executive Briefing

Guarantor information is fundamental to SACCO lending. Yet the collection, verification, use, disclosure, and retention of guarantor personal data raise important obligations under Kenya's Data Protection Act, 2019. Drawing on lessons from a real complaint before the Office of the Data Protection Commissioner (ODPC Complaint No. 1966 of 2024), this executive briefing examines how routine lending processes can create unintended legal, regulatory, and governance risks — and the practical measures SACCOs can implement to strengthen compliance.

FormatLive, 60 minutes + Q&A
AudienceBoards & Management
CostFree to attend
RecordingSent to registrants

Companion reading: The Hidden Data Protection Liability in Every SACCO Loan File →

Free cheat sheet: 18 SACCO Data Protection Red Flags →

The Blind Spot

Your credit policy has a consent trail for the borrower. Does it have one for the guarantor?

Most SACCO data protection reviews start and end with the member applying for the loan — the KYC form, the credit check, the disbursement. The guarantor is treated as paperwork: a signature that makes the loan possible, not a person whose ID number, phone number, employer and salary details are now sitting in your files and, in many cases, being shared with credit reference bureaus, employers, or recovery agents.

The ODPC's 2024 enforcement record shows that gap is exactly where regulators are now looking. A lawful basis for processing the borrower's data does not automatically extend to the guarantor's — origination, credit scoring, debt collection and account closure are each treated as needing their own basis. For a SACCO board, that turns "we have consent to lend" from an answer into a question with several parts.

This briefing sets out, in practical terms, what a defensible guarantor data file looks like — and what to fix on Monday morning if yours doesn't.

Agenda

60 minutes, four working parts.

2:00 PM

The determination, in plain terms

What ODPC Complaint No. 1966 of 2024 actually found, and why "we have the borrower's consent" wasn't a defence.

2:15 PM

Mapping your guarantor data lifecycle

Where guarantor data enters your SACCO, where it's stored, and every point it's shared onward — CRBs, employers, recovery agents.

2:35 PM

What a defensible file looks like

The lawful basis, documentation and consent language a guarantor file needs to withstand an ODPC inquiry.

2:50 PM

Live Q&A

Bring your SACCO's specific guarantorship process — we'll work through it live where time allows.

What You Will Learn

Five things you'll walk away able to do.

The legal status of guarantor personal data under the Data Protection Act, 2019.

Common data protection risks arising during loan processing and guarantor management.

Lessons from recent regulatory enforcement.

Governance measures SACCOs should implement to reduce legal and operational risk.

Practical recommendations for strengthening compliance within lending operations.

Why Attend

Practical insight into where regulatory expectations are heading.

Participants will gain practical insights into emerging regulatory expectations and governance considerations affecting the management of guarantor information within SACCO lending operations.

Who Should Attend

Built for the people who own this risk.

Board Directors
Chief Executive Officers
Legal Officers
Compliance Officers
Risk Managers
Credit Managers
Internal Auditors
Data Protection Officers
ICT Managers
Senior Operations Managers
Your Host

Led by the firm's founder.

Patrick Muchangi, Advocate of the High Court of Kenya

Muchangi Patrick

Advocate of the High Court of Kenya · Data Privacy & Protection Lawyer

Managing Partner, Muchangi Patrick & Associates Advocates, and Founder of the Kenya Privacy Law Review (KPLR). Patrick advises technology companies, financial institutions and public bodies on data protection, ODPC compliance and technology law in Nairobi.

He publishes the Kenya Privacy Law Review, tracking ODPC determinations and High Court data protection jurisprudence as they're decided, and regularly advises SACCOs and digital lenders on the practical side of Data Protection Act compliance.

Registration

Attendance is complimentary, but registration is required.

Can't make the live session? Register anyway — we'll send the recording and slides to everyone who signs up.

You'll receive the Zoom link by email ahead of the session, plus the recording and slides afterward. We'll also add you to the KPLR monthly briefing — unsubscribe anytime.

You're registered.

Look out for an email with the Zoom link ahead of 12 August. See you there.

Important Notice. This executive briefing is provided for educational and professional development purposes. It does not constitute legal advice. Participants requiring advice on specific circumstances should seek independent legal counsel.

Stay ahead of Kenya's data protection & AI regulation

A short monthly briefing from the Kenya Privacy Law Review — new ODPC determinations, guidance notes, and compliance deadlines. No spam, unsubscribe anytime.