DATA PROTECTION MANUAL FOR NON-PROFIT ORGANISATIONS IN KENYA

A Practical Toolkit for Managing Privacy Within Your Non-Profit Organisation (1st Edition 2026)

Overview

Kenya’s non-profit organisations handle some of the country’s most sensitive personal information, including beneficiary records, health data, case files, and donor details, often without a clear path to legal compliance. This manual provides non-profit organisations in Kenya with a practical framework to bridge the gap between legal theory under the Data Protection Act, 2019 and real-world application. Developed out of a recognition that data protection is directly tied to the dignity, safety, autonomy, and trust of the communities served, this publication translates complex privacy laws into operational steps for non-profit staff.

Why this toolkit is essential

  • Built on Relationships of Trust: Non-profit work relies on community trust, making responsible data handling an ethical and operational necessity.
  • Grounded in Constitutional and Statutory Rights: Anchored in Article 31 of the Constitution of Kenya 2010 and operationalized by the Data Protection Act, 2019.
  • Tailored for Vulnerable Contexts: Provides specific safeguards for handling sensitive data belonging to survivors of violence, displaced persons, children, and marginalized communities.

Key modules covered in the manual

  • Introduction to Privacy: Explores privacy as a fundamental human right under Article 31 of the Constitution of Kenya and outlines multi-dimensional privacy typologies.
  • Informational Privacy and Data Protection: Clarifies distinctions between privacy, data protection, and data security, while mapping the full data lifecycle.
  • Legal and Regulatory Framework: Examines constitutional foundations alongside international and regional instruments, including the UDHR, ICCPR, GDPR, and the Malabo Convention.
  • The Data Protection Act, 2019: Breaks down statutory objects, key definitions, legal contexts such as the Huduma Namba controversy, and subsidiary regulations.
  • The Principles of Data Protection: Details the core Section 25 principles including purpose limitation, data minimisation, accuracy, storage limitation, and accountability.
  • Lawful Bases for Data Processing: Guides organisations on selecting valid legal grounds under Section 30(1) of the DPA, such as contractual necessity, legal obligation, and legitimate interest.
  • Consent and Vital Interests as Lawful Basis: Addresses valid consent conditions, safeguards for vulnerable populations, and emergency decision-making under vital interests.
  • Rights of Data Subjects: Explains individual rights under Section 26 of the DPA and operational steps for handling Data Subject Requests (DSRs) within 14-day statutory timelines.
  • Obligations of Data Handlers and Consequences of Non-Compliance: Covers responsibilities of data controllers and processors, mandatory registration, Data Protection Impact Assessments (DPIAs), Data Protection Officers (DPOs), and 72-hour breach notifications.
  • Cross-Border Data Transfer: Details legal mechanisms for international data transfers, including adequacy decisions, Standard Contractual Clauses (SCCs), cloud services, and Transfer Impact Assessments (TIAs).
  • Setting Up a Privacy Program: Delivers an operational guide across 13 core components, featuring Records of Processing Activities (ROPA), data classification, and incident management.
  • The Office of the Data Protection Commissioner (ODPC): Explains the statutory mandate, oversight functions, complaint handling procedures, and enforcement mechanisms of the ODPC.

Who should read this manual

  • Executive Leaders and Board Members seeking sector-specific compliance and governance frameworks.
  • Data Protection Officers (DPOs) and Compliance Leads designing and operating internal privacy programs.
  • Programme Officers and Field Staff managing beneficiary intake, surveys, case records, and community engagements.
  • M&E Personnel and IT Administrators establishing secure data collection, cloud storage, and transfer protocols.

Author and Publishing Partners

This manual is an initiative of Amnesty International Kenya, authored by Victor Ndede, Aurelia Miheso, Danford Momanyi, Philip Kisaka, Teresia Wanjiku, Zeddy Misiga, and Mary Angela Odhiambo. It was developed through a collaboration between Amnesty International Kenya, DPO 360 Africa Limited, and ICON Data and Learning Labs.