ROMER · Insights
Informational only · not legal advice
romer.co.ke
Issue 01
Quarter 1 · 2026
Spotlight · Third-Party Compliance
Six Years In:
Are We There Yet?
Marking six years of Kenya’s Data Protection Act, and why your compliance is only as strong as your weakest vendor.

In this issue
01Half Year in Reviewpublic sector & HR
02Third-Party Riskthe 2025 cases
03Looking Ahead2026 radar
04How Romer Can Help
From the CEO
A note from Mercy Barasa
CEO & Founder, Romer
As we settle into the second half of 2026, we also mark six years since the Data Protection Act (DPA) came into force in Kenya. Initially the DPA was perceived as a barrier to growth. Businesses were adapting to digital operations, and suddenly the law required new measures, new processes and new accountability, which meant additional expense.
But the DPA was never meant to slow businesses down. It was designed to protect the very people who enable our organisations to exist: our customers, users, members, patients and employees. It reminded us that personal data is not just any other data set: it is an extension of people, and therefore must be treated with dignity, care and responsibility.
Today we have seen a remarkable shift. Many organisations have moved beyond the mindset of “comply because the law requires it” to embracing data protection from a strategic standpoint, as a competitive advantage and a driver of trust. This year’s Data Privacy Day theme, “Trust the Data, Drive the Future,” underscored exactly that: highlighting the importance of good governance in AI, secure cross-border data flows and stronger privacy frameworks as foundations for a thriving digital economy.
40%+
of complaints in our review of recent ODPC determinations came from the digital credit / finance and insurance sectors. Many violations trace not to weak internal controls, but to third-party service providers.
This is why, in this newsletter, we place a spotlight on third-party compliance. As more businesses rely on outsourced services, vendor management and accountability have become essential pillars of effective data protection compliance.
“Remember: you are only as strong
as your weakest link.”
MERCY BARASA, CEO & FOUNDER

01
2026 Half Year · Follow our journey
The Highlights
From the public sector to human resources
22–24 APR 2026
Naivasha · Public Sector Workshop
Public Interest Is Not a Free Pass
Why data protection compliance still matters in the public sector

One of the most interesting discussions during the recent Data Protection for the Public Sector workshop centred on a question many public officers have asked since the Act was enacted: “If most government processing is necessary for national security or undertaken in the public interest, are public institutions really required to comply with the Data Protection Act?”
Government institutions collect and process personal data to issue national identity documents, administer healthcare, collect taxes, deliver social protection programmes, conduct censuses, manage public finances and implement national development initiatives, most under statutory mandates and for the benefit of the public. Many participants therefore expressed the view that these activities fall within the exemptions relating to public interest, public authority and national security. As the discussions progressed, and as we examined the recently issued ODPC Guidance Notes for the Public Sector, a different picture emerged.
The guidance makes it clear that public institutions are subject to the Act and its Regulations whenever they process personal data. Exercising official authority or pursuing a public interest objective does not remove the obligation to comply. Public interest and official authority allow government entities to process personal data without relying on consent in many circumstances, and may limit certain data subject rights where exercising them would undermine the public purpose. A citizen may not always be able to object or demand erasure where processing is necessary for public health monitoring or law enforcement. Yet this does not exempt public institutions from the core principles of data protection.
“Public interest may justify processing, but it does not eliminate responsibility.”
Workshop takeaway
Public entities must still process personal data lawfully, fairly and transparently. They must collect only what is necessary for a specific purpose, keep it accurate, apply appropriate security safeguards, maintain accountability mechanisms and set clear retention periods. They must provide privacy notices, facilitate applicable data subject rights, conduct Data Protection Impact Assessments for high-risk processing, report breaches, implement privacy by design and register where required.
Too often, compliance is viewed as a regulatory checkbox exercise, something completed because the law requires it. In reality, compliance is a strategic asset. Trust is one of the most valuable resources any government can possess: citizens are more willing to share information, adopt digital services and support innovation when they trust the institutions processing their data. Conversely, a lack of trust can slow national progress. The Huduma Namba case is a powerful example: a transformative national digital identity initiative stalled by concerns around privacy, safeguards, exclusion and governance. The issue was never simply about technology. It was about trust.

As Kenya advances towards greater digitalisation and data-driven governance, guided by the Kenya National Digital Master Plan 2022–2032’s vision of a connected, citizen-centric ecosystem, that trust becomes even more critical. Achieving the vision requires more than technology infrastructure. It requires trusted infrastructure.
8 MAY 2026
Nairobi · Inaugural HR Data Protection Summit
Employers: Stop Using Consent as a Default Legal Basis

At our inaugural HR data protection summit, one issue kept resurfacing: the reliance on consent as the default legal basis for processing employee data. What surprised many attendees was the realisation that consent is often the weakest and least reliable lawful basis available. Can an employee realistically “opt out” of performance monitoring, attendance tracking or workplace supervision without worrying how that decision might be perceived? In most cases, no. The employer–employee relationship is inherently unequal, which makes it difficult to prove consent was freely given.
Employers therefore need to move away from placing every HR process under blanket consent clauses. The legal basis should be carefully matched to the specific activity. During recruitment, employers may rely on consent at the initial application stage, but the primary basis for most recruitment processing is contractual necessity. Employers should clearly explain why particular information is collected: to assess qualifications, verify eligibility to work or evaluate suitability. Transparency matters.
Once a candidate receives an offer, “performance of a contract” becomes the basis for processing. Payroll, benefits, work schedules, performance evaluations, staff badges and attendance records all fall squarely within contractual necessity: an employer does not need consent to process salary information or record working hours, because these are directly tied to the role and the employer’s obligations under the contract.
There are also circumstances where employers have a legitimate interest, such as monitoring system access, maintaining training records, or implementing reasonable security, provided employees’ privacy rights are not unfairly overridden. The key requirement is proportionality: a balancing exercise ensuring the processing is necessary, reasonable and connected to a clear business purpose. At the end of the employment cycle, it is good practice to inform the employee or seek permission before giving references, often addressed through exit documentation or employment policies.
By the close of the summit, we concluded that consent is only appropriate where participation is genuinely optional and unrelated to the core employment relationship, for example asking whether an employee would like their photo featured in a company brochure or on social media, which they can reasonably decline without repercussions. Ultimately, identify the correct legal basis for each activity, stay transparent, and process only where necessary, proportionate and lawful.
02
Emerging issues · the 2025 determinations
Third-Party Risk
Holding the Reins
Who’s responsible when a third party gets it wrong?
Under Kenya’s Data Protection Act, there are a few key roles every organisation needs to understand, because confusing the roles is where the problems begin.

Data Controller
Decides what personal data to collect and why. You can outsource the work, but not the responsibility.
Data Processor
A vendor handling data on your behalf: payroll, cloud storage, debt collectors, marketing platforms. Your liability follows them.
Joint Controllers
When two organisations jointly decide how data is used, e.g. a bank and insurer co-creating a bancassurance product, they share responsibility.
Sub-Processors
Your processor’s processor. If a marketing vendor stores your client contacts on a cloud server, that cloud provider is a sub-processor.
In the Hot Seat
Real ODPC cases · real money · real lessons
The ODPC issued over 100 decisions in 2025. Here are the ones every business working with third parties needs to read.
ODPC/COMP/1951/2024Finance / Credit
KES 400,000
What happened
The complainant, who was not a customer, received unsolicited promotional messages, later found to be sent by an independent sales agent. He had never consented to marketing. The company’s defence: the agent was independent and the complainant was not its customer.
The takeaway
The ODPC held the organisation fully liable for its agent. A data controller must ensure any agent processing personal data on its behalf does so lawfully.
ODPC/COMP/1473/2024Finance / Credit
KES 900,000
What happened
The complainant received marketing calls and texts from an independent sales agent without consent. He asked the agent to stop and delete his information, but the messages continued. The organisation argued the agent was no longer under their employment, so they were not responsible.
The takeaway
The ODPC found the organisation liable for violating the complainant’s right to stop unsolicited messages, and emphasised that organisations must sign separate Data Processing Agreements with independent sales agents, distinct from the general commercial contract.
PS: DPAs should contain clauses that protect the Data Controller even after the commercial contract expires.
ODPC/COMP/1501/2025Finance / Credit
KES 500,000
What happened
The complainant received over 50 unsolicited promotional texts between February and May 2025, continuing through September despite express instructions to stop. The organisation argued the messages came from “unaffiliated” or “rogue” agents and were not sent through its official systems.
The takeaway
The ODPC found the organisation liable: the messages promoted its services and came from agents in its marketing operations. Absent evidence to the contrary, an agent’s acts are attributable to the organisation, which failed to show it took effective steps to block or delete the contact after her objection.
ODPC/COMP/1551/2025Insurance
KES 412,500
What happened
The complainant received unsolicited marketing emails dating back to 2020 despite never having a relationship with the company or consenting. She requested to stop and to delete her data in June 2025, but communications continued. The organisation claimed the data was collected voluntarily by its field sales team but could not produce documentary evidence of consent.
The takeaway
The ODPC held the organisation liable for unlawful processing without consent and for violating the right to be informed, emphasising that the burden of proving valid consent lies with the data controller, and it failed to provide credible evidence.
Protecting Yourself
A practical framework for auditing third parties
Knowing you’re responsible is one thing. Doing something about it is another. Here’s how to start getting your third-party house in order.
1
Know who your processors are
Your Records of Processing Activities (ROPA) should list every vendor that touches personal data: cloud storage, payroll, email platforms, CRM tools, debt collectors, everyone. If you don’t have one, start there.
2
Make sure the paperwork exists
Every processor needs a Data Processing Agreement (DPA), not just a commercial contract. A DPA must cover:
✓What data is processed, and why
✓Confidentiality obligations
✓How data subject rights are handled
✓Breach notification timelines
✓Your right to audit
Compliance Checklist
A quick self-audit: where do you stand right now?
Vendor inventory
Up-to-date ROPA listing every processor
Every processor has a signed DPA (not just a service contract)
All DPAs reviewed at least annually
Agents & field staff
Agents covered by a DPA or equivalent
Agents have received data protection training
Agents collect consent in an evidenced format
Incident readiness
DPAs require processors to notify you of breaches immediately
A process to report breaches to the ODPC within 72 hours
High-risk processing
You conduct DPIAs before launching high-risk projects
Joint-controller DPIA responsibility is clearly allocated
Ticked fewer than half? Your exposure is significant. Our Data Protection Gap Analysis is built for exactly this: we check where you are, identify the gaps, and give you a clear roadmap to close them.
3
Match your scrutiny to your risk
Not every vendor carries the same exposure. Concentrate your due diligence, contractual safeguards and audit frequency on the processors handling the most, or the most sensitive, personal data.
Auditing Your
3rd Party
Processors
A risk-proportionate framework
for vendor compliance
Step 1 of 2
Determine the processing
and processor risk profile
Low risk
Medium risk
High risk
#1How many people?
Number of data subjects whose data is shared with the processor
1 pt · under 1,0002 pts · 1,000–10,0003 pts · 10,000+
#2Special category data?
Does the processor handle special category personal data, such as health, biometrics, or racial/ethnic origin?
Health, genetic, biometric, political, religious, financial data
+3 points if yes
#3Otherwise sensitive?
Personal data that, if made public, could embarrass, harm, or be used for ID theft or similar
+2 points if yes
#4Intrusive processing?
Profiling, exact location tracking, systematic monitoring, or combining data sets to create new insights
+2 points if yes
#5Summarise & select audit concept
Add your points. Your total indicates the appropriate audit concept for this processor.
1–2 ptsChoose from concepts 1–6
3–4 ptsChoose from concepts 2–6
5–6 ptsChoose from concepts 3–6
7–10 ptsChoose from concepts 5–6
#6Audit & document
Plan, conduct, and record your audits. Log everything in your ROPA and repeat at set intervals.
✓DPA in place & current
✓Risk tier assigned
✓Audit conducted & logged
✓Next review date set
The 6 Audit Concepts
Concept 1
Passive monitoring
No active audit needed. Monitor public news for incidents. Act only if something surfaces.
Concept 2
Regular confirmation
Periodic written confirmation from the processor of ongoing DPA compliance. Annually or bi-annually.
Concept 3
Annual confirmation
Structured annual audit. Processor confirms compliance, discloses breaches and any sub-processor changes.
Concept 4
Certification check
Verify the processor holds a recognised certification (e.g. ISO 27001) covering your processing. Keep a copy.
Concept 5
3rd-party audit
Commission an independent external audit (e.g. ISAE 3000). Covers all processing done on your behalf.
Concept 6
Full risk assessment
Structured risk assessment first, then a targeted deep-dive audit with questionnaires, docs review, and on-site inspection.
Before you begin · get your foundations right
Build a complete ROPA (Records of Processing Activities)
All processors listed
Cloud, payroll, email, CRM, agents: every vendor that touches personal data
DPA in place
A written Data Processing Agreement with every processor, not just a service contract
DPAs are current
No references to old legislation or expired terms
Transfer safeguards
SCCs or equivalent in place for any processor operating outside Kenya
03
On the radar
Looking Ahead
What’s shaping data protection in 2026
ODPC registration enforcement
The ODPC has started actively enforcing registration for unregistered entities, especially banking and telco agents. If your business relies on agents to onboard customers or offer services on your behalf, this is no longer safely assumed to sit under your umbrella. Some may need to register in their own right. Map out who your agents are and where they sit from a compliance perspective.
Emerging technology
Artificial intelligence, cloud computing and data-driven services were repeatedly flagged as key areas of concern, alongside cross-border data flows, cybersecurity and the ethical use of children’s data. If you operate in any of these spaces, expect more attention from the regulator.
A stronger push for accountability
There’s increasing emphasis on accountability across public and private sectors: how organisations actually handle personal data, not just what’s written in policies. Carry out external audits at least annually to check you’re still on track.
Let’s talk
How Romer Can Help
We’ve curated services to mitigate the exact risks identified in this newsletter.
ABCs of Privacy · self-paced course
Training third parties at scale is hard. Onboard your processors, track completion and issue certificates, evidencing your training efforts without the admin burden.
Gap Analysis
A structured review of all your processes, including your third parties’, confirming compliance with the Act and identifying risks in their processing.
Data Processing & Sharing Agreements
Your first line of defence. Clear, practical contracts that define roles, allocate responsibility and set enforceable obligations for your third parties.
Data Privacy Pulse
An instant assessment of your compliance posture, and that of your third parties. Takes minutes; gives a clear picture of where you stand.
www.privacypulse.romer.co.ke
References
• Danish Data Protection Authority: Audit Guidelines
• Office of the Data Protection Commissioner (ODPC) website
This newsletter is for informational purposes only and does not constitute legal advice. For advice specific to your organisation, please consult a qualified data protection professional.
Reach out to us
Visit us
Elgon Court, Suite C3
01 Ralph Bunche Road
Upper Hill, Nairobi
Office hours: Weekdays 8am–5pm
Comments are closed.