Close Menu
Techdrivers
  • Home
  • Tech News
  • AI & Technology
  • Smartphones
  • Gadgets
  • How-To-Guide
  • Cybersecurity
  • Telecom & Internet
  • Business & Fintech
  • Electric Mobility
  • Terms of Service
What's Hot

A 16-Year-Old Built a Free College-Prep Platform After Frustration With Paywalls

September 29, 2026

AI Automation in Kenya: How Businesses Can Turn Saved Time Into Growth

September 29, 2026

Kenya Airways Brings AI Into Airline Pricing as Demand Keeps Changing

September 29, 2026
Facebook X (Twitter) Instagram
Trending
  • A 16-Year-Old Built a Free College-Prep Platform After Frustration With Paywalls
  • AI Automation in Kenya: How Businesses Can Turn Saved Time Into Growth
  • Kenya Airways Brings AI Into Airline Pricing as Demand Keeps Changing
  • Predictive AI for Startups: Choose the Decision First
  • How Tickets Kenya Is Using Technology to Change Event Ticketing in Kenya
  • How Much Electricity Does Your Home Wi-Fi Actually Use in Kenya?
  • Why Your Laptop Fan Suddenly Gets Loud: 7 Causes and Fixes
  • Why Apple Skipped the iPhone 9 and Microsoft Skipped Windows 9
  • Home
  • Tech News
  • AI & Technology
  • Smartphones
  • Gadgets
  • How-To-Guide
  • Cybersecurity
  • Telecom & Internet
  • Business & Fintech
  • Electric Mobility
  • Terms of Service
Facebook X (Twitter) Instagram YouTube Telegram Threads WhatsApp TikTok
TechdriversTechdrivers
Subscribe
Tuesday, September 29
  • Home
  • Tech News
  • AI & Technology
  • Smartphones
  • Gadgets
  • How-To-Guide
  • Cybersecurity
  • Telecom & Internet
  • Business & Fintech
  • Electric Mobility
  • Terms of Service
Techdrivers
Home » Kenya’s Non-Profits Get New Data Protection Manual as Privacy Risks Grow

Kenya’s Non-Profits Get New Data Protection Manual as Privacy Risks Grow

AMOS ODIPOBy AMOS ODIPOSeptember 27, 2026 Cybersecurity No Comments13 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

Kenya’s non-profit sector handles a huge amount of personal information.

An organisation working with children may collect names, ages, locations and family information. A human-rights organisation may maintain case files involving survivors of violence. A health-focused charity may process medical information, while another organisation may collect identification details, phone numbers and financial information from beneficiaries.

That makes data protection more than an IT issue.

It can affect the privacy, safety and trust of the people non-profit organisations are trying to help.

A new Data Protection Manual for Non-Profit Organisations in Kenya, published by Amnesty International Kenya on September 25, 2026, is designed to help organisations translate Kenya’s data-protection requirements into practical procedures.

The first-edition 2026 manual was developed by Amnesty International Kenya in collaboration with DPO 360 Africa Limited and ICON Data and Learning Labs.

Why Data Protection Matters for Kenyan Non-Profits

Non-profit organisations often operate in environments where the information they collect can be highly sensitive.

Consider a community organisation supporting survivors of gender-based violence.

A beneficiary record could contain:

  • Full name
  • Telephone number
  • Location
  • Identification information
  • Health information
  • Details about an incident
  • Information about family members
  • Photographs
  • Case notes
  • Referrals to other organisations

If such information is exposed, the consequences can go beyond inconvenience.

It could expose a vulnerable person to harassment, discrimination, financial fraud, intimidation or other risks.

The new manual therefore approaches data protection as both a legal and operational responsibility.

Amnesty International Kenya says the toolkit is intended to help organisations connect the requirements of the Data Protection Act, 2019 with day-to-day activities such as beneficiary intake, surveys, case management, cloud storage and information sharing.

Kenya’s Data Protection Framework

Kenya’s data protection framework is anchored in Article 31 of the Constitution of Kenya, which protects the right to privacy.

The Data Protection Act, 2019 provides the main statutory framework governing the processing of personal data in Kenya.

The Office of the Data Protection Commissioner (ODPC) identifies several rights belonging to data subjects, including the right to be informed about how their personal data will be used, access their personal data, object to processing, and seek correction or deletion of certain inaccurate or misleading information.

For non-profits, this means collecting someone’s information is not simply a matter of creating a spreadsheet or filling out an online form.

The organisation needs to consider why the information is being collected, what it will be used for, who can access it, how long it should be retained and what happens when it is no longer required.

What the New Manual Covers

The manual is structured as a practical toolkit rather than simply a discussion of privacy law.

Among the areas covered are privacy concepts, Kenya’s Data Protection Act, lawful bases for processing, consent, data-subject rights, data breaches, cross-border transfers and the creation of organisational privacy programmes.

1. Understanding the Difference Between Privacy, Data Protection and Security

These terms are often used interchangeably, but they address different issues.

Privacy concerns a person’s control and rights regarding their personal information and private life.

Data protection concerns the rules and processes governing how personal data is collected, used, stored and shared.

Data security focuses on technical and organisational measures used to protect information from unauthorised access, loss, alteration or destruction.

A non-profit can therefore have strong cybersecurity tools and still have poor data-protection practices.

For example, an organisation might securely store a database but collect far more information than it actually needs.

Security alone does not solve that problem.

2. Data Minimisation

One of the important principles highlighted in the manual is data minimisation.

The basic idea is straightforward: organisations should avoid collecting personal information that is unnecessary for the purpose for which it is being processed.

Imagine a Kenyan charity organising a food-distribution programme.

If the organisation needs a beneficiary’s name, contact information and location to coordinate delivery, it should consider whether it actually needs additional information such as unrelated family details, copies of documents or extensive personal histories.

Collecting less information can reduce the potential impact of a future breach.

3. Purpose Limitation

Information collected for one reason should not automatically become available for unrelated purposes.

For example, if an NGO collects a beneficiary’s phone number to coordinate an appointment, that does not automatically mean the number should be added to a marketing database.

Organisations need to establish clear purposes for processing personal data and communicate those purposes appropriately.

4. Accuracy and Storage

The manual also addresses data accuracy and storage limitation.

Incorrect information can cause real-world problems.

A wrong telephone number can prevent a beneficiary from receiving assistance. An inaccurate medical record could potentially affect services. An outdated address could result in sensitive correspondence being sent to the wrong person.

Organisations therefore need processes for correcting inaccurate information and deciding how long different categories of data should be retained.

Data Subject Rights Matter Too

A person whose information is being processed is not simply a record in an NGO database.

Under Kenya’s data-protection framework, data subjects have specific rights.

The ODPC lists rights including being informed about the use of personal data, accessing personal data held by a controller or processor, objecting to processing, correcting false or misleading information and seeking deletion of false or misleading data.

The new manual provides guidance on handling Data Subject Requests (DSRs) and highlights statutory timelines, including a 14-day timeframe discussed in the publication.

For an NGO, this means there should be a clear internal process for receiving, verifying, recording and responding to requests.

A staff member should not have to improvise when a beneficiary asks:

“What information do you have about me?”

What Happens When an NGO Suffers a Data Breach?

This is one of the areas where cybersecurity and data protection meet directly.

Suppose an organisation’s laptop containing beneficiary records is stolen.

Or a staff member accidentally sends a spreadsheet containing personal information to the wrong email address.

Or attackers compromise an organisation’s cloud account.

These incidents can potentially become personal-data breaches.

Kenya’s Data Protection Act provides requirements around breach notification. Where a data controller determines that a personal-data breach is likely to result in a risk to the rights and freedoms of a data subject, the Act provides for notification to the Data Commissioner within 72 hours of becoming aware of the breach, subject to the Act’s requirements.

The Act also provides that a data processor that becomes aware of a personal-data breach should notify the data controller without delay and, where reasonably practicable, within 48 hours.

This is why organisations need an incident-response procedure before something goes wrong.

Waiting until after a breach to decide who should be contacted can waste valuable time.

Why Data Protection Officers Matter

The manual also covers the responsibilities of Data Protection Officers and organisational compliance structures.

For organisations that require such arrangements, the DPO function can help coordinate privacy responsibilities across departments.

A privacy programme should not exist only on paper.

Staff collecting information in the field, programme teams managing beneficiaries, finance departments handling donor records and IT teams managing systems can all affect how personal data is processed.

That makes staff training an important part of compliance.

Cross-Border Data Transfers and Cloud Services

Kenyan organisations increasingly use cloud platforms for email, file storage, accounting, customer relationship management, surveys and collaboration.

That creates another important question:

Where is the data being processed or stored?

The manual includes guidance on cross-border transfers, adequacy mechanisms, Standard Contractual Clauses (SCCs), cloud services and Transfer Impact Assessments (TIAs).

For example, a Kenyan NGO might collect beneficiary information through an online form and store the resulting database on an international cloud platform.

The organisation should understand the privacy and contractual arrangements surrounding that processing rather than treating cloud storage as automatically risk-free.

A Practical Example: A Kenyan Community NGO

Consider a fictional organisation called Mwangaza Community Initiative operating in Nairobi and supporting young people from low-income communities.

Its staff collect:

  • Names
  • Phone numbers
  • Age
  • Residential area
  • Emergency contacts
  • School information
  • Programme participation records

The organisation could build a basic privacy programme around several questions.

Before collecting information

Ask:

Why do we need this information?

If a piece of information is not necessary, the organisation should consider whether collecting it is justified.

During collection

Tell the person:

  • What information is being collected
  • Why it is being collected
  • How it will be used
  • Who may receive it where relevant
  • How they can exercise applicable rights

During storage

Limit access to people who actually need the information.

Use appropriate passwords, access controls, backups and security measures.

When sharing information

Confirm that the proposed sharing has an appropriate legal basis and is consistent with the stated purpose.

When information is no longer needed

Apply the organisation’s retention and deletion procedures rather than keeping every record indefinitely.

This kind of workflow turns privacy from a legal document into an operational process.

A 13-Part Privacy Programme

One notable part of the manual is its operational approach to setting up a privacy programme.

The publication describes 13 core components, including Records of Processing Activities (ROPA), data classification and incident management.

For a Kenyan non-profit, a practical programme can start with an inventory of the information it already holds.

For example:

Data categoryPossible examplesKey question
Beneficiary dataNames, contacts, programme recordsWhy is it needed?
Case informationComplaints, case notes, referralsWho can access it?
Health informationMedical records or health detailsIs additional protection required?
Staff informationHR and payroll recordsHow long should it be retained?
Donor informationNames, contacts, contribution recordsWhat is the purpose?
Digital credentialsAccount and system access informationHow is access protected?

The exact requirements will depend on the organisation, the data involved and the circumstances of processing.

What This Means for Kenyan NGO Staff

Data protection is not only the responsibility of the IT department or legal team.

A programme officer can accidentally expose personal data.

A field worker can lose a phone containing beneficiary information.

A finance employee can send a spreadsheet to the wrong recipient.

A communications officer can publish a photograph without properly considering the privacy implications.

A volunteer can download sensitive records onto a personal device.

That means privacy training needs to reach the people actually handling information.

What Ordinary Kenyans Should Know

The manual is written primarily for non-profit organisations, but its subject matter also offers useful lessons for people who provide personal information to organisations.

Before giving an organisation your information, consider asking:

Why do you need it?

How will you use it?

Who will have access to it?

How long will you keep it?

What happens if there is a breach?

People should also be cautious about sending identification documents, health information or other sensitive records through unsecured channels unless there is a legitimate reason to do so.

Kenya’s Growing Cybersecurity Challenge

The need for stronger privacy practices comes as Kenya’s digital environment continues to face significant cybersecurity activity.

TechDrivers recently reported that the National KE-CIRT/CC detected 11.12 billion cyber threats during the 2025/26 financial year, up from 8.62 billion the previous year. The figures represent detected cyber threats rather than 11.12 billion confirmed successful compromises.

For organisations holding sensitive personal information, cybersecurity and data protection therefore need to work together.

A privacy policy cannot compensate for an organisation that leaves accounts unprotected.

Likewise, sophisticated cybersecurity tools cannot fix a process that collects unnecessary personal information or shares it without proper controls.

Related TechDrivers Articles

If you want to understand the wider cybersecurity risks facing Kenyan internet users, read our related guides:

  • What Happens to Your Data After You Delete an App?— deleting an application does not necessarily mean every piece of associated information immediately disappears.
  • How SIM-Swap Fraud Works in Kenya and How to Protect Yourself — explains how attackers can exploit mobile-number-based authentication.
  • How to Protect Your M-PESA Account From Fraud in Kenya — practical security measures for protecting mobile-money accounts.
  • How Facebook Marketplace Scams Work in Kenya and How to Avoid Them — looks at common risks facing people buying and selling online.
  • How Kenya’s Cyber Threats Rose to 11.12 Billion — examines the latest national cybersecurity threat figures.

These topics form part of the bigger question facing Kenya’s digital economy: how do we make digital services useful without treating people’s personal information as an afterthought?

Frequently Asked Questions

What is the Kenya data protection manual for non-profits?

It is a practical 2026 toolkit developed for non-profit organisations operating in Kenya. It explains privacy, data protection, lawful processing, data-subject rights, breach management, cross-border transfers and privacy-programme implementation.

Who published the manual?

The manual is an initiative of Amnesty International Kenya and was developed in collaboration with DPO 360 Africa Limited and ICON Data and Learning Labs.

Who can benefit from the manual?

It is particularly relevant to NGO leaders, boards, Data Protection Officers, compliance teams, programme officers, field staff, monitoring and evaluation teams and IT administrators.

What rights do data subjects have in Kenya?

The ODPC identifies rights including being informed about the use of personal data, accessing personal data, objecting to processing, correcting false or misleading information and seeking deletion of false or misleading information.

How quickly must a qualifying personal-data breach be reported?

Kenya’s Data Protection Act provides a 72-hour notification requirement to the Data Commissioner in circumstances covered by the Act. The Act also addresses notification responsibilities between data processors and controllers.

Does data protection only apply to large NGOs?

No. Organisations should assess their obligations based on the nature and circumstances of their data processing rather than assuming privacy compliance is only a concern for large organisations.

Why is data minimisation important?

Collecting only information that is necessary for a legitimate purpose can reduce the amount of personal data an organisation has to protect and can limit the potential impact of a data breach.

Does using Google Drive or another cloud service automatically make data compliant?

No. Cloud storage is a technology choice, not a complete data-protection programme. Organisations need to consider how personal information is processed, stored, accessed and transferred, including applicable requirements for cross-border processing.

Conclusion: Data Protection Has to Become an Everyday Practice

Kenya’s non-profit organisations often work with people who may already be in vulnerable circumstances.

That makes the information they hold particularly important to protect.

The new Data Protection Manual for Non-Profit Organisations in Kenya provides a practical framework for organisations trying to move from general awareness of privacy law to concrete procedures for collecting, using, storing, sharing and deleting personal information.

The bigger lesson extends beyond NGOs.

As Kenyan organisations move more services, records and interactions online, personal data is becoming an increasingly important part of everyday operations.

Protecting that data requires more than a privacy policy buried on a website.

It requires trained staff, controlled access, clear retention policies, appropriate security measures, documented procedures and a plan for responding when something goes wrong.

For non-profits, that is ultimately about more than compliance.

It is about protecting the people who trusted the organisation with their information.

Post Views: 18
Previous ArticlePeter Ndegwa Takes Key Role in Africa’s Digital Transformation Agenda at GABI 2026
Next Article What Happens When Your M-Pesa Phone Is Stolen in Kenya?
AMOS ODIPO
  • Website
  • X (Twitter)

Amos Odipo is the Founder and Editor of TechDrivers.co.ke, a Kenyan technology and digital media platform covering technology, smartphones, gadgets, AI, telecommunications, the digital economy and electric mobility.

Keep Reading

Cybersecurity By AMOS ODIPOSeptember 27, 2026

What Happens When Your M-Pesa Phone Is Stolen in Kenya?

Cybersecurity By AMOS ODIPOSeptember 23, 2026

What Happens to Your Data After You Delete an App?

Cybersecurity By AMOS ODIPOSeptember 22, 2026

How Facebook Marketplace Scams Work in Kenya and How to Avoid Them

Cybersecurity By AMOS ODIPOSeptember 20, 2026

How SIM-Swap Fraud Works in Kenya and How to Protect Yourself

Cybersecurity By AMOS ODIPOSeptember 20, 2026

How to Protect Your M-PESA Account From Fraud in Kenya

Cybersecurity By AMOS ODIPOSeptember 18, 2026

Kenya Cyber Threats Rise 29% to 11.12 Billion as DDoS and Web Attacks Surge

Add A Comment
Leave A Reply Cancel Reply

Trending Now

Kenya’s EV Charging Infrastructure: Who Is Building the Network?

August 29, 2026

Electric Buses in Kenya: Companies, Prices, Range, Charging and Where They Operate

August 29, 2026

How Electric Motorcycles Are Changing Kenya’s Boda Boda Industry

August 29, 2026

Spiro Electric Motorcycles in Kenya: Prices, Range, Battery Swapping and Running Costs

August 29, 2026

Subscribe to Updates

loader

Get the latest Kenyan tech news, gadget reviews, telecom updates, AI news and useful digital tips delivered to your inbox.

TechDrivers Newsletter

Email Address*

FIRSTNAME

LASTNAME

Subscribe to Updates

loader

Get the latest Kenyan tech news, gadget reviews, telecom updates, AI news and useful digital tips delivered to your inbox.

TechDrivers Newsletter

Email Address*

FIRSTNAME

LASTNAME

Techdrivers
Techdrivers
Facebook X (Twitter) Instagram Pinterest YouTube WhatsApp TikTok Telegram Threads
Facebook X (Twitter) Instagram Pinterest
  • Home
  • About Us
  • Editorial Team
  • Contact Us
  • Advertise With Us
  • Submit a Tech Story
  • Privacy Policy
  • Terms of Service
  • Fact-Checking Policy
  • Corrections Policy
  • Get In Touch
  • Our Authors
© 2026 Techdrivers.co.ke Designed by Techdrivers.

Type above and press Enter to search. Press Esc to cancel.