IVIO Advocates LLP · Nairobi · Mombasa · Kapsabet+254 118 119 199
IVIO Advocates LLP
← All insights

Data protection · 15 July 2026 · Margaret A. Odhiambo

Seventy-two hours: handling a data breach

The clock in the Act is short, but the first task is not notification. It is a documented assessment of what happened and who is exposed, because that assessment decides everything that follows.

Hour zero: contain and record

A personal data breach is any event that leads to unauthorised access to, or the loss, alteration or destruction of, personal data. That includes an email sent to the wrong recipient, a laptop left in a taxi, and a misconfigured storage bucket, not only a hostile intrusion. The first steps are to stop the exposure continuing, preserve the evidence and logs, and start a written record with times. The record is what a regulator reads, and it cannot be reconstructed convincingly after the fact.

The assessment that decides the rest

Notification to the Office of the Data Protection Commissioner is required where the breach presents a real risk of harm to the people whose data was involved, and it must be made without undue delay and in any event within seventy-two hours of becoming aware. Where the risk to those people is high, they must be told as well. Both duties turn on a judgement about severity, so record the reasoning: what data, how many people, whether it was encrypted, whether it can be linked to an identifiable person, whether it enables fraud or exposes something sensitive, and whether it has been recovered.

The notification, in seven parts

  • What happened, and when it was discovered
  • The categories and approximate number of people affected
  • The categories and volume of records involved
  • The likely consequences for those people
  • Measures taken to contain the breach and mitigate harm
  • The name and contact details of the person handling it
  • What remains unknown, and when you will report again

Telling the people affected

Where communication is required, it goes to the individuals in clear language, not in the language of an incident report. It should say what happened, what data was involved, what the organisation has done, what the person should do, and how to reach someone who can answer questions. A notice that reads as though it were drafted to limit liability tends to produce the complaint it was written to avoid.

Partial information is not a reason to wait

The seventy-two hours run from awareness, not from the completion of the investigation. Where the facts are still developing, notify with what is known, say what is not yet established, and supplement. Late notification with a complete account is treated less favourably than prompt notification that was later corrected.

Processors and suppliers

If the breach happened at a processor, the controller still carries the duty to notify, and the processor's duty is to tell the controller without undue delay. That obligation belongs in the contract with a defined notification period, along with a duty to cooperate with the investigation. Organisations discover the gap in those clauses at precisely the wrong moment.

Afterwards

Every breach must be recorded even where no notification was required, together with the reasoning for that decision. The record of breaches is itself a document the Commissioner may ask to see, and a pattern of small incidents with no remedial action is a finding in its own right.

This guide is general information about the law in Kenya and is not advice on your particular circumstances. Speak to an advocate about your own facts.


This guide is general information about the law in Kenya and is not advice on your particular circumstances.

Speak to an advocate