IVIO Advocates LLP · Nairobi · Mombasa · Kapsabet+254 118 119 199
IVIO Advocates LLP
← All insights

Data protection · 12 August 2026 · Margaret A. Odhiambo

When does your organisation need a DPIA?

A data protection impact assessment is not a form to be filed. It is the record that shows you thought about the risk to people before you built the thing, and it is the first document a regulator asks for.

What triggers the obligation

Under the Data Protection Act 2019 an assessment is required where a processing operation is likely to result in a high risk to the rights and freedoms of the people whose data is involved. In practice that threshold is met more often than organisations expect. Systematic and extensive profiling that leads to automated decisions, processing of sensitive data at scale, monitoring of a publicly accessible area, large-scale processing of health or financial records, the use of a new technology on personal data, and the combining of datasets collected for different purposes all point towards an assessment.

Two practical rules help. First, if the processing is new to the organisation and touches a lot of people, assume an assessment is needed until you have written down why it is not. Second, if you cannot describe the purpose of the processing in one sentence, the assessment will find the problem for you.

What the document has to contain

A defensible assessment describes the processing rather than the project: what data, from whom, by what means, for what purpose, for how long, and to whom it is disclosed. It states the lawful basis and, where consent is relied on, how consent is obtained and withdrawn. It then identifies the risks to the people concerned — not the risks to the organisation — and sets out the measures that reduce each one, with the residual risk stated plainly.

The assessment, in seven parts

  • A description of the processing and its purpose
  • The lawful basis, and necessity and proportionality
  • Data flows, including any transfer out of Kenya
  • Risks to the rights of the people affected
  • Mitigations, and the residual risk after them
  • Consultation: who was asked, and what they said
  • The decision, who made it, and the review date

Do it before the build, not after

An assessment carried out after a system is live can only recommend changes that are expensive. Carried out at design stage it is often the cheapest document an organisation produces, because the mitigations are still configuration choices: collecting one field instead of five, setting a retention period, separating identifiers from analytics, restricting who can see a record.

Consultation is part of the record

Where the risk is material, consult the people who will be affected or their representatives, and record what came back. Where residual high risk remains after mitigation, the Office of the Data Protection Commissioner should be consulted before the processing begins. Organisations sometimes skip this because the answer may be inconvenient; the absence of consultation is itself a finding.

Keep it alive

An assessment is tied to a processing operation, not to a date. When the purpose changes, a new data source is added, a processor is replaced, or the technology is materially altered, the assessment is revisited. Set a review date at the outset and put the assessment under the same version control as the system it describes.

What good looks like

A short document that a non-specialist can follow, signed off by someone with authority, referenced in the register of processing activities, and traceable to the controls actually implemented. Length is not evidence of rigour. If the assessment cannot be reconciled with what the system does, it is worse than not having one.

This guide is general information about the law in Kenya and is not advice on any particular processing operation. If you are unsure whether an assessment is required, speak to an advocate about your own facts.


This guide is general information about the law in Kenya and is not advice on your particular circumstances.

Speak to an advocate