What triggers the obligation
Under the Data Protection Act 2019 an assessment is required where a processing operation is likely to result in a high risk to the rights and freedoms of the people whose data is involved. In practice that threshold is met more often than organisations expect. Systematic and extensive profiling that leads to automated decisions, processing of sensitive data at scale, monitoring of a publicly accessible area, large-scale processing of health or financial records, the use of a new technology on personal data, and the combining of datasets collected for different purposes all point towards an assessment.
Two practical rules help. First, if the processing is new to the organisation and touches a lot of people, assume an assessment is needed until you have written down why it is not. Second, if you cannot describe the purpose of the processing in one sentence, the assessment will find the problem for you.
What the document has to contain
A defensible assessment describes the processing rather than the project: what data, from whom, by what means, for what purpose, for how long, and to whom it is disclosed. It states the lawful basis and, where consent is relied on, how consent is obtained and withdrawn. It then identifies the risks to the people concerned — not the risks to the organisation — and sets out the measures that reduce each one, with the residual risk stated plainly.
The assessment, in seven parts
- A description of the processing and its purpose
- The lawful basis, and necessity and proportionality
- Data flows, including any transfer out of Kenya
- Risks to the rights of the people affected
- Mitigations, and the residual risk after them
- Consultation: who was asked, and what they said
- The decision, who made it, and the review date
Do it before the build, not after
An assessment carried out after a system is live can only recommend changes that are expensive. Carried out at design stage it is often the cheapest document an organisation produces, because the mitigations are still configuration choices: collecting one field instead of five, setting a retention period, separating identifiers from analytics, restricting who can see a record.
Consultation is part of the record
Where the risk is material, consult the people who will be affected or their representatives, and record what came back. Where residual high risk remains after mitigation, the Office of the Data Protection Commissioner should be consulted before the processing begins. Organisations sometimes skip this because the answer may be inconvenient; the absence of consultation is itself a finding.
Keep it alive
An assessment is tied to a processing operation, not to a date. When the purpose changes, a new data source is added, a processor is replaced, or the technology is materially altered, the assessment is revisited. Set a review date at the outset and put the assessment under the same version control as the system it describes.
What good looks like
A short document that a non-specialist can follow, signed off by someone with authority, referenced in the register of processing activities, and traceable to the controls actually implemented. Length is not evidence of rigour. If the assessment cannot be reconciled with what the system does, it is worse than not having one.
This guide is general information about the law in Kenya and is not advice on any particular processing operation. If you are unsure whether an assessment is required, speak to an advocate about your own facts.
This guide is general information about the law in Kenya and is not advice on your particular circumstances.
Speak to an advocate