Course · Kenya · 21 modules
Africa Data Protection Course: Kenya Edition
Kenya's data protection regime taught from the primary texts: the Data Protection Act, 2019 (Cap. 411C), the three 2021 Regulations and the Access to Information Act, with every case study drawn from published ODPC determinations and court rulings in the Data Protection Enforcement Tracker.
Log in to enrol →§ Modules
| # | Module | Covers |
|---|---|---|
| Module 0 | How Kenya's law works | Three lessons. By the end, a learner can draw Kenya's data protection system from memory: the statute stack, the regulator, and what enforcement actually costs. |
| Module 1 | What is data protection (Foundations) | Three lessons: the constitutional root, the statutory vocabulary, and the principles that every Kenyan determination cites. |
| Module 2 | The global baseline and how Kenya diverges | Most learners arrive with GDPR reflexes. This module keeps what transfers, and marks precisely where Kenyan law walks its own path. Two lessons. |
| Module 3 | Kenya in the African landscape | One lesson in the Kenya edition; the full comparative treatment lives in the Pan-African edition. The purpose here is orientation: where Kenya sits, and what that means for a Kenyan practice with regional clients. |
| Module 4 | Lawful basis for processing | Three lessons: the s.30 menu, consent as Kenya actually polices it, and the January 2024 cluster of decisions that made unauthorised marketing photos one of the most reliably compensated wrongs in Kenyan data protection. |
| Module 5 | Data subject rights | Three lessons: the rights architecture, the two rights that generate the casework (erasure and objection), and automated decisions, where Kenya has real machinery most advisers have never operated. |
| Module 6 | Special categories of data (and children) | Three lessons: what counts as sensitive in Kenya (wider than you think), the permitted-grounds machinery, and children's data, where Kenyan schools have been writing the case law with their marketing departments. |
| Module 7 | Controller vs processor | Two lessons: the classification and its consequences, and the contract the General Regulations actually require, clause by clause. |
| Module 8 | Privacy by design and default | Two lessons: what ss.41-42 actually demand and when, and the published data protection policy Kenya requires, which most Kenyan websites still do not have in the required shape. |
| Module 9 | Cross-border transfers | Three lessons: the s.48 gateways read closely, the sensitive-data double lock and the Commissioner's kill switch, and the localisation lever nobody prices in. |
| Module 10 | Breach notification | Three lessons: the s.43 clock architecture, the deemed-harm categories that decide notifiability for you, and the incident file Kenya requires you to be able to produce. |
| Module 11 | Data protection officers | Two lessons: what s.24 actually says (softer than most summaries claim, and that includes ours until this course's body-read caught it), and the DPO role as the Act defines it. |
| Module 12 | Records of processing and audits | Kenya does not copy the GDPR's Article 30 record-of-processing-activities architecture; it assembles the same accountability result from four smaller duties. Two lessons. |
| Module 13 | Data protection impact assessments | Three lessons: when a DPIA is triggered (Kenya wrote you the list), the sixty-day rule that surprises everyone, and Worldcoin as the definitive account of what skipping this module costs. |
| Module 14 | The ODPC in practice | Module 0 introduced the office; this module teaches how to work with it as a practitioner: reading its output, using its instruments, and predicting its behaviour from its published record. Two lessons. |
| Module 15 | Penalties and enforcement trends | Three lessons: the complaint-to-collection pipeline end to end, the money mechanics (fines vs compensation, and which one scales), and what the published record says regulators actually punish. |
| Module 16 | Operating across multiple jurisdictions | One working lesson. The Kenya edition teaches the method from the Kenyan vantage point; the Pan-African edition is where the per-country columns get filled in earnest. |
| Module 17 | Building a compliance programme | The synthesis module: everything read so far, assembled into a programme a Kenyan organisation can actually run. Two lessons plus the artifact pack the capstone reuses. |
| Module 18 | Registration with the ODPC | Kenya is a registration jurisdiction with criminal consequences for getting it wrong, and the first arrests in comparable regimes (Ghana, Module 15's regional sidebar) were registration arrests. Three lessons. |
| Access to Information supplement | Access to information and the DPA: the overlap | Public entities and many private bodies live under two information statutes at once: one that compels disclosure and one that restrains it. This module teaches the joint, where most Kenyan public-sector information disputes actually happen. Two lessons. |
| Capstone | Capstone: counsel to a company entering Kenya | The learner is counsel. The client is fictional; every legal consequence in the marking key is real and cited. The four deliverables below are the study framework: what a real engagement letter for this client would actually require, section by section. The graded submission on t |