Course · Kenya · 21 modules

Africa Data Protection Course: Kenya Edition

Kenya's data protection regime taught from the primary texts: the Data Protection Act, 2019 (Cap. 411C), the three 2021 Regulations and the Access to Information Act, with every case study drawn from published ODPC determinations and court rulings in the Data Protection Enforcement Tracker.

Log in to enrol →

§ Modules

#ModuleCovers
Module 0How Kenya's law worksThree lessons. By the end, a learner can draw Kenya's data protection system from memory: the statute stack, the regulator, and what enforcement actually costs.
Module 1What is data protection (Foundations)Three lessons: the constitutional root, the statutory vocabulary, and the principles that every Kenyan determination cites.
Module 2The global baseline and how Kenya divergesMost learners arrive with GDPR reflexes. This module keeps what transfers, and marks precisely where Kenyan law walks its own path. Two lessons.
Module 3Kenya in the African landscapeOne lesson in the Kenya edition; the full comparative treatment lives in the Pan-African edition. The purpose here is orientation: where Kenya sits, and what that means for a Kenyan practice with regional clients.
Module 4Lawful basis for processingThree lessons: the s.30 menu, consent as Kenya actually polices it, and the January 2024 cluster of decisions that made unauthorised marketing photos one of the most reliably compensated wrongs in Kenyan data protection.
Module 5Data subject rightsThree lessons: the rights architecture, the two rights that generate the casework (erasure and objection), and automated decisions, where Kenya has real machinery most advisers have never operated.
Module 6Special categories of data (and children)Three lessons: what counts as sensitive in Kenya (wider than you think), the permitted-grounds machinery, and children's data, where Kenyan schools have been writing the case law with their marketing departments.
Module 7Controller vs processorTwo lessons: the classification and its consequences, and the contract the General Regulations actually require, clause by clause.
Module 8Privacy by design and defaultTwo lessons: what ss.41-42 actually demand and when, and the published data protection policy Kenya requires, which most Kenyan websites still do not have in the required shape.
Module 9Cross-border transfersThree lessons: the s.48 gateways read closely, the sensitive-data double lock and the Commissioner's kill switch, and the localisation lever nobody prices in.
Module 10Breach notificationThree lessons: the s.43 clock architecture, the deemed-harm categories that decide notifiability for you, and the incident file Kenya requires you to be able to produce.
Module 11Data protection officersTwo lessons: what s.24 actually says (softer than most summaries claim, and that includes ours until this course's body-read caught it), and the DPO role as the Act defines it.
Module 12Records of processing and auditsKenya does not copy the GDPR's Article 30 record-of-processing-activities architecture; it assembles the same accountability result from four smaller duties. Two lessons.
Module 13Data protection impact assessmentsThree lessons: when a DPIA is triggered (Kenya wrote you the list), the sixty-day rule that surprises everyone, and Worldcoin as the definitive account of what skipping this module costs.
Module 14The ODPC in practiceModule 0 introduced the office; this module teaches how to work with it as a practitioner: reading its output, using its instruments, and predicting its behaviour from its published record. Two lessons.
Module 15Penalties and enforcement trendsThree lessons: the complaint-to-collection pipeline end to end, the money mechanics (fines vs compensation, and which one scales), and what the published record says regulators actually punish.
Module 16Operating across multiple jurisdictionsOne working lesson. The Kenya edition teaches the method from the Kenyan vantage point; the Pan-African edition is where the per-country columns get filled in earnest.
Module 17Building a compliance programmeThe synthesis module: everything read so far, assembled into a programme a Kenyan organisation can actually run. Two lessons plus the artifact pack the capstone reuses.
Module 18Registration with the ODPCKenya is a registration jurisdiction with criminal consequences for getting it wrong, and the first arrests in comparable regimes (Ghana, Module 15's regional sidebar) were registration arrests. Three lessons.
Access to Information supplementAccess to information and the DPA: the overlapPublic entities and many private bodies live under two information statutes at once: one that compels disclosure and one that restrains it. This module teaches the joint, where most Kenyan public-sector information disputes actually happen. Two lessons.
CapstoneCapstone: counsel to a company entering KenyaThe learner is counsel. The client is fictional; every legal consequence in the marking key is real and cited. The four deliverables below are the study framework: what a real engagement letter for this client would actually require, section by section. The graded submission on t