Data protection for Kenyan SACCOs: ODPC registration, processor contracts, impact assessments and breach clocks
What the Data Protection Act, 2019 and its 2021 Regulations require of a SACCO as controller and of its software vendor as processor — registration and fees, the mandatory contract terms, when a DPIA is due, the 48- and 72-hour breach clocks, cross-border transfers and the penalty ceiling.
What the law is
The Data Protection Act, No. 24 of 2019 commenced on 25 November 2019 and is administered by the Office of the Data Protection Commissioner (ODPC). Four sets of regulations made under it in 2021 fill in the mechanics: the General Regulations, the Registration of Data Controllers and Data Processors Regulations, the Complaints Handling Procedure and Enforcement Regulations, and the Civil Registration Regulations. Section references below are to the Act unless a regulation is named.
The Act applies to any controller or processor established in Kenya and to one established elsewhere that processes personal data of "data subjects located in Kenya" (s.4(b)(ii)). A SACCO's software vendor is within reach wherever it hosts.
Who is the controller and who is the processor
A SACCO decides why and how its members' data is processed: it is the controller. A software provider that processes that data on the SACCO's documented instructions is the processor (s.2). The relationship must be a written contract under which the processor acts only on instructions (s.42(2)); the General Regulations list the terms it must contain: subject matter, duration, nature and purpose, data types, data-subject categories, the controller's rights, instructions, confidentiality commitments, security measures, deletion or return on termination at the controller's election, and audit and inspection rights (reg. 24(2)). Sub-processors need the controller's prior authorisation and the processor remains liable (reg. 25). A processor that goes beyond its instructions is deemed a controller for that processing (s.42(3)).
Registration with the ODPC
No one may act as a controller or processor unless registered (s.18(1)). Entities with turnover below KES 5 million and fewer than ten employees are exempt (Registration Regs reg. 13(2)) but still owe the Act's principles and transfer rules (reg. 13(3)). The exemption does not apply to entities processing for the purposes in the Third Schedule, which include "provision of financial services" (item 8). The Schedule does not name SACCOs, credit or lending; whether a given SACCO or its processor sits inside item 8 is a question for counsel, and the conservative reading is that it does.
Fees (Second Schedule) are paid once and then every two years, per role: KES 4,000 for entities with up to 50 employees and turnover up to KES 5 million; KES 16,000 for 51 to 99 employees and turnover to KES 50 million; KES 40,000 above that. A certificate is issued within fourteen days (reg. 8) and lasts twenty-four months (reg. 9); changes must be notified within fourteen days (reg. 15). The register is public and republished every thirty days (s.21(3); reg. 14). Processing while unregistered or on an expired certificate is an offence under s.73 (reg. 18).
Sensitive data, biometrics and impact assessments
Biometric data is sensitive personal data (s.2). Before any processing "likely to result in high risk" the controller must carry out a data protection impact assessment (s.31(1)) and submit the report sixty days before processing starts (s.31(5)). The General Regulations list the triggers, which include automated decisions with legal effect "or use of sensitive personal data as an element to determine access to services", "processing biometric or genetic data", large-scale processing and innovative technology (reg. 49). Silence from the Commissioner for sixty days after submission is deemed approval (reg. 52(3)).
For a SACCO, that reaches identity capture at onboarding: a selfie compared with a national ID is biometric processing, and using the result to admit or refuse a member is sensitive data determining access to a service. The assessment belongs to the SACCO as controller, with the processor's input on the safeguards.
Data subjects' clocks
- Access requests are met within seven days, free (General Regs reg. 9).
- Rectification, erasure, restriction and objection each carry a fourteen-day clock (regs 7(3), 8(3), 10(4), 12(3)).
- Consent is not freely given when it is a non-negotiable part of the terms and conditions (reg. 4(4)(b)).
- Every controller must publish a data protection policy (reg. 23) and keep a retention schedule (reg. 19).
Breach clocks
Where unauthorised access creates "a real risk of harm", the controller notifies the Commissioner within seventy-two hours of becoming aware and the data subject in writing within a reasonably practical period (s.43(1)). A processor notifies its controller without delay and, where practicable, within forty-eight hours (s.43(3)). The General Regulations deem a real risk of harm where an identification number is exposed with a Second Schedule class of data, which includes salary, card and bank account numbers, creditworthiness, "advances, loans and other facilities" and outstanding debts (reg. 37; Second Schedule). Almost every field in a SACCO ledger is on that list. No data-subject communication is required where safeguards such as encryption rendered the data unintelligible (s.43(6)).
Sending data outside Kenya
A transfer needs one of four bases: appropriate safeguards, an adequacy decision, strict necessity, or the data subject's explicit consent after disclosure of the risks (General Regs reg. 40). Ratification of the African Union Convention on Cyber Security and Personal Data Protection by the destination country, a reciprocal agreement with Kenya, or binding corporate rules are deemed safeguards (reg. 42). Sensitive data leaves Kenya only with consent and confirmed safeguards (s.49(1)). The localisation rule requires processing in Kenya, or at least one serving copy in a Kenyan data centre, only for listed public purposes such as civil registration, elections and public finance systems (reg. 26); no private financial-services category appears in that list. A SACCO choosing a vendor should still ask where each copy of its data sits and which transfer basis the contract relies on.
Complaints, notices and penalties
Anyone may complain to the ODPC, free, in any form (Complaints Regs reg. 4); it is acknowledged within seven days and concluded within ninety (s.56(5)). The respondent gets twenty-one days to answer (reg. 11). An enforcement notice allows at least twenty-one days to comply; ignoring it is an offence carrying a fine up to KES 5 million or two years' imprisonment (s.58). Administrative fines are capped at KES 5 million or, for an undertaking, 1% of the previous year's turnover, whichever is lower (s.63), plus up to KES 10,000 a day per breach until rectified (reg. 20(4)). The general offence penalty is a fine up to KES 3 million, ten years' imprisonment, or both (s.73). Data subjects may claim compensation for distress, not only financial loss (s.65).
What to ask a software vendor
- Are you registered with the ODPC as a processor, and in which fee band? (regs 4, 13; Second Schedule)
- Does our contract carry every term in General Regulations reg. 24(2), including audit rights and deletion-or-return on exit?
- Which sub-processors do you use, and where is each copy of our data? (reg. 25; reg. 40–47)
- How do you get a breach notice to us inside forty-eight hours? (s.43(3))
- What do you contribute to our impact assessment for identity capture? (s.31; reg. 49)
SenteRail answers these in its processor agreement and in SACCO data governance under KDPA. It does not describe itself as "ODPC certified"; registration is a duty, not a badge.