Skip to content
Guide 6 min read Facts checked 1 September 2026

The Data Protection Act 2019, for people who hold ID numbers and payslips

Registration with the ODPC, lawful basis, what a KYC file may hold and for how long, what a breach obliges you to do, and the penalties — written for a lender rather than a lawyer.

If you hold a national ID number, a payslip, a next-of-kin's phone number and a photograph of somebody's shop, you are a data controller under the Data Protection Act, 2019. That is every lender in Kenya, including the ones no financial regulator supervises. This is what the Act actually asks of you, written for the person who runs the operation rather than for a lawyer.

Why it applies to you even if nobody licenses you

The Act does not attach to a licence. It attaches to the processing of personal data about identifiable living people. A credit-only lender with two branches, a SASRA-regulated SACCO and a licensed digital credit provider are in exactly the same position on this, which surprises people used to thinking of compliance as something that arrives with a regulator.

It also reaches further than the borrower. Guarantors, next of kin, employer contacts, and the referees on an application form are all data subjects whose data you are processing, usually without ever having spoken to them.

Registration with the ODPC

Data controllers and processors are required to register with the Office of the Data Protection Commissioner, subject to thresholds set by regulation based on turnover and headcount — thresholds a lender of very modest size can cross. Certain categories of processing require registration regardless of size, and financial services sits close to several of them.

Registration is not onerous and not expensive. Not being registered when you should be is the first thing anybody looks at, which makes it the cheapest problem on this page to fix.

Lawful basis, and why "they consented" is the weakest answer

You need a lawful basis for each thing you do with personal data. For a lender, most processing rests comfortably on performance of a contract (you cannot service a loan without the borrower's details) or legal obligation (CRB submission, AML records, tax records).

Consent is the basis people reach for first and it is the most fragile, because consent can be withdrawn and must be freely given. Consent obtained as a condition of getting a loan is not freely given in any meaningful sense. Rely on contract and legal obligation for the core, and save consent for the genuinely optional things — marketing above all.

Marketing is worth separating carefully. "We may contact you about other products" bundled into a loan agreement is exactly the pattern the Act is aimed at. A separate, unticked, refusable opt-in costs you nothing and is the difference between a defensible position and an indefensible one.

What a KYC file may hold

The principle is minimisation: collect what you need for the stated purpose, and no more. Two habits in Kenyan lending sit uncomfortably against it:

  • Collecting the whole phonebook. Some digital lenders have historically requested access to a borrower's contacts. The DCP regime addressed this directly, and quite apart from that it is very difficult to justify under minimisation: you have collected personal data about hundreds of people who have no relationship with you at all.
  • Photographing everything. A photograph of the borrower's business premises may be justifiable for a business loan. A photograph of the inside of their home is harder, and "we have always done it" is not a basis.

Some of what a lender holds is sensitive personal data under the Act — health information, for instance, if a loan application asks about it — which carries higher requirements. If you do not need it, the strongest compliance position is not to have it.

Retention: the obligation people forget runs both ways

Two duties pull against each other and both are real. AML, tax and financial record-keeping rules require you to keep records for defined periods. The Act requires you not to keep personal data longer than necessary for the purpose.

The resolution is a written retention schedule that says, per category of data, how long it is kept and why. For example: loan and repayment records for the statutory retention period; declined application data for a much shorter one; marketing contact data until consent is withdrawn. Then delete on schedule rather than never.

"We keep everything forever, just in case" is not a schedule and is not defensible. Neither is a schedule that exists as a document but has never deleted anything.

The rights a borrower can exercise

Data subjects can, broadly:

  • ask what you hold about them and get a copy;
  • have inaccurate data corrected;
  • object to certain processing, and withdraw consent where consent was the basis;
  • in defined circumstances, ask for erasure.

Erasure is where lenders panic, and mostly should not: you are not obliged to delete records you are legally required to keep, and an outstanding loan is a live contract. What you cannot do is treat "we are a lender" as a blanket exemption from the whole chapter.

The practical requirement is operational rather than legal: can you actually produce everything you hold about one person, across every system, within a reasonable time? For most lenders the honest answer involves a core system, a spreadsheet, a WhatsApp history and a filing cabinet. That is the gap worth closing.

If something goes wrong

Where a breach presents a real risk to the rights and freedoms of the people affected, the Act requires notification to the Data Commissioner within a defined period, and communication to the affected data subjects where the risk is high.

The clock starts when you become aware, which is the argument for being able to become aware. Access logs, an append-only audit trail, and knowing which staff account can export what are not just good hygiene — they are the difference between reporting a breach accurately and reporting that something might have happened at some point.

Your software vendor is a data processor

If a third party processes personal data on your behalf — your loan management system, your SMS gateway, your hosting provider — they are a data processor and the relationship needs to be governed by a written contract with specified terms. That is what a data processing agreement is for, and it is why any credible vendor selling to Kenyan lenders publishes one.

Three things to check in it:

  1. Is your data separated from other customers' data, and how? "Multi-tenant" spans everything from a database per customer to a shared table with a column marking whose row it is.
  2. Can you get a full export at any time, including while an invoice is disputed?
  3. What happens on exit — is there a destruction schedule with a number of days on it, in writing?

Our own answers to those are on the security page and in the data processing addendum, and the reasoning behind the third question is in the buyer's guide.

Penalties

The Act provides for administrative penalties up to a ceiling expressed both as a shilling figure and as a proportion of annual turnover, with the lower of the two applying. For most lenders reading this, the shilling ceiling is the binding one and it is large enough to matter. There is also the part that does not appear in the statute: a borrower base that finds out you lost their ID numbers.

Topics

Data Protection Act Kenya ODPC registration KYC data retention customer data lender compliance