Financial and digital lenders top violators of data privacy in Kenya
Report reveals that with respect to data subject rights management, data handlers ought to establish a structured protocol for receiving, verifying, and responding to data subject requests
Financial and digital lenders are among the top violators of data privacy in Kenya, a report released by the Office of the Data Protection Commissioner (ODPC) for 2024 reveals.
According to the report, over 80 per cent of digital users do not comply with data protection regulations in Kenya, highlighting gaps in how data handlers deal with data subject rights, particularly the right to erasure.
“The high non-compliance rate points to underlying challenges, including a lack of awareness about legal obligations, technical challenges in managing data, and procedural inefficiencies,” the report acknowledges.
The report reveals that 47.4 per cent of all the cases were awarded for damages to complainants, 27.7 per cent cases were issued with enforcement notices, 21.1 per cent cases were both fined and issued with enforcement notices. Only 9.2 per cent of cases were amicably settled, while 1.3 cases were dismissed.
The report reveals that with respect to data subject rights management, data handlers ought to establish a structured protocol for receiving, verifying, and responding to data subject requests.
These include ensuring that there is a clear communication channels with data subjects, and implementing identity verification steps to prevent unauthorized access to personal data.
The report also said there is a need to maintain compliance timelines set out under the Data Protection (General) Regulations, automate the request processing for efficiency where possible, and keep records of data subject requests for audit and compliance purposes.
It also advised that data handlers should have comprehensive data request procedures, train staff on handling requests, leverage on technology, and regularly assess or audit their data protection compliance operations.
According to the ODPC, improper consent management, unsolicited communication, data breaches, and third party harassment were some of the issues that the organisation determined in 2024.
Out of the 51 cases determined, 34 were awarded for damages to the complainants. The awarded damages ranged from Ksh25, 000 to Ksh1, 200,000. The higher penalties and award for the damages in favour of the complainants targeted repeat offenders, willful non-compliance, and data processing for commercial gain.
About 18 complaints resulted in enforcement notices, while 16 cases resulted in both awards for damages and enforcement notice. Some complaints were resolved amicably or dismissed. The fines and enforcement notices highlight growing regulatory scrutiny.
The ODPC also issued enforcement notices to address violations. The report also noted major systemic changes that emphasise express consent, strict enforcement of data subject rights, and penalties for obstructing investigations.
The recommendations made by the ODPC include strengthening sector-specific compliance frameworks, enhancing ODPC resources, promoting public awareness, and adopting privacy-enhancing technologies.
The report also calls for fostering cross-sector collaboration and addressing compliance gaps. Doing, so the report noted, Kenya can build a robust data protection ecosystem that safeguards individual privacy, strengthens accountability, and supports sustainable economic growth.
The report calls for strengthening sector-specific compliance frameworks, particularly for high-risk industries like financial services, health, and education, to address their unique data protection challenges.
“Sector regulators should explore co-regulation with ODPC to achieve the objectives of the Data Protection Act. Enhancing regulatory oversight by equipping the ODPC with more resources and ensuring data protection laws keep pace with technological advancements is critical,” the study reveals.
The study also noted that public awareness and education are key, with proposed campaigns to inform citizens of their rights and mandatory training for organisations to improve compliance.
Strengthening data subject rights through clearer complaint mechanisms and ensuring timely responses to requests is another priority. Cross-sector collaboration is encouraged to bridge systemic gaps, while leveraging technology is recommended to enhance enforcement and mitigate data breaches.
Additionally, it advises that policymakers should monitor informal sectors to identify compliance gaps and implement interventions without stifling innovation. “These measures aim to create a strong, adaptable data protection framework that balances individual privacy with economic development,” he says.



