An employee’s laptop is stolen from a parked car. It holds a spreadsheet of client names, phone numbers and identity card copies. What happens next is governed by Kenya’s data breach notification rules , and the first hours matter.

What counts as a personal data breach in Kenya?
A breach is wider than a hack. It includes accidental or unlawful destruction, loss or alteration of personal data, and unauthorised disclosure of or access to it: a misdirected email, a lost file, a database exposed by a misconfigured server. Under the Data Protection Act 2019, the duty to notify turns on the risk the incident poses to the people whose data was involved, not on how the incident happened.
When must you notify the ODPC and the people affected?
A controller that becomes aware of a breach must notify the Office of the Data Protection Commissioner without undue delay and, where feasible, within seventy-two hours. Where the breach is likely to affect data subjects , for example exposure of financial, health or identity data , the affected people must also be informed in clear language, with steps they can take to protect themselves. Where unauthorised access to a computer system is suspected, the Computer Misuse and Cybercrimes Act 2018 is also engaged, and the Kenya Law website publishes both statutes.
What should a breach response plan contain?
- A named response team with defined roles for IT, legal and communications.
- Logging and detection that show what happened and when.
- Templates for notifying the ODPC and affected individuals.
- Vendor clauses requiring processors to report incidents promptly.
- A post-incident review that fixes the root cause, not just the symptom.
Processors owe the controller a duty to alert it without undue delay, which makes well-drafted supplier contracts part of any response plan. Our contract lawyers can review vendor terms for that purpose. Businesses reviewing their readiness often coordinate the legal and technical workstreams through a governance exercise rather than waiting for an incident , see our governance advisory services. Even where notification is not required, keep an internal record of the incident and the reasoning: a documented assessment is easier to defend if questions come later.
For guidance on your specific situation, contact CS Advocates LLP , call, WhatsApp, or book a confidential consultation at our Westlands, Nairobi office.