Most organisations keep personal data far longer than any purpose justifies , because deleting feels risky and keeping feels safe. The Data Protection Act 2019 takes the opposite view: personal data should be retained no longer than necessary for the purpose collected, and then deleted or anonymised. A retention schedule turns that principle into something a business can operate.

How long may personal data be kept in Kenya?
The starting point is the storage limitation principle in the Data Protection Act 2019, published on Kenya Law: retention must be limited to the time necessary for the purposes for which it was collected. Two qualifications shape the answer. Some statutes impose minimum periods , tax records, for instance, must be kept for the period required under the Tax Procedures Act 2015, and employment and company records carry their own obligations. Some data also sits in records whose retention serves an evidential function. The exercise is not “delete everything quickly” but “justify every category’s period”.
What belongs in a retention schedule?
- An inventory of personal data by category , customers, employees, marketing lists, CCTV, support tickets
- The purpose and lawful basis for each category, drawn from the data map
- A retention period for each category, with the statute or business justification noted beside it
- The deletion or anonymisation method, including backups and vendor-held copies
- An accountable owner and a review date, so the schedule is maintained rather than filed
How is deletion carried out defensibly?
Deletion should be technical, not cosmetic: removal from live systems, indexed backups and processor environments, executed under instruction where vendors hold the data. Documentation matters , a log of what was deleted, when, and under which schedule entry evidences discharge of the obligation. Litigation holds are the recognised exception: where a dispute is reasonably anticipated, relevant data may be preserved, but the hold should be deliberate, scoped and lifted when the matter ends.
Where do organisations go wrong?
The recurring failures are unbounded backups, data held by departed vendors, and special categories , biometrics, health data , kept under ordinary schedules. The Office of the Data Protection Commissioner has treated over-retention as a compliance failure in its own right. Our governance and advisory practice prepares retention schedules and deletion programmes, and our practice areas page describes the wider work.
For guidance on your specific situation, contact CS Advocates LLP , call, WhatsApp, or book a confidential consultation at our Westlands, Nairobi office.