An email arrives from a customer: “send me everything you hold about me.” Data subject access requests are among the most common exercises of rights under the Data Protection Act 2019, and among the most mishandled , not from obstruction, but because no process is ready when the request lands. What follows is what the right covers and how to respond defensibly.

What can a data subject ask for in Kenya?
- Confirmation of whether personal data about them is being processed, and access to that data
- Information about the purposes of processing, the recipients, and safeguards for cross-border transfers
- Rectification of inaccurate or incomplete data
- In defined circumstances, an end to processing based on legitimate interests or direct marketing
- A copy of the data in a form that is clear and intelligible , not a database dump
How should an organisation handle an access request?
With a process, not an improvisation. The request should be routed to a single intake point , many obligations under the Act fail at the level of an email no one owns. Verify the requester’s identity proportionately; log the date of receipt, because the clock starts immediately; search the systems the data map identifies, including mailboxes and vendor-held records; and review the results before release. Some material may be withheld , other people’s personal data, legally privileged documents , but the exemptions are construed carefully, and the response should explain any redactions. The right arises under the Act, published on Kenya Law, with procedural detail in the regulations made under it.
What are the risks of getting the response wrong?
The requester may complain to the Office of the Data Protection Commissioner, which can investigate and take enforcement action, examining the underlying processing more closely than a tidy response would have invited. Refusing a request without documented justification is treated more severely than a late one, and employees’ requests , a recurring source , deserve the same discipline as customers’.
What should be in place before a request arrives?
A data map, an owner named for requests, a response template, and a short policy telling staff what to do the moment such an email appears. Our governance and advisory practice helps organisations build that readiness and advises on contested requests, and our practice areas page describes the wider compliance work.
For guidance on your specific situation, contact CS Advocates LLP , call, WhatsApp, or book a confidential consultation at our Westlands, Nairobi office.