Digital credit grew in Kenya faster than its compliance did, and data protection became the flashpoint: lending apps that harvested phone contacts, listed borrowers publicly, or pressed guarantors through messaging have all faced the consequences. For fintech teams building on that market today, the Data Protection Act 2019 is not an afterthought , it is part of the product.

Why are digital lenders under data protection scrutiny?
The Office of the Data Protection Commissioner has investigated and fined digital credit providers over collections practices , contacting people harvested from a borrower’s phone book, disclosing debts to employers and family, and processing data with no lawful basis at all. The pattern predated the Act’s full enforcement, but the Act now gives the regulator a complete toolkit: registration duties, consent standards, enforcement notices and financial penalties.
What does the law require before an app collects data?
- Registration with the ODPC as a data controller and processor, with activities accurately described
- A lawful basis for each purpose , consent that is specific, not bundled into terms of service
- Privacy notices that a borrower can actually read: who processes what, why, for how long, and who receives it
- Restraint on access to device features , access to contacts, messages or location must be justified for the credit purpose
- Data protection impact assessments for high-risk processing such as credit scoring and automated decisions
Where credit information is shared with reference bureaus, the arrangements must sit within the credit information sharing framework, and the data sharing agreements behind it should be in writing and reviewed like any material contract. The Act is on Kenya Law.
What should fintech teams review before launch?
Consent screens and the notice behind them; collections scripts and the conduct of third-party agents; retention limits on application data and device records; the security of embedded software kits that quietly lift data; and hosting arrangements where personal data leaves Kenya, which require the transfer safeguards the Act contemplates. Our banking and securities practice advises lenders on regulatory licensing and product structures, and our governance and advisory practice on the data protection programme that must sit underneath. Our practice areas page sets out the combined work.
For guidance on your specific situation, contact CS Advocates LLP , call, WhatsApp, or book a confidential consultation at our Westlands, Nairobi office.