Data protection is not just a legal document. It is an operational discipline. We do not write 40-page policies that gather dust. We audit how data actually moves in your business, from WhatsApp groups to unlocked filing cabinets, and build practical, enforceable guardrails.
The Data Protection Act (2019) requires "appropriate technical and organizational measures." Most founders think this means buying expensive cybersecurity software. It does not. It means basic operational discipline.
A photo of a customer's ID, an M-Pesa receipt, or a new employee's KRA PIN is snapped and dropped into a "Logistics Team" WhatsApp group. It is fast. It is convenient. And it is a direct, easily provable violation of the Data Protection Act. If that phone is lost, your business is exposed.
Founders worry about hackers, but the biggest breaches happen in the back office. Employee files left on desks in open-plan areas. Old distributor contracts with sensitive pricing sitting in unlocked cabinets. Disposed documents thrown in the general bin, not shredded.
You are building a new customer loyalty app, a distributor portal, or implementing biometric attendance. You are collecting new data at scale, but you have no formal Data Protection Impact Assessment (DPIA) to map the risks before launch. The ODPC will map them for you, and the fines are not theoretical.
Plain-English questions about how data actually moves through your business, not legal jargon. Answer for how things really run, not how the policy on the shelf says they should.
Your answers never leave this page. Nothing is stored, tracked, or sent anywhere until you choose to share your score.
The WhatsApp Liability. Do employees routinely share sensitive information (customer IDs, KRA PINs, M-Pesa receipts, or employee bank details) via personal or business WhatsApp groups?
The Physical File Illusion. Are physical files containing sensitive information (HR records, supplier contracts, customer ledgers) stored in unlocked cabinets or openly accessible areas in the office?
The Blind Collection. If the ODPC asked you today to prove how and when a specific customer or employee consented to you collecting their data, could you produce that record in under 24 hours?
The Hoarding Habit. Do you keep customer, supplier, or former employee data indefinitely "just in case," with no formal process for securely deleting or destroying it when it is no longer needed?
The Third-Party Leak. Do you share customer delivery details, contact information, or pricing data with external parties (e.g. independent delivery riders, external accountants, or new distributors) without any formal data-sharing agreement or confidentiality clause?
The Ghost Access. When an employee resigns or is terminated, is there a formal, immediate checklist to revoke their access to company emails, WhatsApp business groups, shared drives, and physical premises?
The Device Risk. Do staff members use personal, unmanaged phones or laptops to access, store, or process official company and customer data, with no remote-wipe capability if the device is lost or stolen?
The Disposal Blind Spot. Are outdated documents containing sensitive data (e.g. old invoices, ID copies, payroll sheets) thrown into general waste bins rather than being securely shredded or destroyed?
The Shadow IT. Are employees using unauthorized, free, or unvetted third-party apps (e.g. random online PDF converters, unapproved cloud storage, or AI tools) to process company documents or customer data?
The Incident Void. If a staff member lost a company phone containing customer data tomorrow, do you have a documented, step-by-step process for containing the breach and notifying the relevant parties, including the ODPC if required?
The Biometric Blind Launch. Are you currently using, or planning to use, biometric systems (fingerprint or face ID for attendance or access) without having conducted a formal Data Protection Impact Assessment (DPIA) for this specific technology?
The Policy Fiction. Do you have a data protection or privacy policy that was copied from the internet, but your team has never been trained on it and it does not reflect how your business actually operates day-to-day?
Enter a WhatsApp number or email to unlock your score.
We use this only to personalize the WhatsApp message below and follow up on your results. It stays in your browser, is never sent to our servers, and only reaches us if you hit send.
Want to walk through this together? Message your score and I will tell you exactly what to fix first. No charge, no obligation.
We act as your operational translator. We take the requirements of the law and turn them into one-page, actionable runbooks your staff will actually follow.
Before the regulator audits you, we do. We walk your floor, review your HR files, map your customer data flows, and check your digital channels.
Deliverable: A direct, prioritized Risk Report with a "Pass, Condition, or Fail" verdict and immediate mitigation steps.
For businesses launching new systems, apps, or customer-facing processes. We sit with your operations team, map the actual workflow, and document the data risks before you launch, ensuring you meet ODPC requirements without delaying your project.
We do not hand you a generic, 40-page legal template. We build concise, one-page data handling runbooks tailored to specific roles, e.g. "How the Depot Manager Handles Delivery Data," "How HR Stores Employee Records."
A no-jargon session for your team. We explain exactly what they can and cannot do with customer and company data, turning your staff from your biggest liability into your first line of defense.
Just like our Transition Readiness Assessments, we do not do this from a boardroom across town.
We are on-site. We observe how data is collected, stored, shared, and destroyed across your digital and physical operations. We interview key staff.
We analyze the gaps, draft the risk report, and co-create the one-page runbooks with your team to ensure they are actually workable.
A working session with you and your senior team to review the findings and agree on the 30-day implementation plan.
A standalone Data Protection Audit and Runbook Design is typically priced between KES 80,000 and KES 150,000, depending on the size of your team, the complexity of your data flows, and whether a DPIA is required.
Can also be bundled as an add-on to your Transition Readiness Assessment for a consolidated operational health check.
Message me with a short description of your business and the data you handle, and I will give you a straight number before we start.
If your question is not here, that is what the WhatsApp button is for.
Not necessarily. We handle the operational mapping and practical policy design. If your business requires formal legal registration with the ODPC or complex legal counsel, we can work alongside your existing lawyer to ensure the operational reality matches the legal paperwork.
Then you find out now, on your terms, with a clear roadmap to fix it. A "Condition" or "Fail" verdict is not a judgment; it is a prioritized sequence of actions to get you compliant before an external party forces your hand.
No. The pattern we see applies to every business that handles data: manufacturing, retail, agro-processing, distribution, and logistics. If you have employees, customers, or suppliers, you have data governance risks.
Absolutely. What we see in your books, operations, and data flows stays strictly confidential. We operate under a strict Non-Disclosure Agreement (NDA). Nothing leaves the engagement without your sign-off.
Most businesses handling personal data at scale need to register with the ODPC, though the exact threshold depends on your revenue and the volume of data you process. We are not a law firm, but as part of the audit we tell you where you stand and connect you with legal counsel for the registration itself if you need it.
Not automatically, but how most businesses do it usually is. Sending an ID photo or M-Pesa receipt into a personal or unsecured WhatsApp group, with no access controls and no record of who saw it, is exactly the kind of practice the Data Protection Act was written to stop. It is one of the most common findings in our audits.
Send one sentence: what kind of data your business collects, and the single thing that worries you most about how it is currently stored. That is enough for an honest answer.
You will get an honest answer on whether this is right for you. Even if the answer is no. I typically reply within a few hours on WhatsApp during business days.