Insights / Regulatory & Compliance

Your Company Just Had a Data Breach. What Do You Actually Do in the First 72 Hours?

By Clay & Associates Advocates · 3 min read ·

A man focused on his laptop screen responding to an urgent matter

Section 43 of the Data Protection Act, 2019 gives you 72 hours from becoming aware of a breach to notify the Office of the Data Protection Commissioner, where there is a real risk of harm to the people whose data was involved. Most companies spend that window in a state of confused escalation rather than a defined sequence of steps. Here is what those 72 hours actually need to look like.

The clock starts when you become aware, not when you are certain

The 72-hour period runs from when the company first becomes aware that a breach occurred, not from when a full investigation confirms exactly what happened. Waiting for complete certainty before starting the clock is not a safe reading of the Act. If your organisation uses a third-party data processor, that processor is separately required to notify you within 48 hours of becoming aware of a compromise on their side, which in practice means you may have as little as 24 hours left to act once they tell you.

Hours 1 to 6: contain and confirm

Stop the ongoing exposure first, revoke compromised credentials, isolate affected systems, close the specific gap that allowed access. In parallel, start a written, chronological log of what is known and when it was learned. This log is not optional paperwork, it is one of the specific things your eventual notification to the Commissioner is required to contain, and starting it late means reconstructing it from memory afterward.

Hours 6 to 24: work out whether it is actually notifiable

Not every incident meets the threshold. The trigger is unauthorised access to or acquisition of personal data where there is a real risk of harm to the data subject, not every security event a company experiences. Establish, as best you can this early, what data was actually involved, how many people are affected, and what categories of personal data were exposed. Where full detail is not yet available within the window, Kenyan practice, consistent with how the ODPC has generally handled these cases, accepts a preliminary notification based on what is known, followed by a more complete one once the investigation concludes, rather than waiting past 72 hours for a complete picture.

Before hour 72: notify the Commissioner, with the right content

The notification needs to cover, at minimum, when and how the company became aware of the breach, a chronological account of the steps taken since, details of how the breach occurred where known, the number of data subjects affected, and the categories of personal data involved. If you genuinely cannot meet the 72-hour deadline, the notification must be accompanied by an explanation for the delay, this is a real allowance built into the framework, not a technicality to avoid mentioning.

Deciding whether to notify the affected individuals

This is a separate decision from notifying the Commissioner, triggered by the same real-risk-of-harm standard but owed directly to the people affected rather than the regulator. The Act does not prescribe a specific format, an email to identifiable individuals, a notice on your website, or a notice in a newspaper of wide circulation are all accepted depending on how many people are affected and whether you can actually reach them directly. What matters is that the notice is not delayed simply because the format was not obvious.

Why the first 72 hours matter beyond the deadline itself

Beyond the administrative fine, which can reach KES 5,000,000 or one percent of annual turnover, affected individuals can separately claim compensation for financial loss, identity theft, reputational harm, or emotional distress. A company that can show a disciplined, documented response in the first 72 hours is in a materially better position, both with the regulator and in any later claim, than one that can only show confusion followed by a late, thin notification.

Sources

&

Clay & Associates Advocates
This article is general information, not legal advice. For advice on your matter, speak to counsel.

Related Insights

Discover more