Insights / Regulatory & Compliance

Outsourcing Your Data Protection Officer in Kenya

By Clay & Associates Advocates · 6 min read ·

A software developer working on a laptop, representing the technical compliance work an outsourced data protection officer oversees under Kenya's Data Protection Act.

Kenya’s Data Protection Act does not require every business to hire a full-time employee to hold the title of data protection officer. It requires certain businesses to designate one, and the Act’s own wording leaves the “how” open in a way that many businesses, and some of their advisers, tend to read more narrowly than the text actually supports. For a growing company deciding how to meet this obligation without adding permanent headcount, understanding exactly what the law requires, and does not require, is the first commercial decision to get right.

When the Data Protection Act Actually Requires a DPO

Section 24(1) of the Data Protection Act, 2019 sets out three circumstances in which a data controller or data processor must designate a data protection officer: where the processing is carried out by a public body or private body, other than a court acting in its judicial capacity; where the entity’s core activities consist of processing operations which, by their nature, scope or purpose, require regular and systematic monitoring of data subjects; or where the entity’s core activities consist of processing sensitive categories of personal data. That last category has grown wider than many businesses realise, since Kenya’s data protection framework now treats categories such as political affiliation and trade union membership as sensitive data requiring heightened handling. A fintech running behavioural scoring, a health-tech platform, an HR software provider, and an employer processing biometric attendance data can all fall within these criteria even without intending to.

What the Act Actually Says About Who Can Hold the Role

This is where the statute is more permissive than most businesses assume. Section 24(2) states that a data protection officer “may be a staff member” of the data controller or data processor, and may fulfil other tasks and duties provided this does not create a conflict of interest. The word “may” is doing real work here: the Act does not say the officer must be an employee, only that an employee is one permitted option. Nothing in section 24 restricts the role to an internal appointment, and section 24(5) confirms the actual qualifying criterion is substantive, not employment status: a person may be designated a data protection officer if they hold relevant academic or professional qualifications, including knowledge and technical skills in data protection matters. A business is entitled to read this as permitting a contracted, external appointment, provided the appointee is genuinely qualified and the conflict-of-interest safeguard in section 24(2) is respected.

The Statutory Duties a DPO Must Actually Perform

Section 24(7) sets out five specific duties: advising the data controller or processor and its employees on data processing requirements under the Act or any other written law; ensuring compliance with the Act on the controller’s or processor’s behalf; facilitating capacity building among staff involved in data processing; providing advice on data protection impact assessments; and co-operating with the Data Commissioner and other authorities on data protection matters. Section 24(6) additionally requires the data controller or processor to publish the officer’s contact details on its website and communicate them to the Office of the Data Protection Commissioner, so that both data subjects and the regulator have a working point of contact regardless of whether that person sits inside the business or outside it.

Group Entities and Shared Appointments

The Act also anticipates that one data protection officer will often serve more than one entity. Section 24(3) allows a group of entities to appoint a single data protection officer, provided that officer is accessible by each entity in the group, and section 24(4) allows several public bodies to share a single designated officer, taking into account their organisational structures. This is a further textual signal that the drafters did not intend the role to be tied to a single employer’s payroll: an arrangement in which one qualified officer serves several related or unrelated entities is expressly contemplated, which is exactly the structure an outsourced DPO service provides.

Why Outsourcing Is Often the More Defensible Option, Not a Shortcut

For a small or mid-sized business, hiring a dedicated, suitably qualified employee purely to hold this role is rarely proportionate to the risk it is meant to manage, and a poorly qualified internal appointee creates its own exposure if the Data Commissioner ever tests whether section 24(5)’s qualification standard was actually met. An external appointment from a firm that specialises in Kenyan data protection compliance can meet that qualification bar more reliably than an internal generalist given the title as an afterthought, while still satisfying the accessibility and contact-publication requirements in sections 24(3) and 24(6). The conflict-of-interest concern in section 24(2), which exists specifically to prevent a DPO from also being the person whose processing decisions the DPO is meant to police, is in some respects easier to manage with an external appointee than with an internal one wearing two hats.

What to Check Before Appointing an External DPO

A business considering this route should confirm three things before signing an engagement: that the proposed officer’s qualifications are documented in a way that would satisfy section 24(5) if the Data Commissioner asked; that the engagement contract clearly separates the officer’s advisory and compliance functions from any other services the same firm provides to avoid a conflict of interest; and that the contact-publication obligation in section 24(6) is actually carried out on the business’s own website, not left as an internal arrangement the public cannot see. None of this is complicated to get right, but each is a point the Office of the Data Protection Commissioner can and does test during an inquiry.

How We Can Help

Clay & Associates Advocates acts as outsourced data protection officer for businesses across financial services, technology and other regulated sectors, and advises on the wider compliance obligations under the Data Protection Act. Our coverage of Kenya’s cross-border data transfer compliance regime and the expanded definition of sensitive personal data covers related obligations that a designated DPO is responsible for advising on. Contact our Regulatory & Compliance practice to discuss appointing an external data protection officer for your business.

Sources: The Data Protection Act, 2019, sections 24 and 25.

Frequently asked questions

Does Kenyan law require a data protection officer to be a full-time employee?
No. Section 24(2) of the Data Protection Act states that a data protection officer “may be” a staff member, which permits but does not require an internal appointment. The qualifying test in section 24(5) is the person’s relevant academic or professional qualifications, not their employment status.

Which businesses actually need to designate a DPO?
Any public or private body carrying out data processing, unless its core activities require regular and systematic monitoring of data subjects on a significant scale or involve sensitive categories of personal data, in which case designation becomes necessary under section 24(1).

Can one data protection officer serve more than one company?
Yes. Section 24(3) allows a group of entities to appoint a single data protection officer, provided that officer remains accessible to each entity, which is the same structure an outsourced DPO arrangement uses.

What happens if the DPO also has a conflict of interest?
Section 24(2) prohibits a data protection officer from taking on other tasks or duties that would create a conflict of interest with the compliance function, which is a key reason businesses structure the role as an independent external appointment rather than adding it to an existing internal role.

&

Clay & Associates Advocates
This article is general information, not legal advice. For advice on your matter, speak to counsel.

Related Insights

Discover more