You collect client information — email addresses, phone numbers, sometimes financial or sensitive case details. Every day, that creates a compliance exposure most small firms and consultants haven’t actually looked at closely. It doesn’t have to be complicated, but it also isn’t optional.
Why this matters now
Kenya’s Data Protection Act was enacted in 2019, with the Office of the Data Protection Commissioner (ODPC) formally established and enforcement regulations following in 2020-2021. The Act gives the Data Commissioner real enforcement power: administrative fines of up to KES 5 million, or 1% of a company’s annual turnover — whichever is lower — for non-compliance, plus separate criminal penalties (fines up to KES 3 million or imprisonment up to 10 years) for specific offences like unauthorized disclosure of personal data.
A Data Protection Amendment Bill was proposed in 2025 that would change “whichever is lower” to “whichever is higher” for larger organizations — worth watching if you’re a bigger practice, though it isn’t current law yet.
Beyond the legal exposure, there’s a quieter cost: clients and partners increasingly expect a professional to have their data practices in order. It’s become a trust signal in its own right. A firm without a visible privacy policy looks like it hasn’t thought about this — and for a law firm specifically, that impression cuts especially deep, since data handling is close to the core of what clients are trusting you with in the first place.
The 4 things you actually need
1. Privacy Policy. A clear, specific statement of how you collect, use, store, and protect client data. It needs to be on your website, easy to find, and actually describe what your firm does — not a generic template with the wrong company name still in it (a more common problem than you’d expect).
2. Terms of Service. The rules of engagement with clients — what they’re agreeing to by working with you or using your site. Close to non-negotiable if you operate digitally in any capacity.
3. Cookie Policy. If your website uses any tracking — Google Analytics, Hotjar, or similar — you need disclosure and a consent mechanism. This isn’t optional under current guidance, even for simple analytics.
4. Data Processing Agreements. If you use third-party tools — email providers, a CRM, hosting — you need agreements in place that protect client data as it passes through those systems. This is frequently the most overlooked of the four, since it involves vendors rather than your own site.
The practical reality
Most consultants and professionals don’t realize that compliance isn’t about achieving legal perfection. It’s about demonstrating that you take data seriously, in a way a client or regulator can actually verify. Proper policies in place means you’re protected and visibly so. Their absence means you’re exposed — and increasingly, a sophisticated client will notice.
How this connects to your broader digital credibility
This is exactly the kind of signal we score under the Confidence category in the Digital Trust Index™ — SSL, privacy policy, terms of service, and consistent professional presentation all sit in the same bucket. Across the 100 firms we’ve scored, Confidence averages just 53%, meaning roughly half of what’s achievable is being left on the table, often for exactly this reason: nobody on the team was specifically responsible for noticing these documents were missing or outdated.
FAQ
Do I need a lawyer to write my privacy policy?
A template is a reasonable starting point, but it should be reviewed and adapted to reflect what your specific practice actually collects and how you actually use it. For a firm handling especially sensitive data, proper legal review is worth the investment.
Does this apply if I'm a solo consultant, not a registered company?
Yes — the Data Protection Act applies to data controllers and processors broadly, not just larger registered entities. Firm size doesn’t exempt you from the underlying obligations.
What's the single fastest fix if I have none of the 4 documents in place?
Start with the privacy policy — it’s the most visible, most expected document, and its absence is the most immediately noticeable gap to a visiting client.
Is this legal advice?
No — this is general awareness information, not legal advice specific to your situation. For anything beyond the basics, especially given real regulatory exposure, consult a lawyer qualified in Kenyan data protection law.