Table of Contents
- Introduction
- What Makes Health Data Different
- Step 1: Register With the ODPC
- Step 2: Get Your Lawful Basis Right
- Step 3: Build a Compliant Privacy Notice
- Step 4: Apply Data Minimisation
- Step 5: Lock Down Security
- Step 6: Run a DPIA
- Step 7: Breach Response Plan
- Step 8: Formalise Vendor Contracts
- Step 9: Set a Retention Period
- Step 10: Honour Patient Data Rights
- The Bottom Line
- Frequently Asked Questions
- Want Your HMIS to Handle Compliance?
Key Compliance Requirements for Kenyan Health Facilities Under the Data Protection Act
If you manage a clinic or hospital in Kenya and store patient records on a computer, a cloud-based HMIS, or even a well-organised Excel sheet, you are already subject to one of the strictest data protection Kenya clinics regimes in East Africa whether you’ve formally registered for it or not.
The risk is real. The Office of the Data Protection Commissioner (ODPC) has moved firmly from awareness into active enforcement. In a recent reporting period, it determined 96 complaints and issued dozens of enforcement and penalty notices. Compensation orders now run into the hundreds of thousands of shillings.
KMPDC added a healthcare-specific requirement on top of the DPA itself. Since January 2025, every new health facility registration must include a valid Certificate of Data Handler and/or Processor from the ODPC. Existing facilities were given until the end of March 2025 to get certified. If your facility hasn’t done this yet, you are already behind. This can affect your ability to renew or expand your KMPDC licence.
Under the Data Protection Act, 2019 (DPA), patient information isn’t just “personal data” – it’s classified as sensitive personal data, alongside things like a person’s health status, genetic data, and biometric data. That classification means health facilities carry a heavier compliance burden than an ordinary retail business. The ODPC can impose administrative fines of up to KES 5 million or 1% of annual turnover. Criminal sanctions and compensation claims from affected patients can also apply.
The good news: compliance here is not abstract legal theory. The ODPC has published a dedicated Guidance Note on the Processing of Health Data that spells out, almost step by step, exactly what a hospital, clinic, laboratory, or pharmacy needs to have in place. This article walks you through it in plain language.
First, Understand What Makes Health Data Different
Under the DPA, “health data” covers any information about a patient’s past, present, or future physical or mental health. This includes not just diagnoses, but anything collected in the course of registering for or receiving health services. Because this falls under “sensitive personal data,” the law requires healthcare providers to apply extra safeguards that don’t apply to, say, a shop collecting a customer’s phone number for a loyalty program.
Practically, this means two things for your data protection Kenya clinics compliance:
1. You need a valid lawful basis for every category of patient data you collect and process not just a general “patients agree to share info” assumption.
2. You need documented, demonstrable safeguards – the law puts the burden of proof on you to show compliance, not just claim it.
Step 1: Register With the ODPC (and Get Your KMPDC Certificate)
The law requires all health sector entities to register with the ODPC regardless of their size, turnover, or number of employees. Healthcare is one of the categories the law singles out for compulsory registration alongside financial services and telecoms. You can register through the ODPC’s online portal. Fees vary depending on whether you fall into the micro/small, medium, or large data controller tier.
KMPDC now requires every health facility new or already licensed to hold a valid Certificate of Data Handler and/or Processor. KMPDC has effectively made this certificate a precondition for facility licensing. If you’re renewing your KMPDC registration this year, get this sorted before you’re caught at the counter without it.
Action this week: Confirm whether your facility is registered with the ODPC and holds a current KMPDC Certificate of Data Handler/Processor. If not, start the application immediately, this is now a licensing issue, not just a legal-compliance nicety.
Step 2: Get Your Lawful Basis for Processing Right and Document It
The ODPC’s guidance requires facilities to identify one lawful basis for each processing activity before it begins. You must document that basis. For most day-to-day clinical work, you’ll rely on one of these:
Common Lawful Bases for Health Data Processing
Performance of a contract – treating a patient under an agreed service (including insurance-funded care).
Consent – freely given, informed, specific, and revocable. This is different from medical/clinical consent to a procedure, and you need to track both separately.
Vital interests – emergency situations where the patient can’t consent (e.g., an unconscious patient needing urgent care).
Legal obligation – reporting requirements to public health authorities, for example.
Legitimate interest – routine administrative processing like appointment scheduling and billing.
Medical Consent vs. Data Protection Consent
Critical, often-missed distinction: Medical consent (the patient agreeing to a procedure) and data protection consent (the patient agreeing to how their data is collected, stored, and shared) are legally separate. A signed treatment consent form does not automatically cover you for using that patient’s data for research, marketing, or sharing with a third-party lab. Each of those needs its own basis, clearly identified before you start.
Action Step: Map Your Data Categories
Action: Map out every category of patient data you collect (registration details, clinical history, lab results, billing/insurance data) and write down the specific lawful basis for each. Don’t rely on a single blanket justification for everything.
Step 3: Build a Compliant Privacy Notice
Every patient-facing form, registration desk, and digital intake process needs a privacy notice covering, at minimum:
• What categories of data you collect and why
• How data is collected, stored, and kept up to date
• How confidential waste is disposed of
• Security measures in place (encryption, passwords, firewalls)
• Who counts as a “trusted third party” you may share data with
• What happens if data is lost or stolen
• Rules for sharing or transferring data outside the facility
• The patient’s rights and how to exercise them
• Contact details for your Data Protection Officer, if you have one
Present this notice at patient registration and reference it on documents the facility issues, don’t bury it in a policy nobody reads.
Step 4: Apply Data Minimisation to Every Intake Form
A common compliance gap is registration forms collecting far more than clinically necessary. Occupation, next-of-kin details for every visit type, marital status for a routine outpatient consult all collected “just in case.” Under the data minimisation principle, you should only collect what’s necessary for the specific health purpose at hand. This is a key aspect of data protection Kenya clinics compliance. Review your intake forms and cut anything you can’t clearly justify as clinically or administratively necessary.
Step 5: Lock Down Security – Encryption, Access Control, and Local Storage
The DPA requires facilities to implement strong technical and organisational safeguards, including:
Access controls – password-protected accounts and role-based access. A receptionist should not view full clinical histories they don’t need for their role.
Encryption – both at rest (stored records) and in transit (data moving between your HMIS and, say, an insurer’s claims portal).
Data localisation – the DPA requires facilities to store and process personal data within Kenya. Exceptions apply only in narrow circumstances involving explicit consent or an adequately protective destination country. If your HMIS or cloud vendor hosts your patient database entirely offshore with no local copy, that’s a compliance gap worth raising with them directly.
Physical security – locked records rooms, controlled access to server areas, and secure disposal procedures for paper records and retired hardware.
Step 6: Run a Data Protection Impact Assessment (DPIA) Before Rolling Out New Systems
You must run a DPIA whenever a new system or process creates high risk to patient rights. This includes rolling out a new EMR system, launching a patient app, or starting a research study involving patient data. Even where it’s not strictly mandatory, the ODPC recommends running one anyway, since it’s the practical tool for spotting privacy gaps before they become breaches. If a DPIA turns up high residual risk you can’t mitigate, you must consult the Data Commissioner before going live.
Action: Before signing off on any new HMIS module, patient portal, or third-party integration, run a DPIA. Don’t treat it as paperwork to backfill after the system is already live with patient data in it.
Step 7: Have a Breach Response Plan Ready – Not One You’ll Write During the Crisis
This is where most facilities get caught out. The clock starts the moment you become aware of a breach, not when you’ve finished investigating it:
72 hours – you must notify the ODPC within 72 hours of becoming aware of a personal data breach.
48 hours – if you use a third-party data processor, they must notify you within 48 hours of discovering a breach. This gives you time to meet the 72-hour ODPC deadline.
Affected patients – you must also notify them in writing without undue delay where the breach carries real risk to their rights.
Your notification to the ODPC must include specific details: when and how the breach was discovered, a timeline of what you did afterward, how many patients were affected, what categories of data were exposed, the likely harm, and what you’re doing to fix it and stop it happening again. Trying to assemble all of that from scratch during an actual breach is how facilities miss the deadline. Draft the template and the internal escalation process now, while there’s no fire to put out.
Step 8: Formalise Contracts With Every Vendor Who Touches Patient Data
Your HMIS provider, an external lab, a billing company, an insurer’s claims platform – any of these that process patient data on your behalf must be bound by a written Data Processing Agreement. This confirms they act only on your instructions and are bound by the same obligations you are as the data controller. If your current HMIS vendor can’t produce this kind of agreement, that’s a red flag worth acting on before your next audit, not after.
Step 9: Set (and Justify) a Real Retention Period
The DPA doesn’t provide a fixed number of years for how long to keep patient records. However, it does require you to have a specific, documented, and justifiable retention policy, rather than keeping everything indefinitely “just in case.” A common approach used by facilities is retaining non-returning or deceased patients’ records for around seven years before secure destruction or anonymisation. Your policy should state your own number and the reasoning behind it, and you should review it periodically.
Step 10: Know and Be Ready to Honour Patient Data Rights
Patients have enforceable rights over their own records. Each has a practical deadline your front desk and records team need to know:
Right to access their data – respond within 7 days.
Right to rectification of inaccurate records – correct within 14 days.
Right to data portability (e.g., transferring records to a new facility) within 30 days, in a structured, machine-readable format.
Right to erasure, object to processing, and not be subjected to purely automated decision-making.
If your team doesn’t currently have a documented process for handling these requests – who receives them, who verifies identity, who actually pulls and formats the data that’s a gap an ODPC audit will find quickly.
The Bottom Line
None of this requires turning your clinic into a law firm. It requires treating patient data the way you’d want your own medical file treated: collected for a clear reason, protected properly, shared only with good cause, and deleted when there’s no longer a reason to keep it. Facilities that build these habits into their daily HMIS workflows rather than bolting on compliance after an ODPC notice arrives are the ones that pass audits calmly and keep their KMPDC licence uninterrupted. Data protection Kenya clinics must prioritize is building compliance into everyday operations.
Want Your HMIS to Handle Compliance for You, Not Against You?
Manually tracking consent, access requests, retention schedules, and breach timelines across paper files and disconnected systems is exactly how facilities end up on the wrong side of an ODPC audit. Sapiens IT Lab builds HMIS platforms for Kenyan hospitals and clinics with role-based access control, encrypted records, audit trails, and Kenya-based hosting built with DPA and KMPDC compliance in mind from day one.
Want a free compliance gap-check on your current patient records system? Book a free 15-minute HMIS demo via WhatsApp or request a free on-site IT assessment – our team will review your current data handling setup and flag exactly where your compliance gaps are, at no cost.
Chat with Us on WhatsAppFrequently Asked Questions
Do small private clinics in Kenya need to register with the ODPC?
Yes. All health sector entities must register with the ODPC regardless of their turnover or employee count. Healthcare is one of the sectors the law requires to register outright, alongside financial services and telecoms.
What is the Certificate of Data Handler/Processor, and do I need it?
This certification comes from the ODPC. KMPDC now requires it as part of health facility licensing. New facility registrations have needed it since January 2025. Existing facilities were required to obtain it by March 31, 2025. Without it, your facility’s KMPDC licensing status can be affected.
How much can the ODPC fine a health facility for a data breach?
Administrative fines from the ODPC can reach up to KES 5 million or 1% of annual turnover. Criminal penalties and patient compensation claims can apply on top of that.
How quickly must we report a data breach?
You must report to the ODPC within 72 hours of becoming aware of a breach. If your HMIS vendor or another processor discovers the breach first, they must tell you within 48 hours. This gives you time to meet the ODPC deadline.
Can we store patient data on servers outside Kenya?
Generally, no – the DPA requires facilities to store and process personal data within Kenya. Exceptions apply only in narrow circumstances such as explicit patient consent or a destination country with adequate protections. Confirm this directly with your HMIS or cloud vendor.




