Managing human resources in Kenya has changed significantly since the full implementation of the Data Protection Act, 2019. For foreign companies, non-governmental organisations, and local enterprises, employee records are no longer just internal files. They are highly regulated repositories of personal and sensitive data. Understanding how the data protection act hr kenya framework governs your operations is essential to avoid severe penalties, which can reach up to five million shillings or one percent of your annual turnover.
As an employer, you act as both a data controller and a data processor. Every piece of information you collect, from a candidate resume during recruitment to medical records for health insurance, falls under the jurisdiction of the Office of the Data Protection Commissioner (ODPC). This guide provides practical, legally grounded insights into handling employee data lawfully in Kenya, ensuring your HR practices align with compliance requirements in 2026.
The Intersection of Employment Law and Data Protection
HR operations are fundamentally built on gathering personal information. However, the Employment Act Cap 226 and the Data Protection Act must be read together. While the Employment Act requires employers to keep specific records, such as disputes, leave days, and wages, the Data Protection Act dictates how that information must be collected, stored, secured, and eventually destroyed. You can read more about these mandatory files in our guide on employee records required by law in Kenya.
Under the law, employees are data subjects. They possess specific rights that you must respect. These rights include the right to be informed about why their data is being collected, the right to access their personal data, the right to object to processing, and the right to demand correction or deletion of false or outdated information. Balancing these rights with your operational needs requires a structured approach to HR data management.
If your organisation lacks the internal capacity to manage these complex regulatory intersections, partnering with professionals who offer HR outsourcing services in Kenya can mitigate compliance risks significantly. Structured outsourcing ensures that your employment contracts, HR policies, and employee handbooks are audited to meet both labour laws and data privacy standards.
Compliance Requirements Under the Data Protection Act HR Kenya Framework
Data protection is not a one-time project. It is a continuous cycle that starts before an employee is hired and continues long after they leave your organisation. To ensure complete compliance, HR departments must evaluate how they handle data at every stage of the employment lifecycle.
1. The Recruitment Phase
Compliance begins the moment you post a job advertisement. When candidates submit their CVs, cover letters, and academic certificates, they are trusting you with their personal data. HR departments often collect more information than necessary at this stage.
Under the principle of data minimisation, you should only collect information that is strictly relevant to assessing the candidate suitability for the role. For instance, asking for national identification numbers, NHIF or SHIF details, or bank account information during the initial application stage is unnecessary and violates the Act. This information should only be requested once an offer of employment has been made and accepted. For more on compliant hiring practices, see our guide on recruitment in Kenya.
Additionally, job applications must include a clear privacy notice. This notice should inform applicants why you are collecting their data, how long you will retain it if they are unsuccessful, and who will have access to it. If you use third-party agencies for talent acquisition, ensure they are legally compliant by utilizing professional recruitment services in Kenya that adhere strictly to ODPC guidelines.
2. Active Employment and Payroll Management
Once an employee joins your organisation, the volume of data you process increases. You must collect bank details, Kenya Revenue Authority (KRA) PINs, identity numbers, and emergency contact details. This data is essential for running payroll and fulfilling statutory obligations.
In 2026, statutory deductions in Kenya require the processing of sensitive data. Employers must calculate and remit the Social Health Insurance Fund (SHIF) levy at 2.75% of gross salary to the Social Health Authority, the Affordable Housing Levy (AHL) at 1.5%, and NSSF contributions. Processing these payments requires sharing data with government portals. The law allows this processing because it is necessary for compliance with statutory obligations, meaning you do not need explicit consent for these specific activities. However, the transmission of this data must remain secure. Be sure to review the latest SHIF rates for employers in Kenya to ensure your calculations are accurate.
Using secure payroll software is critical. Many organisations find that managing these calculations and security standards internally is too demanding. Engaging professional payroll processing services in Kenya ensures that salary processing, tax compliance, and statutory filings are managed within a highly secure, ODPC-compliant environment. All filings must be fully remitted by the 9th day of each month to avoid heavy statutory interest and penalties.
3. Separation and Data Retention
When an employee leaves your organisation, you cannot simply keep their files indefinitely. The Data Protection Act establishes the principle of storage limitation. Personal data must not be kept longer than necessary for the purpose for which it was collected.
However, this requirement sometimes conflicts with other Kenyan laws. For example, the Employment Act Cap 226, which you can access via Kenya Law, requires employers to keep certain records for at least six years to defend against potential labour disputes. Tax laws also require financial records to be kept for several years. Your HR data retention policy must strike a balance. Once the statutory retention period expires, you must securely delete, shred, or anonymise the former employee data.
Establishing the Legal Basis for Processing Employee Data
You cannot process personal data simply because an individual is your employee. Every processing activity must be justified by at least one legal basis recognized under Section 30 of the Data Protection Act. HR departments often mistakenly rely solely on consent. In an employment relationship, consent is rarely considered freely given due to the power imbalance between the employer and the employee. Therefore, relying on consent as your primary legal basis can be risky.
Fortunately, the Act provides other valid legal bases that are much more appropriate for HR operations:
- Performance of a Contract: You process bank details, job titles, and performance metrics because they are necessary to fulfill the employment contract. You should ensure these terms are clearly defined in your employment contract in Kenya.
- Legal Obligation: Processing KRA PINs, SHIF registration details, and NSSF numbers is required by Kenyan law. You do not need to ask for consent to deduct and remit taxes.
- Legitimate Interests: This includes activities like monitoring company email accounts or installing CCTV cameras in the office for security. However, you must conduct a Legitimate Interest Assessment (LIA) to ensure your business interests do not override the employee right to privacy.
Handling Sensitive Personal Data in the Workplace
The Data Protection Act treats certain categories of information with a higher level of protection. Sensitive personal data includes an employee health status, biometric data, family details, religious beliefs, and trade union membership. The processing of this data is subject to strict limitations.
For instance, if your office uses biometric fingerprint scanners for access control or attendance tracking, you are processing biometric data. You must conduct a Data Protection Impact Assessment (DPIA) before deploying such systems. This assessment helps you identify risks to employee privacy and implement security measures to protect the biometric templates from unauthorised access or theft.
Similarly, medical records collected for company insurance schemes or sick leave management must be kept strictly confidential. Access to this information should be restricted to authorized medical personnel or specific HR staff members who require it to manage benefits. It must never be stored in general employee files where other staff might view it.
Cross-Border Data Transfers for Multinational Entities
Many foreign companies and non-governmental organisations operating in Kenya use global HR management systems. These platforms often host employee data on servers located outside Kenya, such as in Europe, the United States, or South Africa.
Section 48 of the Data Protection Act prohibits the transfer of personal data outside Kenya unless you have proof of appropriate safeguards, or the recipient country has an adequate level of data protection. When using cloud-based HR portals, you must ensure that your service level agreements contain standard contractual clauses approved by the ODPC. Alternatively, utilizing a local employer of record in Kenya can simplify this process, as they handle the local employment and compliance requirements on your behalf, keeping data handling aligned with local statutes.
Practical Action Steps for HR Leaders
To align your HR department with the Data Protection Act, you should implement several practical changes immediately:
- Register with the ODPC: Every employer operating in Kenya must register as a data controller or data processor with the Office of the Data Protection Commissioner.
- Conduct a Data Audit: Map out all the personal data your HR department collects, where it is stored, who has access to it, and how it is eventually destroyed.
- Update Employment Contracts: Ensure your contracts contain clear data protection clauses detailing how the organisation processes employee information.
- Train Your HR Team: Your internal HR staff must understand security measures, such as locking physical filing cabinets, password-protecting spreadsheets containing salary details, and identifying phishing attempts.
- Appoint a Data Protection Officer: Depending on the size of your organisation and the nature of the data you process, you may be legally required to designate a DPO to oversee compliance.
Compliance is an ongoing responsibility that protects your organisation from reputational damage and financial penalties while fostering trust with your workforce. By implementing clear policies and secure systems, you ensure your business remains compliant with the laws of Kenya.


