Kenyan schools handle some of the most sensitive personal data that exists about a family — a child's health information, academic performance, disciplinary history, family financial circumstances, and biometric data in some cases. Yet data privacy is one of the least understood compliance areas among Kenyan school principals. This guide covers what the law requires and what practical steps bring your school into compliance.
Kenya's Data Protection Act (2019) establishes comprehensive requirements for how any organisation — including schools — collects, processes, stores, and shares personal data. The Act is enforced by the Office of the Data Protection Commissioner (ODPC), which has the power to investigate complaints and impose penalties for non-compliance.
Schools are data controllers under the Act, meaning they determine how and why personal data is processed. This creates specific legal obligations, not just good practice recommendations.
Health information and disciplinary records are considered sensitive personal data under the Act, requiring an even higher standard of protection than general personal data.
Schools must have a lawful basis for every category of data they collect. For most school data, this basis is the performance of a contract (the education service) or a legal obligation (regulatory reporting requirements like NEMIS). Data collected beyond what is necessary for these purposes requires explicit parental consent.
Data collected for one purpose should not be used for an unrelated purpose without consent. A parent's phone number collected for emergency contact purposes should not be added to a marketing list for a school fundraising event without their agreement.
Schools should only collect data that is genuinely necessary. A common compliance gap is collecting excessive information during admission — family details unrelated to the child's education, for example — without a clear purpose or lawful basis for holding it.
Schools must implement appropriate technical and organisational measures to protect data from unauthorised access, loss, or disclosure. This is where paper-based systems create significant risk — a filing cabinet with student health records is not secure in any meaningful sense, while a properly access-controlled digital system with role-based permissions is.
Practical risk area: WhatsApp groups where sensitive student information is shared visibly to other parents are a common and serious data privacy risk in Kenyan schools. A parent typing a child's medical condition or fee balance into a group chat visible to 40 other families is a data breach, even if unintentional.
Schools regularly share data with third parties — the Ministry of Education (NEMIS), TSC, exam bodies, and increasingly digital service providers including school management platforms. The Data Protection Act requires that any third party processing school data on the school's behalf does so under a clear data processing agreement, with appropriate security measures in place.
When selecting a school management system, principals should verify that the provider has clear data protection practices — encryption, access controls, and a documented commitment to not sharing school data with unauthorised parties.
Parents (on behalf of their children, who are minors) have rights under the Data Protection Act including the right to access what data the school holds about their child, the right to request correction of inaccurate data, and the right to be informed about how their data is used. Schools should have a simple, clear process for parents to exercise these rights — even a straightforward email address for data requests satisfies this obligation for most schools.
Edupath SMS uses role-based access controls, encrypted connections, and multi-tenant data isolation to keep every school's data secure and private. Free to start.
Create Free Account