Kenyan schools handle some of the most sensitive personal data that exists about a family — a child’s health information, academic performance, disciplinary history, family financial circumstances, and biometric data in some cases. Yet data privacy is one of the least understood compliance areas among Kenyan school principals. This guide covers what the law requires and what practical steps bring your school into compliance.
The legal foundation — Data Protection Act 2019
Kenya’s Data Protection Act (2019) establishes comprehensive requirements for how any organisation — including schools — collects, processes, stores, and shares personal data. The Act is enforced by the Office of the Data Protection Commissioner (ODPC), which has the power to investigate complaints and impose penalties for non-compliance.
Schools are data controllers under the Act, meaning they determine how and why personal data is processed. This creates specific legal obligations, not just good practice recommendations.
What counts as personal data in a school context
- Student names, dates of birth, admission numbers, and photographs
- Academic records — assessment results, report cards, attendance history
- Health information — medical conditions, allergies, disability status
- Family information — parent contact details, home address, financial circumstances relevant to fee payment
- Disciplinary records
- Biometric data where used for attendance or identification systems
Health information and disciplinary records are considered sensitive personal data under the Act, requiring an even higher standard of protection than general personal data.
Core obligations for schools
Lawful basis for collection
Schools must have a lawful basis for every category of data they collect. For most school data, this basis is the performance of a contract (the education service) or a legal obligation (regulatory reporting requirements like NEMIS). Data collected beyond what is necessary for these purposes requires explicit parental consent.
Purpose limitation
Data collected for one purpose should not be used for an unrelated purpose without consent. A parent’s phone number collected for emergency contact purposes should not be added to a marketing list for a school fundraising event without their agreement.
Data minimisation
Schools should only collect data that is genuinely necessary. A common compliance gap is collecting excessive information during admission — family details unrelated to the child’s education, for example — without a clear purpose or lawful basis for holding it.
Security safeguards
Schools must implement appropriate technical and organisational measures to protect data from unauthorised access, loss, or disclosure. This is where paper-based systems create significant risk — a filing cabinet with student health records is not secure in any meaningful sense, while a properly access-controlled digital system with role-based permissions is.
Practical risk area: WhatsApp groups where sensitive student information is shared visibly to other parents are a common and serious data privacy risk in Kenyan schools. A parent typing a child’s medical condition or fee balance into a group chat visible to 40 other families is a data breach, even if unintentional.
Data sharing with third parties
Schools regularly share data with third parties — the Ministry of Education (NEMIS), TSC, exam bodies, and increasingly digital service providers including school management platforms. The Data Protection Act requires that any third party processing school data on the school’s behalf does so under a clear data processing agreement, with appropriate security measures in place.
When selecting a school management system, principals should verify that the provider has clear data protection practices — encryption, access controls, and a documented commitment to not sharing school data with unauthorised parties.
Parental rights under the Act
Parents (on behalf of their children, who are minors) have rights under the Data Protection Act including the right to access what data the school holds about their child, the right to request correction of inaccurate data, and the right to be informed about how their data is used. Schools should have a simple, clear process for parents to exercise these rights — even a straightforward email address for data requests satisfies this obligation for most schools.
Practical steps to improve compliance
- Move sensitive student records from paper filing to access-controlled digital systems
- Avoid parent WhatsApp groups for anything involving individual student data
- Ensure only staff who need access to sensitive data (health records, discipline records) have it
- Review what data is collected at admission and remove anything not genuinely necessary
- Choose technology providers who can demonstrate clear data protection practices
Manage student data securely and responsibly.
Edupath SMS uses role-based access controls, encrypted connections, and multi-tenant data isolation to keep every school’s data secure and private. Free to start.
Create Free Account