Who must send a breach notification letter in Kenya
Under the Data Protection Act, 2019, the duty to notify falls on data controllers - organisations that decide how and why personal data is processed. If a breach is likely to result in a risk to the rights and freedoms of data subjects, the controller must notify the Office of the Data Protection Commissioner (ODPC) without delay, and in any event within 72 hours of becoming aware of it (section 43(1)). Processors - vendors and service providers holding data on a controller's behalf - should pass breach information to the controller without undue delay so the controller can meet its own deadline.
The clock starts at awareness, not at full confirmation. If key facts are still missing at the 72-hour mark, notify in phases: send what you have, then follow up. The Act allows phased notification; what it does not allow is silence.
Not sure whether your incident is notifiable? Our guide to data breach notification requirements in Kenya explains what counts, and how to notify the ODPC about a data breach covers the submission process end to end.
What the letter must contain (section 43(4))
Section 43(4) of the Act sets the minimum content of a notification to the ODPC. A compliant letter covers five things:
- Nature of the breach. What happened, which systems or processes were involved, and the categories of personal data concerned.
- Categories and approximate number of data subjects affected. For example: approximately 4,200 customer records containing names, phone numbers and national ID numbers.
- Likely consequences of the breach. The realistic harms: identity theft, unauthorised account access, financial fraud, exposure of sensitive records.
- Measures taken or proposed. Containment already done, remediation under way, and steps to prevent recurrence.
- A contact point. The data protection officer or other person the ODPC can follow up with.
The ODPC's own report a data breach form asks for controller details, a breach description and remedial action - the same structure as the letter below, so you can lift each section straight into the form.
Notifications to affected data subjects carry their own content requirements under the Data Protection (General) Regulations, 2021: the nature of the breach, the likely consequences, the measures taken, and a contact point, plus recommendations for protective steps individuals can take themselves. The second template below is built for that.
Data breach notification letter template: ODPC
Copy the letter, replace every [FIELD], and send it within 72 hours of awareness.
To: The Data Protection Commissioner, Office of the Data Protection Commissioner, Nairobi From: [ORGANISATION NAME] ([REGISTRATION NUMBER]), [POSTAL ADDRESS] - acting as data controller Date: [DATE] Re: Notification of a personal data breach under section 43 of the Data Protection Act, 2019
Dear Sir/Madam,
We write to notify the Office of a personal data breach in accordance with section 43 of the Data Protection Act, 2019.
1. Nature of the breach. On [DATE AND TIME] we became aware that [DESCRIBE THE INCIDENT: what happened, how it was discovered, which systems were involved]. The categories of personal data involved are [CATEGORIES: e.g. names, contact details, ID numbers, financial records] belonging to [DATA SUBJECT GROUPS: e.g. customers, employees].
2. Data subjects affected. Approximately [NUMBER] data subjects are affected: [BREAKDOWN IF KNOWN].
3. Likely consequences. We assess that the breach may result in [LIKELY HARMS: e.g. identity theft, unauthorised access to accounts, financial loss, exposure of sensitive records].
4. Measures taken and proposed. We have [CONTAINMENT ALREADY DONE: e.g. isolated affected systems, revoked compromised credentials, engaged forensic support]. Further measures include [REMEDIATION PLAN WITH TIMELINE].
5. Contact point. The contact for this notification is [DPO OR OFFICER NAME], [TITLE], reachable at [EMAIL] and [PHONE].
6. Notification status. This is the [initial / follow-up] notification, submitted within 72 hours of awareness as required by section 43(1). [If phased:] We will submit a final report by [DATE] once [OUTSTANDING INVESTIGATION OR ITEM] is complete.
We are available to provide any further information the Commission may require.
Yours faithfully,
[NAME] [TITLE], [ORGANISATION]
Data subject breach notification template
Where the breach is likely to result in high risk to affected individuals, the Act (section 44) requires notifying them without undue delay. Use this second letter for that duty.
Subject: Important notice - a data breach affecting your information
Dear [NAME],
We are writing to inform you of an incident affecting the personal data we hold about you. On [DATE], [DESCRIBE WHAT HAPPENED IN PLAIN LANGUAGE].
The information involved may include [CATEGORIES OF DATA]. This may result in [CONSEQUENCES IN PLAIN TERMS: e.g. someone could attempt to use your details for fraud].
We have taken the following steps: [MEASURES TAKEN]. To protect yourself, we recommend that you [PRACTICAL STEPS: e.g. change your password immediately, monitor your bank statements, watch out for phishing messages claiming to be from us].
You can reach our data protection officer, [NAME], at [EMAIL] or [PHONE] with any questions.
We regret the inconvenience and remain committed to protecting your data.
Sincerely, [NAME], [TITLE], [ORGANISATION]
Penalties for failing to notify
Skipping the letter is not a paper violation. The ODPC can impose administrative fines of up to KES 5 million or, in the case of an undertaking, up to 1% of the preceding financial year's annual turnover - whichever is lower (section 65). Where a failure to notify is pursued as an offence, conviction carries a fine of up to KES 3 million, imprisonment of up to ten years, or both. A well-documented notification, sent on time, is also the organisation's best evidence that it took the duty seriously.
After you send the letter
- Keep the record. File the letter, the ODPC acknowledgement and all follow-ups. Breach records are the backbone of any later audit or investigation.
- Complete the phased report. If you notified in phases, send the final report when the outstanding facts are confirmed.
- Close the loop with data subjects. Track questions and complaints from your notification letter and respond through the same contact point.
- Feed lessons into the response plan. Update your internal data breach response plan so the same gap cannot bite twice.
For the full workflow - detection, assessment, decision, notification - see the step-by-step guide to data breach notification in Kenya and a worked data breach notification example. The overview is in our guide to data breach notification in Kenya, and the practical sequence is in the data breach notification procedure.
This template reflects the requirements of the Data Protection Act, 2019 and the Data Protection (General) Regulations, 2021. It is a starting point, not legal advice - have counsel review before sending in high-stakes incidents.