What a data breach response plan is
A data breach response plan is the documented playbook an organization follows in the first hours and days after discovering unauthorized access to personal data: who declares the incident, who contains it, who assesses the scope, and who notifies the regulator and the people affected. Under section 43 of the Kenya Data Protection Act, 2019, a data controller must notify the Office of the Data Protection Commissioner (ODPC) without delay, and within 72 hours of becoming aware of the breach. A plan that is not written down and tested is why organizations miss that window, and the exposure is real: administrative fines of up to KES 5 million or 1% of annual turnover (whichever is lower), and on conviction, a fine of up to KES 3 million, imprisonment of up to ten years, or both.
The plan, phase by phase
Hour 0 to 4: detect, contain, declare
Record the detection time first: the 72-hour clock starts when the organization becomes aware of the breach, not when the investigation concludes. Contain the incident by revoking compromised credentials, isolating affected systems and preserving logs. Then formally declare it so a single incident lead owns the response from that point.
Hour 4 to 24: assess scope and risk
Establish what personal data was accessed or acquired, in which categories, and the approximate number of data subjects affected. Ask whether there is a real risk of harm to those people. That assessment drives both the ODPC notification and the separate duty to communicate with the data subjects.
Hour 24 to 48: the processor chain
If a vendor or data processor suffered the breach, section 43(3) requires them to notify you, the controller, without delay and where reasonably practicable within 48 hours of becoming aware. Contracts should demand faster notice than the statutory floor, and vendor reviews should test that the contact path actually works.
By hour 72: notify the ODPC
Section 43(1) requires notification to the Data Commissioner without delay and within 72 hours. The notification should describe the nature of the breach, the categories and approximate number of data subjects affected, the likely consequences, and the measures taken or proposed, with controller and DPO contact details. These are the same fields the ODPC breach report form asks for. If full facts are not available in time, the Act allows the information to be provided in phases without undue delay, but the first notice must land inside the window.
After the ODPC: communicate with data subjects
Where the breach is likely to harm the people affected, section 43(1)(b) requires communicating with them in writing within a reasonably practical period: the nature of the breach, the likely consequences, the measures taken, and a contact point. The notification letter template guide carries the exact wording for both the regulator and the data subjects.
Week one: review
Close the incident with a root-cause review, updated controls, and retained evidence for the ODPC's follow-up questions.
Who owns each step
| Role | Responsibility |
|---|---|
| Incident lead / DPO | Declares the incident, owns the 72-hour clock, signs the ODPC notification |
| IT / security | Containment, forensics, log preservation |
| Legal | Notification content review, regulator correspondence |
| Communications | Data-subject letters and holding statements |
| Vendor management | Processor notifications and the 48-hour chain |
The plan on one page
A minimal plan that survives contact with a real incident fits on a single page:
- Detection time recorded and clock owner named
- Containment steps and who executes them
- Scope assessment: data categories, approximate data subjects, risk of harm
- ODPC notification owner and the 72-hour deadline
- Data-subject communication owner and channel
- Post-incident review date
Common failure points
The recurring misses are deciding to investigate before deciding to notify (the clock does not wait), a DPO who is unreachable on the day, vendors discovering their own breach late against the 48-hour rule, and plans that have never been tested. A dry run twice a year is what turns a document into a plan.
How Sovereign Intel helps
Sovereign Intel by Arxivolt maps your compliance gaps and monitors exposure so your team can respond inside the 72-hour window. Book a consultation to pressure-test your response plan before the ODPC does.