Kenya's 72-hour breach clock is unforgiving, and the ODPC data breach notification form is where it gets tested. When a personal data breach occurs, section 43(1) of the Data Protection Act requires the data controller to notify the Office of the Data Protection Commissioner without delay and in any event within 72 hours of becoming aware of it. The ODPC's report-a-breach form runs six sections, and a first-time reporter can burn hours of that window working out what each field actually wants.
This guide walks through the form field by field so you can prepare everything up front and file in one sitting. If you have not yet drafted the notification letter itself, start with our fill-in data breach notification letter template; the letter and the form draw on the same facts, and the letter is where most of the drafting happens.
Before you start: gather these details
Have the following ready before you open the form:
- Your organisation's ODPC registration number and registered address, plus the contact details of your Data Protection Officer or authorised representative
- The date the breach occurred, or your best estimate, and the exact date your organisation became aware of it
- The categories of people affected (customers, employees, suppliers) and the approximate number in each category
- The categories of personal data involved: identity data, contact data, financial data, health data, credentials, or combinations
- What you have done so far to contain the breach and mitigate its effects
- Supporting documents: your incident response policy, internal incident reports, and copies of communications already sent to affected people
The step-by-step guide to data breach notification in Kenya covers the full sequence around this form, from containment to regulator follow-up.
Section I: Controller details
The form opens with who is reporting. Enter your organisation's registered name exactly as it appears on your ODPC registration certificate, the registration number, physical address, and the Data Protection Officer or representative's phone and email. All ODPC correspondence about this breach goes to these contacts, so use a monitored mailbox rather than an individual's address where you can.
If the breach happened at a data processor acting on your behalf, the processor must report the breach to you without undue delay, and you file with the ODPC as the controller. Enter your own details here and describe the processor's involvement in the breach narrative.
Section II: Breach details
This is the heart of the form and where most of the 72-hour assessment happens.
Nature of the breach. Describe what happened in plain language: unauthorised access, disclosure, loss, alteration, or destruction of personal data. Name the systems involved and how the breach came to light.
Categories and approximate numbers of data subjects affected. The form asks for affected people grouped by category, with counts in bands. Your duty to describe the nature of the breach, the categories and the approximate number of data subjects concerned comes from section 43(4) of the Act, so these numbers matter; give your honest best estimate and flag it as preliminary if it is one.
Categories of personal data involved. Select everything that applies. Special categories such as health data or financial records raise the risk level and, with it, the expectation that you also notify the affected people directly.
Occurrence and discovery dates. The form asks when the breach occurred and when you became aware of it. The 72-hour clock runs from awareness, not from occurrence, which is why the second date is the legally decisive one. If your organisation cannot show when it became aware, that gap is exactly the kind of thing an investigation will probe. Our article on what happens if you do not report a breach to the ODPC within the required timeframe covers the consequences of missing this window.
Was the notification made within 72 hours? The form asks directly. Answer accurately. If you are inside the window, the answer is simply yes. If you are late, a notification that explains the delay is treated very differently from silence followed by a late filing.
Primary cause. Choose the closest fit, such as system failure, human error, malicious attack, or process failure, then support it with a sentence of detail in the narrative field.
Section III: Communication with data subjects
The form asks whether and how you have told the people whose data was breached. Where the breach is likely to result in a high risk to their rights and freedoms, section 44 of the Act requires you to communicate with the affected data subjects without undue delay, covering the nature of the breach, its likely consequences, the measures taken, and a contact point.
If you have already sent notifications, describe them here and attach copies in Section IV. If your risk assessment says individual notification is required and you have not yet sent anything, say so and give your timeline. For the letter itself, use our sample data subject notification letter, which covers exactly the content the Act expects.
Section IV: Attachments
Attach what you have, clearly named and dated:
- Your incident response policy, if it was followed
- Internal incident reports or preliminary findings
- Copies of notifications sent to data subjects, with send dates
- Any other evidence of containment or mitigation
The ODPC may request more documents later, so keep your complete incident file, not just what you attach.
Section V: Confidentiality request
If public disclosure of the report would harm an investigation, a commercial interest, or the people affected, the form lets you request confidential treatment. State the request and your reasons briefly. The ODPC decides whether to honour it; the request does not change your reporting obligations in any way.
Section VI: Review and submit
Before submitting, re-check three things: the discovery date and the 72-hour answer are consistent, the affected-people numbers in Section II match the letter you sent, and every contact detail is current. Keep the submission confirmation or reference number with your incident file.
If you do not yet have full details, do not wait. The Act allows notification in phases: submit the first notice within 72 hours with what you know, and follow up as the investigation fills the gaps.
What happens after you submit
The ODPC may acknowledge the report, ask for more information, open an inquiry, or issue directions on remediation. Respond within any deadline they set and keep the incident file growing. Failure to notify a breach as required carries serious consequences: the ODPC can impose administrative fines of up to KES 5 million or, in the case of an undertaking, up to 1% of the preceding financial year's annual turnover, whichever is lower, and on conviction an offender faces a fine of up to KES 3 million, imprisonment of up to ten years, or both.
Related reading
- Data breach notification in Kenya: the legal framework in one place
- Data breach notification requirements for the ODPC: what a valid notification must contain
- Data breach notification procedure: containment, assessment, and escalation steps
- Data breach notification example: a worked example from discovery to filing