Legal
Data processing addendum
The DPA template has not been drafted. The homepage, every service page and the governance page all state that processing is governed by a Data Processing Addendum meeting the Kenya Data Protection Act 2019 and GDPR Article 28. That claim is not supportable until this instrument exists and has been executed. Either complete it before launch or remove the claim from the pages that make it.
Required content
GDPR Article 28(3) prescribes the terms a processor contract must contain. The Kenya Data Protection Act 2019 imposes a parallel set. A compliant addendum covers at minimum:
- Subject matter, duration, nature and purpose of the processing
- Categories of personal data and of data subjects
- Processing only on documented instructions from the controller
- Confidentiality obligations binding on personnel
- Technical and organisational security measures, listed specifically
- Terms governing sub-processors, including authorisation and change notification
- Assistance with data subject rights requests
- Assistance with breach notification, impact assessments and prior consultation
- Deletion or return of personal data at the end of the engagement
- Audit and inspection rights
- Cross-border transfer mechanism where data leaves Kenya
Sub-processor register
A published sub-processor register is a separate obligation from the addendum itself. It must list every party that processes client personal data on our behalf — hosting, email, error tracking, any managed service — with its role, location and the safeguard relied upon for any transfer. Change notification terms are agreed in the addendum and honoured against this register.