Real-World Asset Tokenisation in Kenya: Legal Questions Founders Should Resolve
Before tokenising property or other assets, founders should resolve a set of foundational legal questions. Here is a practical map.
Read insight →A step-by-step approach to data protection compliance for early-stage Kenyan companies, from registration to day-to-day practice.
Data protection has moved from a back-office afterthought to a board-level expectation. For Kenyan startups, building a practical compliance programme early is far easier than retrofitting one after growth, an investor request, or a complaint.
For an early-stage company, data protection can feel like a problem for later. In practice, the opposite is true. Personal data sits at the centre of most digital products: user accounts, payment details, location, device information and behavioural data. The way that data is collected and handled shapes user trust, investor confidence and regulatory exposure from the very first release.
Three forces tend to bring data protection to the surface for a growing company: a user complaint, an investor’s due diligence questionnaire, and the company’s own move into regulated activities such as lending or payments. In each case, a company that has built compliance in from the start is in a far stronger position than one scrambling to assemble it under pressure.
Kenya’s data protection framework is overseen by the Office of the Data Protection Commissioner. Depending on the nature and scale of processing, organisations may be required to register, and the framework sets out obligations around lawful processing, transparency, security and the rights of individuals.
The practical first step is to understand your position: what personal data you hold, why you hold it, where it sits, and who has access. This data map is the foundation of everything else. It tells you whether registration applies, what notices you need, and where your risks are concentrated. Requirements may change and should be confirmed against the current law and regulator guidance before you act.
Personal data must be processed on a recognised lawful basis. Consent is the one founders reach for instinctively, but it is not always the right or strongest basis, and consent that is bundled, pre-ticked or unclear is weak. Other bases, such as the performance of a contract or a legitimate purpose, may fit better for core product functions.
Whatever the basis, transparency is non-negotiable. A clear privacy notice should tell users what data you collect, why, who you share it with and how long you keep it, in language they can actually understand. For a startup, a single well-written notice that matches what the product really does is worth more than a long template copied from elsewhere that does not.
Write the privacy notice from your data map, not from a template. If the notice and the product disagree, it is the notice, and your credibility, that will suffer.
Modern products are assembled from third-party services: hosting, analytics, payment processors, messaging tools and more. Each one that touches personal data is a point of exposure. Where a vendor processes data on your behalf, the relationship should be governed by appropriate contractual terms setting out how the data may be used, how it is protected, and what happens when the relationship ends.
Cross-border transfers deserve particular attention, because many popular tools store data outside Kenya. Knowing where your users’ data physically goes, and on what terms, is part of a credible programme.
Individuals have rights over their personal data, which may include access, correction and deletion. A startup does not need an elaborate system to honour these, but it does need a defined route: a contact point, a simple internal process, and a sensible timescale. The first time a user asks what data you hold is not the moment to invent a process.
A practical compliance programme for a Kenyan startup can be built in a clear sequence:
None of these steps requires a large budget. What they require is attention at the right time. Built in early, compliance becomes a quiet strength of the business; left late, it becomes an expensive scramble. If you would like help designing a programme that fits your stage and product, we would be glad to assist.
Many organisations that process personal data have registration obligations, though the position depends on the nature and scale of processing. You should confirm whether registration applies to your specific activities against the current law and ODPC guidance.
Broadly, a controller decides why and how personal data is processed, while a processor acts on the controller’s instructions. Your role affects your obligations, and a startup can be both for different activities.
A proportionate programme need not be expensive. Much of the value comes from getting the foundations right early, which is far cheaper than remediating problems later.
The information on this website is general in nature, is not legal advice, and does not create an advocate-client relationship. It should not be relied upon for any specific matter. Requirements may change and should be confirmed against the current law, regulations and regulator guidance before action is taken. Please contact Njau & Associates Advocates for advice on your circumstances.
Before tokenising property or other assets, founders should resolve a set of foundational legal questions. Here is a practical map.
Read insight →Employee share ownership can attract and retain talent, but only if it is structured carefully. The key legal and governance points.
Read insight →