Compliance

Kenya's Data Protection Act and WhatsApp Marketing: What the ODPC Expects

By the HabariChat team · Updated July 2026

Short answer A customer's phone number is personal data, so the Data Protection Act, 2019 applies the moment you build a marketing list. You need consent that was freely given, specific and informed, and you need to be able to prove you obtained it. Customers can ask what you hold, ask you to correct or delete it, and object to marketing at any time, and you must act on that. Depending on your size and sector you may also need to register with the Office of the Data Protection Commissioner. The good news is that WhatsApp's own opt-in rules cover most of the same ground, so one set of habits satisfies both.
This is a plain-language guide, not legal advice. The Act, its regulations and the ODPC's guidance are updated over time, and how they apply depends on your specific business. Confirm your position with the ODPC or your advocate before relying on anything here.

Why this applies to you

Kenyan businesses often assume data protection is a bank and telco problem. It is not. The Act governs anyone who decides how and why personal data gets used, and it does not set a floor of company size for that duty. A phone number attached to a name, a purchase history or a location is personal data. A boutique in Westlands with 400 WhatsApp contacts is processing personal data exactly as much as a bank is, just at a smaller scale.

The practical trigger is the moment you move numbers into a list in order to message them. From there you are a data controller for that list.

The consent standard

This is the part most marketing lists fail. Consent under the Act must be freely given, specific and informed, and you must be able to demonstrate it. Unpack that into what it means at a till or a checkout page:

Which means none of the following give you a lawful basis for marketing:

The practical routes to getting this right are in our guide to building a WhatsApp marketing list, including wording you can copy.

The rights your customers have

Your contacts hold rights you have to be able to service. In a small business this usually means knowing who handles the request and how fast.

The customer canWhat you have to do
Ask what data you hold about themTell them, within a reasonable time
Ask you to correct itFix it
Ask you to delete itDelete it, unless you have a legal reason to keep it such as tax records
Object to direct marketingStop marketing to them, immediately and permanently
Withdraw consentHonour it, and make withdrawing as easy as giving it was

The last two are the ones that bite in messaging. A customer who replies STOP has objected. There is no grace period, no "one more campaign because it was already scheduled", and no requiring them to call the office during working hours to be removed.

Registration with the ODPC

Separately from how you handle data, some businesses must register as a data controller or processor. The registration regulations set thresholds based on annual turnover and number of employees, with smaller entities below those thresholds generally exempt, and mandatory registration for certain activities regardless of size, including where processing personal data at scale is central to what you do.

Two things worth knowing. Thresholds and the list of mandatory categories are revised from time to time, so check your position against current ODPC guidance rather than something you read a year ago. And being exempt from registration does not exempt you from the rest of the Act. It removes a form, not a duty.

What to keep on file

If a complaint reaches the ODPC, the question is what you can show. Keep it simple and keep it current:

For a small business this is a spreadsheet column and a page on your website, not a compliance department.

Penalties, and how real they are

The Commissioner can issue enforcement notices requiring you to stop or change what you are doing, and can impose administrative fines. The Act caps these at up to KES 5 million, or for an undertaking up to one per cent of annual turnover, whichever is lower.

More relevant than the ceiling is that the ODPC has acted on complaints about unsolicited marketing messages, so this is an enforced regime rather than a dormant one. And the fine is rarely the real cost. An enforcement notice that stops you contacting your customer list is far more damaging to a growing business than the money.

Two rulebooks, one set of habits. The Act and WhatsApp's own policy ask for nearly the same things: permission before you message, clarity about what you will send, and an opt-out you honour at once. Businesses get into trouble by treating compliance as paperwork done after the marketing. Done at the point of collection, it costs nothing and it also happens to produce a list that responds, because everyone on it asked to be there.

A practical compliance checklist

Where HabariChat helps

Compliance is mostly a process question, but the process is far easier when the tooling matches it. HabariChat records how each contact arrived and what they opted into, keeps marketing and transactional permissions separate, and skips anyone who has opted out on every future campaign automatically, so an opt-out cannot be undone by a colleague loading an old spreadsheet.

Everything runs on the official WhatsApp Business API, which means the platform is operating under Meta's terms rather than around them. Our security page covers how data is held, and the privacy policy sets out what HabariChat does with it as a processor acting for you.

Market on WhatsApp with the record-keeping built in

Consent, opt-outs and contact sources tracked as you go, on the official WhatsApp Business API. Free for 14 days, no card required.

Start your free trial

Frequently asked questions

Does Kenya's Data Protection Act apply to a small business sending WhatsApp messages?

Yes. The Act applies to anyone who decides how and why personal data is processed, and a customer's phone number is personal data. Size affects whether you must register with the ODPC, but it does not exempt you from the duties around consent, transparency and customer rights.

What consent do I need before sending marketing messages in Kenya?

Consent must be freely given, specific and informed, and you must be able to demonstrate you obtained it. In practice that means the person actively agreed to receive marketing from your business, knew what they were agreeing to, and you have a record of when and how. Silence, a pre-ticked box or the mere fact that someone bought from you is not consent to market to them.

Do I have to register with the Office of the Data Protection Commissioner?

It depends on your size and your sector. Registration regulations set thresholds based on annual turnover and number of employees, and mandatory registration applies to certain activities regardless of size, including businesses whose core activity involves processing personal data at scale. Check your position against the current ODPC guidance, since thresholds and categories are updated from time to time.

What are the penalties for unlawful direct marketing in Kenya?

The Data Protection Commissioner can issue enforcement notices and administrative fines, with the Act setting a ceiling of up to KES 5 million or, for an undertaking, up to one per cent of annual turnover, whichever is lower. The ODPC has acted on complaints about unsolicited marketing messages, so this is enforced rather than theoretical.

How does this relate to WhatsApp's own rules?

They overlap almost entirely. Both require a clear, recorded opt-in before you message someone and both require you to honour an opt-out. Meeting WhatsApp's requirement properly gets you most of the way to meeting the Act, which means one set of habits satisfies both.