Guide

The Data Protection Act for Kenyan Schools: A Practical Guide

Written by EduCore Team · Nairobi, Kenya ·

A school holds some of the most sensitive data there is: children's names, families, health notes, discipline records and fee histories. Kenya's Data Protection Act applies to all of it, and the regulator has already fined a school for posting pupils' photos without consent. This guide sets out what the ODPC actually asks of schools, in plain terms.

General information, not legal advice. Read the ODPC's own Guidance Note for the Education Sector and take advice for your school's situation.

Start Here

Your school is the data controller

The Act separates the organisation that decides why and how personal data is used, the controller, from one that handles it on the controller's behalf, the processor. A school deciding to collect admission details, take attendance and publish results is the controller. A software vendor storing that data for you is a processor.

The point that surprises many principals: handing data to a vendor does not hand over the responsibility. The ODPC expects schools to choose processors that give sufficient guarantees and to bind them with a written contract. If something goes wrong with data a vendor holds, the regulator will still come to the school first.

What The ODPC Expects

Seven things every school should have in place

  1. 01

    Register with the ODPC

    Mandatory for education institutions, whatever their size. Registration is separate from having a privacy policy.

  2. 02

    Tell people what you do with their data

    Give a plain-language privacy notice at enrolment: what you collect, why, who receives it, how long you keep it, security measures, their rights and who to contact. Give a copy again at the start of each year if you can.

  3. 03

    Get valid consent where you rely on it

    For a child, that means a parent or guardian, freely given, specific and informed, and withdrawable without penalty. The ODPC suggests verifying the person giving consent really is the parent or guardian.

  4. 04

    Collect less, keep it for less time

    Ask only for what a stated purpose needs. Set retention periods, and destroy records securely when they expire. The guidance recommends reviewing the accuracy of records yearly.

  5. 05

    Honour people's rights

    Access within seven days, correction of wrong records, erasure where there is no reason to keep the data, and a copy in a structured, machine-readable format for portability.

  6. 06

    Secure it and be ready for a breach

    Access controls, backups, encrypted transmission, staff training and a written incident plan. Report a breach to the ODPC within 72 hours of becoming aware and tell affected people in writing.

  7. 07

    Assess high-risk processing

    A data protection impact assessment is required where processing is likely to be high risk, and the ODPC recommends one when it is unclear. Biometrics and large-scale tracking of children are the obvious candidates.

The ODPC's guidance note ends with a compliance checklist that maps to all of these. It is worth printing and walking through with your board.

Where Schools Get Caught

Four everyday situations

None of these needs new software. They need a decision and a written rule.

Marks, arrears and discipline in WhatsApp groups

The ODPC lists disclosing academic records, fee balances, behavioural issues or health information to a wider group as a privacy concern. Message each parent about their own child.

Photos and results in public

Prospectus photos, website galleries, and top-performer lists all need parental consent for the specific use. General crowd shots where no child is identifiable are the ODPC's suggested safer option.

Biometric attendance and health records

Biometric and health data are sensitive personal data. The guidance expects explicit consent, a clear purpose, and biometrics only where nothing less intrusive will do. CCTV in boarding areas is flagged as high-risk.

Handing data to software vendors

A vendor holding student data is your processor. You stay responsible as controller, so the vendor should be bound by a written contract and chosen with due diligence.

The ODPC has also published a guidance note on processing children's data, which is the place to go for consent, age and parental verification in more detail.

Choosing Software

Six questions for any school-software vendor

  • Will you sign a written data processing agreement that binds you to act only on our instructions?
  • Where is our data stored, and which sub-processors touch it?
  • Do you use our data for advertising, analytics of your own, or anything beyond running our service?
  • How and when do we get our data back, and when do you delete it?
  • How fast will you tell us about a breach?
  • Are biometric and health features opt-in, with access restricted more tightly than ordinary records?

A rule about where data lives

Under Regulation 26 of the Data Protection (General) Regulations, 2021, personal data processed for the purpose of offering early childhood and basic education must be processed through a server and data centre in Kenya, or at least one serving copy must be stored in a data centre in Kenya. Software hosted in the cloud may run on servers outside Kenya, so this is a question worth putting to every vendor in writing. How the rule applies to a given school and arrangement is a legal question; take advice if the answer is unclear.

Our Own Answers

How EduCore answers, including the part we haven't solved

For school data, EduCore acts as the processor and the school is the controller. EduCore Technologies Ltd states in its privacy policy that it is registered with the ODPC and names a data protection officer. The biometric attendance and health record modules are opt-in for each school, with tighter access than ordinary records, and the school remains responsible for obtaining the explicit consent those data require. If EduCore becomes aware of a security incident affecting a school's data, it notifies the school without undue delay so the school can meet its own reporting duties. A school owner or principal can export the school's core records to Excel at any time.

The unresolved part: EduCore's database is hosted in the EU (Frankfurt, Germany), and its error-monitoring provider also uses an EU endpoint. We do not currently have a Kenya-based serving copy of the database, and as a platform serving Kenyan basic-education schools we likely fall within Regulation 26. We say so in our privacy policy, we are working through the engineering and legal steps to address it, and we would rather you hear it from us than discover it. If this matters for your school, raise it with us and with your adviser before you sign up. Details on sub-processors are in Part B of the privacy policy, and our approach to isolation and access is on the security page.

Common Questions

Frequently asked questions

Does a school have to register with the ODPC?

Yes. The ODPC's education-sector guidance says institutions in the education sector are expected to register as data controllers or processors, and that education institutions are subject to mandatory registration regardless of size or turnover. Registration is done through the ODPC.

Can we post photos of pupils on our website or social media?

Only with the parent or guardian's consent, obtained for that purpose. A child's image is personal data. In 2023 the ODPC fined a school KSh 4.55 million for posting images of minors without parental consent, according to law-firm reports of the penalty notices.

Is it acceptable to pin exam results on the notice board or post them in a class WhatsApp group?

The ODPC's guidance lists both as privacy concerns and says schools should get parental consent before publishing children's results, with an option to publish names without scores. Many schools find it simpler to send each parent their own child's results directly.

How quickly must we answer a parent's request for their child's data?

The General Regulations give seven days from receipt of a data access request. A parent or guardian can request access on behalf of a child, including academic, disciplinary and health records.

What do we do if student data is leaked or lost?

Report it to the ODPC without delay and within 72 hours of becoming aware, and tell affected people in writing within a reasonable period. Keep a written record of what happened and what you did. If a vendor holds the data, your contract should oblige them to tell you promptly.

Must school data be stored in Kenya?

Regulation 26 of the General Regulations requires processing for the purpose of offering early childhood and basic education to be done through a server and data centre in Kenya, or with at least one serving copy stored in a Kenyan data centre. How that applies to a particular school and vendor is a legal question, so ask your vendor where data is stored and take advice if the answer is unclear. EduCore's current position is set out above.

This guide summarises publicly available ODPC guidance and legislation as of September 2026 and is general information, not legal advice. EduCore is not affiliated with the ODPC. Check the current text of the Act, regulations and guidance notes, and take advice from a Kenyan advocate for your school's circumstances.

Questions?

Ask us the hard questions before you decide.

Bring the vendor checklist above to a demo. We will answer each one directly.