HR Data Protection Kenya: A Practical Guide for Managing Employee Records Under the Data Protection Act

HR Data Protection Kenya: A Practical Guide for Managing Employee Records Under the Data Protection Act

HR Guide to Employee Records Under Kenya's DPA


HR teams in Kenya sit at the center of more personal data than almost any other function in a business. Payroll numbers, national ID copies, medical certificates, disciplinary letters, performance scores, next of kin details, sometimes even religious or ethnic information collected years ago for a form nobody remembers the purpose of. The Data Protection Act, 2019 does not treat any of this as routine paperwork. It treats it as regulated personal data, and HR teams are, in legal terms, running a data processing operation every single day.

This guide is written as a practical playbook for HR managers, organized around the actual lifecycle of employee data: collection, storage, processing, sharing, and disposal, with specific guidance on the record types HR handles most, payroll, performance reviews, and health information, and a clear section on when the right move is to bring in specialized legal counsel rather than handle something internally.


Collection: Only Take What You Actually Need

The starting point for every HR data practice should be the Act's data minimization principle: collect only what is genuinely necessary for a specific, identified purpose. In practice, this means resisting the instinct to build an all purpose onboarding form that asks for everything that might conceivably be useful someday.

At the point of collection, HR should be able to answer, for every field on an intake form, why that specific piece of information is needed and what it will be used for. Marital status might be genuinely necessary for a benefits scheme, but is not necessary for a general employee database if the organization offers no such benefit. Religious affiliation might matter for accommodating specific leave requests, but should not be collected as a default field for every new hire regardless of relevance.

Sensitive personal data, health information, biometric data, criminal history, requires a clearly identified lawful basis before collection, not after. Where consent is the basis, it must be a real, freely given choice, not a checkbox buried in an employment contract an employee has no genuine ability to negotiate.


Storage: Access Controls and Data Segregation

Once collected, employee data needs to be stored in a way that limits access to those who genuinely need it. A common gap in Kenyan HR departments is storing sensitive records, medical certificates, disciplinary files, salary information, in the same shared drive or filing system accessible to the entire HR team or, worse, line managers outside HR entirely.

Good practice separates data by sensitivity and need to know. Payroll data should be accessible to payroll and finance staff, not the whole HR function. Medical information should be restricted even further, often to a single designated contact, with line managers informed only of the practical outcome, such as approved leave, rather than the underlying medical detail. Physical documents, ID copies, signed medical certificates, should be stored in locked, access controlled locations, not left in open filing cabinets or shared office spaces.

Digital storage should include basic technical safeguards proportionate to the sensitivity of the data: password protection, encryption where feasible, and audit trails showing who accessed sensitive employee files and when.


Processing: Payroll, Performance Reviews, and Health Records

Different categories of HR data carry different processing risks, and each deserves specific handling.

Payroll records. Payroll processing is generally justified as necessary for performance of the employment contract and compliance with statutory tax and social security obligations, rather than requiring separate consent. The main compliance risk here is less about lawful basis and more about who has access to salary data and how long it is retained after the statutory minimum period has passed, plus proper data processing agreements where payroll is outsourced to an external provider.

Performance reviews and disciplinary records. These records should be factual, proportionate, and tied to the specific employment purpose they serve. A performance review is legitimate HR data, but including unrelated personal commentary, speculation about an employee's personal circumstances, or informal opinions not tied to actual performance creates unnecessary risk if the employee later exercises their right of access and sees exactly what was written about them. Disciplinary records should be retained only as long as genuinely relevant, generally tied to a defined period after resolution, not kept indefinitely as a standing file.

Health information. This is sensitive personal data under the Act and warrants the highest level of care. Medical certificates supporting sick leave, disability accommodations, or health insurance enrollment should be collected only to the extent necessary, shared only with the specific people who need to act on them, and never used as a basis for decisions unrelated to their original purpose, such as informal assumptions about an employee's capability based on a medical certificate submitted for an unrelated absence. Employers should also be cautious about pre employment health screening, ensuring any such requirement is genuinely justified by the role rather than a routine step applied to every candidate regardless of position.


Sharing: Third Parties, Outsourced Providers, and Government Bodies

HR data regularly leaves the organization, to payroll processors, background check firms, insurance providers, statutory bodies like KRA and NSSF, and sometimes group companies in multinational structures. Each of these transfers needs to rest on a clear legal basis and, where a third party is processing data on the organization's behalf rather than under its own independent authority, a written data processing agreement setting out what the provider can and cannot do with the data.

Background check and recruitment agencies deserve particular attention. These firms should be registered with the ODPC where required, engaged under a proper processor agreement, and should not retain candidate data indefinitely once a hiring decision has been made and the engagement concludes.

Where employee data is shared across borders, for example to a regional or global HR system operated by a parent company, this triggers Kenya's cross border transfer requirements under Section 48 of the Act, which generally require documented safeguards or another recognized legal basis before the transfer occurs.


Disposal: Retention Schedules and Secure Deletion

Employee data should not be kept indefinitely, but Kenyan employers also operate under separate statutory retention obligations from tax and employment law that specify minimum periods certain records must be kept. The practical answer is a documented retention schedule, rather than either indefinite retention out of caution or premature deletion that creates its own compliance risk.

A reasonable retention schedule typically sets specific periods for each category, statutory records held for the legally required minimum, general personnel files retained for a defined period after employment ends, and sensitive data such as biometric access credentials deleted promptly once the specific purpose no longer applies, generally immediately upon an employee's departure for building or system access data. When records reach the end of their retention period, disposal should be genuinely secure, permanent deletion for digital records and confidential shredding for physical documents, not simply moving files to an unused folder or storage box.


An HR Data Protection Checklist

Before considering your organization compliant, HR teams should be able to confirm: every data field collected at onboarding has a clear, documented purpose, sensitive data such as health and biometric information is stored separately with restricted access, every third party handling employee data on the organization's behalf is under a written processing agreement, a documented retention schedule exists covering every major category of employee record, employees have a clear, practical channel to request access to or correction of their own data, and any employee monitoring in place, email, devices, CCTV, attendance systems, is disclosed in policy and proportionate to its stated purpose.

Gaps in any of these areas are common, even in otherwise well run HR departments, simply because data protection compliance has historically been treated as a legal afterthought rather than a core HR operating discipline.


When to Bring in Specialized Legal Counsel

Most day to day HR data handling can be managed internally once clear policies and a retention schedule are in place. A few situations, however, genuinely call for specialized legal input rather than an internal best guess: designing or auditing an HR privacy policy and retention schedule from scratch, responding to an employee's formal data access, rectification, or complaint request where the response could carry legal consequences, structuring cross border data sharing arrangements with a parent company or regional office, handling a data breach involving employee records, particularly health or biometric data, negotiating data processing agreements with payroll, background check, or benefits providers, and preparing for or responding to an ODPC inquiry or investigation involving employee data.

Firms such as Kathurima N Advocates work with HR teams on exactly these situations, conducting HR data protection audits to identify gaps before they become complaints, drafting policies and processing agreements that meet the Act's requirements, and stepping in directly when an access request, breach, or ODPC matter needs a properly handled legal response rather than an internal improvisation.


Final Thoughts

HR data protection in Kenya is not a separate compliance project bolted onto existing HR practice, it is a discipline that touches nearly every process HR runs, from the first onboarding form to the last document shredded after an employee leaves. Building that discipline around a clear lifecycle, collect only what is needed, store it securely, process it for its stated purpose, share it only under proper agreements, and dispose of it on schedule, turns data protection from a source of regulatory risk into a genuinely well run HR operation

0 Comments

No comments yet — be the first to share your thoughts.

Leave a Comment

Your email address will not be published. Comments are reviewed before appearing.

WhatsApp