Data protection consultancy, end to end
From establishing where you stand against the Data Protection Act to the controls, documentation and training that keep you there.
Data Protection Compliance & DPA Readiness
Establish where you stand against Kenya's Data Protection Act, then close the gaps in a defensible order.
Learn moreData Protection Impact Assessments
Assess the privacy risk in a new system, product or processing activity before it goes live — not after.
Learn moreData Governance & Classification
Know what data you hold, where it lives, who can reach it, and how long you are entitled to keep it.
Learn moreAccess Control & Authentication
Multi-factor authentication and role-based access control, so only authorised personnel reach sensitive data.
Learn moreData Masking & Anonymisation
Share and analyse data without exposing the people in it — for vendors, testing and non-production systems.
Learn moreTraining & Awareness
Equip your team to recognise phishing, handle personal data correctly and respond when something goes wrong.
Learn more
Data Protection Compliance & DPA Readiness
We assess your current handling of personal data against the Data Protection Act, 2019 and the regulations made under it, then produce a prioritised remediation roadmap. That covers lawful basis, consent mechanics, data subject rights, retention, breach notification and your obligations as a data controller or processor — including registration with the Office of the Data Protection Commissioner where it applies.
What you get
- Gap assessment against the DPA and its regulations
- Prioritised remediation roadmap with owners and timelines
- Policy set: privacy notice, retention, breach response
- ODPC registration support for controllers and processors
Data Protection Impact Assessments
Where processing is likely to result in high risk to data subjects, a DPIA is not optional. We run the assessment end to end: mapping the processing, identifying risks to individuals, testing necessity and proportionality, and documenting the mitigations. The output is a record you can put in front of a regulator, a board or a prospective client.
What you get
- Processing maps and data flow diagrams
- Risk register scored by likelihood and severity
- Necessity and proportionality assessment
- Signed-off DPIA report and mitigation plan
Data Governance & Classification
Most protection failures are inventory failures — organisations cannot secure data they have not catalogued. We build the data inventory, apply a classification scheme proportionate to your business, and put retention and disposal schedules behind it, so that access decisions and deletion obligations both have something concrete to reference.
What you get
- Data inventory and records of processing activities
- Classification scheme and handling rules per tier
- Retention and secure disposal schedules
- Third-party and cross-border transfer register
Access Control & Authentication
We design and implement authentication and access control that matches the sensitivity of what you hold: multi-factor authentication, role-based access control, session management and tokenisation. The goal is least privilege that people will actually work with, backed by access reviews that keep it true over time.
What you get
- Role model and least-privilege access matrix
- MFA rollout plan and enforcement policy
- Session, token and credential handling standards
- Periodic access review process
Data Masking & Anonymisation
Personal data routinely leaks through the side doors: test environments, vendor extracts, analytics pipelines. We put masking and anonymisation in front of those paths so sensitive fields are protected before data leaves a trusted environment, and advise on where true anonymisation takes the data outside the Act's scope versus where pseudonymisation still leaves you accountable.
What you get
- Masking rules for non-production and vendor extracts
- Anonymisation vs pseudonymisation assessment
- Privacy-preserving analytics patterns
- Re-identification risk review
Training & Awareness
Controls fail at the human edge. We run interactive training on data protection obligations, secure handling practice, and recognising phishing and social engineering — tailored to the roles that actually touch personal data in your organisation, and repeated on a cadence rather than delivered once and forgotten.
What you get
- Role-based training modules for staff and leadership
- Phishing simulation and follow-up coaching
- Data handling quick-reference guides
- Awareness calendar and completion reporting
Real-life strategy to reach your goals
Whatever the engagement, the work is judged against the same standard.
Specific
Oriented to goals you actually set, not generic maturity scores.
Measurable
Based on your business, with outcomes you can verify.
Accurate
Aligned to current regulation and global practice.
Reliable
Findings you can put in front of a board or a regulator.
Timely
Delivered on a schedule that matches your obligations.
Sustainable
Designed so it still holds twelve months after we leave.
Our consultation is always in sync with your strategy
We offer tailored data protection consulting that syncs seamlessly with your strategic vision, keeping your business secure and compliant while it achieves its goals.