Kenya Data Protection Act and Payment Data Storage
Under Kenya's DPA 2019, storing Paystack payment data (email, phone, transaction reference) is lawful on the basis of "performance of a contract". You must: (1) register with the Office of the Data Protection Commissioner (ODPC) if you process personal data, (2) conduct a Data Protection Impact Assessment (DPIA) before deploying a payment system at scale, (3) notify the ODPC within 72 hours of a data breach, (4) have a privacy notice disclosing what payment data you collect, and (5) not transfer customer data outside Kenya without adequate safeguards.
How Kenya's DPA 2019 Applies to Payment Data
The Kenya Data Protection Act 2019 defines personal data broadly — any information relating to an identified or identifiable natural person. In your Paystack integration, this includes:
- Customer name, email address, and phone number
- Transaction reference linked to a specific customer
- IP address at time of payment
- Device identifiers collected during checkout
- Any metadata you attach to transactions (e.g., member ID, order contents)
You are both a data controller (you decide what to collect and why) and in some cases a data processor (if you handle data on behalf of another business). Both roles require ODPC registration.
The lawful basis for storing payment data is performance of a contract (DPA Section 30(1)(b)) — you need the data to fulfill the purchase agreement with your customer. You do not need a separate consent tick-box for this, but you must disclose it in a privacy notice.
DPA 2019 Obligations for Kenyan Payment Data Handlers
1. ODPC Registration
Register with the Office of the Data Protection Commissioner at odpc.go.ke. Registration is required for any data controller or processor. The fee and process are set by the ODPC regulations.
2. Privacy Notice
Before a customer pays, they must be able to access a privacy notice explaining: what data you collect at checkout, the lawful basis, how long you retain it, and how they can exercise their rights (access, rectification, erasure).
3. Data Protection Impact Assessment (DPIA)
Conduct a DPIA before deploying a payment system that processes personal data at scale or uses automated decision-making. Document the assessment and retain it.
4. Security Measures
Implement appropriate technical and organisational measures: encrypt data at rest and in transit, restrict access to payment tables, maintain audit logs of who accesses payment records.
5. Breach Notification
If your payment database is breached:
- Notify the ODPC within 72 hours of becoming aware of the breach
- Notify affected data subjects (customers) as soon as reasonably practicable
- Document the breach and remediation steps in your breach register
6. Data Retention and Deletion
Define a retention period. For financial records in Kenya, 5-7 years is common to align with KRA requirements. After this period, delete or anonymise customer payment records.
Learn More
This guide is part of the Paystack security and compliance guide.
Key Takeaways
- ✓Kenya's DPA 2019 requires all data processors and controllers to register with the Office of the Data Protection Commissioner (ODPC).
- ✓Storing customer email, name, phone, and transaction reference is lawful as "performance of a contract" — no separate consent required for payment records.
- ✓Never store card numbers, CVVs, or PINs. Paystack handles this by design and your integration should never receive raw card data.
- ✓Conduct a DPIA (Data Protection Impact Assessment) before launching a payment feature that processes personal data at scale.
- ✓Breach notification to the ODPC is required within 72 hours of discovery. Customer notification must follow as soon as practicable.
- ✓Cross-border data transfers (e.g., storing Kenyan customer data on EU/US servers) are permitted with adequate safeguards — standard contractual clauses or adequacy decisions.
Frequently Asked Questions
- Does accepting M-Pesa via Paystack trigger any additional DPA obligations?
- No additional obligations beyond standard DPA requirements. M-Pesa payment data (phone number, transaction ID) is personal data like any other. Store only what you need, disclose it in your privacy notice, and apply the same retention and security measures as for card payments.
- Can I use Google Analytics or Meta Pixel on my checkout page under Kenya's DPA?
- Third-party analytics tools on checkout pages may collect personal data (IP, device fingerprint) and transfer it to servers outside Kenya. This requires a lawful basis (typically consent) and adequate safeguards for the cross-border transfer. Consider whether analytics on the payment page is necessary — the checkout completion event can be tracked without third-party scripts on the payment page itself.
- What rights do Kenyan customers have over their payment data?
- Under DPA 2019, customers have the right to: access their payment records you hold, have inaccurate data corrected, request erasure (within limits — financial records may need to be retained for legal reasons), object to processing, and data portability. Your system must have a way to handle these requests.
- Are there penalties for non-compliance with Kenya's DPA?
- Yes. The DPA 2019 provides for fines of up to KES 3 million or up to 1% of annual global turnover, whichever is higher, for violations. Serious violations can lead to criminal liability for directors. The ODPC has been increasing enforcement activity since 2023.
Ready to build real-world apps?
Join the McTaba Labs full-stack marathon (4 months full-time · 6 months part-time). Learn M-Pesa, USSD, and WhatsApp engineering while shipping 8 production apps.
Apply to the McTaba Marathon