ODPC & the Kenya Data Protection Act: a hospital administrator's checklist
The Office of the Data Protection Commissioner is issuing enforcement notices to hospitals. Here's what a compliant HIMS looks like — and what it doesn't.
Kenya's Data Protection Act, 2019 places specific obligations on Data Controllers and Data Processors — categories that include every hospital handling patient records. The Office of the Data Protection Commissioner (ODPC) has been increasingly active with enforcement, and the fines are not trivial: up to KES 5 million per breach, or 1% of annual turnover.
What you must have
- Registration as a Data Controller with the ODPC (renewable annually)
- A published privacy notice explaining what patient data you collect and why
- Documented consent capture at registration, including SMS/email marketing consent (separate opt-in)
- A process to handle Data Subject Access Requests (DSARs) within 7 days
- A breach notification workflow: 72 hours to the ODPC, 'without undue delay' to affected patients
- Role-based access control on all patient records with a full audit trail
- Data residency: patient data should not leave Kenya without explicit safeguards
The DSAR trap
The most common enforcement trigger is a botched DSAR. A patient asks for a copy of their record. Your team can't easily assemble it because records live in seven systems. Seven days pass. The patient complains to the ODPC. A compliant HIMS produces a full patient record export — clinical, financial, communications — in one click.
How MERIDIAN handles this
Every patient has a Consent tab tracking marketing, research and data-sharing consents with revocation history. DSAR export is one click and produces a FHIR bundle plus a human-readable PDF. Breach detection runs on the audit log. And Plaxera Concepts Ltd is a registered Data Controller — your DPO can reference our registration in your own filings.