CASE STUDIES
-
Sector: Real Estate / Property Management
Location: Nairobi, Kenya
Operations: Managing 100+ residential and commercial units
Challenge:
Property management firm processing tenant personal data, landlord information, maintenance records, surveillance footage, and financial transactions needed ODPC registration and ROPA covering all property operations.
Our Solution:
- Data mapping across tenant management, payments, surveillance, and maintenance operations
- ODPC registration with detailed ROPA for property management activities
- Policy framework including tenant privacy notices, CCTV data handling, and data retention schedules
- Vendor compliance for payment processors and maintenance contractors
- Staff training on handling tenant data responsibly
Outcome:
- ODPC registered within 8 weeks
- Comprehensive ROPA covering all property management operations
- Tenant-facing privacy notices implemented across all properties
- Reduced liability for landlord and tenant data handling
Duration: July 2023 - November 2023
-
Sector: Climate Tech / Renewable Energy
Location: Kisumu, Kenya
Stage: Early-stage, pre-Series A
Challenge:
Clean energy startup collecting customer usage data, payment information, and IoT device data needed compliance framework for investor due diligence and operational scaling.
Our Solution:
- Rapid data protection audit focused on IoT and customer data
- ODPC registration completed within 4 weeks (fast-track for investor timeline)
- Investor due diligence documentation package
Outcome:
- ODPC registered ahead of investor due diligence deadline
- Compliance framework ready
Duration: May 2024 - July 2024
-
Sector: Agriculture / Export / Manufacturing
Location: Mombasa, Kenya
Operations: Export operations to EU.
Challenge:
Tea exporter processing farmer supplier data, employee records, and international customer information needed ODPC registration and data governance frameworking.
Our Solution:
- Data mapping covering supplier networks, export operations, and international customers
- ODPC registration with cross-border transfer documentation
- Policy framework including international data transfer safeguards
- Vendor compliance for logistics and shipping processors
Outcome:
- ODPC registered within 6 weeks
- No disruption to international operations
Duration: September 2023 - February 2024
-
Sector: Health / Non-Profit / Consortium
Location: Nairobi, Kenya (National operations)
Operations: Multi-member umbrella organization
Challenge:
NGO umbrella body managing sensitive beneficiary health data, donor reporting requirements, and member organization information needed compliance with DPA 2019 and international donor standards (EU, USAID).
Our Solution:
- Comprehensive audit of beneficiary data protection practices
- ODPC registration tailored to NGO consortium structure
- Policy framework aligned with DPA 2019 and EU GDPR donor requirements
- Fractional DPO services for ongoing donor compliance
Outcome:
- ODPC registered with beneficiary data safeguards
- DPO support ensuring continuous compliance
Duration: March 2022 - December 2024
-
Sector: Food Services / B2B Distribution
Location: Nairobi, Kenya
Operations: Multi-regional distribution network
Challenge:
Company processing customer business data, employee records, supplier information, and logistics data needed comprehensive compliance framework and vendor management protocols.
Our Solution:
- Data mapping across sales, logistics, HR, and vendor operations
- Vendor compliance assessments and processor agreements
- Policy development including data retention, security, and third-party data sharing
- Employee training on data handling in distribution operations
Outcome:
- ODPC registered within 3 weeks
- Vendor compliance protocols established
- Reduced data protection risk across supply chain operations
Duration: June 2024 - October 2024
-
Sector: HealthTech / Digital Health
Location: Nairobi, Kenya
Stage: Incubation
Challenge:
Health data processing startup required compliance with DPA 2019 for grant eligibility and investor due diligence. Faced audits from funders and incubation program compliance requirements.
Our Solution:
- Comprehensive data protection audit focused on health data processing
- ODPC registration with specialized ROPA for sensitive health information
- Data Protection Impact Assessments (DPIAs) for high-risk processing
- Grant compliance documentation for funders
- Policy framework including health data security protocols
Outcome:
- Successfully passed funder compliance audit
- ODPC registered with full health data safeguards
- Grant funding approved with compliance documentation in place
- Routine ongoing DPO advisory for scaling operations
Duration: January 2024 - Present