Tax & Compliance
You Hold Your Tenants' Data. Here's What That Makes You.
Every Kenyan landlord who keeps a tenant's ID number, phone number or M-Pesa history is a data controller under the Data Protection Act, 2019. What that means in practice, what PropTraka handles for you, what stays yours, and why most landlords don't need to register with the ODPC.
6 min read
Important. This guide explains general obligations under Kenya's Data Protection Act, 2019 and how PropTraka supports them. It is not legal advice. For your specific circumstances — particularly if you manage at scale or hold data on behalf of other owners — engage an advocate. The Office of the Data Protection Commissioner publishes current guidance at odpc.go.ke.
The word nobody used with you
You collected a copy of an ID. You saved a phone number so you could send a rent reminder. You kept a record of who paid what, and when.
Those are ordinary, sensible things a landlord does. They are also, under Kenyan law, processing personal data — and the person who decides why and how it happens is called the data controller.
That is you. Not your agent, not your caretaker, and not PropTraka. You decided to collect it and you decided what it's for, and under section 2 of the Act that decision is what makes someone the controller.
This isn't a warning. It's a role with a short list of duties attached, most of which you are probably already doing by instinct. The point of this guide is to make the list explicit, so nothing on it surprises you later.
What PropTraka carries, and what stays with you
When you use PropTraka, the split is set out in our Data Processing Addendum and it is deliberately unambiguous:
For Tenancy Data: the Customer is the Data Controller; and PropTraka is the Data Processor, processing only on the Customer's documented instructions.
In plain terms:
We carry the machinery. Encrypted storage, access logging, the retention clock that deletes records when their period expires, security of processing under section 41(4) and Regulation 32, and a 48-hour duty to tell you if anything goes wrong on our side (section 43(3)). We process only on your instructions — we do not decide new purposes for your tenants' data.
You carry the judgement. Why you collect a piece of information, whether you actually need it, what you tell the tenant, and how you answer them when they ask. No platform can do those for you, because they are decisions, not features.
That division is not a PropTraka invention. It is the roles test in the Act, applied activity by activity.
The five duties, in order of how often they come up
1. Collect only what you actually need
The commonest mistake is not malice, it's habit — photographing an entire ID when a name and number would do, or keeping a payslip long after the tenancy started.
Ask of each field: what decision does this let me make? If there isn't one, don't collect it. Fewer fields is not a compromise; under the Act it is the standard.
2. Tell the tenant why
A tenant is entitled to know what you hold and what it's for. This does not require a legal document. One clear paragraph in the tenancy agreement, or a line on the application form, is enough — and PropTraka's tenancy templates already carry one.
What it should say: what you collect, why, who else sees it, how long you keep it, and how to reach you with a question.
3. Keep it secure — including off-platform
Data inside PropTraka is encrypted and access-logged. The exposure is almost always outside it: the ID photo sitting in your WhatsApp gallery, the tenant list on a shared laptop, the spreadsheet emailed to a caretaker.
If a copy exists somewhere PropTraka can't see, PropTraka can't protect it. This is the single most useful thing most landlords can tighten in an afternoon.
4. Answer the tenant when they ask
A tenant may ask to see what you hold, correct it, delete it, restrict how it's used, object to a use, take it elsewhere, or withdraw a consent they previously gave. They may also complain directly to the ODPC.
You don't need to memorise the list. You need a way to answer it — PropTraka handles subject requests on your behalf so a request doesn't become an emergency.
5. Report a breach within 72 hours
If personal data is lost, exposed or accessed by someone who shouldn't have it, the controller notifies the Commissioner within 72 hours of becoming aware (section 43(1)–(2)). "Becoming aware" starts the clock, not "finishing the investigation."
If the breach happens on our side, we tell you within 48 hours so your own window is still open. A lost phone with tenant photos on it is your side — and it counts.
Do you have to register with the ODPC?
Probably not, and this is the part most landlords get wrong in the anxious direction.
Registration as a data controller is mandatory only where both of these are true: annual turnover or revenue of KES 5 million or more, and ten or more employees. Meeting just one does not trigger it. A handful of specific sectors must register regardless of size — financial services, healthcare, telecommunications, crime prevention and hospitality among them — but ordinary residential letting is not on that list.
So most individual landlords and small managers are exempt from registering.
The duties above are not affected by that exemption. Registration is an administrative formality; the obligations to minimise, inform, secure, respond and report apply to every controller regardless of size. Being exempt from the register is not being exempt from the Act — that distinction is the one worth remembering from this whole guide.
If you cross either threshold, or you manage property on other owners' behalf at scale, take advice — the roles get more interesting when you hold data for someone else.
What good looks like
You are in reasonable shape if:
- Every field you collect has a reason you could say out loud
- Your tenancy agreement says what you hold and why
- Tenant documents live in PropTraka, not in a WhatsApp gallery
- You know who to contact if something leaks, and you'd move within 72 hours
- Old tenancies age out rather than accumulating forever
None of that requires a compliance department. It requires deciding once and then keeping the habit.
References
- Data Protection Act, 2019 (No. 24 of 2019) — controller and processor roles (s.2), security of processing (s.41(4)), processing on documented instructions (s.42(2)(b)), breach notification (s.43), sensitive personal data (s.49).
- Data Protection (General) Regulations, 2021 — security measures (Reg 32), processor terms and processing particulars (Reg 24(2)).
- Data Protection (Registration of Data Controllers and Data Processors) Regulations, 2021 (Legal Notice No. 265) — registration thresholds and sector exceptions.
- Office of the Data Protection Commissioner — guidance and complaints: odpc.go.ke · info@odpc.go.ke · +254 20 2655555
- PropTraka Data Processing Addendum — the controller/processor split for Tenancy Data: /dpa