Your Email Isn't Fair Game: Consent Under Kenya's Data Protection Act

Published Nov 4, 2025 by Raymond M., CFE in Compliance

0

Your Email Isn't Fair Game: Consent Under Kenya's Data Protection Act

For years, I've watched Kenyan businesses routinely add customers to mailing lists without consent. Here's what you need to know about consent requirements under Kenya's Data Protection Act.

I've lost count of how many times it's happened. You contact a business for a specific purpose (a quote, an inquiry, a one-time transaction), and suddenly you're receiving their marketing emails. Sometimes it's weekly newsletters. Other times it's promotional campaigns. Occasionally, it's both, along with partner offers you never asked for.

The pattern is frustratingly consistent across sectors. Retailers, service providers, financial institutions, and tech companies. It doesn't seem to matter whether you're dealing with a multinational corporation or a local business. The assumption appears universal: if you've given us your email address for one purpose, we can use it for another. This isn't how data protection works.

What the Law Actually Says

Kenya's Data Protection Act (2019) is unambiguous about consent. Section 30 requires that consent must be freely given, specific, informed, and an unambiguous indication of a data subject's wishes. Let's break down what this means in practice.

"Freely given" means you had a genuine choice. If obtaining a service requires you to agree to marketing communications, that's not free consent. It's a condition of service, which the Act explicitly prohibits for processing that isn't necessary for the primary purpose.

"Specific" means consent for one thing doesn't cover another. Agreeing to receive an invoice via email doesn't mean you've agreed to receive marketing emails. These are distinct purposes requiring distinct consent.

"Informed" means you were told what you're consenting to. Vague statements like "we may contact you with offers" don't cut it. You need to know what communications you'll receive, how often, and from whom.

"Unambiguous" means your agreement must be clear. Pre-ticked boxes fail this test. So does silence. Consent requires a positive action.

Why "You Can Unsubscribe" Isn't a Defence

I've heard this justification repeatedly when raising the issue with businesses: "But we include an unsubscribe link in every email." This misses the fundamental point. The question isn't whether I can opt out. The question is whether I opted in.

The Data Protection Act operates on an opt-in model for marketing communications, not opt-out. Adding someone to your mailing list and then giving them the option to leave doesn't comply with the law. You need their consent before the first marketing email goes out, not after. This isn't a technicality. It reflects a basic principle: individuals control their personal data. Businesses don't get to use that data however they want and then offer an exit route when people object.

The Business Case for Compliance

Beyond legal obligation, there's a practical reason businesses should care about proper consent. Marketing to people who haven't agreed to receive your communications produces poor results. Your open rates suffer. Your click-through rates drop. Your brand perception takes a hit when people associate you with spam. Conversely, audiences who've actively opted in are more engaged. They're expecting your communications. They're interested in what you're offering. The quality of your mailing list matters more than its size.

There's also the enforcement angle. The Office of the Data Protection Commissioner has powers to investigate complaints, issue compliance orders, and impose financial penalties. Fines can reach KES 5 million or 1% of annual turnover, whichever is lower. For a business operating on thin margins, that's not a negligible risk.

What Businesses Need to Do

If you're running marketing operations, audit your consent mechanisms. Ask yourself these questions:

Are you obtaining explicit consent before adding people to mailing lists? Not implied consent, not assumed consent, but clear, documented agreement?

Are you separating transactional communications from marketing communications? Someone who needs to receive order confirmations hasn't necessarily agreed to promotional emails.

Are you keeping records of consent? If someone complains or the regulator investigates, can you demonstrate that the person agreed to receive your communications?

Are you making it as easy to withdraw consent as it was to give it? Unsubscribe processes should be straightforward, not buried behind multiple clicks or requiring account logins.

Are you respecting the withdrawal of consent immediately? Once someone unsubscribes, they should stop receiving marketing communications within a reasonable timeframe (typically within 48 hours for email).

What Consumers Should Know

You have rights under the Data Protection Act. If a business has added you to their mailing list without your consent, you can:

  • Submit a complaint directly to the business and demand that they remove you from their database.
  • Exercise your right to erasure under Section 35 of the Act, requiring the organisation to delete your personal data where there's no lawful basis for processing it.
  • File a complaint with the Office of the Data Protection Commissioner if the business doesn't respond or refuses to comply.

The regulator's complaint portal is accessible via their website, and the process doesn't require legal representation.

The Bigger Picture

This issue extends beyond marketing emails. It's symptomatic of a broader challenge: businesses treating the Data Protection Act as a compliance checkbox rather than a framework that fundamentally changes how they handle personal information.

The Act has been in force since November 2019. We're well past the adjustment period. Organisations have had time to update their systems, train their staff, and revise their practices. Continued non-compliance at this stage isn't an oversight. It's a choice to prioritise convenience over legal obligation.

For consumers, the gap between legal rights on paper and practical enforcement remains significant. Many people don't know they can complain. Others don't know where to complain. Some assume nothing will change even if they do complain.

Enforcement starts with awareness. Businesses are more likely to comply when they know customers understand their rights and are willing to assert them. Regulators are more likely to prioritise issues that generate consistent complaints.

A Simple Standard

The principle here isn't complicated. Before you add someone to your mailing list, ask them. Make it clear what they're agreeing to. Record their agreement. Honour their choice if they change their mind. That's not onerous. That's basic respect for personal autonomy and legal compliance. Further, in a digital economy where trust is currency, it's also good business practice.

Have you experienced similar issues with unsolicited marketing communications? How do you think businesses can better balance their marketing objectives with data protection obligations?

By Raymond M., CFE
Forensic & Cyber Security Consultant

Prev: Digital Forensics Behind the Scenes: What Cybercrime Investigations Are Revealing…