Skip to content
Practice areas Data Protection & Privacy

Personal data

Turn privacy obligations into an operating system.

Kenyan data-protection compliance, contracts and incident support that teams can use in day-to-day operations.

Run the 2-minute check
Kenyan operations team reviewing a data map and privacy controls
HTLA / Personal data Privacy audits and compliance packs

01Written scope before work begins

02Indicative fees or pricing factors explained

03Digital-first document handling

04A clear response within one business day

Recognise the moment

This may be the right route if…

Start with the situation, not the legal label. We will confirm the correct scope after reviewing the basic record.

01

Customers are asking privacy questions

A contract, procurement review or investor process requires clearer evidence of compliance.

02

Personal data flows through several tools

The organisation cannot confidently explain what it collects, why, where it goes or how long it is retained.

03

An incident or complaint has occurred

The team needs to preserve facts, assess notification duties and respond consistently.

Interactive diagnostic / about 2 minutes

Privacy readiness check

Answer three practical questions. The result is indicative guidance, not legal advice, and nothing is submitted.

Question 1 of 3Can your team identify the personal data it holds and the reason for each use?

What we can take responsibility for

Scope, deliverables and fee clarity.

These are starting points rather than packages forced onto every matter. Third-party costs and final scope are confirmed separately in writing.

01

Privacy readiness audit

  • Data-use and document review
  • Priority gap analysis
  • Practical remediation plan

Fee guidanceQuoted according to organisation and data scope

TimingDelivered in stages where the data environment is broad

02

Compliance documentation

  • Privacy notices and policies
  • Key data-processing terms
  • Implementation guidance

Fee guidanceFixed scope after document inventory

TimingSequenced around the highest-risk uses first

03

Incident and regulatory support

  • Fact and obligation assessment
  • Response and notification advice
  • Regulatory correspondence within scope

Fee guidanceQuoted according to urgency and exposure

TimingImmediate preservation and escalation decisions come first

See indicative privacy fees

Professional fees exclude VAT and official or third-party disbursements unless the written quote states otherwise.

A visible working relationship

Know what happens on both sides.

The process changes with the matter. The responsibility to keep the route visible does not.

  1. 01

    Map the real data use

    YouIdentify systems, people, vendors and priority data flows.

    HTLAWe translate the operation into a usable legal and risk map.

  2. 02

    Fix what matters first

    YouConfirm operational owners and commercial deadlines.

    HTLAWe rank obligations by harm, enforcement and business consequence.

  3. 03

    Embed the controls

    YouAssign owners and use the agreed documents and playbooks.

    HTLAWe prepare the pack and support practical implementation.

Representative engagement

A growing service is asked for a compliance pack

Situation
Personal data is handled across staff, cloud vendors and customer workflows, but the documents describe only part of the reality.
Legal route
Map priority flows, correct the public and contractual record, and assign practical incident responsibilities.
Safeguard
A privacy policy alone is not an operational compliance programme.

Before you instruct

Practical questions.

Clear answers help you decide whether to share documents, book advice or continue researching.

01What does a practical data-protection audit cover?

The scope can include data uses, legal bases, notices, policies, vendor terms, retention, security responsibilities and incident readiness.

02Do all organisations need the same compliance documents?

No. The right pack depends on the people, data, purpose, risk, sector and relationships involved.

03Can you assist after a data breach?

Yes. Preserve facts and restrict speculative communication while the incident and any notification duties are assessed.

04Can you support an ODPC matter?

Yes, subject to conflict, capacity, the procedural stage and a review of the relevant record.

Choose the level of commitment

Move from uncertainty to a scoped next step.

Ask on WhatsApp