Data Protection Notice

Compliance with Kenya Data Protection Act, 2019

Last updated: February 05, 2026

Compliance Statement

254rent is committed to compliance with the Kenya Data Protection Act, 2019 (Act No. 24 of 2019) and all applicable data protection regulations. This notice explains how we process your personal data in accordance with Kenyan law.

1. Data Controller

Data Controller: 254rent
Registration: [Company Registration Number]
Address: Nairobi, Kenya
Data Protection Officer: dpo@254rent.com

2. Legal Basis for Processing (Section 31, DPA 2019)

Under the Kenya Data Protection Act, 2019, we process your personal data based on the following legal grounds:

  • Consent: You have given clear consent for us to process your data for specific purposes
  • Contract Performance: Processing is necessary for the performance of a contract or to take steps before entering into a contract
  • Legal Obligation: Processing is necessary for compliance with a legal obligation
  • Legitimate Interests: Processing is necessary for our legitimate interests (e.g., fraud prevention, service improvement)

3. Your Rights Under the DPA 2019

As a data subject under the Kenya Data Protection Act, 2019, you have the following rights:

3.1 Right of Access (Section 26)

You have the right to obtain confirmation as to whether we process your personal data and access to that data, including:

  • What personal data we hold about you
  • Why we are processing it
  • Who we share it with
  • How long we keep it

3.2 Right to Rectification (Section 27)

You have the right to have inaccurate personal data corrected and incomplete data completed.

3.3 Right to Erasure (Section 28)

You have the right to request deletion of your personal data in certain circumstances, including when:

  • The data is no longer necessary for the original purpose
  • You withdraw consent and there is no other legal basis
  • The data has been unlawfully processed

3.4 Right to Restrict Processing (Section 29)

You have the right to restrict our processing of your personal data in certain circumstances.

3.5 Right to Data Portability (Section 30)

You have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit that data to another controller.

3.6 Right to Object (Section 31)

You have the right to object to processing of your personal data for direct marketing purposes or where processing is based on legitimate interests.

4. Data Processing Principles (Section 25, DPA 2019)

We process your personal data in accordance with the following principles:

  • Lawfulness, Fairness, and Transparency: We process data lawfully, fairly, and transparently
  • Purpose Limitation: We collect data for specified, explicit, and legitimate purposes
  • Data Minimization: We only collect data that is adequate, relevant, and necessary
  • Accuracy: We keep data accurate and up-to-date
  • Storage Limitation: We retain data only for as long as necessary
  • Integrity and Confidentiality: We ensure appropriate security of personal data
  • Accountability: We are responsible for and demonstrate compliance with these principles

5. Data Security Measures (Section 43, DPA 2019)

We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction, including:

  • Encryption of data in transit and at rest
  • Access controls and authentication
  • Regular security assessments and audits
  • Staff training on data protection
  • Incident response procedures

6. Data Breach Notification (Section 43, DPA 2019)

In the event of a data breach that is likely to result in a high risk to your rights and freedoms, we will:

  • Notify the Office of the Data Protection Commissioner within 72 hours
  • Notify affected data subjects without undue delay
  • Provide information about the nature of the breach and measures taken

7. Cross-Border Data Transfers (Section 48, DPA 2019)

If we transfer your personal data outside Kenya, we ensure that:

  • The recipient country has adequate data protection laws, or
  • Appropriate safeguards are in place (e.g., standard contractual clauses, binding corporate rules)
  • You have given explicit consent to the transfer

8. Exercising Your Rights

To exercise any of your rights under the Kenya Data Protection Act, 2019, please contact us:

  • Email: dpo@254rent.com
  • Phone: +254 703 922 274
  • Address: Nairobi, Kenya

We will respond to your request within 30 days as required by the DPA 2019.

9. Complaints

If you believe we have not handled your personal data in accordance with the Kenya Data Protection Act, 2019, you have the right to lodge a complaint with:

  • Office of the Data Protection Commissioner
  • Email: info@odpc.go.ke
  • Website: www.odpc.go.ke

10. Updates to This Notice

We may update this Data Protection Notice from time to time to reflect changes in our practices or legal requirements. We will notify you of any material changes and update the "Last updated" date.

This notice is provided in compliance with the Kenya Data Protection Act, 2019 (Act No. 24 of 2019).