Data Privacy for Kenyan NGO Websites: What You Need to Know

An NGO website can collect much more personal information than an organisation may realise.

A contact form might collect a person’s name, email address and telephone number. A careers page might receive CVs and employment histories. A programme application might collect information about beneficiaries. A newsletter form might collect contact details. An event registration system might collect attendance information.

Some NGOs also work with particularly sensitive information involving children, health, disability, refugees, survivors of violence or other vulnerable groups.

That makes data privacy an important consideration when designing, developing and managing an NGO website in Kenya.

Kenya’s Data Protection Act, 2019 establishes the country’s legal framework for the protection of personal data, with the Office of the Data Protection Commissioner (ODPC) responsible for regulating the processing of personal data and protecting data subjects’ rights.

For NGOs, website privacy is therefore not simply a matter of putting a “Privacy Policy” link in the footer.

It involves understanding:

  • What personal data the website collects
  • Why it is collected
  • The legal basis for processing
  • Who has access to it
  • Where it is stored
  • Which third parties receive it
  • How long it is retained
  • How it is protected
  • What rights individuals have
  • What happens if the information is compromised

This guide explains the major data privacy issues Kenyan NGOs should consider when building or managing a website.

Important: This article is general information about website privacy and data protection. It is not legal advice. NGOs should obtain professional advice about their specific obligations, processing activities, contracts and regulatory circumstances.


What Is Data Privacy?

Data privacy concerns how an organisation collects, uses, stores, shares and protects information relating to identifiable individuals.

For an NGO website, this can include information submitted directly by users as well as information collected through website technologies.

Examples include:

  • Names
  • Email addresses
  • Telephone numbers
  • Physical addresses
  • CVs
  • Employment information
  • Photographs
  • IP addresses
  • Location information
  • Online identifiers
  • Survey responses
  • Donation information
  • Programme applications
  • Event registrations
  • Newsletter subscriptions

The website may also interact with other systems that process personal data.

For example:

Website → CRM → Email platform

or:

Website → Application form → Cloud storage

or:

Website → Donation platform → Payment processor

Understanding the entire data flow is more important than looking at the website in isolation.


Kenya’s Data Protection Framework

The primary legislation is the Data Protection Act, 2019.

The Act establishes principles governing the processing of personal data and provides rights to individuals whose personal data is being processed.

The ODPC is responsible for implementing and enforcing the framework, including regulating data controllers and processors and protecting individuals’ privacy rights.

The ODPC also provides registration and compliance mechanisms for organisations processing personal data.

For an NGO, the important point is that data protection should be considered an organisational responsibility, not simply a technical website feature.


Is an NGO a Data Controller?

Potentially, yes.

The ODPC defines a data controller as an entity that determines the purposes and means of processing personal data.

The ODPC specifically identifies charities among examples of organisations that can act as data controllers.

For example, suppose an NGO operates a website containing a volunteer registration form.

The NGO decides:

  • Why the information is collected
  • What information is collected
  • How it will be used
  • Who within the organisation can access it

The NGO may therefore be acting as the data controller.


What Is a Data Processor?

A data processor processes personal data on behalf of a data controller.

The ODPC gives examples including cloud computing providers and CRM or ERP providers that have access to personal data.

For an NGO website, processors could potentially include:

  • Website hosting providers
  • Cloud storage providers
  • CRM platforms
  • Email marketing platforms
  • Form providers
  • Analytics providers
  • Recruitment platforms
  • Donation platforms
  • IT service providers

The distinction matters because the NGO needs to understand what its external service providers are doing with personal information.


Do Kenyan NGOs Need to Register With the ODPC?

This is an important question for nonprofits.

The ODPC states that public entities and non-profit-making entities such as charities and religious organisations are required to register, regardless of revenue or turnover.

The ODPC’s registration portal also specifically provides a category for Not for Profit Entities & Religious Institutions.

The registration process requires organisations to provide information about their processing activities, including categories of personal data, purposes of processing, data subjects, transfers and safeguards.

This means an NGO should not assume that being a nonprofit automatically means its data protection responsibilities are minimal.

Website data collection should be considered alongside the organisation’s broader data processing activities.


Website Privacy Is Only One Part of Data Protection

A common mistake is to think:

“We have a privacy policy, so our website is compliant.”

A privacy policy is important, but it is only one component.

An NGO should also consider:

  • Internal data protection policies
  • Data collection practices
  • Data retention
  • Staff access
  • Security
  • Third-party processors
  • Data processing agreements
  • Data subject requests
  • Breach response
  • International data transfers
  • Staff training
  • Beneficiary protection
  • Record keeping

The website is one part of the organisation’s wider data processing environment.


What Personal Data Does an NGO Website Collect?

Start with a data inventory.

List every website feature that collects or generates information about individuals.

Contact forms

Usually collect:

  • Name
  • Email
  • Telephone number
  • Message

Newsletter forms

Usually collect:

  • Email address
  • Name, sometimes

Careers pages

May collect:

  • Name
  • Contact information
  • CV
  • Employment history
  • Education
  • References
  • Qualifications

Event registration

May collect:

  • Name
  • Organisation
  • Email
  • Telephone number
  • Attendance information
  • Dietary requirements

Programme applications

May collect substantially more information, potentially including sensitive personal data.

Donations

May involve:

  • Name
  • Email
  • Contact information
  • Transaction information
  • Payment information

The payment provider may process payment card information rather than the NGO’s own website.

Analytics

May involve:

  • IP addresses
  • Device information
  • Browser information
  • Usage information
  • Online identifiers

The exact data collected depends on the analytics configuration and provider.


Do Not Collect Data Simply Because You Can

One of the most useful privacy principles for website design is data minimisation.

The ODPC’s published principles include collecting data that is adequate, relevant and limited to what is necessary for the purpose for which it is processed.

Suppose an NGO has a simple contact form.

It may need:

Name

Email

Message

Does it really need:

  • National ID number?
  • Date of birth?
  • Physical address?
  • Employer?
  • Gender?
  • Marital status?

If those fields are not necessary for the purpose of the form, collecting them creates additional privacy responsibilities without an obvious benefit.


Tell People Why You Are Collecting Their Data

People should be able to understand what happens to information they submit.

For example, beside a newsletter form, an NGO could explain that the email address will be used to send the organisation’s newsletter.

For a job application, applicants should receive appropriate information about how their personal data will be handled.

The ODPC describes the right to be informed as a key data subject right. It includes informing people about how their personal data will be used.

The organisation’s privacy information should therefore be understandable and accessible.


Create a Proper Privacy Notice

A privacy notice should reflect what your organisation actually does.

Depending on the NGO’s activities, it may explain:

  • Who the organisation is
  • What personal data is collected
  • Why it is collected
  • How it is used
  • The relevant legal basis
  • Who it is shared with
  • How long it is retained
  • Where it is stored
  • International transfers where relevant
  • Data subject rights
  • How to contact the organisation
  • How privacy concerns can be raised

The ODPC has indicated that privacy notices should explain relevant processing practices and provide a mechanism for people to exercise their rights.

Do not simply copy a generic privacy policy from another NGO.

Your privacy notice should describe your actual processing activities.


What Rights Do Data Subjects Have?

Kenya’s data protection framework gives individuals several rights regarding their personal data.

The ODPC identifies rights including:

  • Right to be informed
  • Right to access personal data
  • Right to rectification
  • Right to erasure
  • Right to data portability
  • Right to object to processing
  • Right to restrict processing

This means an NGO should have a process for dealing with data subject requests.

For example, if someone contacts the NGO asking what personal information it holds about them, there should be an internal process for handling that request.

This is an organisational process, not something that can be solved entirely through website development.


Build Data Subject Requests Into Your Website Strategy

Your website should make it reasonably clear how someone can contact the organisation about privacy.

For example, the privacy notice can provide a dedicated privacy contact address.

The organisation should then establish internally:

  1. Who receives the request?
  2. Who verifies the request?
  3. Who searches for the relevant data?
  4. Who approves the response?
  5. How is the response documented?
  6. What happens if another organisation holds the information?

The exact procedure should be based on the organisation’s legal and operational requirements.


Be Extremely Careful With Beneficiary Data

This is one of the most important considerations for NGOs.

A commercial website might collect customer contact information.

An NGO could collect information about people in highly vulnerable circumstances.

Examples include organisations working with:

  • Children
  • Refugees
  • Survivors of gender-based violence
  • People living with HIV
  • People with disabilities
  • Patients
  • Displaced people
  • Victims of conflict
  • People experiencing poverty
  • Human rights beneficiaries

The potential consequences of exposing this information can be serious.

A website should therefore collect and publish only information that is genuinely necessary and appropriate.


Sensitive Personal Data Requires Additional Care

The ODPC’s registration system specifically asks organisations to identify whether they process sensitive categories such as health status, biometric data, GPS location data and other sensitive information.

An NGO website could encounter sensitive information through:

  • Health programme registration
  • Disability programmes
  • Gender-based violence services
  • Refugee assistance
  • Child protection
  • Human rights programmes
  • Beneficiary surveys

For example, a programme application form should not be treated like a normal “Contact Us” form if it collects health or other sensitive information.

The organisation should assess the legal basis, necessity, security and handling of that information before collecting it.


Children and NGO Websites

NGOs working with children need to take particular care with personal data and online content.

A website may involve:

  • Child names
  • Photographs
  • School information
  • Age
  • Location
  • Health information
  • Family information
  • Programme participation

Before publishing information about children, consider:

  • Is publication necessary?
  • Has appropriate consent or authorisation been obtained?
  • Could publication create a safety risk?
  • Does the image reveal a location?
  • Does the story disclose sensitive circumstances?
  • Is the child’s dignity protected?

The safest approach is not necessarily to publish as much information as possible.

Sometimes an anonymised story is more appropriate.


Photography Is Also a Privacy Issue

NGOs often use photography extensively.

A photograph can constitute personal data where an individual is identifiable.

This means photography should be considered within the organisation’s broader privacy and communications processes.

For website photographs, consider:

  • Who appears in the image?
  • Are they identifiable?
  • What is the purpose of publishing the photograph?
  • Was appropriate consent or authorisation obtained?
  • Could publication create harm?
  • Is the photograph still appropriate years later?

Do not treat photography as completely separate from data protection simply because it is visual content.


Do Not Publish Beneficiary Information Just to Tell a Better Story

A powerful case study does not need to reveal someone’s full identity.

For example, instead of publishing:

Jane Wanjiku, 34, from [specific village], living with [specific medical condition]…

the organisation may be able to tell the same story using less identifying information.

For example:

A smallholder farmer in western Kenya participated in the programme and subsequently adopted new agricultural practices.

The appropriate level of detail depends on the programme, consent, risk and purpose.


Be Careful With Contact Forms

A basic contact form may look harmless.

But it still involves personal data.

At minimum, consider:

  • What information is collected?
  • Why is it collected?
  • Where is it stored?
  • Who receives submissions?
  • How long are submissions retained?
  • Is the data sent by email?
  • Is a third-party form service involved?

If form submissions are emailed to five staff members and automatically stored in a CMS indefinitely, the organisation should know that this is happening.


Recruitment Forms Are More Sensitive Than Contact Forms

An NGO’s careers section may collect significant personal information.

A CV can contain:

  • Name
  • Address
  • Phone number
  • Email
  • Employment history
  • Education
  • Professional qualifications
  • References
  • Other personal information

If a website stores CVs indefinitely, the organisation should consider whether this is necessary and how long the information should be retained.

A better recruitment process may use a dedicated applicant tracking system rather than storing hundreds of CVs permanently inside the website.


Avoid Storing Sensitive Information in the CMS Without a Reason

A website CMS is designed primarily for managing content.

It should not automatically become the organisation’s database for sensitive beneficiary information.

For example, if a programme needs to collect detailed beneficiary information, consider whether a dedicated and appropriately secured system is more suitable.

The website can provide the entry point while the sensitive information is handled by a system designed for that purpose.


Understand Where Website Data Is Stored

Your NGO may be based in Nairobi while its website and services operate across several countries.

For example:

Website hosting: Kenya

Email platform: United States

CRM: Europe

Analytics: United States

Cloud storage: Another jurisdiction

This matters because data may be transferred outside Kenya.

The ODPC identifies restrictions and safeguards around transfers of personal data outside Kenya, including requirements relating to adequate safeguards or consent in relevant circumstances.

The ODPC registration process itself asks organisations whether data resides outside Kenya and, if so, which countries are involved.

Therefore, your NGO should know where its website-related personal data is actually processed.


Third-Party Services Can Create Privacy Risks

Modern websites frequently rely on external services.

Examples include:

  • Google Analytics
  • Mailchimp
  • HubSpot
  • Salesforce
  • Microsoft services
  • Google Workspace
  • Cloudflare
  • Form services
  • Event registration platforms
  • Donation platforms
  • Recruitment systems
  • Video platforms

The NGO should understand:

What data does this service receive?

Why does it receive it?

Where does it process the data?

How is the data protected?

What agreement governs the relationship?

Can the data be deleted or exported?

These questions should be answered before connecting a third-party service to the website.


Google Analytics and Website Analytics

Analytics can be extremely useful.

An NGO may want to know:

  • Which programmes visitors are interested in
  • Which publications are downloaded
  • Which pages receive the most traffic
  • Where visitors come from
  • Whether a campaign generated traffic
  • How people navigate the website

But analytics can involve information about users and devices.

The organisation should therefore understand its analytics configuration and ensure that its use of analytics is consistent with its privacy obligations.

Do not assume that installing Google Analytics or another analytics tool is automatically a privacy-neutral activity.


Cookies and Tracking Technologies

Websites may use cookies and similar technologies for:

  • Essential website functions
  • Login sessions
  • Analytics
  • Preferences
  • Marketing
  • Embedded services

Your NGO should understand which cookies and tracking technologies are actually being used.

A website redesign is a good opportunity to audit them.

Ask:

  • What cookies are installed?
  • Which are essential?
  • Which are analytics-related?
  • Which are third-party?
  • What information do they collect?
  • Are they necessary?
  • How are users informed?

Avoid installing dozens of tracking scripts simply because they are available.


Newsletter Subscriptions

A newsletter subscription is a straightforward example of personal data processing.

The NGO should consider:

  • What information is collected?
  • Why is it collected?
  • What email platform is used?
  • Where is the information processed?
  • How can someone unsubscribe?
  • How are inactive subscribers handled?
  • How long is the information retained?

The unsubscribe process should be straightforward.

If someone unsubscribes, the organisation should have a process for ensuring that they are no longer sent marketing or newsletter communications where applicable.


Donation Forms and Payment Information

NGOs accepting online donations should carefully distinguish between the information the NGO receives and the information handled by the payment provider.

Ideally, sensitive payment credentials should be handled by a properly configured payment service rather than unnecessarily passing them through the NGO’s own website.

The NGO should understand:

  • What donor information it receives
  • What the payment provider receives
  • Where the information is processed
  • What information is stored
  • How donation records are retained
  • How donor communications are managed

Do not collect payment information directly through a custom website form unless there is a clear technical and compliance basis for doing so.


Job Applications and Data Retention

A common problem is leaving old job applications on a website indefinitely.

Suppose an NGO receives 2,000 applications over several years.

If all CVs remain permanently accessible in a website database, the organisation has accumulated a significant amount of personal data.

A documented retention policy should define how long different categories of information are retained and when they are securely deleted or anonymised, subject to applicable legal and organisational requirements.


Website Security Is Part of Privacy

Privacy and security are closely connected.

If personal information is collected securely but stored in a poorly protected system, privacy can still be compromised.

Website security measures can include:

  • HTTPS
  • Strong passwords
  • Multi-factor authentication
  • Role-based access
  • Secure hosting
  • Software updates
  • Security monitoring
  • Backups
  • Firewalls
  • Malware protection
  • Access logging
  • Secure APIs
  • Encryption where appropriate

The ODPC’s registration process asks organisations to describe technical, organisational and physical safeguards used to protect personal data. Examples include encryption, firewalls, access controls, multi-factor authentication, backups and security patch management.


Limit Administrator Access

Not everyone who works for an NGO needs access to all website data.

For example:

Communications officer

May need to publish articles.

Programme officer

May need to submit project content.

HR staff

May need access to recruitment information.

IT administrator

May need technical access.

External developer

May need temporary technical access.

These roles should not automatically have identical permissions.

Use role-based access wherever possible.


Remove Former Staff and Contractor Access

An often-overlooked privacy risk is old user accounts.

When an employee leaves, or a web agency finishes a project:

  • Remove unnecessary accounts
  • Change shared credentials
  • Revoke API keys where appropriate
  • Remove old FTP access
  • Remove unnecessary database access
  • Review administrator accounts
  • Review third-party service access

Website governance should include an offboarding process.


Have a Data Breach Response Plan

A data breach can involve:

  • Stolen credentials
  • Hacked databases
  • Exposed files
  • Misconfigured cloud storage
  • Lost devices
  • Malware
  • Phishing
  • Accidental disclosure
  • Unauthorised access

The NGO should have a documented process for responding.

The Data Protection Act and related regulations establish obligations around notifiable personal data breaches. The ODPC’s regulations provide for notification to the Data Commissioner in specified circumstances, and the affected individuals or public may also need to be notified depending on the circumstances.

Do not wait until a breach happens to decide who is responsible.

Your incident response process should identify:

  1. Who receives the alert?
  2. Who assesses the incident?
  3. Who contains the breach?
  4. Who determines notification obligations?
  5. Who communicates with affected individuals?
  6. Who documents the incident?
  7. Who handles technical remediation?

Website Developers Should Not Be the Only People Responsible for Privacy

A web agency can implement:

  • Secure forms
  • Access controls
  • HTTPS
  • Data deletion functions
  • Cookie controls
  • Privacy notices
  • Secure integrations

But the agency cannot determine all of the NGO’s legal or organisational requirements.

The NGO must decide:

  • Why data is collected
  • What data is necessary
  • How long it should be retained
  • Who should have access
  • Which programmes require additional safeguards
  • What donor requirements apply
  • What its privacy policies should say

Privacy is therefore a joint organisational and technical responsibility.


Include Privacy Requirements in Your Website RFP

If an NGO is procuring a new website, data protection should be included in the project requirements.

An RFP can ask prospective agencies to explain:

  • How personal data will be protected
  • Where website data will be stored
  • Which third-party services will be used
  • How administrator access will work
  • How backups will be handled
  • How data will be deleted
  • How forms will be secured
  • How integrations will work
  • How the website will support privacy requirements
  • How security incidents will be handled

This gives the NGO an opportunity to evaluate privacy before selecting a supplier.

It also prevents data protection from becoming an expensive technical change late in the project.

For organisations preparing procurement documents, see our guide on how to write an RFP for website development services.


Include Privacy Responsibilities in the Website Contract

The website development agreement should clearly address relevant data protection responsibilities.

Depending on the project, this can include:

  • Confidentiality
  • Data processing
  • Security
  • Access control
  • Third-party services
  • Data storage
  • Data deletion
  • Breach notification
  • Intellectual property
  • Source code
  • Handover
  • Hosting
  • Maintenance

If an agency will have access to personal data, the relationship should be properly documented.

This is one reason we recommend reviewing a website development contract checklist for Kenyan NGOs before signing.


Create a Website Data Inventory

A simple data inventory can make privacy management much easier.

For example:

Website feature Data collected Purpose Stored where Third party Retention
Contact form Name, email, message Respond to enquiries CMS/email Hosting provider Defined internally
Newsletter Name, email Newsletter Email platform Email provider Until unsubscribe/according to policy
Careers CV, contact details Recruitment Recruitment system Recruitment provider Defined internally
Event registration Name, email, attendance Event management Event platform Event provider Defined internally
Analytics Usage/device data Website analysis Analytics platform Analytics provider Provider configuration

The exact fields and retention periods should reflect the NGO’s actual practices.

This exercise often reveals services that nobody realised were receiving personal data.


Create a Data Flow Map

A data flow map shows where information travels.

For example:

Website

↓

Contact form

↓

Email server

↓

Communications team

Or:

Programme application

↓

Website

↓

Cloud database

↓

Programme team

↓

CRM

↓

Reporting system

This makes it much easier to identify privacy and security risks.


Review Your Website’s Plugins and Integrations

NGO websites often accumulate plugins over time.

A WordPress website, for example, may have plugins for:

  • Forms
  • Analytics
  • Social media
  • Donations
  • Events
  • CRM
  • Email marketing
  • Maps
  • CAPTCHA
  • Security
  • Chat

Each plugin can potentially process or expose data.

During a website redesign, perform an integration audit.

Ask:

Do we still need this?

What data does it process?

Who operates it?

Is it updated?

Is there a safer alternative?

Removing unnecessary integrations can reduce both security and privacy risk.


Privacy Should Be Designed Into the User Experience

Privacy is not only a legal document.

It is also a UX issue.

For example, a form asking for twelve pieces of information may feel intrusive.

A form asking for three relevant pieces of information feels much more proportionate.

Good privacy-aware UX can include:

  • Clear explanations
  • Short forms
  • Relevant fields
  • Plain language
  • Visible privacy information
  • Appropriate consent mechanisms
  • Easy withdrawal where applicable
  • Accessible controls

Privacy and good UX often reinforce each other.


Avoid Dark Patterns

Do not design forms to manipulate people into providing more information than they intended.

Examples of problematic patterns include:

  • Preselecting unnecessary options
  • Hiding important privacy information
  • Making unsubscribe difficult
  • Using confusing language
  • Making “accept” obvious while hiding alternatives
  • Requiring unnecessary personal information

The website should make important privacy choices understandable.


Data Privacy and SEO

Privacy should not come at the expense of discoverability.

A privacy notice should be:

  • Publicly accessible
  • Easy to find
  • Clearly labelled
  • Written in understandable language

It does not need to be hidden from search engines.

Likewise, important programme information should remain public while sensitive beneficiary information is protected.

The principle is:

Make public information easy to discover.

Keep private information appropriately protected.


Do Not Publish Personal Data in Public Content

Before publishing website content, check whether it contains unnecessary personal information.

Potential examples include:

  • Staff personal telephone numbers
  • Personal email addresses
  • Beneficiary names
  • Home addresses
  • Identification numbers
  • Exact GPS coordinates
  • Personal medical information
  • Children’s information
  • Internal contact lists

Ask:

Does the public need this information?

If not, do not publish it.


Staff Information Also Deserves Consideration

An NGO website may publish information about:

  • Executive director
  • Board members
  • Programme managers
  • Country directors
  • Researchers
  • Communications staff

The organisation should consider what information is necessary.

For example, publishing:

Jane Doe, Programme Director

jane@organisation.org

may be appropriate.

Publishing a staff member’s personal mobile number and home address usually serves a very different purpose.

Use organisational contact channels where possible.


Review Old Website Content During a Redesign

A website redesign is an excellent opportunity to conduct a privacy audit.

Look through the old website for:

  • Old beneficiary stories
  • Outdated photographs
  • Personal email addresses
  • Staff phone numbers
  • Old job applications
  • Embedded spreadsheets
  • Publicly accessible files
  • Old forms
  • Forgotten downloads
  • Old project databases
  • Documents containing personal information

A new website should not simply migrate every piece of content from the old website.

Content migration should include privacy review.


Check Publicly Accessible Files

Sometimes sensitive information is not visible through normal website navigation but remains publicly accessible through a direct URL.

Examples include:

  • Old PDFs
  • Excel files
  • CSV files
  • Uploaded application documents
  • Internal reports
  • Backup files
  • Old Word documents

During a website security and privacy audit, review the media library and publicly accessible directories.

Remove or appropriately restrict files that should not be public.


Data Privacy and NGO Donor Requirements

Donor-funded programmes can introduce additional privacy considerations.

A donor may have requirements concerning:

  • Beneficiary data
  • Monitoring information
  • Photography
  • Case studies
  • Research data
  • Reporting
  • Data sharing
  • Data storage
  • International transfers

The donor agreement should therefore be reviewed alongside Kenyan data protection requirements.

One does not automatically replace the other.

For more on donor communications, see our guide to NGO donor branding guidelines.


Data Privacy and International Development Work

International NGOs and Kenyan organisations working with overseas partners can have complex data flows.

For example:

Kenyan NGO

→ international donor

→ cloud platform

→ overseas consultant

→ monitoring system

Personal information can potentially cross multiple jurisdictions.

The NGO should know:

  • What information is being transferred
  • Why it is transferred
  • Where it is going
  • Who receives it
  • What safeguards apply
  • What contractual arrangements exist

The ODPC’s framework specifically addresses transfers of personal data outside Kenya.


Create a Privacy Governance Process

Privacy should have clear ownership inside the organisation.

Depending on the NGO’s size, responsibility may involve:

  • Data Protection Officer
  • IT
  • Communications
  • HR
  • Programme teams
  • Legal
  • Senior management

The important thing is that responsibilities are defined.

For example:

Communications

Owns website content and public privacy information.

IT

Owns technical security.

HR

Owns recruitment data.

Programme team

Owns beneficiary data.

Management

Owns organisational policy and risk decisions.

The exact structure will depend on the NGO.


A Practical Data Privacy Checklist for Kenyan NGO Websites

Before launching or redesigning your website, review the following.

Data collection

  • Every website form has been identified
  • Each field has a defined purpose
  • Unnecessary fields have been removed
  • Sensitive information is not collected unnecessarily
  • Data collection purposes are documented

Privacy information

  • Privacy notice exists
  • Privacy notice reflects actual website practices
  • Data subject rights are explained
  • Privacy contact information is provided
  • Relevant legal basis is addressed
  • Retention practices are explained appropriately

ODPC compliance

  • NGO’s registration obligations have been assessed
  • Relevant data controller/processor roles are understood
  • Processing activities have been documented
  • Appropriate safeguards are in place
  • Relevant organisational policies exist

Third parties

  • Hosting provider identified
  • Analytics tools reviewed
  • Email platform reviewed
  • CRM reviewed
  • Forms reviewed
  • Payment providers reviewed
  • Recruitment systems reviewed
  • International data transfers assessed

Security

  • HTTPS enabled
  • Administrator access controlled
  • Multi-factor authentication considered
  • Software updated
  • Backups configured
  • Access permissions reviewed
  • Security monitoring considered
  • Incident response process established

Beneficiary protection

  • Beneficiary data collection reviewed
  • Children’s data handled appropriately
  • Sensitive information protected
  • Photography reviewed
  • Case studies reviewed
  • Publication risks assessed

Governance

  • Data owners identified
  • Website administrators identified
  • Former staff access removed
  • Retention periods documented
  • Data subject request process established
  • Website content reviewed periodically

What Should an NGO Do Before Launching a New Website?

A useful privacy review can follow this sequence.

Step 1: Inventory the data

Identify everything the website collects.

Step 2: Map the data flows

Determine where the information goes.

Step 3: Identify third parties

List every external platform that receives website information.

Step 4: Review the purposes

Ask why each category of data is being collected.

Step 5: Minimise

Remove unnecessary fields and unnecessary tracking.

Step 6: Review privacy information

Ensure the privacy notice reflects actual processing.

Step 7: Review security

Test forms, accounts, integrations and hosting.

Step 8: Review beneficiary content

Check photographs, stories and programme information.

Step 9: Review international transfers

Identify where data is processed outside Kenya.

Step 10: Document responsibilities

Determine who manages privacy after launch.


Data Privacy Should Be Part of Website Procurement

Privacy should be considered before selecting a web development agency.

When preparing an NGO website RFP or Terms of Reference, include requirements around:

  • Data protection
  • Security
  • Hosting
  • Third-party integrations
  • Forms
  • Analytics
  • Access control
  • Backups
  • Data deletion
  • Handover
  • Maintenance

Ask prospective agencies how they approach privacy and security.

A good agency should be able to explain the technical implementation clearly.

For a broader procurement framework, see our article on what to look for in a web design agency for your NGO.


Final Thoughts

For Kenyan NGOs, website privacy should be treated as an organisational responsibility supported by good technology and good UX.

The most important question is not:

“Do we have a privacy policy?”

It is:

“Do we understand what personal data we collect, why we collect it, where it goes, who can access it and how we protect it?”

That question should be answered before a website is launched.

For NGOs, the stakes can be particularly high because websites may interact with vulnerable populations, beneficiaries, job applicants, donors, volunteers and programme participants.

A privacy-conscious website should therefore:

  • Collect only necessary information
  • Explain why information is collected
  • Provide appropriate privacy information
  • Respect data subject rights
  • Protect sensitive information
  • Carefully manage third-party services
  • Secure website administration
  • Control access
  • Understand international data transfers
  • Have a breach response process
  • Review content before publication
  • Include privacy requirements in procurement and contracts

Data protection is not something to bolt onto an NGO website after development.

It should be considered from the first stage of strategy, UX research and information architecture, through design and development, and then throughout the website’s operational life.

That approach produces a website that is not only safer, but also more trustworthy for the people an NGO exists to serve.


About Zedafrica

Zedafrica is a creative technology company in Nairobi specialising in web design, development, UI/UX design and UX research.

For NGOs and development-sector organisations, we design digital experiences that consider user needs, information architecture, accessibility, security, content governance and the practical requirements of organisations working in complex environments.

Privacy requirements should be considered from the beginning of a website project rather than added after development.

Explore Zedafrica’s website design services

Explore Zedafrica’s UX research services

Schedule a conversation with Zedafrica

Zedafrica