An NGO website can collect much more personal information than an organisation may realise.
A contact form might collect a person’s name, email address and telephone number. A careers page might receive CVs and employment histories. A programme application might collect information about beneficiaries. A newsletter form might collect contact details. An event registration system might collect attendance information.
Some NGOs also work with particularly sensitive information involving children, health, disability, refugees, survivors of violence or other vulnerable groups.
That makes data privacy an important consideration when designing, developing and managing an NGO website in Kenya.
Kenya’s Data Protection Act, 2019 establishes the country’s legal framework for the protection of personal data, with the Office of the Data Protection Commissioner (ODPC) responsible for regulating the processing of personal data and protecting data subjects’ rights.
For NGOs, website privacy is therefore not simply a matter of putting a “Privacy Policy” link in the footer.
It involves understanding:
This guide explains the major data privacy issues Kenyan NGOs should consider when building or managing a website.
Important: This article is general information about website privacy and data protection. It is not legal advice. NGOs should obtain professional advice about their specific obligations, processing activities, contracts and regulatory circumstances.
Data privacy concerns how an organisation collects, uses, stores, shares and protects information relating to identifiable individuals.
For an NGO website, this can include information submitted directly by users as well as information collected through website technologies.
Examples include:
The website may also interact with other systems that process personal data.
For example:
Website → CRM → Email platform
or:
Website → Application form → Cloud storage
or:
Website → Donation platform → Payment processor
Understanding the entire data flow is more important than looking at the website in isolation.
The primary legislation is the Data Protection Act, 2019.
The Act establishes principles governing the processing of personal data and provides rights to individuals whose personal data is being processed.
The ODPC is responsible for implementing and enforcing the framework, including regulating data controllers and processors and protecting individuals’ privacy rights.
The ODPC also provides registration and compliance mechanisms for organisations processing personal data.
For an NGO, the important point is that data protection should be considered an organisational responsibility, not simply a technical website feature.
Potentially, yes.
The ODPC defines a data controller as an entity that determines the purposes and means of processing personal data.
The ODPC specifically identifies charities among examples of organisations that can act as data controllers.
For example, suppose an NGO operates a website containing a volunteer registration form.
The NGO decides:
The NGO may therefore be acting as the data controller.
A data processor processes personal data on behalf of a data controller.
The ODPC gives examples including cloud computing providers and CRM or ERP providers that have access to personal data.
For an NGO website, processors could potentially include:
The distinction matters because the NGO needs to understand what its external service providers are doing with personal information.
This is an important question for nonprofits.
The ODPC states that public entities and non-profit-making entities such as charities and religious organisations are required to register, regardless of revenue or turnover.
The ODPC’s registration portal also specifically provides a category for Not for Profit Entities & Religious Institutions.
The registration process requires organisations to provide information about their processing activities, including categories of personal data, purposes of processing, data subjects, transfers and safeguards.
This means an NGO should not assume that being a nonprofit automatically means its data protection responsibilities are minimal.
Website data collection should be considered alongside the organisation’s broader data processing activities.
A common mistake is to think:
“We have a privacy policy, so our website is compliant.”
A privacy policy is important, but it is only one component.
An NGO should also consider:
The website is one part of the organisation’s wider data processing environment.
Start with a data inventory.
List every website feature that collects or generates information about individuals.
Usually collect:
Usually collect:
May collect:
May collect:
May collect substantially more information, potentially including sensitive personal data.
May involve:
The payment provider may process payment card information rather than the NGO’s own website.
May involve:
The exact data collected depends on the analytics configuration and provider.
One of the most useful privacy principles for website design is data minimisation.
The ODPC’s published principles include collecting data that is adequate, relevant and limited to what is necessary for the purpose for which it is processed.
Suppose an NGO has a simple contact form.
It may need:
Name
Message
Does it really need:
If those fields are not necessary for the purpose of the form, collecting them creates additional privacy responsibilities without an obvious benefit.
People should be able to understand what happens to information they submit.
For example, beside a newsletter form, an NGO could explain that the email address will be used to send the organisation’s newsletter.
For a job application, applicants should receive appropriate information about how their personal data will be handled.
The ODPC describes the right to be informed as a key data subject right. It includes informing people about how their personal data will be used.
The organisation’s privacy information should therefore be understandable and accessible.
A privacy notice should reflect what your organisation actually does.
Depending on the NGO’s activities, it may explain:
The ODPC has indicated that privacy notices should explain relevant processing practices and provide a mechanism for people to exercise their rights.
Do not simply copy a generic privacy policy from another NGO.
Your privacy notice should describe your actual processing activities.
Kenya’s data protection framework gives individuals several rights regarding their personal data.
The ODPC identifies rights including:
This means an NGO should have a process for dealing with data subject requests.
For example, if someone contacts the NGO asking what personal information it holds about them, there should be an internal process for handling that request.
This is an organisational process, not something that can be solved entirely through website development.
Your website should make it reasonably clear how someone can contact the organisation about privacy.
For example, the privacy notice can provide a dedicated privacy contact address.
The organisation should then establish internally:
The exact procedure should be based on the organisation’s legal and operational requirements.
This is one of the most important considerations for NGOs.
A commercial website might collect customer contact information.
An NGO could collect information about people in highly vulnerable circumstances.
Examples include organisations working with:
The potential consequences of exposing this information can be serious.
A website should therefore collect and publish only information that is genuinely necessary and appropriate.
The ODPC’s registration system specifically asks organisations to identify whether they process sensitive categories such as health status, biometric data, GPS location data and other sensitive information.
An NGO website could encounter sensitive information through:
For example, a programme application form should not be treated like a normal “Contact Us” form if it collects health or other sensitive information.
The organisation should assess the legal basis, necessity, security and handling of that information before collecting it.
NGOs working with children need to take particular care with personal data and online content.
A website may involve:
Before publishing information about children, consider:
The safest approach is not necessarily to publish as much information as possible.
Sometimes an anonymised story is more appropriate.
NGOs often use photography extensively.
A photograph can constitute personal data where an individual is identifiable.
This means photography should be considered within the organisation’s broader privacy and communications processes.
For website photographs, consider:
Do not treat photography as completely separate from data protection simply because it is visual content.
A powerful case study does not need to reveal someone’s full identity.
For example, instead of publishing:
Jane Wanjiku, 34, from [specific village], living with [specific medical condition]…
the organisation may be able to tell the same story using less identifying information.
For example:
A smallholder farmer in western Kenya participated in the programme and subsequently adopted new agricultural practices.
The appropriate level of detail depends on the programme, consent, risk and purpose.
A basic contact form may look harmless.
But it still involves personal data.
At minimum, consider:
If form submissions are emailed to five staff members and automatically stored in a CMS indefinitely, the organisation should know that this is happening.
An NGO’s careers section may collect significant personal information.
A CV can contain:
If a website stores CVs indefinitely, the organisation should consider whether this is necessary and how long the information should be retained.
A better recruitment process may use a dedicated applicant tracking system rather than storing hundreds of CVs permanently inside the website.
A website CMS is designed primarily for managing content.
It should not automatically become the organisation’s database for sensitive beneficiary information.
For example, if a programme needs to collect detailed beneficiary information, consider whether a dedicated and appropriately secured system is more suitable.
The website can provide the entry point while the sensitive information is handled by a system designed for that purpose.
Your NGO may be based in Nairobi while its website and services operate across several countries.
For example:
Website hosting: Kenya
Email platform: United States
CRM: Europe
Analytics: United States
Cloud storage: Another jurisdiction
This matters because data may be transferred outside Kenya.
The ODPC identifies restrictions and safeguards around transfers of personal data outside Kenya, including requirements relating to adequate safeguards or consent in relevant circumstances.
The ODPC registration process itself asks organisations whether data resides outside Kenya and, if so, which countries are involved.
Therefore, your NGO should know where its website-related personal data is actually processed.
Modern websites frequently rely on external services.
Examples include:
The NGO should understand:
What data does this service receive?
Why does it receive it?
Where does it process the data?
How is the data protected?
What agreement governs the relationship?
Can the data be deleted or exported?
These questions should be answered before connecting a third-party service to the website.
Analytics can be extremely useful.
An NGO may want to know:
But analytics can involve information about users and devices.
The organisation should therefore understand its analytics configuration and ensure that its use of analytics is consistent with its privacy obligations.
Do not assume that installing Google Analytics or another analytics tool is automatically a privacy-neutral activity.
Websites may use cookies and similar technologies for:
Your NGO should understand which cookies and tracking technologies are actually being used.
A website redesign is a good opportunity to audit them.
Ask:
Avoid installing dozens of tracking scripts simply because they are available.
A newsletter subscription is a straightforward example of personal data processing.
The NGO should consider:
The unsubscribe process should be straightforward.
If someone unsubscribes, the organisation should have a process for ensuring that they are no longer sent marketing or newsletter communications where applicable.
NGOs accepting online donations should carefully distinguish between the information the NGO receives and the information handled by the payment provider.
Ideally, sensitive payment credentials should be handled by a properly configured payment service rather than unnecessarily passing them through the NGO’s own website.
The NGO should understand:
Do not collect payment information directly through a custom website form unless there is a clear technical and compliance basis for doing so.
A common problem is leaving old job applications on a website indefinitely.
Suppose an NGO receives 2,000 applications over several years.
If all CVs remain permanently accessible in a website database, the organisation has accumulated a significant amount of personal data.
A documented retention policy should define how long different categories of information are retained and when they are securely deleted or anonymised, subject to applicable legal and organisational requirements.
Privacy and security are closely connected.
If personal information is collected securely but stored in a poorly protected system, privacy can still be compromised.
Website security measures can include:
The ODPC’s registration process asks organisations to describe technical, organisational and physical safeguards used to protect personal data. Examples include encryption, firewalls, access controls, multi-factor authentication, backups and security patch management.
Not everyone who works for an NGO needs access to all website data.
For example:
Communications officer
May need to publish articles.
Programme officer
May need to submit project content.
HR staff
May need access to recruitment information.
IT administrator
May need technical access.
External developer
May need temporary technical access.
These roles should not automatically have identical permissions.
Use role-based access wherever possible.
An often-overlooked privacy risk is old user accounts.
When an employee leaves, or a web agency finishes a project:
Website governance should include an offboarding process.
A data breach can involve:
The NGO should have a documented process for responding.
The Data Protection Act and related regulations establish obligations around notifiable personal data breaches. The ODPC’s regulations provide for notification to the Data Commissioner in specified circumstances, and the affected individuals or public may also need to be notified depending on the circumstances.
Do not wait until a breach happens to decide who is responsible.
Your incident response process should identify:
A web agency can implement:
But the agency cannot determine all of the NGO’s legal or organisational requirements.
The NGO must decide:
Privacy is therefore a joint organisational and technical responsibility.
If an NGO is procuring a new website, data protection should be included in the project requirements.
An RFP can ask prospective agencies to explain:
This gives the NGO an opportunity to evaluate privacy before selecting a supplier.
It also prevents data protection from becoming an expensive technical change late in the project.
For organisations preparing procurement documents, see our guide on how to write an RFP for website development services.
The website development agreement should clearly address relevant data protection responsibilities.
Depending on the project, this can include:
If an agency will have access to personal data, the relationship should be properly documented.
This is one reason we recommend reviewing a website development contract checklist for Kenyan NGOs before signing.
A simple data inventory can make privacy management much easier.
For example:
| Website feature | Data collected | Purpose | Stored where | Third party | Retention |
|---|---|---|---|---|---|
| Contact form | Name, email, message | Respond to enquiries | CMS/email | Hosting provider | Defined internally |
| Newsletter | Name, email | Newsletter | Email platform | Email provider | Until unsubscribe/according to policy |
| Careers | CV, contact details | Recruitment | Recruitment system | Recruitment provider | Defined internally |
| Event registration | Name, email, attendance | Event management | Event platform | Event provider | Defined internally |
| Analytics | Usage/device data | Website analysis | Analytics platform | Analytics provider | Provider configuration |
The exact fields and retention periods should reflect the NGO’s actual practices.
This exercise often reveals services that nobody realised were receiving personal data.
A data flow map shows where information travels.
For example:
Website
↓
Contact form
↓
Email server
↓
Communications team
Or:
Programme application
↓
Website
↓
Cloud database
↓
Programme team
↓
CRM
↓
Reporting system
This makes it much easier to identify privacy and security risks.
NGO websites often accumulate plugins over time.
A WordPress website, for example, may have plugins for:
Each plugin can potentially process or expose data.
During a website redesign, perform an integration audit.
Ask:
Do we still need this?
What data does it process?
Who operates it?
Is it updated?
Is there a safer alternative?
Removing unnecessary integrations can reduce both security and privacy risk.
Privacy is not only a legal document.
It is also a UX issue.
For example, a form asking for twelve pieces of information may feel intrusive.
A form asking for three relevant pieces of information feels much more proportionate.
Good privacy-aware UX can include:
Privacy and good UX often reinforce each other.
Do not design forms to manipulate people into providing more information than they intended.
Examples of problematic patterns include:
The website should make important privacy choices understandable.
Privacy should not come at the expense of discoverability.
A privacy notice should be:
It does not need to be hidden from search engines.
Likewise, important programme information should remain public while sensitive beneficiary information is protected.
The principle is:
Make public information easy to discover.
Keep private information appropriately protected.
Before publishing website content, check whether it contains unnecessary personal information.
Potential examples include:
Ask:
Does the public need this information?
If not, do not publish it.
An NGO website may publish information about:
The organisation should consider what information is necessary.
For example, publishing:
Jane Doe, Programme Director
may be appropriate.
Publishing a staff member’s personal mobile number and home address usually serves a very different purpose.
Use organisational contact channels where possible.
A website redesign is an excellent opportunity to conduct a privacy audit.
Look through the old website for:
A new website should not simply migrate every piece of content from the old website.
Content migration should include privacy review.
Sometimes sensitive information is not visible through normal website navigation but remains publicly accessible through a direct URL.
Examples include:
During a website security and privacy audit, review the media library and publicly accessible directories.
Remove or appropriately restrict files that should not be public.
Donor-funded programmes can introduce additional privacy considerations.
A donor may have requirements concerning:
The donor agreement should therefore be reviewed alongside Kenyan data protection requirements.
One does not automatically replace the other.
For more on donor communications, see our guide to NGO donor branding guidelines.
International NGOs and Kenyan organisations working with overseas partners can have complex data flows.
For example:
Kenyan NGO
→ international donor
→ cloud platform
→ overseas consultant
→ monitoring system
Personal information can potentially cross multiple jurisdictions.
The NGO should know:
The ODPC’s framework specifically addresses transfers of personal data outside Kenya.
Privacy should have clear ownership inside the organisation.
Depending on the NGO’s size, responsibility may involve:
The important thing is that responsibilities are defined.
For example:
Communications
Owns website content and public privacy information.
IT
Owns technical security.
HR
Owns recruitment data.
Programme team
Owns beneficiary data.
Management
Owns organisational policy and risk decisions.
The exact structure will depend on the NGO.
Before launching or redesigning your website, review the following.
A useful privacy review can follow this sequence.
Identify everything the website collects.
Determine where the information goes.
List every external platform that receives website information.
Ask why each category of data is being collected.
Remove unnecessary fields and unnecessary tracking.
Ensure the privacy notice reflects actual processing.
Test forms, accounts, integrations and hosting.
Check photographs, stories and programme information.
Identify where data is processed outside Kenya.
Determine who manages privacy after launch.
Privacy should be considered before selecting a web development agency.
When preparing an NGO website RFP or Terms of Reference, include requirements around:
Ask prospective agencies how they approach privacy and security.
A good agency should be able to explain the technical implementation clearly.
For a broader procurement framework, see our article on what to look for in a web design agency for your NGO.
For Kenyan NGOs, website privacy should be treated as an organisational responsibility supported by good technology and good UX.
The most important question is not:
“Do we have a privacy policy?”
It is:
“Do we understand what personal data we collect, why we collect it, where it goes, who can access it and how we protect it?”
That question should be answered before a website is launched.
For NGOs, the stakes can be particularly high because websites may interact with vulnerable populations, beneficiaries, job applicants, donors, volunteers and programme participants.
A privacy-conscious website should therefore:
Data protection is not something to bolt onto an NGO website after development.
It should be considered from the first stage of strategy, UX research and information architecture, through design and development, and then throughout the website’s operational life.
That approach produces a website that is not only safer, but also more trustworthy for the people an NGO exists to serve.
Zedafrica is a creative technology company in Nairobi specialising in web design, development, UI/UX design and UX research.
For NGOs and development-sector organisations, we design digital experiences that consider user needs, information architecture, accessibility, security, content governance and the practical requirements of organisations working in complex environments.
Privacy requirements should be considered from the beginning of a website project rather than added after development.
Explore Zedafrica’s website design services
