For a Kenyan NGO, a website is more than an online brochure.
It may collect personal information from programme participants, job applicants, donors, volunteers and newsletter subscribers. It may publish reports containing sensitive information about communities and beneficiaries. It may host annual reports, financial information, research publications and programme results. It may also be subject to requirements from donors, partners, regulators and the organisation’s own policies.
That means website compliance should be considered as part of the website planning and governance process, not something added after development is complete.
There is no single law or universal checklist that makes every NGO website “compliant”. Instead, compliance depends on several areas, including Kenyan data protection requirements, the organisation’s regulatory obligations, donor and funder requirements, accessibility standards, cybersecurity practices, content governance and the way the website collects and publishes information.
This guide explains the major areas Kenyan nonprofits should consider when planning, redesigning or managing their websites.
Important: This article provides general information for website planning and should not be treated as legal advice. NGOs should obtain appropriate professional advice where their specific regulatory, contractual or donor obligations require it.
NGO website compliance means ensuring that an organisation’s website, content, technology and related processes meet the legal, contractual, regulatory and organisational requirements that apply to it.
These requirements can come from several sources.
An NGO operating in Kenya may have obligations under laws and regulations relating to areas such as:
The website itself may not be directly regulated by every one of these laws. However, the activities conducted through the website can create obligations.
For example, a website contact form that collects a person’s name, telephone number and email address involves the processing of personal data.
NGOs often operate under grants and contracts that impose additional requirements.
These may concern:
These requirements can differ significantly between funders and individual grant agreements.
An NGO should therefore avoid assuming that one donor’s website requirements automatically apply to every project.
An NGO may also have internal policies governing:
The website should support these policies rather than operate separately from them.
International standards can also influence how an NGO website is designed.
For example, the World Wide Web Consortium’s WCAG 2.2 provides internationally recognised guidance for making web content accessible to people with disabilities. WCAG is structured around four principles: perceivable, operable, understandable and robust.
For many NGOs, data protection is one of the most important website compliance issues.
The Data Protection Act, 2019 establishes the legal framework for regulating the processing of personal data in Kenya and provides rights for data subjects as well as obligations for data controllers and processors.
This is particularly relevant to NGOs because their websites can collect information from a wide range of people.
Examples include:
Start by identifying every place where information enters your organisation through the website.
This could include:
The NGO should understand what information is collected, why it is collected, where it goes, who can access it and how long it is retained.
The ODPC distinguishes between data controllers and data processors.
A data controller determines the purpose and means of processing personal data, while a data processor processes personal data on behalf of a controller.
For example, an NGO may be the data controller for information collected through its website, while a third-party email marketing platform, CRM, cloud provider or other service provider may process information on the NGO’s behalf.
This distinction matters when selecting website technologies and third-party services.
The NGO should know which external systems receive website data.
This is an area where NGOs should pay particular attention.
The ODPC states that public entities and non-profit-making entities such as charities and religious organisations are required to register as data handlers regardless of revenue or turnover.
The ODPC registration process also asks organisations to provide information about personal data processing and the technical, organisational and physical safeguards they have implemented.
Therefore, website compliance should not be treated as simply adding a privacy policy to the footer.
The organisation should consider its broader data protection practices.
An NGO website that collects personal information should clearly explain what happens to that information.
A privacy notice should be appropriate to the organisation’s actual processing activities and should explain relevant matters such as:
The ODPC identifies data subject rights including the right to be informed, access, rectification, erasure, data portability, objection to processing and restriction of processing.
A website privacy notice should therefore be written around the organisation’s actual practices rather than copied from another NGO.
This is particularly important for organisations working with vulnerable populations.
An NGO website may contain stories, photographs, testimonials or case studies involving:
Publishing information about these individuals can create privacy, safeguarding and ethical risks.
Before publishing a photograph, name, testimonial or case study, organisations should consider:
In some cases, anonymisation may be more appropriate than publication.
Donor-funded projects frequently have specific communication and visibility requirements.
These may determine:
However, donor requirements are not identical.
An NGO should check the relevant grant agreement, communications plan, branding guidelines and other contractual documentation before publishing donor-funded project material.
This is particularly important when multiple funders support different programmes.
For a more detailed discussion, see our guide to NGO donor branding guidelines for Kenyan nonprofits.
Your website can play an important role in demonstrating how the organisation creates impact.
For many NGOs, this includes publishing:
This is not simply about satisfying compliance requirements.
A well-organised website can also help potential funders, partners, journalists, researchers and members of the public understand what the organisation actually does.
However, impact reporting should be handled carefully. Numbers and claims should be accurate, current and supported by the organisation’s underlying reporting processes.
See our guide on how to showcase donor-funded impact on your NGO website.
An NGO’s mission is often centred around inclusion, participation and reaching people who may otherwise be underserved.
The website should reflect those principles.
WCAG 2.2 is the current W3C Recommendation for web accessibility. It addresses accessibility across desktop and mobile experiences and includes requirements covering areas such as text alternatives, keyboard access, navigation, forms and understandable content.
For an NGO website, accessibility can include:
Accessibility should be considered during design and development, not simply tested after the website has been completed.
See our detailed guide to website accessibility for Kenyan NGOs.
NGO websites frequently contain large document libraries.
These may include:
Simply uploading a PDF does not necessarily make the document accessible.
Where appropriate, PDFs should have:
For particularly important information, consider publishing HTML web pages alongside downloadable PDFs.
Website security is another important part of NGO website compliance.
The consequences of a compromised NGO website can go beyond temporary downtime.
A compromised website could:
At minimum, NGOs should consider:
Security responsibilities should also be clearly defined between the NGO, hosting provider and web development agency.
A surprisingly common governance problem is allowing too many people to have unrestricted website access.
An NGO may have:
Not everyone needs administrator access.
A better approach is to assign appropriate permissions according to responsibilities.
For example:
Communications team:
Create and edit content.
Programme team:
Submit or review programme content.
IT or technical administrator:
Manage technical settings.
External developer:
Receive temporary technical access when required.
When staff or contractors leave the organisation, their access should be removed.
Website compliance also involves governance and ownership.
An NGO should retain control over:
Do not allow a web agency to be the sole owner of critical digital assets.
The organisation should be able to change agencies, hosting providers or internal administrators without losing access to its website.
This should also be addressed in the website development contract.
A credible NGO website should make it easy to understand the organisation.
Depending on the organisation, this may include:
The exact information that should be published will depend on the organisation and its legal, regulatory and contractual obligations.
The key principle is to make important organisational information easy to find and keep it accurate.
An outdated website can undermine an NGO’s credibility.
Imagine a potential donor visiting a website and finding:
The organisation may technically still have a functioning website, but it does not present a trustworthy digital presence.
Create a content governance process that defines:
Forms deserve particular attention because they are often the point where the website starts collecting personal data.
Before creating a form, ask:
Why are we collecting this information?
Do not collect information simply because the CMS makes it easy to add another field.
For example, if an event registration only requires a person’s name, email and attendance preference, there may be little justification for collecting additional information unrelated to the event.
Consider:
This is particularly important for recruitment forms, beneficiary registration and programme applications.
Modern NGO websites often depend on external platforms.
Examples include:
Each service can introduce additional considerations around personal data, cookies, security and international data transfers.
The website team should maintain a record of important third-party services and understand what information each service receives.
Analytics are useful for understanding how people use an NGO website.
For example, an organisation may want to know:
However, analytics technologies can involve personal data or identifiers.
The NGO should therefore understand what its analytics tools collect and configure them appropriately for its privacy requirements.
A privacy review should cover analytics, advertising technologies, embedded services and other tracking technologies used on the website.
Many NGO websites contain a careers section.
Job applications can involve significant amounts of personal information, including:
The careers section should therefore be treated as a data collection system, not simply a page containing vacancies.
Consider:
NGOs working with children and vulnerable populations should consider safeguarding when publishing website content.
A website can unintentionally expose vulnerable individuals through:
A communications team should have clear internal rules for determining what can be published.
Website developers can implement technical controls, but they cannot determine whether a particular beneficiary story is ethically or legally appropriate to publish.
That decision belongs within the organisation’s safeguarding, communications and data governance processes.
NGOs often publish valuable material on their websites.
This can include:
The organisation should know whether it owns the rights to everything it publishes.
This is particularly important when content comes from:
Do not assume that paying someone to create content automatically gives the NGO every intellectual property right associated with that work.
Contracts should address ownership and permitted use.
Compliance should be addressed before a website development project begins.
If an NGO is commissioning a new website, the procurement documents should clearly communicate relevant requirements.
For example, the project scope can address:
This allows agencies to price and plan for these requirements from the beginning.
It also gives the NGO a clearer basis for evaluating proposals.
A website specification that only says “modern, responsive website” is unlikely to address the organisation’s full compliance requirements.
The final website development agreement should turn important requirements into contractual responsibilities.
The contract can address:
This becomes especially important when an external agency will have access to the organisation’s systems or personal data.
For a detailed discussion, see our website development contract checklist for Kenyan NGOs.
Before launching a new NGO website, consider reviewing the following.
Website compliance should not end when the website goes live.
A website changes constantly.
New employees join. Projects end. New grants begin. Donor requirements change. Forms are added. Third-party services are connected. New reports are uploaded. Analytics tools are changed. Software requires updates.
For that reason, NGOs should periodically review their websites rather than treating compliance as a one-time launch requirement.
A useful annual review can examine:
Compliance should influence the website project from the beginning.
When selecting a web design and development agency, look for a team that understands more than visual design.
The agency should be able to discuss:
For a Kenyan NGO, local context can also be important.
The website should work well for users accessing it through mobile devices and variable internet connections. It should make important information easy to find and should provide a straightforward content management experience for the organisation’s internal team.
NGO website compliance in Kenya is not about adding a privacy policy and putting a few donor logos in the footer.
It is a broader combination of data protection, security, accessibility, donor requirements, content governance, transparency, ownership and organisational policies.
The best time to address these issues is before a website is designed and developed.
By including compliance requirements in the project brief, procurement documents, technical specification, content strategy and website development contract, an NGO can reduce risk and create a website that is easier to manage over the long term.
For organisations planning a new website or major redesign, compliance should therefore be treated as a core project requirement rather than an afterthought.
Zedafrica is a creative technology company in Nairobi specialising in web design, development, UI/UX design and UX research.
We work with organisations that need digital experiences that are not only visually strong, but also practical, accessible, usable and built around the needs of their audiences.
For NGOs and development-sector organisations, this can include website strategy, UX research, information architecture, website design, development, content migration and ongoing digital support.
If your organisation is planning a new NGO website or a major redesign, compliance requirements should be considered from the beginning of the project.
Learn more about Zedafrica’s website design services
