NGO Website Compliance in Kenya: What Nonprofits Need to Know

NGO Website Compliance in Kenya: What Nonprofits Need to Know

For a Kenyan NGO, a website is more than an online brochure.

It may collect personal information from programme participants, job applicants, donors, volunteers and newsletter subscribers. It may publish reports containing sensitive information about communities and beneficiaries. It may host annual reports, financial information, research publications and programme results. It may also be subject to requirements from donors, partners, regulators and the organisation’s own policies.

That means website compliance should be considered as part of the website planning and governance process, not something added after development is complete.

There is no single law or universal checklist that makes every NGO website “compliant”. Instead, compliance depends on several areas, including Kenyan data protection requirements, the organisation’s regulatory obligations, donor and funder requirements, accessibility standards, cybersecurity practices, content governance and the way the website collects and publishes information.

This guide explains the major areas Kenyan nonprofits should consider when planning, redesigning or managing their websites.

Important: This article provides general information for website planning and should not be treated as legal advice. NGOs should obtain appropriate professional advice where their specific regulatory, contractual or donor obligations require it.


What Does NGO Website Compliance Mean?

NGO website compliance means ensuring that an organisation’s website, content, technology and related processes meet the legal, contractual, regulatory and organisational requirements that apply to it.

These requirements can come from several sources.

1. Kenyan laws and regulations

An NGO operating in Kenya may have obligations under laws and regulations relating to areas such as:

  • Data protection
  • Privacy
  • Cybersecurity and information security
  • Intellectual property
  • Employment and recruitment
  • Financial reporting
  • Tax
  • Consumer protection, where applicable
  • Communications and electronic transactions

The website itself may not be directly regulated by every one of these laws. However, the activities conducted through the website can create obligations.

For example, a website contact form that collects a person’s name, telephone number and email address involves the processing of personal data.

2. Donor and funding requirements

NGOs often operate under grants and contracts that impose additional requirements.

These may concern:

  • Donor acknowledgement
  • Branding
  • Programme descriptions
  • Publication of results
  • Communications
  • Visibility
  • Disclaimer language
  • Use of donor logos
  • Photography and consent
  • Safeguarding
  • Intellectual property
  • Reporting

These requirements can differ significantly between funders and individual grant agreements.

An NGO should therefore avoid assuming that one donor’s website requirements automatically apply to every project.

3. Organisational policies

An NGO may also have internal policies governing:

  • Data protection
  • Safeguarding
  • Communications
  • Photography
  • Social media
  • Information security
  • Brand usage
  • Publications
  • Accessibility
  • Records management

The website should support these policies rather than operate separately from them.

4. International standards and best practices

International standards can also influence how an NGO website is designed.

For example, the World Wide Web Consortium’s WCAG 2.2 provides internationally recognised guidance for making web content accessible to people with disabilities. WCAG is structured around four principles: perceivable, operable, understandable and robust.


1. Data Protection Should Be a Priority

For many NGOs, data protection is one of the most important website compliance issues.

The Data Protection Act, 2019 establishes the legal framework for regulating the processing of personal data in Kenya and provides rights for data subjects as well as obligations for data controllers and processors.

This is particularly relevant to NGOs because their websites can collect information from a wide range of people.

Examples include:

  • Programme participants
  • Beneficiaries
  • Volunteers
  • Employees
  • Job applicants
  • Donors
  • Newsletter subscribers
  • Event participants
  • Researchers
  • Partners
  • Suppliers
  • People submitting enquiries

What personal data does your website collect?

Start by identifying every place where information enters your organisation through the website.

This could include:

  • Contact forms
  • Newsletter subscription forms
  • Job application forms
  • Volunteer applications
  • Event registration
  • Donation forms
  • Feedback forms
  • Survey tools
  • Membership applications
  • Programme registration
  • Download forms
  • Cookies and analytics
  • Embedded third-party services

The NGO should understand what information is collected, why it is collected, where it goes, who can access it and how long it is retained.


Data Controller vs Data Processor

The ODPC distinguishes between data controllers and data processors.

A data controller determines the purpose and means of processing personal data, while a data processor processes personal data on behalf of a controller.

For example, an NGO may be the data controller for information collected through its website, while a third-party email marketing platform, CRM, cloud provider or other service provider may process information on the NGO’s behalf.

This distinction matters when selecting website technologies and third-party services.

The NGO should know which external systems receive website data.


Do NGOs Need to Register With the ODPC?

This is an area where NGOs should pay particular attention.

The ODPC states that public entities and non-profit-making entities such as charities and religious organisations are required to register as data handlers regardless of revenue or turnover.

The ODPC registration process also asks organisations to provide information about personal data processing and the technical, organisational and physical safeguards they have implemented.

Therefore, website compliance should not be treated as simply adding a privacy policy to the footer.

The organisation should consider its broader data protection practices.


2. Have a Clear Privacy Notice

An NGO website that collects personal information should clearly explain what happens to that information.

A privacy notice should be appropriate to the organisation’s actual processing activities and should explain relevant matters such as:

  • What information is collected
  • Why it is collected
  • How it is used
  • Who it may be shared with
  • How long it is retained
  • Relevant data subject rights
  • How people can contact the organisation
  • How privacy-related complaints or requests can be made

The ODPC identifies data subject rights including the right to be informed, access, rectification, erasure, data portability, objection to processing and restriction of processing.

A website privacy notice should therefore be written around the organisation’s actual practices rather than copied from another NGO.


3. Be Careful With Beneficiary Information

This is particularly important for organisations working with vulnerable populations.

An NGO website may contain stories, photographs, testimonials or case studies involving:

  • Children
  • Refugees
  • Survivors of violence
  • People living with disabilities
  • Patients
  • Low-income communities
  • Victims of disasters
  • Human rights beneficiaries
  • People experiencing discrimination or persecution

Publishing information about these individuals can create privacy, safeguarding and ethical risks.

Before publishing a photograph, name, testimonial or case study, organisations should consider:

  • Was appropriate consent obtained?
  • Does the person understand how the information will be used?
  • Could publication put the person at risk?
  • Does the information reveal sensitive circumstances?
  • Is identifying the person actually necessary?
  • Is the information still appropriate to publish?
  • Does the organisation have a policy governing this type of content?

In some cases, anonymisation may be more appropriate than publication.


4. Donor Branding and Visibility Requirements

Donor-funded projects frequently have specific communication and visibility requirements.

These may determine:

  • How donor logos are displayed
  • Where acknowledgement appears
  • Which language is used
  • How project information is presented
  • How donor funding is described
  • Whether disclaimers are required
  • How photographs and project materials are used

However, donor requirements are not identical.

An NGO should check the relevant grant agreement, communications plan, branding guidelines and other contractual documentation before publishing donor-funded project material.

This is particularly important when multiple funders support different programmes.

Related guide

For a more detailed discussion, see our guide to NGO donor branding guidelines for Kenyan nonprofits.


5. Make Donor-Funded Work Transparent

Your website can play an important role in demonstrating how the organisation creates impact.

For many NGOs, this includes publishing:

  • Programme information
  • Project locations
  • Beneficiary numbers
  • Results
  • Research
  • Annual reports
  • Publications
  • Case studies
  • Success stories
  • Monitoring and evaluation findings
  • Programme updates
  • Financial information where appropriate
  • Donor acknowledgements

This is not simply about satisfying compliance requirements.

A well-organised website can also help potential funders, partners, journalists, researchers and members of the public understand what the organisation actually does.

However, impact reporting should be handled carefully. Numbers and claims should be accurate, current and supported by the organisation’s underlying reporting processes.

Related guide

See our guide on how to showcase donor-funded impact on your NGO website.


6. Website Accessibility Matters

An NGO’s mission is often centred around inclusion, participation and reaching people who may otherwise be underserved.

The website should reflect those principles.

WCAG 2.2 is the current W3C Recommendation for web accessibility. It addresses accessibility across desktop and mobile experiences and includes requirements covering areas such as text alternatives, keyboard access, navigation, forms and understandable content.

For an NGO website, accessibility can include:

  • Good colour contrast
  • Keyboard navigation
  • Proper heading structure
  • Alternative text for meaningful images
  • Captions for video
  • Accessible forms
  • Clearly labelled buttons
  • Descriptive links
  • Readable typography
  • Visible focus states
  • Logical navigation
  • Accessible PDFs and documents
  • Compatibility with assistive technologies

Accessibility should be considered during design and development, not simply tested after the website has been completed.

Related guide

See our detailed guide to website accessibility for Kenyan NGOs.


7. Make Important Documents Accessible

NGO websites frequently contain large document libraries.

These may include:

  • Annual reports
  • Research papers
  • Policy documents
  • Programme reports
  • Training materials
  • Toolkits
  • Strategic plans
  • Financial reports
  • Publications
  • Evaluation reports

Simply uploading a PDF does not necessarily make the document accessible.

Where appropriate, PDFs should have:

  • Proper document structure
  • Searchable text
  • Correct heading hierarchy
  • Meaningful document titles
  • Appropriate reading order
  • Alternative text for relevant images
  • Sufficient colour contrast
  • Accessible links
  • Properly tagged tables

For particularly important information, consider publishing HTML web pages alongside downloadable PDFs.


8. Secure the Website and Its Administration

Website security is another important part of NGO website compliance.

The consequences of a compromised NGO website can go beyond temporary downtime.

A compromised website could:

  • Expose personal information
  • Deface the organisation’s website
  • Redirect visitors to malicious websites
  • Compromise administrator accounts
  • Distribute malware
  • Alter programme information
  • Damage the organisation’s reputation

At minimum, NGOs should consider:

  • HTTPS
  • Strong administrator passwords
  • Multi-factor authentication where available
  • Role-based access
  • Regular software updates
  • Secure hosting
  • Backups
  • Malware monitoring
  • Firewall protections
  • Secure forms
  • Limited administrator privileges
  • Removal of unused accounts
  • A process for handling security incidents

Security responsibilities should also be clearly defined between the NGO, hosting provider and web development agency.


9. Control Who Has Access to the Website

A surprisingly common governance problem is allowing too many people to have unrestricted website access.

An NGO may have:

  • Communications staff
  • Programme staff
  • IT staff
  • External agencies
  • Consultants
  • Donor-funded project teams
  • Former employees
  • Volunteers

Not everyone needs administrator access.

A better approach is to assign appropriate permissions according to responsibilities.

For example:

Communications team:
Create and edit content.

Programme team:
Submit or review programme content.

IT or technical administrator:
Manage technical settings.

External developer:
Receive temporary technical access when required.

When staff or contractors leave the organisation, their access should be removed.


10. Keep Website Ownership Under the Organisation

Website compliance also involves governance and ownership.

An NGO should retain control over:

  • Domain name
  • Hosting account
  • Website CMS
  • Source code
  • Google Analytics or equivalent analytics account
  • Search Console
  • Email accounts
  • DNS
  • Cloud services
  • Social media accounts
  • Third-party integrations
  • Website backups

Do not allow a web agency to be the sole owner of critical digital assets.

The organisation should be able to change agencies, hosting providers or internal administrators without losing access to its website.

This should also be addressed in the website development contract.


11. Be Transparent About Who the Organisation Is

A credible NGO website should make it easy to understand the organisation.

Depending on the organisation, this may include:

  • Organisation name
  • Mission and vision
  • Areas of operation
  • Programmes
  • Leadership
  • Board or governance information
  • Contact information
  • Physical or postal address where appropriate
  • Registration information where appropriate
  • Partner information
  • Donor information
  • Reports and publications

The exact information that should be published will depend on the organisation and its legal, regulatory and contractual obligations.

The key principle is to make important organisational information easy to find and keep it accurate.


12. Keep Reports and Information Up to Date

An outdated website can undermine an NGO’s credibility.

Imagine a potential donor visiting a website and finding:

  • A country director who left two years ago
  • Projects listed as “current” that ended several years ago
  • An expired strategic plan
  • Old contact information
  • Broken publication links
  • Events from previous years on the homepage
  • Outdated programme statistics

The organisation may technically still have a functioning website, but it does not present a trustworthy digital presence.

Create a content governance process that defines:

  • Who owns each section
  • Who approves content
  • How frequently content is reviewed
  • Who updates leadership information
  • Who updates programme pages
  • Who manages reports
  • Who checks links
  • Who removes outdated information

13. Be Careful With Website Forms

Forms deserve particular attention because they are often the point where the website starts collecting personal data.

Before creating a form, ask:

Why are we collecting this information?

Do not collect information simply because the CMS makes it easy to add another field.

For example, if an event registration only requires a person’s name, email and attendance preference, there may be little justification for collecting additional information unrelated to the event.

Consider:

  • What fields are necessary?
  • What is the purpose of each field?
  • Who receives the information?
  • Where is it stored?
  • How long is it retained?
  • Is consent required?
  • What happens after submission?
  • Is the information sent to a third-party platform?

This is particularly important for recruitment forms, beneficiary registration and programme applications.


14. Review Third-Party Services

Modern NGO websites often depend on external platforms.

Examples include:

  • Google Analytics
  • Google Maps
  • Mailchimp
  • HubSpot
  • Salesforce
  • Microsoft services
  • Payment gateways
  • Event registration platforms
  • Video platforms
  • Social media embeds
  • Cloud storage
  • CRM systems

Each service can introduce additional considerations around personal data, cookies, security and international data transfers.

The website team should maintain a record of important third-party services and understand what information each service receives.


15. Consider Cookies and Analytics

Analytics are useful for understanding how people use an NGO website.

For example, an organisation may want to know:

  • Which programmes receive the most interest?
  • Which publications are downloaded?
  • Which countries visitors come from?
  • Which campaigns generate traffic?
  • Which pages have high exit rates?

However, analytics technologies can involve personal data or identifiers.

The NGO should therefore understand what its analytics tools collect and configure them appropriately for its privacy requirements.

A privacy review should cover analytics, advertising technologies, embedded services and other tracking technologies used on the website.


16. Make Recruitment Information Professional and Current

Many NGO websites contain a careers section.

Job applications can involve significant amounts of personal information, including:

  • Names
  • Contact information
  • CVs
  • Employment history
  • Education
  • References
  • Professional qualifications
  • Other information supplied by applicants

The careers section should therefore be treated as a data collection system, not simply a page containing vacancies.

Consider:

  • Where applications are stored
  • Who can access them
  • How long they are retained
  • Whether third-party recruitment systems are involved
  • What privacy information applicants receive
  • How old vacancies are removed

17. Include Safeguarding Considerations

NGOs working with children and vulnerable populations should consider safeguarding when publishing website content.

A website can unintentionally expose vulnerable individuals through:

  • Names
  • Photographs
  • Locations
  • Personal stories
  • Geographical information
  • Programme details
  • Testimonials
  • Videos
  • Social media integrations

A communications team should have clear internal rules for determining what can be published.

Website developers can implement technical controls, but they cannot determine whether a particular beneficiary story is ethically or legally appropriate to publish.

That decision belongs within the organisation’s safeguarding, communications and data governance processes.


18. Consider Intellectual Property

NGOs often publish valuable material on their websites.

This can include:

  • Research
  • Photographs
  • Videos
  • Training materials
  • Reports
  • Illustrations
  • Infographics
  • Software
  • Datasets

The organisation should know whether it owns the rights to everything it publishes.

This is particularly important when content comes from:

  • Consultants
  • Photographers
  • Researchers
  • Development partners
  • Freelancers
  • Donors
  • External agencies

Do not assume that paying someone to create content automatically gives the NGO every intellectual property right associated with that work.

Contracts should address ownership and permitted use.


19. Think About Website Compliance During Procurement

Compliance should be addressed before a website development project begins.

If an NGO is commissioning a new website, the procurement documents should clearly communicate relevant requirements.

For example, the project scope can address:

  • Data protection
  • Security
  • Accessibility
  • Content governance
  • Donor requirements
  • Analytics
  • Hosting
  • Backups
  • Ownership
  • Source code
  • Documentation
  • Training
  • Maintenance
  • Post-launch support

This allows agencies to price and plan for these requirements from the beginning.

It also gives the NGO a clearer basis for evaluating proposals.

A website specification that only says “modern, responsive website” is unlikely to address the organisation’s full compliance requirements.


20. Include Compliance in the Website Contract

The final website development agreement should turn important requirements into contractual responsibilities.

The contract can address:

  • Scope of work
  • Data protection responsibilities
  • Confidentiality
  • Security requirements
  • Intellectual property
  • Source code ownership
  • Domain ownership
  • Hosting
  • Third-party services
  • Accessibility
  • Content migration
  • Testing
  • Acceptance
  • Maintenance
  • Support
  • Data breaches
  • Termination
  • Handover

This becomes especially important when an external agency will have access to the organisation’s systems or personal data.

For a detailed discussion, see our website development contract checklist for Kenyan NGOs.


21. Create a Website Compliance Checklist

Before launching a new NGO website, consider reviewing the following.

Data protection

  • Personal data collection has been documented
  • Website forms have been reviewed
  • Privacy notice is available
  • Data processing responsibilities are understood
  • Third-party services have been reviewed
  • Data retention practices are defined
  • Appropriate ODPC requirements have been assessed
  • Security safeguards are in place

Content

  • Organisation information is accurate
  • Leadership information is current
  • Programme information is current
  • Reports and publications are correctly labelled
  • Donor acknowledgements are accurate
  • Donor branding requirements have been checked
  • Beneficiary stories have been appropriately reviewed
  • Photography and testimonials have been cleared for publication

Accessibility

  • Images have appropriate alternative text
  • Forms are accessible
  • Navigation works using a keyboard
  • Colour contrast has been tested
  • Headings are structured correctly
  • Links are descriptive
  • Videos have appropriate captions where required
  • Important documents have been reviewed for accessibility

Security

  • HTTPS is enabled
  • Administrator accounts are secured
  • Unnecessary users have been removed
  • Backups are configured
  • Software is kept updated
  • Hosting security has been reviewed
  • Access permissions are appropriate

Governance

  • NGO owns the domain
  • NGO controls hosting
  • NGO owns or controls analytics accounts
  • Source code ownership is documented
  • Website credentials are securely managed
  • Website content owners are assigned
  • Content review responsibilities are defined
  • Agency handover procedures are documented

NGO Website Compliance Is an Ongoing Process

Website compliance should not end when the website goes live.

A website changes constantly.

New employees join. Projects end. New grants begin. Donor requirements change. Forms are added. Third-party services are connected. New reports are uploaded. Analytics tools are changed. Software requires updates.

For that reason, NGOs should periodically review their websites rather than treating compliance as a one-time launch requirement.

A useful annual review can examine:

  1. Data collection
  2. Privacy information
  3. ODPC obligations
  4. Donor requirements
  5. Beneficiary content
  6. Website accessibility
  7. Security
  8. User permissions
  9. Third-party services
  10. Domain and hosting ownership
  11. Website content
  12. Documents and reports
  13. Analytics
  14. Backup and recovery
  15. Website development and maintenance contracts

What Should a Kenyan NGO Look for When Building a Compliant Website?

Compliance should influence the website project from the beginning.

When selecting a web design and development agency, look for a team that understands more than visual design.

The agency should be able to discuss:

  • Information architecture
  • UX research
  • Content strategy
  • Accessibility
  • Performance
  • Security
  • CMS governance
  • Data protection
  • SEO
  • Analytics
  • Hosting
  • Maintenance
  • Content migration
  • Third-party integrations

For a Kenyan NGO, local context can also be important.

The website should work well for users accessing it through mobile devices and variable internet connections. It should make important information easy to find and should provide a straightforward content management experience for the organisation’s internal team.


Final Thoughts

NGO website compliance in Kenya is not about adding a privacy policy and putting a few donor logos in the footer.

It is a broader combination of data protection, security, accessibility, donor requirements, content governance, transparency, ownership and organisational policies.

The best time to address these issues is before a website is designed and developed.

By including compliance requirements in the project brief, procurement documents, technical specification, content strategy and website development contract, an NGO can reduce risk and create a website that is easier to manage over the long term.

For organisations planning a new website or major redesign, compliance should therefore be treated as a core project requirement rather than an afterthought.

Related NGO Website Compliance Guides

  • NGO Donor Branding Guidelines: How to handle donor visibility and branding requirements.
  • Donor-Funded Impact Reporting: How to communicate programme results and impact online.
  • Data Privacy for Kenyan NGO Websites: How Kenyan nonprofits should approach personal data and privacy.
  • Website Accessibility for Kenyan NGOs: Practical accessibility standards and best practices.

About Zedafrica

Zedafrica is a creative technology company in Nairobi specialising in web design, development, UI/UX design and UX research.

We work with organisations that need digital experiences that are not only visually strong, but also practical, accessible, usable and built around the needs of their audiences.

For NGOs and development-sector organisations, this can include website strategy, UX research, information architecture, website design, development, content migration and ongoing digital support.

If your organisation is planning a new NGO website or a major redesign, compliance requirements should be considered from the beginning of the project.

Learn more about Zedafrica’s website design services

Explore Zedafrica’s UX research services

Schedule a conversation with Zedafrica

Zedafrica