Understanding and closing your data protection gaps
Kenyan organisations handle more personal data digitally every year — customer records, employee data, transaction histories. Data protection advisory identifies how that data is actually handled today, and where the gaps are against good practice.
Practical, not just legal
This is technical and organisational advisory — not legal interpretation of your specific obligations, which needs a qualified lawyer.
Data Handling Review
Understanding what personal data you collect, where it's stored, and who can access it.
Learn more → IData Protection Impact Assessment
A structured DPIA for a specific data processing activity.
Learn more → GReadiness Advisory
Closing gaps between current practice and good-practice data protection standards.
Learn more →Data protection questions
No — RETIS provides technical and organisational data protection advisory, not legal advice. For specific legal interpretation of your obligations, consult a qualified lawyer.
A Data Protection Impact Assessment evaluates how a specific data processing activity affects individuals' privacy. Whether you need one depends on your specific processing activities — this is exactly what a DPIA engagement scopes out.
They're related but distinct — a cybersecurity risk assessment covers your security posture broadly; data protection advisory focuses specifically on how personal data is collected, stored, used and protected.
RETIS provides readiness advisory — identifying and closing gaps in your data handling practices — see GRC Kenya for the broader compliance readiness service this connects to.
Talk to RETIS about your data handling
Tell us about your organisation and we'll follow up — no obligation.
