Skip to content
Kenya Compliance Hub

Data Protection Act & HR Systems:Why Your Excel Sheet Is a Compliance Risk

·
3 min read
Stay Compliant with Factorial
See how Factorial helps teams stay compliant with the Data Protection Act — retention controls, secure access, and audit trails built in. Discover Factorial
Written by

HR teams have quietly become custodians of some of the most sensitive personal data in the country — national ID numbers, medical records, next-of-kin details, bank accounts, even biometric clock-in data. Under the Data Protection Act, 2019, that makes every HR department a data controller, whether they’ve thought of themselves that way or not.

For executives responsible for compliance, 2026 is when this stopped being theoretical.

The Data Protection Act Is No Longer a Paper Tiger

If your mental model of the Kenyan Data Protection Act is “a law that exists but isn’t really enforced,” it’s time to update it. The Office of the Data Protection Commissioner (ODPC) determined roughly 96–127 complaints in 2025, bringing the cumulative total to around 357 determinations and 20 penalty notices since the Act came into force.

Total fines have exceeded KES 26 million, alongside 184 compensation orders that pay damages directly to affected individuals — some awards reaching KES 500,000 per person through 2024. Under Section 63, the Data Commissioner can impose administrative penalties of up to KES 5 million, or 1% of annual turnover — whichever is lower.

Data Protection Act Compliance: Excel Sheets vs. Purpose-Built HR Architecture

Most teams don’t compare these two side by side until something goes wrong. Here’s what the gap actually looks like under the Data Protection Act’s core requirements:

Requirement (Data Protection Act) Excel Sheet / Shared Drive  DPA-Compliant HR Architecture
Consent tracking No record of what an employee agreed to, or when. Documented, timestamped consent per data use.
Data retention limits Files kept indefinitely by default – a direct violation. Configurable auto-retention (e.g. 6–12 months) with scheduled erasure.
Access control Anyone with the file link can open it — no permission tiers. Role-based access; only authorised users see sensitive fields.
Audit trail No log of who viewed, edited, or shared the file. Full activity log — who accessed what, and when.
Breach detection & 72-hour notification Breach may go unnoticed for weeks. Centralised system flags anomalies; supports fast, documented response.
Data subject access requests Manual search across scattered files, slow and error-prone. Structured records make retrieval and response straightforward.
Backup & version integrity One corrupted or lost file can mean permanent data loss. Cloud-based redundancy and version history.
Cross-border transfer safeguards No mechanism to verify or restrict where data travels. Governed data flows aligned to Section 48 transfer requirements.

The pattern is consistent: Excel wasn’t built to answer the questions the Data Protection Act asks — who consented, for how long, who accessed it, and how fast can you prove it. Spreadsheets have no native way to answer any of those under audit.

Adopting DPA-Compliant Architecture.

The table above isn’t hypothetical. It’s the difference between a spreadsheet and a system built to answer the Data Protection Act’s questions on demand. Factorial closes that gap with retention controls, permissioned access, and audit trails as standard features.

Using Factorial is safer than Excel or the mail. 

  • ISO/IEC 27001:2023 certified:The global benchmark for information security management, covering how data is stored, accessed, and protected across the platform.
  • SOC 2 Type I and Type II reports: Independent, audited verification of security controls over time, not just a point-in-time claim.
  • Encryption in transit and at rest: These are available on Factorial with data hosted on AWS infrastructure backed by daily backups retained for 30 days for disaster recovery.
  • Single Sign-On (SSO) and Multi-Factor Authentication (MFA):Access control that a shared spreadsheet link simply cannot replicate.
  • Continuous penetration testing and vulnerability scanning, including a bug bounty program via HackerOne.
  • Compliance mapped across regulatory regimes — GDPR, UK-GDPR, LGPD, and CCPA — the same underlying architecture (retention controls, access permissions, audit logs) that Kenya’s Data Protection Act requires.

For recruitment data specifically, Factorial’s ATS applies structured governance most Kenyan HR spreadsheets never touch:

  • Configurable data retention: Job application data can be set to auto-erase (defaulting to 6 months) and talent pool data to 12 months, rather than being kept indefinitely, which the law prohibits.
  • Data erasure controls: Permissioned, auditable deletion instead of manually hunting through folders when a candidate withdraws consent.
  • Purpose-limited collection: Built-in guardrails against gathering more candidate data than a role actually requires.
  • Documented consent trails: The exact gap that cost the employer in the January 2025 photo ruling.

FAQs: Factorial and GDPR/Data Protection Compliance

Common questions on how Factorial handles data protection for HR and recruitment data.

Yes. Factorial states it is the first HR software built to be 100% GDPR compliant, designed to guarantee that customer and employee data is protected at all times — including the suppliers Factorial itself works with.

Factorial lets companies set a configurable retention period for both Job Applications and the Talent Pool. By default, job application data is set to erase after 6 months and talent pool data after 12 months, though this can be adjusted — while keeping in mind national data retention laws.

Admins can activate "Data Erasure" under Settings → Recruitment → Candidate Data, which automatically erases candidates whose data retention permission has expired. Factorial flags this with a warning, since some candidate information may be lost once erasure is switched on.

Factorial's guidance flags core GDPR recruitment principles: data shouldn't be processed more than necessary, applicants must be informed of their rights before and after applying, and applicants have a right to access information and results from each stage of the hiring process.

That's because spreadsheets and email have no built-in retention limits, access controls, or audit trails — data can sit indefinitely, be shared without oversight, and leave no record of who accessed it. Factorial's architecture is built around GDPR compliance by design, addressing exactly these gaps.

Faith is a storyteller and demand-generation focused marketing specialist passionate about helping businesses communicate their value with clarity and influence. She specialises in content strategy, brand positioning, and thought leadership, and has worked with Kenyan businesses, giving her a strong understanding of the Kenyan market and audience.