The Kenya Data Protection Act and your church: what you need to know
Yes, the Act applies to churches
The Kenya Data Protection Act (2019), enforced by the Office of the Data Protection Commissioner (ODPC), applies to any organisation that processes personal data — including churches, fellowships, and para-church bodies. If you hold member names, phone numbers, giving records, or attendance logs, you are a data controller under the Act.
What churches must do
How Shiriki helps
Shiriki encrypts all data in transit and at rest. Card payments are processed by PCI DSS-compliant Paystack — we never see or store card numbers. Role-based access control means only authorised administrators can see sensitive records. Members can be soft-deleted (anonymised) rather than hard-deleted, preserving statistical integrity while removing personal identifiers.
Every church’s data can be exported at any time in CSV, Excel, or PDF format. Your church’s data belongs to your church, and you can take it with you if you ever leave the platform.
Practical steps for your church
Product lead at Shiriki. Writes about how technology can serve the local church without getting in the way.
Have a project in mind?
Talk to our team about giving, membership, and communication for your church.