Data Protection Policy

1. Introduction

1.1 This policy outlines the principles and procedures governing the collection, processing, storage, and disposal of personal data by Wanjiku Joy & Company Advocates in compliance with the Data Protection Act 2019 and its subsidiary legislation.

1.2 The policy ensures the lawful, secure, and ethical handling of personal and sensitive data, helping maintain compliance with data protection laws while protecting individuals' privacy rights.

1.3 This policy also complies with the Constitution of Kenya (2010), the Advocates Act (2012) and its subsidiary legislation, and the Data Protection Act (2019) and its subsidiary legislation.

1.4 The scope of this policy covers all employees, clients, and third parties handling data.

1.5 It applies to all data processing activities related to business purposes, including:

2. Definitions

2.1 Personal data: Information that may be used to identify an individual, including contact details (name, address, email, phone number), identification details (ID/passport number, date of birth), billing information, contractual or transactional data, case data, and communication records.

2.2 Sensitive personal data: Delicate personal information requiring additional safeguards such as biometric details, health records, marital status, family information, or sex of the data subject.

2.3 Processing: Any action performed on personal data—collection, storage, transmission, retrieval, use, or destruction.

2.4 Data Controller: The Firm—responsible for determining the purposes and means of processing personal data.

2.5 Data Processor: Any individual or entity processing data on behalf of the Firm through a written contract.

2.6 Data Subject: Any individual whose data is processed by the Firm, including clients, representatives, partners, or witnesses.

2.7 Third Party: Any external person or organization processing Firm data, including regulators, courts, opposing counsel, and service providers such as hosting or accounting firms.

3. Types of Personal Data Collected

4. Data Processing Principles

As per Section 25 of the Data Protection Act 2019, personal data must be handled in a manner that:

5. Lawful Basis for Data Processing

6. Data Subject Rights and Privacy Notice

7. Responsibilities of the Firm

8. Security and Access Controls

The Firm ensures data confidentiality and protection against unauthorized access or disclosure through:

9. Third Parties

10. Data Retention and Disposal

Data Type Retention Period Disposal Method
Client Records 7 years Secure shredding using paper destruction tools

11. Enforcement

12. Policy Review and Amendments

This policy will be reviewed annually or when new data protection laws are enacted.


Wanjiku Joy & Company Advocates
Nakuru, Kenya
+254743257967
info@wanjikujoycompanyadvocates.co.ke