Data Protection. DPA, 2019.
Your client lists, financials, and staff records deserve real protection, under real law. This page sets out how Tieghtsuite complies with the Kenya Data Protection Act, 2019 (No. 24 of 2019).
Your client lists, financials, and staff records deserve real protection, under real law. This page sets out how Tieghtsuite complies with the Kenya Data Protection Act, 2019 (No. 24 of 2019).
Tieghtsuite is registered as a data controller with the Office of the Data Protection Commissioner and processes personal data in line with the Data Protection Act, 2019, and its subsidiary regulations, including the Data Protection (General) Regulations, 2021 and the Data Protection (Registration of Data Controllers and Data Processors) Regulations, 2021.
We hold a registration certificate as a data controller. Where you use Tieghtsuite to process your own clients' and staff's data, we act as your data processor under a written contract, as required by section 42 of the Act.
Registration reference: Tieghtsuite, registration certificate issued by the ODPC. (Insert your certificate number and link to the ODPC register here before launch.)
The Data Protection Act, 2019, gives effect to Article 31(c) and (d) of the Constitution of Kenya — the right of every person not to have their information unnecessarily required, revealed, or the privacy of their communications infringed. The Act establishes the Office of the Data Protection Commissioner (ODPC), sets out how personal data may be lawfully processed, and gives every Kenyan data subject enforceable rights.
For a business software handling invoices, M-Pesa payments, payroll, and staff records, compliance is not optional — and it should never be a surprise. That's why we built data protection into how the Service works, not bolted it on.
Section 25 of the Act requires every data controller and processor to ensure personal data is handled lawfully and fairly. Here is how each principle works in Tieghtsuite:
Under the Act, the data controller determines the purpose and means of processing; the data processor processes data on the controller's behalf. In practice:
We apply technical and organisational measures appropriate to the risk (section 21 of the Act), including:
In the event of a personal data breach, we will follow section 43 of the Act: assess the risk to affected individuals, notify the Office of the Data Protection Commissioner within 72 hours where required, and notify affected data subjects when the breach poses a high risk to their rights and freedoms — with enough information to act on it.
Under section 26 of the Act, every data subject has the right to:
To exercise a right for your own account, email hello@tieghtsuite.com or WhatsApp +254 728 679 710. We verify your identity first, then act without undue delay. If you are a client or staff member of a business using Tieghtsuite, direct your request to that business first — they are the controller of your data; we will support them in meeting it.
The Act requires data controllers and processors to register with the Data Commissioner, subject to the thresholds in the Registration Regulations, 2021. As a provider of financial-services software, Tieghtsuite falls within the mandatory registration categories and holds a valid registration.
The Office of the Data Protection Commissioner (ODPC) is the independent regulator. You can find guidance on your own obligations at www.odpc.go.ke, and lodge a complaint there if you are ever dissatisfied with how your data has been handled.
Questions about how your data is handled, a request to exercise your rights, or anything else data-related:
This page is for general information about our compliance approach and does not constitute legal advice. We recommend you consult a qualified Kenyan lawyer on any question specific to your business. See also our Privacy Policy and Terms of Service.