ProductsData PrivacyDSR Automation
Kenya DPA 2019 - ss.26-28 - Rights of Data Subjects

Meet every DSR deadline. Without the spreadsheet.

Automated DSR intake, routing, verification, and fulfilment with a full ODPC audit trail. Handle access, erasure, portability, and rectification at scale - no spreadsheet required.

DSR Automation product screenshot

Why this matters

Built for your compliance outcomes

Stay ahead of the deadline

SLA clock starts from intake

  • Countdown starts at submission
  • Escalation alert at 5 days
  • Breach alert fires before deadline
  • ODPC-format timeline export

Any request type

All 6 DSR types supported

  • Access, erasure, portability, rectification
  • Restriction and objection workflows
  • Type-specific guided fulfilment
  • Partial fulfilment with explanation

Compliant verification

Verify without over-collecting

  • Upload-based identity verification
  • Clock pauses during verification
  • Maker-checker review available
  • Proportional - no over-collection

ODPC audit trail

One-click ODPC log export

  • Immutable request-by-request log
  • Action history with timestamps
  • Operator and approver records
  • CSV and structured PDF export

Features

Everything you need, nothing you don't

Request Intake Portal

Branded self-service portal where subjects submit requests via web form or email. Multi-channel intake supported.

Automated Routing

Requests routed to the right team based on type, business unit, and data location. No manual triage.

Identity Verification

Configurable verification workflow - document upload or manual review - proportional to the request, with the SLA clock paused.

SLA Countdown

Visible countdown with team escalation alerts at configurable thresholds. Deadline never sneaks up on you.

Fulfilment Workflow

Step-by-step guided workflow for each request type, including data search, retrieval, redaction, and response packaging.

ODPC Audit Export

Export your complete DSR log in ODPC-compliant format at any time - CSV or structured PDF for inspections.

DPA alignment

Every feature maps to a DPA section

Dira is built from the Act, not retrofitted to it. Here's exactly how each capability addresses your Kenya DPA 2019 obligations.

Product FeatureDPA 2019 SectionWhat it fulfils
Access request intakes.26(1)Receive and process requests for copies of personal data held about the subject
Response timeline enforcements.26(5)Meet the prescribed response period without undue delay
Identity verifications.26(2)Verify identity before disclosure without requesting more data than necessary
Erasure processings.40Assess erasure grounds and process right-to-erasure requests with documented reasoning
Data portability exports.38Provide data in structured, machine-readable format to the subject or another controller
Rectification workflows.40(1)Accept and process requests to correct inaccurate or incomplete personal data

How it works

Step-by-step workflow

01

Subject submits request

Via self-service portal, email, or API. Dira captures all metadata and starts the SLA countdown clock immediately.

02

Identity verified

Dira routes a verification request to the appropriate team. Clock pauses during verification - compliant with DPA proportionality requirements.

03

Request fulfilled

Step-by-step guided workflow for the request type. Team retrieves, redacts, and packages data. Maker-checker review available.

04

Subject notified, log closed

Data subject receives their response. ODPC-format record created automatically. SLA clock closes. Audit trail complete.

FAQ

Common questions

What is the DSR deadline under Kenya DPA 2019?
The Data Protection (General) Regulations 2021 set a 7-day response period for data subject requests, with data portability requests allowed up to 30 days under s.38(6). Dira tracks the correct deadline per request type automatically, and you can configure stricter internal SLAs.
What request types am I required to handle?
Under the DPA 2019 you must handle: right of access (s.26), right to erasure (s.40), right to data portability (s.38), right to object (s.36), right to rectification (s.40), and right to restrict processing (s.34). Dira supports all six types with type-specific workflows.
Can I refuse a data subject request?
Yes, in limited circumstances. You can refuse if the request is manifestly unfounded or excessive (s.26(2)), or if an exemption applies (e.g. national security, legal proceedings). Dira's workflow includes a structured refusal process with ODPC-compliant documentation.
What if I cannot identify the requestor?
You may request additional information to verify identity (s.26(2)). You must not over-collect - only ask for what is necessary. Dira's verification workflow is designed around this proportionality requirement and pauses the SLA clock during verification.

Start using DSR Automation today

30-day free trial. No credit card required. Full access to all Data Privacy products from day one.

30-day free trial No credit card Cancel anytime