What the Kenya Data Protection Act requires of your business
A plain-language walkthrough of controller and processor duties under Kenya's Data Protection Act 2019, ODPC registration, and the 72-hour breach clock.
· 5 min read
LOYCA LIMITED · INTELLIGENCE WITHOUT LIMITS
Cybersecurity advisory, audit, testing and training for organisations that cannot afford to guess.
PRACTICE AREAS & PORTFOLIO
Advise, audit, test, build, govern, watch, train, innovate. Most work starts at the top of that list and moves down.
Click any station to explore the continuous security pipeline
Strategy & Risk Appetite
Most security spend goes wrong at the decision, not the implementation. Our advisory work sets the strategy, the risk appetite, and the roadmap before a single tool is bought — so the money you spend next quarter solves a problem you actually have.
Strategy, board-level guidance, and the security decisions that shape everything downstream.
Why Loyca
A high-precision cybersecurity partner built for organizations with zero tolerance for security blindspots.
GDPR, ISO 27001, PCI DSS and your own sector's supervisory expectations are built into how we scope work — not bolted on at the audit.
The same team that writes your policy can test your application, stand up your SOC, and train the staff who will run it.
Every engagement ends with prioritised, costed remediation your engineers can start on Monday — not a 90-page PDF nobody opens.
Most requested
Six high-impact starting points representing where 90% of our enterprise and institutional clients initiate their cybersecurity journey.
Know where you stand before you spend
Independent guidance on where your real risk sits, what to fix first, and what not to buy.
Do your controls do what you think they do?
Control-by-control audit of your security programme against ISO 27001, NIST CSF, or sector regulator guidance.
Find it before someone else does
Authenticated and unauthenticated scanning across your estate, with findings validated by hand.
Change behaviour, not just completion rates
Organisation-wide awareness programmes with phishing simulation, measured by behaviour rather than attendance.
Securing the systems you are now building with LLMs
Threat modelling and testing for AI features: prompt injection, data leakage, agent permissions, and model supply chain.
Data protection law, handled properly
Compliance with the GDPR and equivalent privacy law: mapping, DPIAs, notices, subject rights, and supervisory authority registration.
Our principal advisors will review your context in a 30-minute scoping call at no cost.
Sectors
API security flaws, payment gateway fraud, instant breach disclosure deadlines.
Fintech Security & Application Pentesting
Insights
A plain-language walkthrough of controller and processor duties under Kenya's Data Protection Act 2019, ODPC registration, and the 72-hour breach clock.
· 5 min read
Why prompt injection cannot be patched away, how it reaches systems that only call a third-party API, and why permissioning the agent is the real control.
· 5 min read
The decision tree for whether a breach must be notified in Kenya, what the ODPC expects in the report, and how the 72-hour clock is actually counted.
· 5 min read
Intelligence Without Limits
We reply to enquiries within one business day. A direct, confidential scoping call before any engagement — at no cost.
You talk to a seasoned cybersecurity consultant, never a sales script.
We operate under mutual NDA before discussing sensitive architecture.
Immediate priorities and costed options, whether you engage us or not.