Dairy processors hold personal data for every farmer in the supply network — IDs, KRA PINs, bank details, GPS, production records, increasingly biometrics. That's thousands of data subjects, all under ODPC's jurisdiction. This is the 15-minute walk that surfaces the policy and system gaps ODPC has been acting on in 2024–2025. Print it. Carry it. Tick as you go.
The walk · 15 minutes
Five stages. Five minutes each.
5 min · stage 1
01Farmer onboarding
- Where does farmer data get captured? (paper / Excel / app / kiosk)
- What fields? ID, KRA PIN, bank, GPS, biometric, photo, signatures
- Is there a consent form? What does it actually say?
- Does the farmer sign it, or is it a buried tick in the app?
- Who sees the data? (ask for the actual list)
- Where is it stored? (filing cabinet, shared drive, WhatsApp, phones)
5 min · stage 2
02Payment & farm records
- Who has access to farmer bank and KRA PIN details?
- How are they transmitted to the bank or payment processor?
- Production records: how long kept, where, who can delete?
- GPS coordinates — who captures, who uses, who gets shared with?
- Cross-system check: does the same farmer ID exist in 3+ places that don't talk? (almost always yes)
5 min · stage 3
03Systems & access
- Ask to see the milk collection app live. Take a screenshot.
- Authentication: passwords, PINs, biometrics, shared logins?
- Audit log: can you see who accessed farmer X last Tuesday?
- Third-party processors: agronomy, payroll, cloud host, biometric vendors — DPAs in place?
- Backup: where, encrypted, who can restore?
3 min · stage 4
04Retention & breach
- Ask: "What happens to farmer data when a farmer stops supplying?" — most have no answer
- Is there a written retention schedule?
- Is there a breach response plan and incident register?
- Has a breach ever been reported to ODPC? (mandatory under Section 43)
2 min · stage 5
05Governance & registration
- Is the company registered with ODPC? (check the public register)
- Registered in the company name or a personal name?
- Annual returns filed?
- Is a DPO designated in writing? (mandatory — Section 24)
- Where is the Data Protection Policy, and when last reviewed?
prep · 5 min before
06Before you walk in
- Pull their ODPC registration — confirm certificate current, not lapsed
- Check if annual returns filed (most haven't)
- Google their milk collection app or payment platform by name
8 red flags that are almost always there
- No ODPC registration — or in a personal name, not the company
- Farmer data sitting on someone's laptop or shared via WhatsApp
- Collection clerks using shared logins — no individual accountability
- Consent is a tick-box, or buried in a supply contract under "terms"
- No DPO designated in writing
- Bank details sent via email or SMS in clear text
- No defined process for what happens to data when the relationship ends
- No breach response plan, no incident register, no Section 43 history
How to close the visit
"If ODPC walked in tomorrow morning, what's the one thing you'd be most worried about them seeing?"
Don't pitch. Their answer tells you exactly where the deal is — and what to price.
Free · self-serve
Take the 8-minute DPO Readiness Assessment at assessment.bitverse.co.ke — concrete gap list, even if you don't work with us.
Working with Bitverse
Registration, policies, farmer onboarding workflows, breach response, and system hardening under one engagement. stephen@bitverse.co.ke