MtaaSmart

Score your gatehouse against the Kenya Data Protection Act.

Thirteen yes/no questions, about three minutes. Your score updates as you go — nothing is sent until you ask for the written report.

01 Data controller registration & governance

Who is accountable, and is the estate registered as the law requires.

1.1 · ODPC licence registration

Is your PMC or estate association registered with the ODPC as a data controller or processor?

Registration is a statutory requirement, not a formality — it is the first thing an investigation checks.

1.2 · Designated data lead

Has the estate board appointed a data protection lead or officer to oversee gate security practices?

Someone must own this. Shared responsibility is, in practice, no responsibility.

1.3 · Third-party guard contracts

Do contracts with security guarding agencies include data confidentiality and non-disclosure clauses?

Guards handle residents' and visitors' personal data daily. The estate stays liable for what a contractor does with it.

02 Gatehouse visitor data collection & privacy

What the gate captures, and who else can see it.

2.1 · Paper logbook exposure

Are paper visitor logbooks kept out of public view, so arriving guests cannot read previous visitors' details?

An open book on the counter discloses names, phone numbers and ID numbers to every person in the queue.

2.2 · Data minimisation

Does the gate collect only essential identification — name, ID, plate — and nothing more?

Collecting extra "just in case" is the most common breach of the minimisation principle.

2.3 · In-memory image purging

If IDs, licences or plates are scanned, are the image files purged immediately after the text is extracted?

A phone gallery full of visitors' ID photographs is a breach waiting to be discovered.

2.4 · One-time-use tokens

Is visitor entry verified with dynamic single-use codes rather than static paper passes?

A pass that works twice is a pass that can be shared, copied or sold.

03 Transparency, consent & resident privacy

Whether people are told what happens to their data, and agreed to it.

3.1 · Gatehouse privacy signage

Is a legible statutory privacy notice posted at the entrance gate?

Visitors must be told the purpose of processing and their rights, before you collect anything.

3.2 · Resident onboarding consent

Do residents explicitly consent to their contact details being used for panic alerts, staff vetting and levy billing?

Consent gathered for one purpose does not extend to another.

3.3 · Staff & service provider vetting

Are domestic worker ID records held in an encrypted database with role-based access?

Household staff records are often the least protected and most sensitive data an estate holds.

04 Data security, storage & incident response

How the data is protected, and what happens on the day it leaks.

4.1 · Encryption standards

Is resident and entry audit data encrypted both in transit and at rest?

A spreadsheet on the gatehouse desktop is neither.

4.2 · 72-hour breach notification

Is there a documented incident response plan to notify the ODPC within 72 hours of a gatehouse data leak?

The clock starts when you become aware, not when you finish investigating.

4.3 · Audit trail retention

Are visitor access logs archived or anonymised once the retention period ends?

Keeping records indefinitely is itself a compliance failure, not a safety net.

Get your written report

Your full report opens on the next screen — every gap, why it carries risk under the Act, and the action that closes it — ready to download as a PDF and table at your board. Your answers are only sent when you submit this.

Fields marked with an asterisk are required.

How MtaaSmart closes these gaps out of the box

  • Zero-typing mobile OCR. No paper logbook on the counter, and nothing written out by hand.
  • Instant image purging. Scanned IDs and plates are discarded the moment the text is extracted.
  • Encrypted cloud logs. Full audit trails, encrypted in transit and at rest, with a documented 72-hour breach process.
  • Resident-led control. Single-use tokens replace static passes, so a code cannot be shared or reused.