The Data Privacy and Governance Society of Kenya (DPGSK) recently hosted a webinar exploring the realities of building a career as a Data Protection Officer (DPO), moving beyond the statutory definition of the role to examine how DPOs operate in organisations, the skills they need, and the career opportunities emerging across Kenya’s data protection and governance landscape.
The session brought together professionals from different points of the data governance ecosystem: a Senior Manager, Data Governance at a leading Kenyan bank, and a fractional Data Protection Officer who provides Data Protection Officer as a Service across multiple organisations. The discussion was moderated by an advocate of the High Court of Kenya and Certified Data Protection Officer in private practice.
The webinar also provided an opportunity for participants to explore an important question: Is becoming a DPO the right career path for me?
Table of Contents
- The DPO Does Not Work in Isolation
- What Does a DPO Actually Do?
- Privacy by Design Starts Before Product Launch
- The DPO Should Not Always Be the Person Saying “No”
- Building Trust Through Data Champions
- A Legal Career Is Not the Only Route Into Data Protection
- The Skills That Matter Beyond the CV
- How Can Aspiring DPOs Build Experience?
- Fractional DPOs: A Growing Career Model
- From Data Protection to Broader Data Governance
- What About Information Security?
- Cross-Border Data Transfers Require More Than a Contract
- The DPO Career Is Bigger Than a Job Title
- From Compliance Function to Business Enabler
- Key Takeaways
The DPO Does Not Work in Isolation
One of the central themes of the discussion was that data protection cannot be separated from the broader data governance ecosystem.
The data governance panellist explained that data governance and data protection are not functions with clearly defined starting and ending points. Instead, they operate through continuous collaboration.
Data governance typically addresses questions around data ownership, policies, standards, quality, lifecycle management and accountability. The DPO function focuses specifically on the protection of personal data and the rights of data subjects.
This creates a natural intersection between the DPO, data governance, information security, risk, compliance, legal and technology teams.
Rather than operating independently, these functions need to work together to understand how data is collected, used, stored, shared, secured and eventually disposed of.
As she noted, the relationship is better understood as a handshake than a handover.
What Does a DPO Actually Do?
The statutory responsibilities of a DPO may appear relatively straightforward, but the day-to-day reality can vary significantly depending on the organisation and sector.
For the fractional DPO on the panel, working in that model means supporting organisations across different industries. Her responsibilities can include developing and reviewing policies, responding to data subject requests, preparing advisory opinions for senior management and boards, supporting projects involving potentially high-risk processing, and advising organisations on Data Protection Impact Assessments (DPIAs).
One of the biggest misconceptions she encounters is the idea that the DPO role can simply be added to an existing employee’s job description.
For example, an organisation may decide that its legal, IT, risk or compliance officer can simply take on the DPO function as an additional responsibility.
The challenge is that this can create conflicts of interest and may undermine the independence required for the DPO to effectively perform an oversight and advisory function.
The DPO also needs sufficient resources and organisational support to perform the role effectively.
Privacy by Design Starts Before Product Launch
The panel used the example of an organisation preparing to launch a new AI-powered product to demonstrate what effective DPO involvement should look like.
The first question should not necessarily be, “Is this AI compliant?”
Instead, the DPO should begin by asking:
What problem are you trying to solve?
Understanding the business objective allows the DPO to determine what data is actually necessary and how it will be used.
From there, the DPO and other relevant teams can examine:
- What personal data will be collected?
- Why is it necessary?
- Where will the data come from?
- Where will it be stored?
- Who will have access?
- Will third-party vendors or processors be involved?
- Will data cross borders?
- What security measures will protect the information?
- How accurate will the system’s outputs be?
- What risks could arise for data subjects?
- Is a DPIA required?
This is where privacy by design becomes practical.
The DPO should not discover a new product when it is already being marketed or launched. Effective involvement begins during the design and development stages, when privacy risks can still be addressed without creating unnecessary delays or costs.
The DPO Should Not Always Be the Person Saying “No”
Another important message from the webinar was the need for DPOs to build trust within their organisations.
A DPO who is perceived only as the person who blocks projects is unlikely to be consulted early enough to provide meaningful advice.
Instead, the DPO should understand the business objective and help teams identify ways of achieving it while managing privacy and data protection risks.
Where risks remain, the DPO’s role is primarily to identify, document and advise on those risks. The final decision to proceed, particularly where the organisation is knowingly accepting a business risk, should generally remain with the appropriate decision-makers within the organisation.
This distinction is important.
The DPO provides oversight and advice. The DPO should not become the business owner of every processing activity, nor should they automatically become the person responsible for operationally executing every DPIA or compliance activity.
Building Trust Through Data Champions
The panel also highlighted the importance of internal data protection champions.
Rather than relying entirely on one DPO to monitor every department and every processing activity, organisations can establish networks of representatives within different business units.
These champions can help identify emerging issues, raise awareness, encourage teams to involve the DPO early and create a stronger organisational culture around data protection.
This shifts data protection from being a centralised compliance function to becoming a shared organisational responsibility.
A Legal Career Is Not the Only Route Into Data Protection
The webinar challenged the assumption that a DPO must come from a legal background.
The data governance panellist’s career demonstrates how professionals with backgrounds in informatics, technology, data analytics, audit and data management can transition into privacy and data protection.
Her experience in data analytics and audit exposed her to how organisations collect, manage and use information. Over time, this broader understanding of data created a natural pathway into data governance and privacy.
The fractional DPO’s journey was different. Coming from a legal background, she had to develop greater technical understanding and learn how to communicate legal and regulatory requirements to people without legal backgrounds.
Both experiences point to the same conclusion:
Data protection is inherently multidisciplinary.
Legal knowledge is valuable, but so are technology, risk management, cybersecurity, data governance, communication, business understanding and problem-solving skills.
The Skills That Matter Beyond the CV
The discussion placed considerable emphasis on skills that are difficult to capture on a CV.
Diplomacy was repeatedly identified as one of them.
A DPO may have to tell a product team that a planned activity presents significant risk or cannot proceed in its current form. At the same time, the DPO must help the team find a workable alternative.
This requires communication, negotiation, emotional intelligence and the ability to understand different perspectives.
The panel also emphasised the importance of being able to communicate with everyone within an organisation, from employees collecting identification documents at an entrance to senior executives and board members making strategic decisions.
Technical knowledge alone is therefore insufficient.
An effective DPO must be able to translate complex legal, technical and regulatory concepts into language that different audiences can understand and act upon.
How Can Aspiring DPOs Build Experience?
For professionals who have never held a DPO title, the panel recommended deliberately building relevant experience before investing heavily in specialised qualifications.
Aspiring DPOs can:
- Study the applicable data protection laws and regulatory requirements.
- Learn how personal data flows through organisations.
- Understand data subject rights and how they are operationalised.
- Participate in data mapping and data flow exercises.
- Learn about DPIAs and privacy risk assessments.
- Work with information security and technology teams.
- Understand third-party and vendor management.
- Learn how risk teams identify and manage organisational risks.
- Shadow experienced DPOs and privacy professionals.
- Volunteer for relevant professional activities and events.
- Build communication and presentation skills.
- Network with professionals working across privacy, technology, risk and governance.
The panel also encouraged participants to make use of free learning opportunities before committing significant financial resources to professional certifications.
The message was simple: test the field before investing heavily in it.
Fractional DPOs: A Growing Career Model
The fractional DPO model also offers an alternative to the traditional full-time corporate career.
Providing DPO services to multiple organisations requires professionals to understand different sectors, regulatory environments and business models.
A financial services client, for example, may have requirements arising from both data protection law and sector-specific financial regulation. An education, telecommunications or public-sector organisation will have a different regulatory and operational context.
For professionals who enjoy variety and continuous learning, this model can provide exposure to multiple industries while developing a broad understanding of privacy and governance.
From Data Protection to Broader Data Governance
For professionals interested in moving beyond privacy into broader data governance, the data governance panellist recommended developing an understanding of established data management frameworks, including the DAMA framework.
This broader perspective encompasses areas such as data quality, metadata, data architecture, data lifecycle management, records management and data governance.
The benefit is that professionals begin to see privacy not as an isolated compliance requirement, but as one component of a much larger data management ecosystem.
For technical professionals, this can provide a pathway from technology into governance and leadership.
For legal professionals, it can provide a pathway from regulatory interpretation into operational data governance.
What About Information Security?
The discussion also clarified the relationship between the DPO and information security teams.
Information security is primarily concerned with protecting information systems and data through technical and organisational safeguards.
The DPO, meanwhile, focuses on personal data protection, data subject rights, lawful processing and privacy risks.
The two functions overlap significantly but are not interchangeable.
Security controls may help protect personal data, but implementing those controls is not, by itself, the entirety of the DPO’s responsibility.
This is another example of why effective privacy programmes require collaboration across multiple functions.
Cross-Border Data Transfers Require More Than a Contract
Cross-border processing was another issue raised during the Q&A.
Where personal data is transferred to overseas processors, support centres or cloud environments, organisations need to understand the applicable legal requirements and establish appropriate contractual and organisational safeguards.
The panel recommended paying particular attention to third-party processors, data processing agreements and contractual provisions governing responsibilities when data is transferred.
Understanding where data is physically and operationally processed is particularly important when organisations use multiple cloud providers, subprocessors and international support hubs.
The DPO Career Is Bigger Than a Job Title
Perhaps the most important takeaway from the webinar was that becoming a DPO should not simply be about adding another certification or job title to a CV.
Aspiring professionals were encouraged to first ask what aspect of data protection genuinely interests them.
Is it:
- Policy development?
- Regulatory work?
- Technology and AI governance?
- Data subject rights?
- Risk management?
- Data governance?
- Cybersecurity?
- Privacy compliance?
- Advocacy and public policy?
The answer can help determine which career path to pursue.
The panellists also stressed that professionals should leverage the skills they already possess. A lawyer brings legal analysis. A technologist brings technical understanding. A risk professional brings risk assessment expertise. A data analyst brings analytical capabilities.
These existing skills can become a unique advantage when combined with data protection knowledge.
From Compliance Function to Business Enabler
The webinar ultimately presented the DPO role as much more than a compliance position.
An effective DPO helps an organisation understand its data, identify risks, protect individuals and make better decisions about how information is used.
The strongest privacy programmes are therefore not built around a DPO who operates in isolation. They are built around organisational cultures where privacy is considered from the beginning of a project, business teams understand their responsibilities and different professional functions work together.
For anyone considering a career in data protection, the advice from the session was clear: get curious, get practical, build relationships, understand the business and keep learning.
You do not necessarily need to start as a lawyer. You do not necessarily need to start as a DPO.
What matters is developing the ability to understand data from multiple perspectives and helping organisations use it responsibly.
Key Takeaways
Data protection is multidisciplinary. Legal, technical, risk, governance and communication skills all have a role.
DPOs should be involved early. Privacy by design is most effective when incorporated during product and process development.
The DPO is an adviser, not a business blocker. The role is to identify risks, provide guidance and help organisations find compliant ways forward.
Collaboration is essential. DPOs need strong relationships with data governance, information security, legal, risk, compliance, technology and business teams.
Practical experience matters. Shadowing, volunteering, assessments, data mapping and exposure to real organisational processes can be as important as formal qualifications.
There is no single DPO career path. Professionals can enter the field from law, technology, data, audit, risk, compliance and other disciplines.
The field is constantly evolving. AI, cross-border data flows and emerging regulatory frameworks mean DPOs must continuously update their knowledge.
The webinar demonstrated that the future of data protection in Kenya will require professionals who can bridge disciplines, understand both regulation and technology, and turn privacy principles into practical organisational action.