SMS Compliance Framework
Navigate Kenya's data protection landscape with confidence. Built-in tools and guidance to keep your messaging fully compliant.
Our Compliance Commitments
MacraSMS is engineered to meet and exceed regulatory requirements for business messaging in Kenya.
ODPC Registered
Fully registered data controller under Kenya's Data Protection Act, 2019. Regular audits ensure ongoing compliance.
- Annual compliance reporting
- Designated Data Protection Officer
- Staff training on data handling
Consent Management
Built-in tools to capture, store, and manage explicit consent before sending any marketing messages.
- Double opt-in workflows
- Consent timestamp logging
- Withdrawal of consent processing
Data Security
End-to-end encryption for message content and customer data. Zero-knowledge architecture for sensitive information.
- AES-256 encryption at rest
- TLS 1.3 in transit
- Kenyan data residency
Audit Trails
Complete immutable logs of all API calls, sends, consent changes, and access events for regulatory review.
- 7-year retention policy
- Tamper-proof logging
- Exportable audit reports
Regulatory Requirements Explained
Understanding your obligations under Kenyan law when sending bulk SMS.
Data Protection Act, 2019
The DPA requires all entities processing personal data (including phone numbers) to register with the ODPC and implement appropriate safeguards. Key obligations include:
- Obtaining explicit, informed consent before processing personal data
- Providing clear privacy notices explaining data usage
- Implementing technical and organizational security measures
- Reporting data breaches within 72 hours of discovery
- Honor data subject rights (access, correction, deletion)
MacraSMS Support: Our platform provides built-in consent capture forms, automated privacy notice delivery, breach notification templates, and data subject request workflows.
Communications Authority Guidelines
The CA regulates SMS content, sender ID usage, and anti-spam measures. Businesses must ensure:
- All marketing messages include valid opt-out instructions
- Sender IDs are registered and approved before use
- Messages do not contain misleading or fraudulent content
- Respect quiet hours (no marketing SMS between 9PM–7AM)
MacraSMS Support: Automated opt-out keyword handling, sender ID registration assistance, content pre-screening tools, and scheduled sending with time-zone awareness.
Sector-Specific Regulations
Certain industries have additional messaging requirements:
- Financial Services: CBK guidelines require transactional SMS to include specific disclosures and fraud warnings
- Healthcare: Patient communication must comply with medical confidentiality standards
- Education: Student/parent messaging requires guardian consent for minors
MacraSMS Support: Industry-specific message templates, compliance checklists, and dedicated support teams familiar with sector regulations.
Your Compliance Checklist
Follow these steps to ensure your SMS program meets all regulatory requirements.
Register as Data Controller
Complete ODPC registration at odpc.go.ke. MacraSMS can provide supporting documentation for your application.
Implement Consent Capture
Use our double opt-in forms or API endpoints to collect explicit consent. Store consent records with timestamps and source attribution.
Create Privacy Notice
Draft a clear privacy notice explaining how you collect, use, and protect phone numbers. Include it in your consent flow and website footer.
Configure Opt-Out Handling
Enable automatic STOP/UNSUBSCRIBE keyword processing. Ensure opt-outs are processed within 24 hours and added to suppression lists.
Train Your Team
Educate staff on data handling best practices, breach reporting procedures, and responding to data subject requests.
Conduct Annual Review
Review your SMS compliance posture annually. Update policies, refresh consent records, and verify technical controls remain effective.
Compliance Resources
Download templates and guides to accelerate your compliance journey.