Records Management

Document Retention and Secure Disposal in Kenya

By Dockria EDMS Team ·

Sources checked 2 October 2026. Practical guidance, not legal advice. Confirm your institution’s applicable obligations with qualified advisers.

“How long should we keep this document?” is not answered by a single Kenyan retention number. A personnel file, procurement record, academic award record and duplicate working copy may have different purposes, legal obligations and end-of-life actions.

This guide is for records managers, privacy leads and operational owners creating a retention schedule. It separates the decisions that must be made before configuring an EDMS. It does not prescribe sector-specific periods or replace advice on a particular record.

Separate five questions before choosing a period

1. Is the record identifiable personal data?

Data Protection Act section 25(g) requires identifiable personal data to be kept no longer than necessary for the purposes for which it was collected. Section 39 sets out the retention rule and its grounds for continued retention, including retention required or authorised by law and retention reasonably necessary for a lawful purpose. These are reasons to document and assess, not permission to keep everything indefinitely.

General Regulations regulation 19 requires a retention schedule covering purpose, period, periodic audit and action after audit. It also requires review of whether continued storage is needed. A folder labelled “archive” is not, by itself, a retention justification.

2. Does a specific obligation apply to this class?

Identify the organisation’s sector, the transaction or activity, and the exact record involved. Have the responsible adviser check applicable legislation, regulator requirements and binding obligations. Record the provision, its scope, its trigger event and any original-document requirement.

Do not copy a period from a different institution or assume that one department’s rule governs all files. This article intentionally gives no numerical tax, employment, financial-services or education retention period: those require a current, record-specific assessment. Where requirements interact, document the resolution rather than silently selecting the longest period.

3. Is it a public record?

Public records need a separate authorisation check. Under Public Archives and Documentation Service Act section 8(2), wilful destruction or disposal of public records except with, and in accordance with, the Director’s written consent is an offence. Section 7 separately addresses authorisation for destruction or disposal of public archives and records within its scope.

For an applicable public-sector collection, confirm the classification, appraisal, transfer and disposal process with the Kenya National Archives and Documentation Service and the institution’s records authority. An internal schedule, a scan or an administrator’s delete permission does not substitute for the required written authority. Private organisations should not assume that every private record is a public record; establish applicability first.

4. Is preservation required for evidence?

Data Protection Act section 40(3) provides for restricting processing, rather than rectifying or erasing, when personal data subject to those requirements is needed for evidence, with notice to the data subject within a reasonable time. Section 34 also addresses restriction in specified circumstances, including legal claims.

A practical preservation-hold procedure should identify the matter, affected records and copies, responsible owner, authority and review date. Seek qualified advice on court orders, investigations and disputes. Suspend conflicting disposal for the scoped records and record who may release the hold. A hold should not become an unexplained instruction to retain the entire repository forever.

5. What end-of-life action is appropriate?

Retention review can result in continued justified retention, transfer to an archive, restriction, or authorised disposal. Section 39(2) and regulation 19 address deletion, erasure, anonymisation or pseudonymisation when retention is no longer necessary. These actions are not interchangeable: pseudonymised data can remain identifiable and needs continued protection.

Regulation 35 includes clear deletion/destruction procedures and testing whether deleted data can be recovered or anonymised data re-identified. Do not describe a recycle-bin move or removal of a name alone as secure disposal or effective anonymisation.

Build one schedule entry at a time

Use the following fields for each record class. Keep the approved schedule version so a later reviewer can understand which rule applied at the time.

  • Identity: class, description, business owner, authoritative copy and storage locations.
  • Purpose and authority: why it is retained, applicable source and provision, scope assessment and approver.
  • Timing: triggering event, approved period, event-date evidence and periodic review date.
  • Exceptions: preservation holds, original-document needs, access restrictions and unresolved legal questions.
  • Outcome: review, transfer, archive or disposal; required authority; executor and evidence to retain.
  • Copies: versions, extracts, shared copies, scanned originals, indexes and backup handling.

Illustrative entry: a closed application file

Record: an unsuccessful application and its supporting documents. Owner: the relevant administration team. Trigger: the documented close of the application process. Period: to be approved after checking purpose, applicable rules and appeal or evidence needs—not a number supplied by this example.

Review: confirm whether an active challenge or hold applies, identify the authoritative copy and check unnecessary duplicates. Action: restrict while a justified hold applies; otherwise carry out the approved end-of-life action only after confirming authority. This is a planning example, not a legal schedule or customer case study.

A secure disposal checklist

  1. Generate a candidate list. Do not treat “due” as “approved for destruction”. Resolve missing trigger dates and classification errors first.
  2. Check current obligations, preservation holds, public-record authority and any requirement to keep originals. Obtain and record the required approvals.
  3. Identify every relevant location: active store, older versions, search indexes, exports, external recipients and managed devices. Distinguish what is under your control.
  4. Choose a method appropriate to the medium and risk. For paper, control custody through destruction. For digital files, validate deletion or sanitisation rather than merely hiding the item.
  5. Document backup expiry, access restrictions and how a restore will avoid reintroducing disposed data into ordinary use. Have privacy and technical owners assess any residual retention.
  6. Record the class, identifiers, authority, date, method, executor and verification outcome. Retain only the evidence necessary for the disposal record under its own justified rule.

If a processor or destruction provider performs the work, obtain evidence of completion and investigate exceptions. A certificate is useful evidence; it does not cure an unauthorised decision to destroy.

Configure software only after approving the rule

Dockria’s Help Center Guide documents file plans, retention policies, review/archive/delete disposition actions and legal holds. Its records-management tools can support an approved process; they do not determine the legal period or grant disposal authority. Test interactions between policies, holds and permissions with fictional records before enabling destructive actions.

For a non-destructive outline of how record states, holds and retention eligibility relate, see the illustrative records lifecycle example. The EDMS evaluation checklist lists the lifecycle questions to test with synthetic records.

If you are still migrating paper, use our digitisation guide alongside this schedule exercise. For public-sector workflows, see government document management. For privacy background, see the KDPA overview; the primary sources below govern the legal points in this article.

Primary sources and limits

No universal period, sector schedule or automatic-compliance promise is made here. Have the organisation’s qualified advisers resolve the applicable schedule before actual disposal.

Test your records workflow with Dockria

Dockria is an independent, end-to-end EDMS. Bring a fictional sample file and your acceptance criteria to a demonstration. Confirm configuration and limitations before using real personal data.

Contact the team or request a demo
Built in Kenya • KDPA-alignedDomino Systems LimitedWestlands, Nairobi