The strongest reporting on a new law is built from the law itself, not the noise around it. In the days after a statute passes, commentary outruns evidence, and claims about what it will do multiply faster than anyone can check them. On 8 November 2019 Kenya enacted the Data Protection Act, and the disciplined response is to assemble what can actually be verified from primary sources on this date, and to hold the rest for follow-ups yet to come.
The tension for a source-led package is between the appetite for consequence and the limits of the record. Much of the interesting story lies in effects that have not happened yet; the honest work today is to fix the baseline precisely.
The Evidence Pack: What the Record Shows
The primary document is the Act itself, which establishes statutory duties for organisations processing personal data — lawful processing, consent, data-subject rights — and lays the foundation for a dedicated regulator. That text is the anchor of any credible package, and it is available in full as the Data Protection Act.
Around it sits verifiable context: the sectors the law reaches — banks, telecoms, health firms, retailers and digital platforms — and the fact that a supervising office is to be established rather than already operating. Everything in the pack should trace back to a document or a stated provision.
The takeaway: the evidence pack starts and ends with the primary text, and every claim in it should be traceable to a source.
The Timeline: Fixing the Baseline
A chronology is the backbone of a source-led story. As of 8 November 2019 the verifiable timeline is short: Kenya has moved from having no comprehensive data-protection law to having one on the statute book. What follows — the standing-up of the regulator, the making of subsidiary regulations, the first enforcement actions — belongs to dates not yet reached and must be logged as pending, not reported as done.
A data visual here is a simple before-and-after: the regime absent, then present, with the enforcement machinery marked as under construction. Precision about what has and has not happened is the whole value of the exercise.
The takeaway: the timeline’s job today is to fix an honest baseline and clearly flag everything still to come.
The Discipline: Separating Fact from Forecast
The temptation in covering a landmark law is to narrate its consequences as if they were settled. The discipline is to separate what the document establishes from what observers expect. Compliance costs, market effects, regional influence and enforcement outcomes are legitimate lines of inquiry, but on this date they are forecasts, and the package should label them as such.
This is what makes a source-led approach durable. A report built strictly on the verifiable record can be trusted later, when the follow-ups arrive, precisely because it did not overreach at the start.
The takeaway: keeping fact and forecast in separate columns is what lets the coverage hold up as events unfold.
The Decision: Publish the Baseline, Schedule the Follow-Ups
For an editor or analyst building coverage of the Act, the call on 8 November 2019 is to publish a tight, source-anchored baseline and to schedule the follow-ups that the story genuinely needs — the regulator’s establishment, the first regulations, early compliance behaviour. Each becomes its own dated report built on new evidence, not on today’s speculation.
The lesson for any operator or newsroom watching this space is that credibility compounds. Fix the baseline honestly now, from primary documents, and every later instalment stands on firmer ground. The Data Protection Act is the anchor event; the disciplined package treats it as the first entry in a longer, evidence-led record rather than the whole story told at once.




