Governor Campaign Data Protection Checklist Kenya gives an aspirant and authorised county campaign team a practical way to organise personal information without treating every contact as a campaign asset. A governor campaign may work across many constituencies, wards, events and teams. That reach increases the need for clear purposes, limited access, accurate records, safe sharing and prompt respect for people's choices.

Important: This guide provides campaign-operations information, not legal advice or a compliance certificate. Vota is not the Office of the Data Protection Commissioner, the Independent Electoral and Boundaries Commission (IEBC), an official voter register, a nomination service, a voting platform, a tallying or results-transmission system, or an official election-reporting source. Software alone cannot make unlawful processing lawful, and it cannot guarantee nomination, support, votes or an election outcome.
Who needs this governor campaign data checklist?
The primary buyer is a governor aspirant, campaign owner or county campaign manager who needs one controlled operating record instead of disconnected phones, spreadsheets and chat groups. A data-protection lead, CRM administrator, volunteer manager, constituency coordinator, ward coordinator, communications approver, events desk, polling-agent coordinator and party administrator may each handle a limited part of the same information flow.
The Governor Campaign Tool is the main Vota workspace for this countywide use case. It supports role-based access, reviewed issue records, supporter and volunteer workflows, field follow-up, promises and evidence. The broader Governor Campaign Management Platform explains the complete commercial offer, while this article stays focused on responsible data operations.
Teams should use Kenya's Data Protection Act and the ODPC's Guidance Notes for Electoral Purposes as primary references. Vota's data-protection page and privacy notice explain its product-specific practices; campaigns still need qualified advice for their circumstances. Political opinions and several other categories of information receive heightened protection. The safest operational habit is to collect less, document why it is needed and avoid inferring what a person never chose to disclose.
Why countywide campaigns face greater data risk
A governor campaign can receive details through public pages, meetings, volunteer forms, calls, issue submissions, event RSVPs and authorised imports. The same person may appear in several workflows for different reasons. Someone who reports a market problem is not automatically a supporter. A person who attends a listening meeting is not automatically a volunteer. A polling agent's assignment record should not become a general marketing list.
Risk increases when a local coordinator exports a spreadsheet, forwards it to an unrelated group or adds extra labels based on assumptions. Copies become difficult to correct or delete, and leadership may no longer know who can see them. Vota's campaign operations software can provide a controlled operating record, but the campaign remains responsible for its purposes, notices, lawful basis, people, devices and decisions.
Ten controls for a responsible governor campaign database
1. Define the purpose before collecting a field
Write a short, specific purpose for each form or workflow. An event RSVP may need a name, contact method, event and accessibility request. A volunteer application may need availability and preferred assignment. A citizen issue may need a location and enough detail for follow-up. Do not use a vague purpose such as “campaign data” to justify collecting everything that might be useful later.
Vota's campaign management software should mirror those separate workflows. Purpose separation helps the team decide which fields, roles, notices and retention periods apply.
2. Map every collection and sharing route
List each public form, paper sheet, import, phone intake, event desk, coordinator upload, external provider and party handover. Record who receives the information, where it enters the controlled system and whether another copy remains. Unknown spreadsheets and personal-phone contact lists are not a reliable data map.
The Party Campaign System may support authorised multi-team coordination, but party sponsorship does not create unlimited permission to share personal information. Define the purpose and access of each handover rather than assuming every party or campaign worker needs the full county database.
3. Document the lawful basis and consent evidence
The team should identify and document the appropriate lawful basis for each purpose. Where it relies on consent, the choice should be informed, specific, demonstrable and capable of being withdrawn. Do not bundle an issue report, event RSVP, volunteer request and promotional subscription into one forced choice.
For supporter engagement, use a consent-led process through the Political Campaign CRM. Record the source, notice version, date and chosen communication route. Do not upload purchased, scraped, leaked or unofficial voter-register data and label it “supporters.”
4. Give a clear notice at the point of collection
Tell people who is collecting the information, why, what will happen next, who may receive it, how long it may be kept and how they can exercise relevant rights. Use plain language that fits the collection channel. A short form can link to fuller information, but the essential purpose should not be hidden.
If the purpose changes materially, pause and review the basis and notice before reusing the information. A contact collected for event logistics should not quietly become part of recurring political marketing.
5. Minimise fields and prohibit sensitive profiling
Collect only the minimum information required for the stated task. A ward name may be enough for routing; an exact home address may not be. Avoid collecting identity documents unless a verified, necessary process genuinely requires them and proper safeguards exist.
Do not profile or target people by ethnicity, religion, health, disability, family circumstances or inferred political opinion. Do not use a resident's language, location, surname, issue or event attendance to guess a sensitive trait. The Supporter and Volunteer Management workflow should record a person's expressed choices and authorised tasks, not hidden political scoring.
6. Give each role the smallest necessary view
Design an access matrix before inviting users. A ward coordinator may need assigned issues and activities in that ward, while the county data lead may need controlled oversight of corrections and exports. A volunteer should not receive the entire supporter list merely because the volunteer has a campaign title.
Use the Campaign Manager Software to assign work without copying the underlying database. Review access when responsibilities change, remove dormant accounts promptly and revoke permissions when a person leaves. Shared passwords defeat accountability and should not be used.
7. Control imports, exports and provider access
Before importing a list, record its source, purpose, basis, notice status, fields, owner and approval. Reject unexplained files. Before exporting, record who requested it, why it is necessary, which fields are included, the recipient and when the copy should be deleted.
External SMS, email, website, creative or analytics providers should receive only what their authorised task requires. Provider access and contracts need a separate professional review. Vota can record approvals and transfer evidence; it does not certify providers or make the transfer lawful.
8. Respect corrections, objections, opt-outs and deletion requests
Create one route for a person to correct inaccurate details, change a communication preference, object where applicable or request action on their information. Assign an owner, record the request date, pause disputed use where appropriate and document the response.
Suppression records require care: the team may need the minimum information necessary to prevent a person from being contacted again without retaining the complete marketing profile. Do not restore a deleted or opted-out contact from an old coordinator spreadsheet during the next import.
9. Set retention and disposal rules
“Keep everything until after 2027” is not a retention policy. Define a period or review event for each category: unsuccessful RSVP, completed volunteer assignment, closed citizen issue, inactive account, vendor file, approved public evidence and election-day readiness record. Consider legal, operational and accountability needs, then delete or anonymise information that no longer has a justified purpose.
Backups, exports and personal devices must be included. Deleting the main record while leaving uncontrolled copies does not complete the work.
10. Prepare for mistakes and security incidents
Document how a team member reports a lost phone, misdirected file, compromised account, unauthorised export or accidental public disclosure. The plan should identify the internal incident owner, immediate containment steps, evidence preservation and routes for qualified technical, legal or regulatory advice.
Do not investigate serious harm through an open chat group. Restrict the incident record to authorised people and avoid spreading the exposed information further.
A practical 30-day setup plan
Days 1-7: inventory and decisions
List collection channels, data categories, purposes, lawful-basis decisions, notices, providers, imports and existing copies. Identify the campaign owner responsible for decisions and the people who need professional advice.
Days 8-14: roles and controlled workflows
Configure county, constituency and ward roles. Separate supporter, volunteer, issue, event and polling-agent records. Test what each role can view, edit, export and approve. The MP Campaign Software and MCA Campaign Software show why constituency and ward access should remain distinct inside a governor campaign hierarchy.
Days 15-21: clean and migrate
Quarantine unexplained lists instead of importing them. Remove unnecessary fields, resolve duplicates, retain source evidence and migrate only approved records. Send no campaign message merely to test whether an old number still works.
Days 22-30: train and rehearse
Train each authorised user on purpose limits, access, secure devices, issue escalation and people's choices. Rehearse an access removal, correction request, opt-out and lost-device incident. Record gaps and assign fixes before expanding the team.
Questions to ask during a Vota demonstration
- Can the workspace separate citizen issues, supporters, volunteers, events and agent-readiness records?
- Can leadership restrict users by responsibility and operating area?
- Can the campaign record the source, purpose and consent evidence where applicable?
- Can access be revoked without deleting required operational history?
- Can public information remain private until an authorised review approves it?
- Can the team record correction, opt-out, deletion and incident follow-up tasks?
- Can exports and important approvals be limited and reviewed?
- Can onboarding start with a small, clean dataset rather than an uncontrolled bulk import?
These questions turn a product demonstration into an operational review. They do not replace a data-protection impact assessment, legal analysis, security assessment or required regulatory process.
Frequently asked questions
Does Vota make a governor campaign automatically compliant?
No. Vota can support controlled records, roles, reviews and follow-up. The campaign remains responsible for its lawful basis, notices, data quality, providers, staff behaviour, security and applicable obligations.
Can a campaign upload the official Register of Voters?
No. Vota is not the official register and should not be used as one. Campaign teams must not present unofficial, leaked or purchased voter data as an authorised supporter database.
Can event attendees be added to the supporter CRM?
Not automatically. An RSVP or attendance record has its own purpose. Any separate supporter communication needs an appropriate, transparent basis and respect for the person's choices.
Can a ward coordinator download all county contacts?
That should not be the default. Access and exports should be limited to the minimum needed for an authorised responsibility and reviewed by the campaign owner.
Does the checklist allow targeted political profiling?
No. The campaign should not infer or target sensitive traits or political opinions. Vota is designed for consent-led, issue-based campaign organisation, not covert profiling or persuasion guarantees.
Build a cleaner governor campaign data workflow
A governor campaign does not need more uncontrolled lists. It needs clear purposes, limited access, traceable decisions and peaceful follow-up. Review Vota's pricing for the countywide Pro package, then request a demonstration using a sample workflow with no real personal data. The team can test roles, notices, issue routing and opt-out handling before deciding how a lawful production setup should proceed.