Compliance

5 Questions to Ask Your AI Vendor About Data Privacy

January 2026 · 7 min read

Share:

Kenya's Data Protection Act 2019 isn't optional. Before signing that AI contract, here are the questions that will reveal if your vendor is compliant—or gambling with your data.

Question 1: Where Is My Data Stored?

Acceptable answers include specific data centers with clear jurisdictional information. "In the cloud" is not an acceptable answer. You need to know the physical location and the legal jurisdiction that applies.

Question 2: Who Has Access to Customer Conversations?

In a properly architected single-tenant system, the answer should be "only you." The vendor should have zero access to your customer data. If they can read your conversations for "quality assurance," that's a red flag.

Warning: Multi-tenant systems where your data mingles with other clients' data are inherently riskier and may not meet Kenya DPA 2019 requirements for regulated industries.

Question 3: What LLM Providers Process My Data?

Understand which AI providers are processing your data and under what terms. Each provider has different data retention and training policies. In an ideal setup, your deployment uses your own API keys with these providers, giving you direct contractual relationships and control.

Question 4: How Do I Delete All My Data?

The right to erasure is fundamental under Kenya DPA 2019. Your vendor should have a clear, documented process for complete data deletion. In single-tenant systems, this is straightforward—you simply shut down your instance.

Question 5: What Happens to Data After Contract Ends?

Your data should be exportable in standard formats and completely deletable when you leave. Beware vendors who make data export difficult or retain data indefinitely "for analytics."

The Compliance Checklist

  • Single-tenant architecture with isolated data
  • Clear data residency and jurisdiction
  • Your own API keys with LLM providers
  • Documented deletion procedures
  • Data export in standard formats

Found this article helpful? Share it with your network.

Share:

Ready to Implement AI for Your Business?

Let's discuss how Ruskins AI Consulting LTD can help you transform your customer experience.

Schedule a Consultation