We guide organisations across Africa and the Middle East through data protection, information security, and regulatory compliance — with clarity and confidence.
From initial gap assessments to ongoing advisory, we handle the full compliance lifecycle so you can focus on growing your business.
We benchmark your current posture against applicable standards, identify gaps, and deliver a prioritised roadmap to full compliance.
Expert advisory on the Kenya Data Protection Act, GDPR, and cross-border data transfer requirements for companies operating across the MEA region.
Readiness advisory and implementation support to help your organisation prepare for ISO/IEC 27001 and SOC 2 Type I & II. We guide the process; formal certification and attestation are performed solely by accredited certification and assurance bodies.
We draft and implement robust information security policies, data protection frameworks, and governance documentation aligned to your sector and scale.
Engaging, tailored programmes to build a genuine culture of compliance across your workforce — from leadership to frontline staff.
Retainer-based advisory to keep your compliance posture current as regulations evolve, your business grows, and new risks emerge.
Mwaura Compliance Partners is a Nairobi-based compliance advisory firm serving technology companies, financial services providers, and enterprises operating across the MEA region.
Founded by Mark Mwaura, an LL.B. graduate specialising in data protection, information security governance and regulatory compliance, we bridge the gap between complex international standards and the regulatory realities of African markets.
We work with organisations at every stage — from startups preparing for their first ISO audit to established businesses navigating evolving data protection regulations. Our approach is practical, commercially aware, and built around your specific context.
We combine international standards knowledge with on-the-ground MEA regulatory insight — something global firms simply cannot replicate.
Deep knowledge of compliance requirements across Kenya, East Africa, and the broader Middle East and Africa region — not a one-size-fits-all approach.
Our legal background means we don't just tell you what to do — we explain why, ensuring your team genuinely understands their obligations.
We deliver working policies, actionable roadmaps, and hands-on implementation support — not lengthy reports that gather dust.
From initial gap assessment through to certification readiness and ongoing advisory, we are your compliance partner at every stage.
Book a free initial consultation to discuss your compliance needs, timeline, and how we can help.
The information provided on this website is for general compliance information purposes only and does not constitute legal advice. All client engagements are governed by written service agreements. Mwaura Compliance Partners is not a law firm and does not offer legal representation or advocate services.
We provide advisory, readiness assessments and implementation guidance for ISO/IEC 27001, SOC 2, GDPR, and the Kenya Data Protection Act. We are not an accredited certification body or licensed CPA firm. Formal certification and SOC attestation decisions are made solely by the relevant accredited bodies.
Mwaura Compliance Partners processes personal data in accordance with the Kenya Data Protection Act, 2019 and, where applicable, the EU GDPR, UAE PDPL, and Saudi PDPL. Data subjects have the right to access, correct, delete, restrict, object to, and port their data. Requests are responded to within 30 days. Complaints may be directed to the ODPC (Kenya), UAE Data Office, or your national authority. Contact: info@mwauracp.com