Data Protection Law in Kenya

Cool-lit modern server room illustrating data protection in Kenya

No Comments

Legal Articles

The Data Protection Act 2019 introduced Kenya’s first comprehensive personal data protection regime and brought it broadly into alignment with international standards, in particular the European Union’s General Data Protection Regulation (GDPR). It applies to every organisation â regardless of size, sector or country of incorporation â that processes personal data in Kenya or processes personal data of data subjects located in Kenya. The Office of the Data Protection Commissioner (ODPC), established under the Act, has registered tens of thousands of data controllers and data processors, issued enforcement orders and begun imposing fines. Compliance is no longer aspirational: it is a legal obligation with real financial and reputational consequences for non-compliance.

At a glance
  • The Data Protection Act 2019 applies to any person who determines the purpose and means of processing personal data in Kenya (a “data controller”) and any person who processes personal data on behalf of a controller (a “data processor”).
  • Registration with the Office of the Data Protection Commissioner (ODPC) is mandatory for data controllers and data processors; unregistered processing is an offence.
  • Personal data may only be processed on a lawful basis â consent, contract, legal obligation, legitimate interest or one of the other permitted grounds â and must be collected for a specified, explicit and legitimate purpose.
  • Sensitive personal data (health, biometric, financial, genetic, political and similar categories) attracts heightened requirements including, in most cases, explicit consent.
  • Data subjects have enforceable rights including the right to access their data, correct inaccuracies, object to processing, and (in certain circumstances) erasure.

The statutory framework

The Data Protection Act 2019 (No. 24 of 2019) is the primary statute. It is supplemented by four sets of subsidiary regulations: the Data Protection (General) Regulations 2021, the Data Protection (Registration of Data Controllers and Data Processors) Regulations 2021, the Data Protection (Complaints Handling Procedure and Enforcement) Regulations 2021, and the Data Protection (Health Records and Information) Regulations 2023. The ODPC also issues guidelines and determinations that carry significant persuasive weight.

The Act is embedded in a broader constitutional framework: Article 31 of the Constitution of Kenya 2010 provides a right to privacy that includes the right not to have information about oneself shared without consent. The Computer Misuse and Cybercrimes Act 2018 provides criminal sanctions for unauthorised access to computer data, data interference and cyber espionage â overlapping in important respects with the data security obligations under the DPA 2019.

Registration

Every data controller and every data processor that operates in Kenya must register with the ODPC. Registration is done through the ODPC’s online portal and requires disclosure of the controller’s or processor’s identity, the categories of personal data processed, the purposes of processing, the categories of data subjects, any transfers of personal data outside Kenya, and the security measures in place. Registration must be renewed annually. Failure to register is an offence carrying a fine of up to KES 3 million or imprisonment of up to 10 years, or both.

Lawful grounds for processing

Personal data may not be processed unless one of the lawful bases in section 30 of the Act applies: the data subject’s consent; the performance of a contract to which the data subject is a party; compliance with a legal obligation; protection of the vital interests of the data subject; performance of a task in the public interest; or the legitimate interests of the controller (subject to a balancing test against the data subject’s interests and fundamental rights). Consent must be freely given, specific, informed and unambiguous; a pre-ticked box or bundled consent (where acceptance of terms of service is made conditional on consent to unrelated data processing) does not constitute valid consent under the Act.

Sensitive personal data â data concerning health, biometric data, genetic data, financial information, political opinions, religious beliefs, trade union membership, race and ethnicity, or criminal records â may only be processed on one of a narrower set of grounds, and in most cases explicit consent is required.

Data subject rights

The Act confers a suite of rights on data subjects. The right of access entitles a data subject to obtain confirmation of whether their personal data is being processed, and a copy of that data. The right to rectification allows a data subject to require correction of inaccurate or incomplete data. The right to erasure (the “right to be forgotten”) entitles a data subject to have their data deleted in certain circumstances â for example, where consent is withdrawn and there is no other lawful basis for processing. The right to object allows a data subject to object to processing based on legitimate interests or direct marketing. Data controllers must respond to rights requests within 30 days.

Data transfers outside Kenya

Personal data may only be transferred to a country outside Kenya if that country provides an adequate level of protection, or if one of the safeguards in section 49 of the Act applies â such as standard contractual clauses approved by the ODPC, binding corporate rules, consent of the data subject to the specific transfer, or the transfer being necessary for the performance of a contract. The ODPC has not yet published an adequacy list for third countries; in the interim, cross-border transfers must rely on one of the alternative safeguards, and the standard contractual clauses route is most commonly used in practice.

Data breach notification

A personal data breach â a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data â must be notified to the ODPC within 72 hours of the controller becoming aware of it, where the breach is likely to result in a risk to the rights and freedoms of data subjects. Where the breach is likely to result in a high risk to data subjects, the data subjects themselves must also be notified without undue delay. Controllers should have an incident response plan and data breach register in place before an incident occurs.

What you should do now

For businesses that handle personal data (all businesses)

Register with the ODPC if you have not done so â registration is mandatory, not voluntary. Conduct a data audit to map what personal data you collect, where it is stored, who processes it, what it is used for and how long it is retained. Update your privacy notice to reflect the Act’s requirements on transparency. Review your consent mechanisms on websites, mobile applications and paper forms; remove pre-ticked boxes and bundled consents. Implement a data subject rights request procedure with a 30-day response tracking system.

For businesses that transfer data internationally

Identify all cross-border data flows â to foreign group companies, cloud service providers, international payment processors, marketing platforms or analytics providers. Where the recipient country does not have an adequacy determination, put standard contractual clauses or another approved safeguard in place before the transfer. Review data processing agreements with third-party processors to ensure they contain the mandatory provisions required by regulation 14 of the General Regulations.

For fintech, health and digital businesses

Businesses that process sensitive personal data â financial data, health data, biometric data for identity verification â should conduct a Data Protection Impact Assessment (DPIA) before implementing any new processing activity that is likely to result in a high risk to data subjects. The ODPC may require a copy of the DPIA. Data minimisation is both a legal obligation and good commercial practice: collect only what you genuinely need, for a purpose you have clearly defined.

Frequently asked questions

Q1. Does the Data Protection Act 2019 apply to sole traders and micro-businesses?

Yes. The Act applies to any natural or legal person who determines the purpose and means of processing personal data, without a small-business exemption. A sole trader who maintains a customer contact list is a data controller and must register with the ODPC. The ODPC has, in practice, focused its enforcement on larger organisations first, but the legal obligation applies regardless of size.

Q2. What are the penalties for non-compliance?

The Act provides for administrative fines of up to KES 5 million (or three times the value of any transaction in question, whichever is higher) for specified violations. Criminal penalties include fines and imprisonment for individuals. The ODPC may also issue enforcement notices requiring a controller or processor to take or refrain from specified actions. In addition, data subjects may claim compensation through the civil courts for damage suffered as a result of a breach of the Act.

Q3. Is employee personal data subject to the Act?

Yes. An employer is a data controller in respect of its employees’ personal data. Processing of employee data for human resources purposes is typically based on the performance of the employment contract and compliance with legal obligations (such as NSSF and NHIF contribution records, and PAYE returns). Sensitive personal data about employees â medical records, disability information, biometric data for access control â requires explicit consent or another specific lawful basis, and employees should be given a clear privacy notice covering the processing of their data.

Q4. What is required in a data processing agreement between a controller and a processor?

Regulation 14 of the Data Protection (General) Regulations 2021 prescribes the mandatory contents of a data processing agreement. It must set out the subject matter, duration, nature and purpose of the processing, the type of personal data and categories of data subjects, and the obligations and rights of the controller. The processor must commit to process data only on the controller’s instructions, implement appropriate security measures, notify the controller of any data breach, assist the controller in responding to data subject rights requests, and delete or return data on termination of the agreement.

Q5. Does processing data about Kenyan data subjects from outside Kenya bring a foreign company within the Act?

Yes. The Act applies to any person who processes personal data of data subjects located in Kenya, regardless of whether the processor is established in Kenya. A foreign company that offers goods or services to persons in Kenya, or monitors their behaviour in Kenya, must comply with the Act, register with the ODPC, and appoint a local representative in Kenya if it does not have an establishment here.

How OLM Law can help

OLM Law advises Kenyan and international businesses on data protection compliance, including ODPC registration, privacy policy drafting, data subject rights procedures, cross-border transfer safeguards, data processing agreement review, data breach response, and representation before the ODPC in complaints and enforcement proceedings. We also advise on the intersection of data protection obligations with sector-specific regulations in financial services, health, telecommunications and technology. To discuss your data protection question, contact us at [email protected].

Sources and authorities

Data Protection Act 2019 (No. 24 of 2019). | Data Protection (General) Regulations 2021. | Data Protection (Registration of Data Controllers and Data Processors) Regulations 2021. | Data Protection (Complaints Handling Procedure and Enforcement) Regulations 2021. | Data Protection (Health Records and Information) Regulations 2023. | Computer Misuse and Cybercrimes Act 2018. | Constitution of Kenya 2010, Article 31. | Office of the Data Protection Commissioner: odpc.go.ke. | All statutes available via kenyalaw.org.

Disclaimer: This article is general commentary on Kenyan law as at September 2026 and does not constitute legal advice. Specific situations require specific advice. No solicitor-client relationship is created by reading this article. OLM Law Advocates LLP accepts no liability for action taken in reliance on it.