Data Protection & Privacy
Data protection and privacy compliance for organisations under the Kenya Data Protection Act.
Compliance programmes under the Kenya Data Protection Act 2019 — data controller and data processor registration with the Office of the Data Protection Commissioner (ODPC), data protection impact assessments (DPIAs), cross-border data transfer authorisations, privacy notices, data-subject request handling, breach notification, and defence of ODPC enforcement proceedings and complaints. We also advise on parallel GDPR alignment for clients with European operations.
OLM Law Advocates LLP is a recognised data protection law firm in Kenya, advising multinational corporations, financial institutions, technology companies, and government entities on compliance with the Data Protection Act, 2019 (No. 24 of 2019) and regulations issued by the Office of the Data Protection Commissioner (ODPC).
Our data protection practice covers the full compliance lifecycle: data protection impact assessments (DPIAs), privacy policy drafting, ODPC registration, staff training, data breach response, and cross-border data transfer advisory. We have particular expertise in advising businesses in regulated sectors — banking, telecommunications, healthcare, and insurance — where data protection compliance intersects with sector-specific regulations.
We also represent clients in ODPC investigations, appeals to the Data Protection Tribunal, and data protection-related disputes. Our team stays current with evolving ODPC guidance and international best practices, including the EU GDPR, to ensure our clients meet both Kenyan and global compliance standards.
Data Protection & Privacy
Data protection and privacy compliance for organisations under the Kenya Data Protection Act.
Compliance programmes under the Kenya Data Protection Act 2019 — data controller and data processor registration with the Office of the Data Protection Commissioner (ODPC), data protection impact assessments (DPIAs), cross-border data transfer authorisations, privacy notices, data-subject request handling, breach notification, and defence of ODPC enforcement proceedings and complaints. We also advise on parallel GDPR alignment for clients with European operations.
What we advise on
We build and run end-to-end data-protection compliance programmes: registration of data controllers and data processors with the Office of the Data Protection Commissioner (ODPC); data-mapping and records of processing activities; data protection impact assessments (DPIAs) for high-risk processing; privacy notices, consent frameworks and cookie compliance; data-processing agreements and data-sharing agreements; cross-border data-transfer mechanisms; appointment and outsourcing of the Data Protection Officer (DPO) role; staff training; and incident-response and breach-notification playbooks. On the contentious side we defend ODPC investigations, audits, complaints and enforcement actions, and we advise on data-subject compensation claims.
Governing law and regulators
Our advice is grounded in the Data Protection Act 2019 and the three sets of subsidiary regulations made under it — the Data Protection (General) Regulations 2021, the Data Protection (Registration of Data Controllers and Data Processors) Regulations 2021, and the Data Protection (Compliance and Enforcement) Regulations 2021 — all enforced by the Office of the Data Protection Commissioner (ODPC). For clients with European or UK operations, we align Kenyan compliance with the EU and UK General Data Protection Regulation (GDPR), whose structure closely mirrors the Kenyan regime, so a single programme can satisfy both.
Key legislation:
- Data Protection Act, 2019 (No. 24 of 2019) — Primary legislation governing data protection in Kenya
- Data Protection (General) Regulations, 2021 — Detailed rules on data subject rights, controller obligations, and transfers
- Data Protection (Registration of Data Controllers and Processors) Regulations, 2021 — Mandatory registration requirements with the ODPC
- Data Protection (Complaints Handling and Enforcement Procedures) Regulations, 2021 — ODPC investigation and enforcement procedures
- Computer Misuse and Cybercrimes Act, 2018 — Cybersecurity obligations intersecting with data protection
Who we act for
We act for technology companies, fintechs and digital-credit providers, banks and financial institutions, health providers and pharmaceutical companies, multinationals with Kenyan subsidiaries, NGOs and development partners, and any business collecting personal data at scale. Sector-specific data protection requirements — especially in banking, health and telecoms — mean that industry knowledge and legal knowledge must work together, and we bring both.
Why OLM for data protection and privacy
Data-protection compliance is not a filing exercise — it is an operational programme that must survive an ODPC audit, a data-subject complaint, or a breach. We build compliance that works in practice, and when a regulator or complainant comes knocking, we defend it with the same team that built it.
Clients choose OLM for:
- Partner-led data protection practice with deep regulatory expertise
- Experience advising multinationals on Kenyan and GDPR compliance alignment
- Track record of successful ODPC registration and regulatory engagement
- Integrated data protection, employment, and corporate advisory
Need to become compliant? Our step-by-step guide to data protection compliance in Kenya covers ODPC registration, DPIAs, consent and cross-border transfer rules under the Data Protection Act. The answers below address broader privacy advisory and enforcement questions.
Our services
Data Protection Act Compliance
End-to-end compliance programmes under the Data Protection Act, 2019 including gap assessments, remediation roadmaps, policy development, and ongoing compliance monitoring.
Data Protection Impact Assessments (DPIAs)
Preparation of DPIAs for high-risk processing activities including biometric data processing, large-scale employee monitoring, and sensitive personal data processing.
Privacy Policy & Notice Drafting
Drafting of privacy policies, cookie notices, data subject access request procedures, and consent management frameworks compliant with the Data Protection Act and ODPC guidelines.
ODPC Registration & Regulatory Engagement
Registration as data controllers and processors with the ODPC, response to ODPC information requests, and representation in ODPC investigations and enforcement actions.
Data Breach Response & Notification
24-hour breach response including containment, forensic investigation, regulatory notification to the ODPC within 72 hours, and data subject notification where required.
Cross-Border Data Transfer Advisory
Advisory on lawful mechanisms for transferring personal data outside Kenya under section 48 of the Data Protection Act, including adequacy decisions, standard contractual clauses, and binding corporate rules.
Frequently asked questions
Who must register with the ODPC in Kenya?
Data controllers and processors with annual turnover above KES 5 million, or those processing sensitive or large-scale data, must register with the Office of the Data Protection Commissioner under the 2021 Registration Regulations, subject to limited exemptions. Registration is online and must be renewed annually. We manage registration and annual renewal for clients.
What is a data protection impact assessment (DPIA)?
A DPIA is a structured risk assessment required before any high-risk processing of personal data — such as large-scale profiling, systematic monitoring, or processing of sensitive data categories. We design and conduct DPIAs and integrate findings into the compliance programme.
Does Kenya's Data Protection Act apply to foreign companies?
Yes. The DPA applies to any person who processes personal data in the context of activities carried out in Kenya, or who processes the personal data of data subjects in Kenya, regardless of where the processing takes place. We advise non-resident entities on their obligations.
What are the penalties for breach of Kenya's Data Protection Act?
The ODPC can impose fines of up to KES 5 million or three years’ imprisonment for individuals, and fines of up to KES 5 million or 1% of annual turnover for organisations. We advise on compliance and defend enforcement actions.
What are data subject rights under the Data Protection Act?
The Data Protection Act grants data subjects the following rights: right to be informed; right of access; right to rectification; right to erasure; right to restrict processing; right to data portability; right to object to processing; and right not to be subject to automated decision-making. Data controllers must respond to data subject access requests within 30 days. We help organisations implement processes to handle data subject requests efficiently and lawfully.
What should I do if my company has a data breach?
In the event of a personal data breach, the Data Protection Act requires the data controller to notify the ODPC within 72 hours of becoming aware of the breach, unless the breach is unlikely to result in risk to data subjects. If the breach is likely to result in high risk to data subjects, the affected individuals must also be notified without undue delay. We provide 24-hour breach response services including containment, investigation, notification drafting, and remediation advice.
Can I transfer personal data outside Kenya?
Under section 48 of the Data Protection Act, personal data may be transferred outside Kenya if: (1) the recipient country has been determined by the ODPC to provide adequate protection; (2) appropriate safeguards are in place (such as standard contractual clauses or binding corporate rules); (3) the data subject has given explicit consent; or (4) the transfer is necessary for specific legal or contractual purposes. We advise on the most appropriate transfer mechanism and draft the necessary documentation.
Explore Related Services
Industry sectors we advise in this area: Financial Services & Fintech · Technology & Telecoms · Health & Pharmaceuticals
Related practice areas: Intellectual Property · Corporate & Commercial · Banking & Finance
See also: Representative Matters · Our Lawyers · All Practice Areas
Latest thinking
Guides and articles: Data Protection & Privacy
Discuss a matter
Speak directly with the advocate responsible for your matter. We respond within one business day.
Contact the firm →