AuditXYZ

Compliance Framework

Data Protection Act, 2019 (Kenya) (Kenya DPA)

Kenya's Data Protection Act establishes a comprehensive framework for personal data protection, creating the Office of the Data Protection Commissioner and granting individuals extensive rights over their personal data.

$5,000–$70,0003–8 months2019 (enforced November 25, 2019)
Issuing BodyParliament of Kenya / Office of the Data Protection Commissioner (ODPC)
First Published2019-11-08
Latest Version2019 (enforced November 25, 2019)
Typical Cost$5,000–$70,000
Typical Timeline3–8 months
Audit RequiredNo
Audit FrequencyNo mandatory periodic external audit. The Data Commissioner may conduct audits and investigations. Data controllers and processors must register with the ODPC.
Geographykenya

Kenya DPA: The Complete Guide

Kenya's Data Protection Act of 2019 is East Africa's most comprehensive data protection law and a model for the region. Enacted to fulfill the data protection mandate in Kenya's 2010 Constitution, the Act establishes the Office of the Data Protection Commissioner as an independent regulatory body and creates a robust framework for protecting personal data. Since the ODPC ramped up active enforcement from 2022 onward — registering thousands of data controllers, issuing regulatory guidance, and investigating complaints — the Kenya DPA has moved firmly from paper law to operational compliance obligation for any organization processing personal data of Kenyan residents.

What the Kenya DPA Is and Who Issues It

The Data Protection Act was assented to on November 8, 2019 and came into force on November 25, 2019. It was enacted by the Parliament of Kenya in fulfillment of Article 31(c) and (d) of the Constitution of Kenya 2010, which guarantee every person the right to privacy of their information, including the right to have collected information corrected and to have information relating to them not be unnecessarily required or revealed.

The Office of the Data Protection Commissioner (ODPC) is the independent regulatory body established under Section 5 of the Act. The Data Commissioner is appointed by the Cabinet Secretary responsible for Information and Communications and serves a term of six years. The ODPC is responsible for:

  • Establishing and maintaining a register of data controllers and processors.
  • Receiving and investigating complaints from data subjects.
  • Conducting investigations and audits, with or without a complaint.
  • Issuing enforcement notices, prohibition notices, and penalty notices.
  • Promoting awareness of data protection rights and obligations.
  • Advising the government on data protection matters and international cooperation.

Three sets of subsidiary regulations were gazetted in 2021 to operationalize the Act: the Data Protection (General) Regulations, the Data Protection (Compliance and Enforcement) Regulations, and the Data Protection (Registration of Data Controllers and Data Processors) Regulations. These regulations provide the procedural detail for registration, complaint handling, breach notification, and Data Protection Impact Assessments.

Active ODPC enforcement accelerated from 2022. By 2024-2025, the ODPC had registered tens of thousands of data controllers and processors, issued multiple enforcement notices to financial institutions and telecommunications operators, conducted audits of credit reference bureaus and data brokers, and published decisions on complaints involving health data, direct marketing, and employment records. The ODPC has made clear that it views registration not as a one-time administrative exercise but as the foundation of ongoing supervisory engagement.

Who Must Comply

The Kenya DPA applies to any data controller or data processor who processes personal data of data subjects located in Kenya, regardless of whether the controller or processor is established in Kenya. The territorial reach is deliberately broad:

Organizations established in Kenya — in any sector, of any size — that process personal data in the course of their activities are within scope. There is no minimum size or turnover threshold; even small businesses and sole traders processing personal data must comply and register with the ODPC.

Organizations outside Kenya that offer goods or services to individuals in Kenya, or that monitor the behavior of individuals in Kenya, are subject to the Act. A Nairobi-headquartered startup's international subsidiary, a US e-commerce platform shipping to Kenya, or a European fintech offering mobile payment services to Kenyan users are all within scope.

Public bodies — government ministries, state corporations, county governments, and public institutions — are subject to the Act in their capacity as data controllers and processors.

Financial services organizations: Kenya's financial sector is one of the most active in mobile money, digital credit, and fintech. The ODPC has specifically targeted mobile lenders, credit reference bureaus, and digital financial services providers in enforcement actions, given the volume and sensitivity of personal financial data processed.

Telecommunications operators are a priority enforcement sector given their access to metadata, location data, and communications content. The ODPC has investigated major telcos for direct marketing violations and unlawful data sharing.

Health sector organizations: Hospitals, pharmacies, health tech platforms, and health insurance providers process sensitive health data subject to the Act's heightened safeguards for sensitive personal data.

Eight Data Protection Principles

The Act is built on eight core data protection principles that apply to all processing of personal data. These principles closely mirror those in the GDPR and POPIA:

1. Lawfulness, fairness, and transparency — Personal data must be processed lawfully, fairly, and in a transparent manner in relation to the data subject. Processing is lawful if it is based on one of the recognized lawful bases: consent, contractual necessity, legal obligation, vital interests, public interest, or legitimate interests.

2. Purpose limitation — Personal data must be collected for specified, explicit, and legitimate purposes and not further processed in a manner incompatible with those purposes. Organizations must articulate their processing purposes at the point of collection.

3. Data minimization — Personal data must be adequate, relevant, and limited to what is necessary in relation to the purposes for which it is processed. Bulk collection of personal data without a specific purpose is prohibited.

4. Accuracy — Personal data must be accurate and, where necessary, kept up to date. Organizations must take reasonable steps to ensure inaccurate data is erased or corrected without delay.

5. Storage limitation — Personal data must not be kept in a form that permits identification of data subjects for longer than necessary for the purposes for which it is processed. Retention periods must be defined and enforced.

6. Integrity and confidentiality — Personal data must be processed in a manner that ensures appropriate security, including protection against unauthorized or unlawful processing, accidental loss, destruction, or damage.

7. Accountability — The data controller is responsible for and must be able to demonstrate compliance with all data protection principles. Accountability requires that organizations document their processing activities, policies, and decisions.

8. Residency — The Act includes a data residency principle that personal data relating to Kenyan citizens should not be transferred outside Kenya unless the receiving country has adequate data protection safeguards. This is enforced through cross-border transfer restrictions.

Data Subject Rights in Depth

Data subjects in Kenya enjoy a comprehensive set of rights that organizations must have operational procedures to fulfill:

Right to be informed: At the point of data collection (or as soon as practicable), data subjects must be informed of the identity of the controller, the purposes of processing, the categories of data collected, any recipients, retention periods, and their rights. Privacy notices must be concise, transparent, and accessible.

Right of access: Data subjects may request confirmation of whether their data is being processed, a copy of their data, and information about the processing. The controller must respond within 21 days of receiving the request and must provide the information free of charge.

Right to rectification: Data subjects may request correction of inaccurate personal data. The controller must rectify without undue delay and inform any recipients of the corrected data.

Right to erasure: Data subjects may request deletion of their personal data when it is no longer necessary for the purposes collected, when consent is withdrawn, when the data has been unlawfully processed, or when it must be erased to comply with a legal obligation.

Right to object: Data subjects may object to processing based on legitimate interests, public interest, or direct marketing. For direct marketing, the objection must be honored immediately and at no cost.

Right to data portability: Data subjects have the right to receive personal data in a structured, commonly used, machine-readable format and to transmit that data to another controller. This right applies where processing is based on consent or contract and is carried out by automated means.

Right not to be subject to automated decision-making: Data subjects have the right not to be subject to decisions based solely on automated processing — including profiling — that produces legal or similarly significant effects. Organizations using AI or algorithmic decision-making for credit scoring, loan approvals, employment decisions, or similar purposes must implement human oversight mechanisms.

Sensitive Personal Data

The Act identifies specific categories of personal data as sensitive, requiring explicit consent and additional safeguards:

  • Health and medical data
  • Ethnic or social origin
  • Religious or philosophical beliefs
  • Political opinions or affiliations
  • Sexual orientation or sex life
  • Genetic data
  • Biometric data used for unique identification
  • Financial information beyond what is publicly available
  • Data of children

Processing sensitive personal data without explicit consent, or outside the narrow statutory exceptions, constitutes a serious violation. Organizations in health, fintech, and HR functions dealing with biometric authentication must be particularly careful about their lawful basis for sensitive data processing.

Registration with the ODPC

All data controllers and processors must register with the ODPC before processing personal data. Registration is conducted through the ODPC's online portal and requires disclosure of:

  • The name and contact details of the data controller or processor.
  • The nature and categories of personal data processed.
  • The purposes for which personal data is processed.
  • Categories of data subjects whose data is processed.
  • Countries or international organizations to which personal data may be transferred.
  • Retention periods.

The ODPC issues a certificate of registration, which must be renewed periodically. The ODPC maintains a public register of registered data controllers and processors. Operating without registration is itself a violation of the Act and is a factor the ODPC considers in assessing compliance seriousness.

Data Protection Impact Assessments

The Data Protection (General) Regulations require data controllers to conduct a Data Protection Impact Assessment (DPIA) before commencing any processing that is likely to result in a high risk to the rights and freedoms of data subjects. High-risk processing includes:

  • Systematic and extensive evaluation of personal aspects of individuals, including profiling.
  • Processing on a large scale of sensitive personal data.
  • Systematic monitoring of publicly accessible areas.
  • Processing of children's data.
  • Use of new technologies with significant privacy implications.

A DPIA must describe the processing, assess its necessity and proportionality, and identify measures to address identified risks. Where the DPIA reveals a high residual risk that cannot be mitigated, the controller must consult the Data Commissioner before processing.

Breach Notification

Data controllers must notify the Data Commissioner of a personal data breach within 72 hours of becoming aware of it, where the breach is likely to result in a risk to the rights and freedoms of natural persons. The notification must include:

  • The nature of the breach, including categories and approximate number of data subjects and records affected.
  • Contact details of the Data Protection Officer.
  • Likely consequences of the breach.
  • Measures taken or proposed to address the breach.

Where the breach is likely to result in a high risk to data subjects, the controller must also notify affected individuals without undue delay. The notification must be in plain language and must include the nature of the breach, the DPO contact, likely consequences, and steps individuals can take to protect themselves.

Enforcement and Penalties

The ODPC's enforcement toolkit includes:

  • Enforcement notices: Requiring a controller or processor to take specific steps to comply within a specified timeframe.
  • Prohibition notices: Prohibiting specific processing activities.
  • Penalty notices: Administrative fines of up to 5 million Kenyan Shillings (approximately $40,000) or 1% of annual turnover for violations of the Act.
  • Criminal prosecution: For serious violations, criminal penalties including fines up to 3 million Kenyan Shillings and imprisonment for up to 10 years.

The ODPC has demonstrated willingness to use its enforcement powers. Enforcement actions through 2024-2025 targeted mobile lenders for processing personal financial data without consent or adequate disclosure, credit reference bureaus for retaining data beyond permissible periods, and organizations for breach notification failures. The ODPC has signaled that registration non-compliance will be a priority enforcement focus in 2026.

Compliance Process and Timeline

PhaseActivitiesTypical Duration
AssessmentData inventory, gap analysis, ODPC registration review3–5 weeks
DesignPrivacy notices, consent mechanisms, rights request workflows4–6 weeks
ImplementationODPC registration, DPIA process, breach notification plan4–7 weeks
OngoingRegistration renewal, complaints handling, audit readinessContinuous

Key compliance steps:

  1. ODPC registration — Register as a data controller or processor through the ODPC online portal before processing commences.
  2. Lawful basis documentation — Map and document the lawful basis for every processing activity, ensuring sensitive data has explicit consent.
  3. Privacy notices — Update customer-facing and employee privacy notices to meet the right to be informed requirements.
  4. Data subject rights workflows — Implement processes for handling access, rectification, erasure, portability, and objection requests within the 21-day response window.
  5. DPIA process — Establish a screening process to identify high-risk processing activities requiring a DPIA.
  6. Breach notification procedure — Build a 72-hour breach notification workflow including detection, documentation, ODPC notification, and individual notification.
  7. Cross-border transfer assessment — Evaluate international data flows and implement contractual or adequacy-based safeguards.

The Kenya DPA shares significant structural DNA with other frameworks, creating compliance efficiencies for organizations operating across multiple jurisdictions:

  • GDPR (approximately 60% overlap): The Kenya DPA was modeled in significant part on the GDPR. The eight principles, data subject rights (including portability and the right to object), DPIA requirements, 72-hour breach notification, and accountability obligations are all directly analogous. GDPR-compliant organizations will find most of their compliance infrastructure adaptable to Kenya DPA with targeted localization. See the GDPR guide for comparison.
  • POPIA (approximately 55% overlap): South Africa's POPIA and the Kenya DPA share a common lineage in GDPR principles. Both require registration with a supervisory authority, impose conditions for lawful processing, and protect special categories of data with heightened safeguards. Key differences include Kenya's 21-day access response window (vs. POPIA's 30 days) and Kenya's explicit DPIA requirement in subsidiary regulations.
  • NDPA (Nigeria): Nigeria's 2023 NDPA and Kenya's DPA are both GDPR-aligned African frameworks, but the NDPA's mandatory annual audit requirement for data controllers of major importance has no direct Kenya equivalent. Organizations operating in both markets need to account for the NDPA's DPCO audit obligation.
  • LGPD (Brazil): Both frameworks include data portability rights, breach notification requirements, and DPA oversight, reflecting the global convergence of data protection standards.

How Privacy Automation Helps

Kenya DPA compliance creates recurring operational demands: 21-day access request responses, 72-hour breach notifications, ODPC registration maintenance, and DPIA documentation. Privacy automation platforms reduce the manual burden across each area.

TruePrivacy covers the Kenya DPA among its 12-plus supported frameworks and offers AI-powered data discovery across 128-plus sources — enabling organizations to build the data inventory needed to respond accurately to data subject access requests and assess breach scope. DSR automation manages the 21-day response deadline with workflow tracking and escalation alerts.

At $5,000 per year with 24-hour onboarding and an AuditXYZ score of 88/100, TruePrivacy is a practical option for organizations managing Kenya DPA alongside GDPR, POPIA, and other frameworks. As a newer platform, TruePrivacy's Kenya-specific ODPC registration guidance is less developed than its GDPR tooling — local legal counsel remains important for the registration process and DPIA consultations with the ODPC. See best privacy management tools for broader comparisons.

Frequently Asked Questions

Does the Kenya DPA apply to a company with no physical presence in Kenya?

Yes. The Act applies to any data controller or processor that processes personal data of data subjects located in Kenya, regardless of where the controller or processor is established. A company offering an app to Kenyan users, a cloud provider hosting Kenyan customer data, or a foreign employer with Kenyan employees is within scope. Such organizations must register with the ODPC and comply with all provisions of the Act.

What is the registration process with the ODPC, and how long does it take?

Registration is conducted through the ODPC's online portal at odpc.go.ke. Applicants complete an online form providing details of the organization, the categories of personal data processed, processing purposes, data subjects, international transfers, and retention periods. The ODPC reviews applications and issues a certificate of registration upon approval. Processing times vary but typically range from two to six weeks. Organizations must update their registration when material changes occur.

What constitutes "high-risk processing" requiring a DPIA under Kenyan regulations?

The Data Protection (General) Regulations identify categories of processing that automatically require a DPIA: systematic and extensive evaluation or profiling of individuals with legal or similarly significant effects; large-scale processing of sensitive personal data; systematic monitoring of publicly accessible areas; use of new or innovative technologies; and processing of children's data. Organizations should also consider conducting voluntary DPIAs for any novel processing activity that could significantly affect individuals' rights and freedoms, even if it does not fall squarely within a mandatory category.

How does the 72-hour breach notification timeline work in practice?

The 72-hour clock begins when the data controller becomes aware that a breach has occurred — not when the breach is fully investigated. In practice, organizations often need to make an initial notification to the ODPC with the information available at the time, followed by supplementary notifications as the investigation progresses. The ODPC's Compliance and Enforcement Regulations provide for notification in stages where a complete picture is not available within 72 hours. Organizations should implement breach response playbooks that trigger ODPC notification workflows immediately upon breach detection.

Can organizations transfer personal data from Kenya to other African countries?

Cross-border transfers require either that the destination country has adequate data protection, that standard contractual clauses or binding corporate rules are in place, or that the data subject has consented to the transfer. The ODPC has not yet published a formal adequacy list but has indicated that countries with GDPR-equivalent frameworks may be considered adequate. Organizations should document their transfer basis for each destination country and monitor ODPC guidance as adequacy determinations develop.

Request a Kenya DPA consultation

Step 1 of 520%

Which framework do you need?

Framework Mappings

Overlap with other frameworks

GDPRMedium60%
POPIAMedium55%

Related frameworks

Get matched with a Kenya DPA auditor in 24 hours

Free, no-obligation — just tell us your email and we'll do the rest.

By submitting, you agree to our privacy policy.