WorldPrivacyAtlas
Laws by country

Jurisdiction Guides / Africa

Kenya Privacy & Data Protection Laws

Every regime below can apply to a business handling Kenya residents' data, depending on whether you have an established presence there, actively offer goods or services to residents, or monitor their behavior. This is a general reference, not a determination for your specific business — run the full questionnaire to see which of these actually apply to you.

Comprehensive Privacy Law · 1

November 25, 2019 (Act); General, Registration and Complaints Regulations in force 2022
Data Protection Act, 2019
Kenya DPA
Verify details

Section 4 applies the Act to a data controller or processor established or ordinarily resident in Kenya and processing personal data while in Kenya, and — extraterritorially — to one not established or ordinarily resident in Kenya but processing the personal data of data subjects located in Kenya. That second limb is a plain territorial-subject test, so a foreign business handling Kenyan users' data is in scope without any local entity. The Office of the Data Protection Commissioner has been among the more active African regulators, with a mandatory registration regime for controllers and processors above specified thresholds, breach notification within 72 hours, data-protection impact assessments, and published enforcement decisions including monetary penalties. Cross-border transfers require an appropriate safeguard or a specified condition, and certain categories of data are subject to localization requirements under sector rules.

Act No. 24 of 2019, s. 4 (application); Data Protection (General) Regulations, 2021Read regulation →

Children & Minors Protections · 1

November 25, 2019; ODPC Guidance Note issued 2025
Data Protection Act, 2019 — processing of personal data relating to a child
Kenya DPA s. 33
Verify details

s. 33 sets two cumulative conditions, and businesses routinely satisfy only the first: a controller or processor may not process a child's personal data unless consent is given by the child's parent or guardian AND the processing is carried out in a manner that protects and advances the rights and best interests of the child. That second limb is a substantive standard, not a formality — parental consent alone does not make an otherwise child-hostile processing purpose lawful. A child is anyone under 18. s. 33(2) requires appropriate age-verification mechanisms without defining them, a gap the ODPC has since addressed in its 2025 Guidance Note for Processing Children's Data, which is the document to read alongside the section. The ODPC has issued rulings on commercial use of minors' data and image rights, so this is actively enforced rather than dormant.

Act No. 24 of 2019, s. 33; ODPC Guidance Note for Processing Children's Data (2025)Read regulation →

Cross-Border Data Transfer · 1

November 25, 2019 (Act); Regulations in force from February 2022
Data Protection Act, 2019 — transfer of personal data outside Kenya
Kenya DPA ss. 48-50
Verify details

Kenya combines a safeguards test with a residual localisation power, and the two are easy to conflate. s. 48 permits transfer where the controller or processor gives the Data Commissioner proof of appropriate safeguards — in practice, that the destination affords protection at least comparable to the Act's — or where the transfer is necessary for one of the listed grounds (performance of a contract with the data subject or pre-contractual steps, a contract concluded in the data subject's interest, vital interests, or a compelling legitimate interest not overridden by the data subject's rights). s. 49 adds requirements around processing sensitive personal data outside Kenya, and s. 50 empowers a localisation requirement for processing the Cabinet Secretary designates as involving strategic interests of the state or protected critical infrastructure, elaborated at reg. 40 of the 2021 General Regulations. Marked 'check': the interaction between ss. 48 and 49 is reported inconsistently across secondary sources, and the ODPC has continued issuing transfer guidance — read the statutory text and current ODPC guidance directly before designing a transfer route.

Act No. 24 of 2019, ss. 48-50; Data Protection (General) Regulations, 2021, reg. 40Read regulation →

Data Security & Breach Notification · 1

November 25, 2019 (Act); Regulations in force from February 2022
Data Protection Act, 2019 — notification of personal data breach
Kenya DPA s. 43
Verify details

Where personal data has been accessed or acquired by an unauthorised person and there is a real risk of harm to the data subject, the controller must notify the Office of the Data Protection Commissioner without undue delay and in any event within 72 hours of becoming aware, and must communicate with the data subject in writing within a reasonable period unless the identity cannot be established. A late notification to the ODPC must be accompanied by reasons for the delay. In practice the ODPC accepts a preliminary notification inside the 72 hours followed by a fuller one once the investigation confirms details. The notification content requirements are set out at s. 43(4)-(5) and elaborated in the 2021 General Regulations. Marked 'check': the ODPC has continued to issue transfer- and breach-related guidance since the Regulations, which a reviewer should check for the current procedural position.

Act No. 24 of 2019, s. 43; Data Protection (General) Regulations, 2021Read regulation →

Other Africa jurisdictions