WorldPrivacyAtlas
Laws by country

Children & Minors Protections

Data Protection Act, 2019 — processing of personal data relating to a child

Kenya DPA s. 33

Kenya · November 25, 2019; ODPC Guidance Note issued 2025

Verify details

s. 33 sets two cumulative conditions, and businesses routinely satisfy only the first: a controller or processor may not process a child's personal data unless consent is given by the child's parent or guardian AND the processing is carried out in a manner that protects and advances the rights and best interests of the child. That second limb is a substantive standard, not a formality — parental consent alone does not make an otherwise child-hostile processing purpose lawful. A child is anyone under 18. s. 33(2) requires appropriate age-verification mechanisms without defining them, a gap the ODPC has since addressed in its 2025 Guidance Note for Processing Children's Data, which is the document to read alongside the section. The ODPC has issued rulings on commercial use of minors' data and image rights, so this is actively enforced rather than dormant.

Act No. 24 of 2019, s. 33; ODPC Guidance Note for Processing Children's Data (2025)Read regulation →

This is a general reference, not legal advice or a determination that this law applies to your specific business. Run the full questionnaire to check against your actual presence, activities, and data types.