WorldPrivacyAtlas
Laws by country

Comprehensive Privacy Law

Data Protection Act, 2019

Kenya DPA

Kenya · November 25, 2019 (Act); General, Registration and Complaints Regulations in force 2022

Verify details

Section 4 applies the Act to a data controller or processor established or ordinarily resident in Kenya and processing personal data while in Kenya, and — extraterritorially — to one not established or ordinarily resident in Kenya but processing the personal data of data subjects located in Kenya. That second limb is a plain territorial-subject test, so a foreign business handling Kenyan users' data is in scope without any local entity. The Office of the Data Protection Commissioner has been among the more active African regulators, with a mandatory registration regime for controllers and processors above specified thresholds, breach notification within 72 hours, data-protection impact assessments, and published enforcement decisions including monetary penalties. Cross-border transfers require an appropriate safeguard or a specified condition, and certain categories of data are subject to localization requirements under sector rules.

Act No. 24 of 2019, s. 4 (application); Data Protection (General) Regulations, 2021Read regulation →

This is a general reference, not legal advice or a determination that this law applies to your specific business. Run the full questionnaire to check against your actual presence, activities, and data types.