Data Security & Breach Notification
Data Protection Act, 2019 — notification of personal data breach
Kenya · November 25, 2019 (Act); Regulations in force from February 2022
Verify detailsWhere personal data has been accessed or acquired by an unauthorised person and there is a real risk of harm to the data subject, the controller must notify the Office of the Data Protection Commissioner without undue delay and in any event within 72 hours of becoming aware, and must communicate with the data subject in writing within a reasonable period unless the identity cannot be established. A late notification to the ODPC must be accompanied by reasons for the delay. In practice the ODPC accepts a preliminary notification inside the 72 hours followed by a fuller one once the investigation confirms details. The notification content requirements are set out at s. 43(4)-(5) and elaborated in the 2021 General Regulations. Marked 'check': the ODPC has continued to issue transfer- and breach-related guidance since the Regulations, which a reviewer should check for the current procedural position.
This is a general reference, not legal advice or a determination that this law applies to your specific business. Run the full questionnaire to check against your actual presence, activities, and data types.