WorldPrivacyAtlas
Laws by country

Data Security & Breach Notification

Data Protection Act, 2019 — notification of personal data breach

Kenya DPA s. 43

Kenya · November 25, 2019 (Act); Regulations in force from February 2022

Verify details

Where personal data has been accessed or acquired by an unauthorised person and there is a real risk of harm to the data subject, the controller must notify the Office of the Data Protection Commissioner without undue delay and in any event within 72 hours of becoming aware, and must communicate with the data subject in writing within a reasonable period unless the identity cannot be established. A late notification to the ODPC must be accompanied by reasons for the delay. In practice the ODPC accepts a preliminary notification inside the 72 hours followed by a fuller one once the investigation confirms details. The notification content requirements are set out at s. 43(4)-(5) and elaborated in the 2021 General Regulations. Marked 'check': the ODPC has continued to issue transfer- and breach-related guidance since the Regulations, which a reviewer should check for the current procedural position.

Act No. 24 of 2019, s. 43; Data Protection (General) Regulations, 2021Read regulation →

This is a general reference, not legal advice or a determination that this law applies to your specific business. Run the full questionnaire to check against your actual presence, activities, and data types.