Almost every modern business processes personal data: customer phone numbers, employee records, CCTV images, payment details, website analytics, marketing lists and supplier contacts. Kenyan data-protection law turns those everyday activities into an accountable business process.

Compliance begins with purpose

Before collecting personal data, be able to explain what is needed, why it is lawful, who will receive it, how long it will be kept and how the individual can exercise their rights.

01

Who—and what—the law covers

The principal statute is the Data Protection Act, 2019 . It applies to processing by controllers and processors established or ordinarily resident in Kenya and, in specified circumstances, to organisations outside Kenya processing personal data of people located in Kenya.

Personal data is information relating to an identified or identifiable natural person. It extends beyond names and ID numbers to identifiers, location, online activity and other information capable of singling someone out. Sensitive personal data receives heightened protection and includes categories defined by the Act, such as health, biometric, genetic, family and certain belief or identity information.

Processing is broader than collection

Recording, organising, storing, altering, retrieving, consulting, using, disclosing, combining, restricting, erasing and destroying personal data can all amount to processing. A business remains responsible for the data lifecycle—not only the form on which information first arrived.

02

Controller, processor or both?

Data controller

Determines why and how personal data is processed—for example, an employer deciding how employee records will be used.

Data processor

Processes personal data on a controller’s behalf under a contractual relationship and without deciding the purpose and means.

A payroll vendor, cloud host, call centre or marketing platform may act as a processor for one activity and a controller for another. Labels in the contract are not decisive if actual conduct points elsewhere.

Controllers should conduct diligence before appointing processors and use written contracts that address instructions, confidentiality, security, sub-processors, rights requests, breach assistance, audits and return or deletion of data. A processor that goes beyond instructions may assume controller responsibilities for that processing.

03

The principles shape every decision

Section 25 of the Act requires personal data to be processed in accordance with core principles.

  • Lawfulness, fairness and transparency: do not use hidden, misleading or unjustified practices.
  • Purpose limitation: collect for explicit, specified and legitimate purposes and avoid incompatible reuse.
  • Data minimisation: take only what is adequate, relevant and necessary.
  • Accuracy: keep information correct and updated where necessary.
  • Storage limitation: retain identifiable data no longer than necessary for the purpose.
  • Security: protect confidentiality, integrity and availability with appropriate measures.
  • Accountability: be able to demonstrate compliance through decisions, records and controls.

A privacy policy alone cannot cure a process that collects excessive information or uses it for an unrelated purpose.

04

Lawful basis and transparency

Processing needs a lawful basis. Depending on the facts, this may include consent, contractual necessity, legal obligation, vital interests, public interest, official authority or legitimate interests. Sensitive personal data and children’s data engage additional restrictions.

Consent must meet statutory standards and should be specific, informed and capable of withdrawal. Pre-ticked boxes, bundled permissions or making unnecessary marketing consent a condition of service can undermine validity. Organisations should record when, how and what an individual agreed to.

Tell people what is happening

At or before collection, provide clear information about the organisation, purpose, legal basis, categories of data, recipients, safeguards, retention, rights, consequences of not providing data and relevant automated decision-making. Privacy notices should match operational reality across forms, apps, cookies, CCTV, HR and customer channels.

05

Data subjects have enforceable rights

The Act gives individuals rights including to be informed, access their personal data, object to processing, correct false or misleading information and seek deletion of false or misleading data. The General Regulations provide procedures and timelines for handling requests.

IntakeCreate accessible channels and train staff to recognise a rights request in ordinary language.

IdentityVerify the requester proportionately without collecting unnecessary new data.

SearchLocate data across email, paper files, systems, archives and relevant processors.

DecisionApply statutory grounds, exemptions and timelines; document any refusal or limitation.

Automated decisions that significantly affect individuals and direct-marketing activities have specific rules. Businesses using scoring, profiling or AI-assisted decisions should examine the data, logic, impact and human-review pathway before deployment.

06

Registration with the ODPC

Section 18 and the Registration Regulations require controllers and processors to register unless an exemption applies. The exemption is based on both turnover or revenue and number of employees, but specified processing activities remain subject to mandatory registration regardless of size.

Registration certificates are valid for 24 months and must be renewed. Changes to registered particulars must be notified as prescribed. Registration is not proof that every processing activity is lawful; it sits alongside the continuing duties under the Act.

The official ODPC registration portal asks applicants to identify purposes, data categories and safeguards. Map those matters before starting the application.

07

Security, privacy by design and impact assessment

Security should reflect the nature of the data, harm that may result, processing context and available safeguards. Useful controls include least-privilege access, multi-factor authentication, encryption, secure backups, patching, logging, vendor oversight, physical security, staff training and tested deletion.

Privacy by design means considering data protection when a system, product or process is conceived—not after launch. Where processing is likely to result in high risk to individuals, the controller must conduct a data protection impact assessment before processing and follow the statutory process where high residual risk remains.

Appoint a data protection officer where the Act requires one or where the organisation’s risk justifies dedicated oversight. Independence, resources and access to decision-makers matter more than the title alone.

08

Prepare for personal-data breaches

A breach can involve loss, unauthorised access, alteration, disclosure or destruction. It is not limited to hacking: a misdirected email, lost phone, exposed spreadsheet or improperly discarded file can qualify.

  1. Contain: stop continuing exposure without destroying evidence.
  2. Assess: identify data, people, systems, recipients and likely harm.
  3. Escalate: involve leadership, security, legal, communications and affected processors.
  4. Notify: where the Act’s threshold is met, the controller must notify the ODPC without delay and within 72 hours of awareness. Processors have a separate duty to notify the controller without delay and, where reasonably practicable, within 48 hours.
  5. Communicate: notify affected individuals where the breach creates the relevant risk, subject to the Act.
  6. Document and improve: preserve the decision record even where notification is not required.

The ODPC provides an official breach-reporting channel . A written response plan is essential because the statutory clock begins before an organisation has perfect information.

09

International transfers and cloud services

Personal data may leave Kenya through foreign cloud hosting, regional support teams, international group systems, analytics tools or payment platforms. The Act and General Regulations require a lawful transfer mechanism and evidence of appropriate safeguards, with special rules for sensitive personal data.

Map where data is stored, mirrored, accessed and backed up. Review vendor terms, sub-processors, government-access risks, security, rights assistance and deletion. A supplier saying “the cloud” is not a complete transfer assessment.

COMPLIANCE CHECKLIST

Build a working privacy programme

  1. Inventory personal data, purposes, systems, recipients and locations.
  2. Assign controller and processor roles for each activity.
  3. Record the lawful basis and additional conditions for sensitive data.
  4. Publish accurate notices and consent language.
  5. Assess ODPC registration and renewal requirements.
  6. Put processor and data-sharing agreements in place.
  7. Set retention periods and defensible deletion routines.
  8. Implement rights-request and complaint procedures.
  9. Conduct DPIAs for likely high-risk processing.
  10. Test breach response and international-transfer safeguards.

PRIVACY IS AN OPERATING SYSTEM

Make the data map match the business.

Compliance becomes manageable when the organisation knows what it holds, why it holds it and who can reach it.
Find data-protection counsel

FAQ

Frequently asked questions

Does Kenya have a comprehensive data-protection law?

Yes. The Data Protection Act, 2019 establishes rules for processing personal data, rights for individuals and oversight by the Office of the Data Protection Commissioner.

Is consent always required to process personal data?

No. Consent is one lawful basis, but the Act and Regulations recognise other bases. The organisation must identify the correct basis before processing and should not use consent where another basis actually explains the activity.

Must every small business register with the ODPC?

The Registration Regulations contain an exemption based on both turnover and employee thresholds, but that exemption does not apply to specified processing purposes and does not remove substantive compliance duties. The organisation must assess its own activities.

How quickly must a personal-data breach be reported?

Where the statutory notification threshold is met, a controller must notify the Data Commissioner without delay and within 72 hours of becoming aware of the breach. A processor must notify the controller without delay and, where reasonably practicable, within 48 hours.

Can a Kenyan business store personal data outside Kenya?

Cross-border transfers are possible only where the applicable statutory conditions and safeguards are met. Businesses should map cloud hosting, support access and vendor locations rather than treating storage as purely technical.

PRIMARY SOURCES

Read the law and guidance

Legal-information notice: This guide provides general information and is not legal, cybersecurity or compliance advice. Duties depend on the data, purpose, technology, sector and risk. Confirm current requirements with the ODPC and qualified Kenyan advisers.