InsightsNavigating Kenya's Data Protection Act: What Businesses Must Do Now
Data Protection10 March 2026

Navigating Kenya's Data Protection Act: What Businesses Must Do Now

The Data Protection Act, 2019 has fundamentally changed how organisations in Kenya collect, process, and store personal data. With enforcement now in full effect, compliance is no longer optional.

7 min read

Disclaimer: This article is provided for general informational purposes only and does not constitute legal advice. The information may not reflect the most current legal developments. No reader should act or refrain from acting on the basis of this article without seeking professional legal advice. LHK & Company Advocates expressly disclaims all liability in respect of actions taken or not taken based on the contents of this article.

01

The Data Protection Landscape in Kenya

Kenya's Data Protection Act, 2019 (DPA) established the Office of the Data Protection Commissioner (ODPC) as the primary regulatory authority overseeing data privacy in the country. Since its commencement, the ODPC has issued guidelines, registered data controllers and processors, and begun enforcement activities.

The DPA applies to any organisation that collects, processes, or stores personal data of individuals in Kenya, regardless of whether the organisation itself is based in Kenya. This extra-territorial reach means that international companies serving Kenyan customers must also comply.

Recent amendments and subsidiary regulations have further clarified obligations around data breach notification, cross-border data transfers, and the rights of data subjects. Organisations that have not updated their practices since the Act's initial passage should conduct a fresh compliance assessment.

02

Key Compliance Obligations for Businesses

Registration with the ODPC is mandatory for all data controllers and data processors. Failure to register constitutes an offence and can attract significant penalties. Businesses must complete the registration process through the ODPC's online portal, providing details of the data they handle and the purposes for which it is processed.

Organisations must implement appropriate technical and organisational security measures to protect personal data. This includes encryption, access controls, regular security audits, and staff training on data handling procedures. The standard of protection must be proportionate to the sensitivity of the data.

Data subjects have extensive rights under the DPA, including the right to be informed, access their data, rectify inaccuracies, object to processing, and request deletion. Businesses must have processes in place to respond to these requests within the timeframes prescribed by law.

03

Cross-Border Data Transfers

Transferring personal data outside Kenya is only permitted if the recipient country or organisation provides adequate data protection safeguards. The ODPC has issued guidance on what constitutes adequate protection, and organisations relying on cross-border transfers should review their arrangements carefully.

Standard contractual clauses, binding corporate rules, and explicit consent from data subjects are among the mechanisms that can be used to legitimise cross-border transfers. However, the specific requirements vary depending on the nature of the data and the destination country.

04

Enforcement and Penalties

The ODPC has the power to conduct investigations, issue enforcement notices, and impose substantial fines for non-compliance. Penalties can include fines of up to KES 5 million or imprisonment of up to ten years for serious offences.

Beyond regulatory penalties, non-compliance with the DPA can expose businesses to civil liability from affected data subjects. Reputational damage from data breaches or privacy violations can also have significant commercial consequences. The message is clear: proactive compliance is both a legal obligation and a business imperative.

In This Article

01The Data Protection Landscape in Kenya
02Key Compliance Obligations for Businesses
03Cross-Border Data Transfers
04Enforcement and Penalties

Need Expert Advice?

Get personalised guidance on how these developments affect you or your business.

Free Consultation

The content of this article is intended for general informational purposes and should not be construed as legal advice or a legal opinion on any specific facts or circumstances. You are advised to consult with a qualified lawyer for advice regarding your individual situation.

This Article is for Information Only

Every legal situation is unique. For advice specific to your circumstances, contact us for a free initial consultation.

Speak to a Lawyer