TerraLex Guide to Data Protection

Welcome to the Terralex cross-border guide to data protection

Data protection continues to be a top issue for companies around the globe. With the ever-changing technology and responding legislation, it is important that businesses be prepared to handle a patchwork of data protection regulations. This guide, prepared by TerraLex members from around the globe, provides initial guidance on some of the key aspects to consider.

How to Use: You can use the tools below to create bespoke reports for the jurisdiction(s) and topic(s) covered. Click into single jurisdiction for one location or use the compare tool to compare multiple jurisdictions. Select the jurisdictions and topics of interest to create your unique report. You also have the option to print or download using the ellipsis button in the top right corner.

Kenya TerraLex Guide to Data Protection Guide

Date posted:
30/04/2026
Last update:
06/06/2023

Legislation and regulations

What national laws regulate the processing of personal data in your jurisdiction?

The Data Protection Act, 2019 (DPA) is the main legislation regulating personal data processing in Kenya. It was enacted to give effect to Article 31(c) of the Constitution of Kenya, 2010 which provides for the constitutional right to privacy. In addition to the provisions of the DPA, the following regulations came into effect in 2022 to supplement the DPA.

(i) The Data Protection (General) Regulations, 2021 which provide for interalia the rights of data subjects, processing of personal data, restrictions on the commercial use of personal data, personal data breaches, elements of data protection by design or default, data protection impact assessment, obligations of Data Processors and controllers and exemptions under the DPA.

(ii) The Data Protection (Complaints Handling Procedure and Enforcement) Regulations, 2021 which provide for the procedure of lodging complaints, admission and response to complaints and the enforcement of the DPA; and

(iii) The Data Protection (Registration of Data Controllers and Data Processors) Regulations, 2021 which provide guidance on the registration of Data Controllers and Data Processors.

To whom do the laws apply?

The DPA is applicable to all Data Controllers (a natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purpose and means of Processing of Personal Data) and Data Processors (a natural or legal person, public authority, agency, or other body which processes Personal Data on behalf of the Data Controller). The DPA applies to use of automated or non-automated means by or for a Data Controller or Data Processor who is established or ordinarily resident in Kenya and processes personal data while in Kenya; or is not established or ordinarily resident in Kenya but processing personal data of data subjects located in Kenya – section 4 of the DPA.

Scope of protection

What type of data is covered by the law?

The DPA covers personal data which includes sensitive personal data. Section 2 of the DPA defines personal data as any information relating to an identified or identifiable natural person and sensitive personal data means data revealing the natural person’s race, health status, ethic social origin, conscience, belief, genetic data, biometric data, personal details, marital status, family details including names of person’s children, parents, spouse or spouses, sex, or the sexual orientation of the data subject.

What are the main exemptions (if any)?

(i) General Exemption: The processing of personal data is exempt from the provisions of the DPA if - it relates to processing of personal data by an individual in the course of a purely personal or household activity – section 51(2(a) of the DPA;

  • if the same is necessary for national security. A Data Controller or Data Processor who processes personal data for national security and wishes to be exempt on that ground is required to apply to the Cabinet Secretary for an exemption. The Cabinet Secretary shall, upon being satisfied that the grounds supporting the application are sufficient, issue a certificate of exemption section 51(2)(b) of the DPA and Regulation 54;
  • on grounds of public interest where such processing exists as a permitted general situation; or permitted health situation – section 51(2)(b) of the DPA. A permitted general situation means collection, use or disclosure by a data controller or data processor of personal data about data subject including for (a) lessening or preventing a serious threat to the life, health or safety of any data subject, or to public health or safety; (b) taking appropriate action in relation to suspected unlawful activity or serious misconduct; (c) locating a person reported as missing; (d) asserting a legal or equitable claim;(e) conducting an alternative dispute resolution process; or (f) performing diplomatic or consular duties. A permitted health situation means collection, use or disclosure by a data controller or data processor of personal data about a data subject, including for— (a) the collection of health information to provide a health service; (b) the collection, use, or disclosure of health data is for health research and related purposes; (c) the use or disclosure of genetic information where necessary and obtained in course of providing a health service; (d) the disclosure of health information for a secondary purpose to a responsible person for a data subject. - Regulation 55, 56 and 57; and its disclosure is required under any written law or an order of the court – section 51(2)(c).

(ii) Journalism, literature, and art: The principles of processing personal data do not apply where:

  • processing is undertaken by a person for the publication of a literary or artistic material;
  • a Data Controller reasonably believes that publication would be in the public interest and where it can be demonstrated that the processing is in compliance with any self-regulatory or issued code of ethics in practice and relevant to the publication in question; and
  • a Data Controller reasonably believes that, in all the circumstances, compliance with the provision is incompatible with the special purposes. The Data Commissioner is required under the DPA to prepare a code of practice containing practical guidance in relation to the processing of personal data for purposes of Journalism, Literature and Art – section 52 of the DPA.

(iii) Research, history, and statistics: Personal data which is processed only for research purposes is exempt from -the provisions of the DPA – section 53 of the DPA. if

  • the data is processed in compliance with the relevant conditions; and
  • results of the research or resulting statistics are not made available in a form which identifies the data subject or any of them.

The Data Commissioner is required under the DPA to prepare a code of practice containing practical guidance in relation to the processing of personal data for purposes of Research, History and Statistics.

(iv) Exemptions by the Data Commissioner: The DPA may prescribe other instances where compliance with certain provisions of the DPA may be exempted – section 54.

What rights do the laws grant to the data owners?

Under sections 26,32(2),35(1),36, 38 and 40 of the DPA, data owners have the right to; (i)To be informed of the use to which their personal data is to be put;

(ii) To access their personal data in custody of Data Controller or Data Processor;

(iii) To object to the processing of all or part of their personal data;

(iv)To correction of false or misleading data; and

(v) To deletion of false or misleading data about them.

(vi) right to know the identity of the third parties to whom their personal data has been or will be transferred to;

(vii) right to withdraw their consent at any time;

(viii) right not to be subject to a decision based solely on automated processing, including profiling produces legal effects concerning or significantly affects the data subject;

(ix) right to object to the processing of their personal data, unless the Data Controller or Data Processor demonstrates compelling legitimate interest for the processing which overrides the data subject's interests, or for the establishment, exercise or defence of a legal claim;

(x) right to data portability which includes the right to:

  • receive personal data concerning them in a structured, commonly used, and machine-readable format;
  • transmit their personal data obtained from in a structured, commonly used, and machine-readable format from one Data Controller or Data Processor to another Data Controller or Data Processor without any hindrance;
  • have their personal data transmitted directly from one Data Controller or processor to another, where technically feasible.

The rights of a data subject are not absolute and can be limited where a Data controller or Data Processor demonstrates a compelling legitimate interest which overrides the data subject’s interest. Notably, under Regulation 12 of the Data Protection (General) Regulations, the right of erasure does not apply where processing of the personal data is necessary:

  • to exercise the right of freedom of expression and information;
  • to comply with a legal obligation;
  • to perform a task carried out in the public interest or in the exercise of official authority;
  • for achieving purposes in the public interest;
  • for scientific research, historical research, or statistical purposes; or
  • for the establishment, exercise, or defense of a legal claim.

Processing requirement and main obligations

What are the lawful grounds for processing personal data or sensitive personal data (if different)?

There is lawful basis through which a data controller or data processor may process personal data. Consent is the most common basis upon which data controllers or data processors process personal data. Other alternative lawful basis applies in the instance where there is a legal basis laid down by law or a legitimate reason overriding the consent requirement. These include:

  1. Undertaking a legal obligation;
  2. Public interest;
  3. Historical, statistical, journalistic, literature and art or Scientific research purposes;
  4. For the performance of a contract;
  5. Public Authority; and
  6. Vital interest.

What are the main obligations imposed by the law?

The obligations for processing Personal data under section 25 of the DPA are to ensure that the personal data is: 1. processed fairly, lawfully, and transparently in relation to any data subject; 2. collected for specified, explicit and legitimate purposes and not further processed in a manner incompatible with those purposes; 3. adequate, relevant, and limited to what is necessary in relation to the purposes for which it is processed; 4. collected only where a valid explanation is provided whenever information relating to family or private affairs is required; 5. Accurate, and where necessary kept to date with every reasonable step being taken to ensure that any inaccurate personal data is erased or rectified without delay; 6. Kept in a form which identifies the data subjects for no longer than is necessary for the purposes which it was collected; 7. not transferred outside Kenya, unless there is proof of adequate data protection safeguards or consent from the data subject.

Do the laws establish a data retention period to be observed?

The DPA under section 25(g) establishes the principle of storage limitation which requires that personal data should not be kept for longer than is necessary for the purposes of collection. Failing to define retention limits is a violation of the Act. Under the Regulations, Data Controllers or Data Processors are required to establish a data retention schedule with appropriate time limits for review of the need for continued storage. Periodic audits of the data retained are also required. Upon lapse of the purpose for which the personal data was collected, a Data Controllers or Data Processor is required to erase, delete, anonymise or pseudonymise the personal data retained.

Must the data processing activities be recorded under the law?

“Processing” under the Data Protection Act means any operation or set of operations which is performed on personal data or on sets of personal data whether or not by automated means, such as (a) collection, recording, organization, structuring; (b) storage, adaptation or alteration; (c) retrieval, consultation or use; (d) disclosure by transmission, dissemination, or otherwise making available; or (e) alignment or combination, restriction, erasure or destruction.

There is no specific requirement under the Data Protection Act to record processing activities. However, in order for a Data Controller or Data Processor to comply with their obligations under the Data Protection Act and other laws, it is important to keep a record of processing activities. Some of the laws which necessitate keeping a record of processing activities are:

  1. The Kenya Employment Act requires employers to keep written particulars of employment for a period of 5 years after termination of employment. These written particulars are; name, age and permanent address of the employee, name of the employer, job description, date of commencement of employment, form and duration of the contract, place of work and hours of work, remuneration, the interval of payment of remuneration and date of commencement of continuous employment. These written particulars shall also state any terms or conditions relating to entitlement to annual leave, public holidays, holiday pay, sickness and sick pay, and pensions and pension schemes.
  2. Under the Kenya Citizenship and Immigration Act, 2011, employers employing foreign nationals are required to keep immigration records for 2 years after the termination of such employment.
  3. The Tax Procedures Act requires taxpayers to keep records for a period of 5 years from the end of the reporting period to which such records relate.
  4. The minimum retention period for directors’ meetings and minutes is 7 years.
  5. The Limitation of Actions Act Cap 22 under section 4 (1) provides that the limitation period within which to bring claims for breach of contract is 6 years. It is therefore prudent to keep records of processing activities for contractual matters for 6 years in case they are required as evidence in a suit.

National authority and DPO

Is there a Data Protection National Authority? If so, what is the National Authority main role?

Yes. The Office of the Data Protection Commissioner Kenya whose main role is to oversee the implementation and enforcement of the DPA.

Does the law impose the obligation of designating a data protection officer (DPO)? If so, what is the role of the DPO under the law?

List: - The DPA under section 24 of the DPA makes a provision for the designation of Data Protection Officers (DPOs) but this obligation is not mandatory. The law does not impose an obligation for the appointment of a Data Protection Officer. Where a Data Controller or Data Processor designates a DPO, they are required to publish the contact details of the data protection officer on the website and communicate them to the Data Commissioner who shall ensure that the same information is available on the official website. The DPA provides that a Data Controller or Data Processor should consider appointing a Data Protection Officer if; the Data Controller or Data Processor is a public or private body, except for courts acting in their judicial capacity;

  • the core activities of the Data Controller or Data Processor involve, the processing of data which by virtue of its nature, scope, or purpose, require regular and systematic monitoring of data subjects;
  • The core activities of the Data Controller or Data Processor require processing of sensitive categories of personal data.

(ii) The role of the DPO is to:

  • advise the Data Controller or Data Processor or their employees of data processing requirements provided under the DPA;
  • ensure on behalf of the Data processor or Data Controller that the DPA is complied with;
  • facilitate capacity building of staff involved in data processing activities;
  • advise on data protection impact assessment; and
  • co-operate with the Data Commissioner on any matters relating to data protection.

Cross-border transfers

What rules regulate the transfer of data outside your jurisdiction?

Cross-border transfers of personal data are regulated under the DPA. The relevant provisions under the DPA under sections 48 and 49 of the DPA and Regulations 39,40,41,42,43, 44, 45, 46,47 and 48 of the Data Protection (General) Regulations. The Data Protection (General) Regulations under Regulation 40 provides that personal data can only be transferred out of Kenya if certain requirements are met. That is:

(i) That the Data Controller or Data Processor has given adequate proof to the Office of the Data Protection Commissioner on adequate safeguards on data security and protection of the personal data including proving that the jurisdictions have commensurate data protection laws;

(ii) The Office of the Data Protection Officer has issued an adequacy decision on the receiving jurisdiction.

(iii) The transfer is necessary:

  • to exercise he right of freedom of expression and information;
  • To comply with a legal obligation;
  • To perform a task carried out in the public interest or in the exercise of official authority;
  • For achieving purposes in the public interest
  • For scientific research, historical research, or statistical purposes; or
  • For the establishment, exercise, or defense of a legal claim;

(iv) . That the consent of the data subject has been obtained.

Is it necessary to notify the National Authority prior to the international transfer?

There is a legal requirement for an adequacy decision by the Data Commissioner that the other country or territory or one or more specified sectors within that other country or the international organization ensures an adequate level of protection of personal data. To rely on this basis, the Data Processor or controller has to notify the Office of the Data Protection Commissioner for the approval before any transfer can be made.

Security standards, data breaches, and sanctions

Do the laws impose any information security standards and/or requirements?

Yes. Under section 41 of the DPA, every Data Processor or Data Controller must implement appropriate technical and organisational measures to effectively implement the data processing principles and integrate necessary safeguards for data processing. The Data Protection (General) Regulations also provide specific obligations in relation to security under the data protection principle of integrity, confidentiality, and availability.

Do the laws establish any kind of mandatory notification duty?

Section 43 of the DPA requires a Data Processor to notify the Data Controller without delay within 48 hours of becoming aware of a breach. The Data Controller must then notify the Office of the Data Protection Commissioner without delay within 72 hours of becoming aware of the breach. The Office of the Data Protection Commissioner has created a data breach notification platform on its website for these purposes.

What are the sanctions for noncompliance with data protection laws?

(i) Section 58 enforcement notice: Where the Data Commissioner is satisfied that a person has failed, or is failing, to comply with any provision of the DPA, the Data Commissioner may serve an enforcement notice on that person requiring that person to take such steps and within such period as may be specified in the notice. Failure to comply with an enforcement notice is an offence and the offender is liable on conviction to a fine not exceeding Kenyan Shillings five million shillings or to imprisonment for a term not exceeding two years, or to both. The maximum amount of the penalty that may be imposed by the Data Commissioner in a penalty notice is up to five million shillings, or in the case of an undertaking, up to one per centum of its annual turnover of the preceding financial year, whichever is lower.

(ii) Section 73 of the DPA provides that any person who contravenes the Act, shall on conviction, be liable to a fine not exceeding Kenyan Shillings three million shillings or an imprisonment term not exceeding ten years or both.

(iii) In addition to the penalty, court may also:

  • order the forfeiture of any equipment or any article used or connected in any way with the commission of an offense.
  • order or prohibit the doing of an act to stop a continuing contravention.
  • issue an entry and search warrant to the Data Commissioner to may enter and search any premises for the purpose of discharging any function or exercising any power under this Act.
  • grant the Data Commissioner a preservation order for the expeditious preservation of personal data including traffic data, where there are reasonable grounds to believe that the data is vulnerable to loss or modification.

Other comments

Other comments

N/A

Disclaimer: This guide contains summaries of general principles of law. It is not a substitute for specific legal advice and should not be relied upon in relation to the application of the law or subject matter covered.