Kenya DPA 2019

Kenya's data-protection law: registration, GDPR-shaped rights, and a commissioner who enforces.

Market regime · Data Protection Act, 2019 (Kenya)

Issued by

Republic of Kenya

Region

Kenya

Effective

2019; ODPC operational 2020, regulations 2021

Oversight

Office of the Data Protection Commissioner (ODPC)

Applies when

You process personal data of data subjects in Kenya

In the catalog

Curated, versioned & cross-mapped

The obligation, plainly.

Kenya's Data Protection Act brought a full modern regime: registration of controllers and processors with the ODPC, principles including elements of data localisation, lawful-processing grounds, data-subject rights extending to portability and automated decisions, impact assessments, and breach notification on a 72-hour clock.

The ODPC is among Africa's most active regulators, with a growing casebook of penalties against household-name companies. For anyone operating in East Africa it is the reference privacy regime, and its GDPR-familiar shape makes cross-mapping natural.

Where programmes are tested.

01

Registration

Controllers and processors above the thresholds registered with the ODPC, and renewed.

02

Principles and rights

Section 25 principles honoured, and rights, access, correction, portability, objection to automated decisions, answered on time.

03

DPIAs and breach clocks

Impact assessments for high-risk processing, and the ODPC notified of qualifying breaches within 72 hours.

04

Section 48 transfers

Cross-border transfers on the Act's grounds, with the safeguards documented.

Curated once, evidenced continuously.

  • The Act is curated and cross-mapped beside the NDPA, GDPR and POPIA, one privacy control set serving every African regulator that drew on the same model.
  • Requirements resolve to shared controls: implement a control once and it counts toward every framework it maps to.
  • Status is evidence-gated: a requirement can't be marked implemented without valid, in-date evidence behind it.
  • Every attestation carries maker/checker, and every action lands in an append-only audit trail.

Kenya DPA 2019, asked plainly.

The questions compliance teams actually ask before an adoption decision or an audit.

Who must register with the ODPC?

Controllers and processors meeting the registration regulations' thresholds, set by turnover, headcount and the nature of processing, with sensitive sectors registrable regardless of size. Registration is renewable and the certificate is routinely requested in due diligence.

What is the breach notification deadline?

72 hours to the Commissioner for breaches presenting a real risk of harm, with affected data subjects informed where the risk is high. The assessment behind the decision must be documented, the same discipline the NDPA and GDPR demand.

Does Kenyan law require data localisation?

Not wholesale: the Act allows the Cabinet Secretary to require certain processing to be done in Kenya, and specific rules, notably in payments and government data, impose local requirements. Transfers otherwise run through section 48's grounds: adequacy, safeguards or consent.

Does the Act reach companies outside Kenya?

Yes, where they process personal data of data subjects located in Kenya. Foreign digital businesses serving the Kenyan market are squarely in scope, and the ODPC's enforcement record shows it acts on complaints against them.

Compliance you can prove.
Walk into your next audit ready.

Book a working demo. We'll map your obligations to the standards you're audited against and the regulators you actually answer to.

The platform, modules, catalog, audit trail and security architecture are live today; the continuous live-evidence engine is in active development, shown in a working demo. Reach us at hello@cardinalgrc.com.