Kenya DPA 2019
Market regime · Data Protection Act, 2019 (Kenya)
Republic of Kenya
Kenya
2019; ODPC operational 2020, regulations 2021
Office of the Data Protection Commissioner (ODPC)
You process personal data of data subjects in Kenya
Curated, versioned & cross-mapped
The obligation, plainly.
Kenya's Data Protection Act brought a full modern regime: registration of controllers and processors with the ODPC, principles including elements of data localisation, lawful-processing grounds, data-subject rights extending to portability and automated decisions, impact assessments, and breach notification on a 72-hour clock.
The ODPC is among Africa's most active regulators, with a growing casebook of penalties against household-name companies. For anyone operating in East Africa it is the reference privacy regime, and its GDPR-familiar shape makes cross-mapping natural.
Where programmes are tested.
Registration
Controllers and processors above the thresholds registered with the ODPC, and renewed.
Principles and rights
Section 25 principles honoured, and rights, access, correction, portability, objection to automated decisions, answered on time.
DPIAs and breach clocks
Impact assessments for high-risk processing, and the ODPC notified of qualifying breaches within 72 hours.
Section 48 transfers
Cross-border transfers on the Act's grounds, with the safeguards documented.
Curated once, evidenced continuously.
- The Act is curated and cross-mapped beside the NDPA, GDPR and POPIA, one privacy control set serving every African regulator that drew on the same model.
- Requirements resolve to shared controls: implement a control once and it counts toward every framework it maps to.
- Status is evidence-gated: a requirement can't be marked implemented without valid, in-date evidence behind it.
- Every attestation carries maker/checker, and every action lands in an append-only audit trail.
Kenya DPA 2019, asked plainly.
The questions compliance teams actually ask before an adoption decision or an audit.
Who must register with the ODPC?
Controllers and processors meeting the registration regulations' thresholds, set by turnover, headcount and the nature of processing, with sensitive sectors registrable regardless of size. Registration is renewable and the certificate is routinely requested in due diligence.
What is the breach notification deadline?
72 hours to the Commissioner for breaches presenting a real risk of harm, with affected data subjects informed where the risk is high. The assessment behind the decision must be documented, the same discipline the NDPA and GDPR demand.
Does Kenyan law require data localisation?
Not wholesale: the Act allows the Cabinet Secretary to require certain processing to be done in Kenya, and specific rules, notably in payments and government data, impose local requirements. Transfers otherwise run through section 48's grounds: adequacy, safeguards or consent.
Does the Act reach companies outside Kenya?
Yes, where they process personal data of data subjects located in Kenya. Foreign digital businesses serving the Kenyan market are squarely in scope, and the ODPC's enforcement record shows it acts on complaints against them.
Where it connects.
The full catalogCompliance you can prove.
Walk into your next audit ready.
Book a working demo. We'll map your obligations to the standards you're audited against and the regulators you actually answer to.
The platform, modules, catalog, audit trail and security architecture are live today; the continuous live-evidence engine is in active development, shown in a working demo. Reach us at hello@cardinalgrc.com.