Kenya's Data Protection Act 2019 (DPA) is one of Africa's most comprehensive data protection frameworks. The Office of the Data Protection Commissioner (ODPC) has moved firmly into an enforcement phase in 2026, with structured regulatory scrutiny and increasing accountability for organisations processing the personal data of Kenyan individuals.
Who does the Kenya Data Protection Act apply to?
The DPA applies to any organisation that collects, holds, processes, or stores personal data in Kenya, or the personal data of individuals within Kenya. Its extraterritorial scope is broad: foreign companies offering goods or services to Kenyan residents, or monitoring their behaviour online, are within scope regardless of where they are established.
Mandatory registration with the ODPC applies to all data controllers and processors. Any person acting as a data controller or processor must be registered, and registration must be renewed every 24 months. Certain sectors – including financial services, healthcare, and telecommunications – must register regardless of their size. Data controllers and processors with annual revenue below KES 5 million and fewer than 10 employees are exempt from registration, unless they operate in a mandatory sector.
What are the key obligations under the Kenya DPA?
Organisations must process personal data on a lawful basis. The six available bases – consent, contractual necessity, legal obligation, vital interests, public interest, and legitimate interests – mirror the GDPR structure. Valid consent must be freely given, specific, informed, and unambiguous. A Data Protection Amendment Bill 2025 has proposed strengthening the fines structure, replacing the current "whichever is lower" formula with "whichever is higher" for administrative penalties.
Cross-border transfers are only permitted where the receiving country or organisation provides an adequate level of protection equivalent to that guaranteed by the DPA. For sensitive personal data, explicit consent is additionally required. Data localisation obligations apply in certain circumstances under Section 50.
Breach notification follows a 72-hour timeline for high-risk breaches, consistent with the GDPR approach.
What Data Protection Officer obligations apply?
The DPA provides for the appointment of a DPO, using permissive rather than mandatory language in contrast to GDPR. However, the ODPC's guidance and enforcement practice have treated DPO designation as a practical expectation for organisations processing personal data at scale. A DPO provides the formal liaison point with the ODPC and carries accountability for the organisation's data protection compliance programme.
How has the ODPC enforced the Act?
The ODPC entered a more assertive enforcement phase in 2025 and 2026. During 2025, Kenyan organisations collectively paid over KES 30 million in compensation for privacy violations. The ODPC demonstrated willingness to act on individual complaints – awarding KES 500,000 in compensation to a former employee whose right to erasure was ignored by a major service provider.
The ODPC conducted nationwide compliance inspections and introduced a 90-day window for complaint resolution. The 2025 Data Privacy Conference in Mombasa signalled the regulator's intention to expand its enforcement capacity, improve audit practices, and align more closely with the African Union Convention on Cyber Security and Personal Data Protection.
The proposed Data Protection Amendment Bill 2025 would substantially increase penalty levels if enacted, bringing them closer to GDPR-scale sanctions.
What this means for your organisation
- The ODPC has moved from awareness-building to active enforcement. Compliance is no longer a future planning obligation – it is a current operational requirement.
- The extraterritorial scope of the Kenya DPA is broad. If you offer services to Kenyan residents online or monitor their behaviour, you are within scope regardless of where you are based.
- The proposed Data Protection Amendment Bill 2025, if enacted, will increase penalty levels substantially – replacing the current lower-of formula with a higher-of formula that more closely resembles GDPR-scale sanctions.
- Registration with the ODPC is mandatory for most organisations processing personal data in Kenya. It is a legal requirement, not an optional step.
What you should do now
- Confirm whether your organisation processes the personal data of individuals in Kenya, including through online services, and assess whether registration with the ODPC is required.
- Identify the lawful basis for each processing activity involving Kenyan data and document the analysis.
- Review your cross-border transfer arrangements for Kenyan data – transfers outside Kenya require adequate safeguards, and transfers of sensitive data require explicit consent.
- Assess whether a DPO designation is appropriate for your scale of processing, given ODPC enforcement practice.
- Monitor the Data Protection Amendment Bill 2025 for enactment – the proposed penalty changes will materially affect the risk profile of non-compliance.
How Priventia helps
Priventia's Regulatory Intelligence layer covers the Kenya Data Protection Act alongside NDPA and POPIA, mapping multi-jurisdiction African obligations in a single assessment. Organisations can identify where African regulatory requirements align with GDPR and where additional or stricter obligations apply.