Kenya
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.
If you collect data about people in Kenya — customers, users, employees — these are the rules you have to follow. Here is the short version.
The short version
Kenya has a real privacy law, and a regulator that really works. Data may leave the country. But you must show the destination protects it about as well as Kenya does, or the person must clearly agree. Some data must stay. Anything used for identity records, elections, public money, basic schooling or front-line health care needs at least one live copy on a server inside Kenya.
Data governance in Kenya
The eight things that decide how you handle data about people in Kenya. Same eight on every country page, so you can compare.
Who has to follow these rules
Yes. The law reaches a company with no office and no staff in Kenya, as long as it handles data about people who are in Kenya. There is no revenue or headcount level that gets you out of the law itself. Size only decides whether you must also put your name on the regulator's public register. You can skip registering if you are small. That means turnover under five million Kenyan shillings a year (roughly 38,000 United States dollars), and fewer than ten staff. That let-off disappears if you work in one of twelve listed activities. Those include gambling, financial services, telephone and internet services, health, education, transport, direct marketing and anything involving genetic data. Kenya does not make you appoint a local representative.
- What you have to do here:
- Register or notify
The Data Protection Act, No. 24 of 2019 (consolidated as Cap. 411C), section 4, applies in two situations. It applies if you are set up or normally living in Kenya and you handle personal data in Kenya. It also applies if you are not set up or normally living in Kenya, but you handle personal data about people located in Kenya. The registration thresholds sit in the Data Protection (Registration of Data Controllers and Data Processors) Regulations, 2021, regulation 13(2) and (4). The twelve override categories are in the Third Schedule. A registration certificate lasts twenty-four months. Fees run from 4,000 shillings for a micro or small business to 40,000 shillings for a large one, with lower renewal fees. Unlike the European Union, the Kenyan regulations do not make a foreign company appoint a local representative. That looks like a real gap, but we cannot confirm it either way.
Sources
- Official sourceOffice of the Data Protection CommissionerData Protection Act, No. 24 of 2019, section 4 (application)
odpc.go.ke
“not established or ordinarily resident in Kenya, but processing personal data of data subjects located in Kenya”
Link checked 18 August 2026
- Official sourceOffice of the Data Protection CommissionerData Protection (Registration of Data Controllers and Data Processors) Regulations, 2021, regulation 13 and Third Schedule
odpc.go.ke
“annual turnover of below five million shillings or annual revenue of below five million shillings”
Link checked 18 August 2026
Where the data is allowed to live
Mostly yes, with homework. Then there are six exceptions. In general you may send personal data abroad if you can show the recipient is bound to protect it about as well as Kenya does. Or the person can say yes after being told the risks. Sensitive data, such as health or biometric records, always needs that explicit yes. But six purposes are different. They are identity and civil registration, elections, and public finance systems. They also cover systems the government has declared protected, early-years and basic schooling, and primary and secondary health care. For those six, a working copy has to live on a server inside Kenya. You can still hold a second copy abroad. Kenya's telephone and internet companies are pulled in through the 'protected systems' door.
- What you have to do here:
- Keep the data in the country
The general answer is conditional, not open. There is always something to put in place before data leaves. The location rules come from regulation 26 of the Data Protection (General) Regulations, 2021, made under section 50 of the Act. Regulation 26(1) gives you a choice. You either handle the data 'through a server and data centre located in Kenya'. Or you 'store at least one serving copy of the concerned personal data in a data centre located in Kenya'. So these are mirror rules, not full bans. A foreign copy stays lawful. Sector by sector, verified today. Government and public administration. Mirror rule. It covers civil registration and legal identity, elections, and public finance administration. Education. Mirror rule, limited to early childhood and basic education. Health. Mirror rule, limited to primary and secondary health care. The regulator's own health guidance goes further. It says it expects health data to be stored and handled in Kenya, unless the patient explicitly consents to a transfer. Telecoms and internet. A mirror rule in reality. The regulator's guidance for the communications sector says most service providers are protected computer systems. That is under the Computer Misuse and Cybercrimes Act. So they must follow regulation 26. Banking and payments. We found no rule on the Central Bank's own site requiring data to stay in Kenya, checked 18 August 2026. The Central Bank's prudential guidelines list an outsourcing guideline, but we could not open its text. Insurance, securities, gambling, mapping and defence. We found no rule on an official government website, checked 18 August 2026. Treat these as unresearched rather than settled. The telecoms subscriber rules were re-made in 2025. They say nothing at all about where data is stored or how long it is kept.
Sources
- Official sourceOffice of the Data Protection CommissionerData Protection (General) Regulations, 2021 (Legal Notice No. 263), regulation 26 — requirement for specified processing to be done in Kenya
odpc.go.ke
“shall (a) process such personal data through a server and data centre located in Kenya; or (b) store at least one serving copy of the concerned personal data in a data centre located in Kenya.”
Link checked 18 August 2026
- Official sourceOffice of the Data Protection CommissionerData Protection Act, No. 24 of 2019, section 50 — the power behind the localisation rule
odpc.go.ke
“through a server or a data centre located in Kenya”
Link checked 18 August 2026
- Official sourceOffice of the Data Protection CommissionerODPC Guidance Note for the Communication Sector — extends the localisation rule to telecoms via 'protected computer systems'
odpc.go.ke
“the service provider must process the data through a server and data centre located in Kenya or store at least one serving copy of the concerned personal data in a data centre located in Kenya.”
Link checked 18 August 2026
- Official sourceOffice of the Data Protection CommissionerODPC Guidance Note on the Processing of Health Data
odpc.go.ke
“personal data is stored and processed in Kenya, except in limited circumstances such as where the data subject has given explicit consent to the transfer”
Link checked 18 August 2026
- Official sourceCommunications Authority of KenyaKenya Information and Communications (Registration of Telecommunications Services Subscriber) Regulations 2025 (Legal Notice No. 90) — checked for localisation and found none
ca.go.ke
Link checked 18 August 2026
What to do: Plan for a database inside Kenya: this data is not allowed to leave.
Sending data out of the country
There are four ways to make a transfer lawful, and you pick one yourself. First, appropriate safeguards: a binding legal document that gives the data protection essentially equal to Kenya's. Second, a decision by the Data Commissioner that the destination country is safe enough. We found no such decision published. Third, necessity, for a short list of purposes. Fourth, the person's explicit consent after being warned of the risks. Sensitive data can only go on consent. There is no government contract template to copy, no approval to apply for, and no filing to make. But you must write the transfer down, and hand the paperwork to the regulator if asked.
- What you have to do here:
- Put a transfer safeguard in place
- Ways to send data out:
- Official 'this country is safe' decision · Approved group rules · Explicit consent
The rules on sending data outside Kenya sit in the Data Protection (General) Regulations, 2021. Regulation 40 sets the four bases. Regulation 41 says appropriate safeguards means a binding legal document that ties the recipient to protection essentially equal to the Act and these Regulations. It also makes you write the transfer down, and produce that paperwork to the Commissioner on request. Regulation 42 treats safeguards as good enough in three cases. The destination country has ratified the African Union Convention on Cyber Security and Personal Data Protection. Or it has a reciprocal data protection arrangement with Kenya. Or binding corporate rules apply. Regulation 43 sets out what binding corporate rules must contain. Regulation 44 lets the Data Commissioner decide that a country is safe enough, and publish that on the office's website. We found no published list, so treat the list as empty. Regulation 46 is the consent route. It also says sensitive personal data may only be sent abroad with the consent of the person it is about. Regulation 47 controls passing data on again. Regulation 48 allows cross-border agreements that name permitted destination countries and give the sender audit access. One limit in our own vocabulary. The main Kenyan route is a contract you assess yourself, with no government template. That does not map cleanly onto any single code in our list, so the list of mechanisms below understates the route most people actually use.
Sources
- Official sourceOffice of the Data Protection CommissionerData Protection (General) Regulations, 2021, regulations 40 to 48 — transfer of personal data outside Kenya
odpc.go.ke
“shall before transferring personal data out of Kenya ascertain that the transfer is based on (a) appropriate data protection safeguards; (b) an adequacy decision made by the Data Commissioner; (c) transfer as a necessity; or (d) consent of the data subject.”
Link checked 18 August 2026
- Official sourceOffice of the Data Protection CommissionerData Protection Act, No. 24 of 2019, sections 48 and 49 — transfer outside Kenya
odpc.go.ke
“appropriate safeguards with respect to the security and protection of the personal data”
Link checked 18 August 2026
The regulator, and whether it actually acts
The Office of the Data Protection Commissioner, and it really works. This is not a paper regulator. In 2026 alone it has published twenty-two decisions naming the companies involved. They cover hospitals, schools, lenders, insurance brokers, a water utility and a savings cooperative. In one April 2026 decision it found a microfinance bank liable. It ordered the data deleted within fourteen days. It also recommended prosecuting the company's directors for obstructing the Commissioner. The office also runs a public register of registered organisations with hundreds of entries, and took an international quality certification in July 2026. Money penalties are capped low, so orders and criminal referrals do more of the work than fines.
- What it costs if you get it wrong:
- Criminal liability · Fixed maximum fine
We rate enforcement active rather than aggressive. The volume and the naming are real, and the office does refer cases for prosecution. But the maximum fine under section 63 is the lower of five million shillings or one per cent of annual turnover. That is around 38,000 United States dollars. It is small by international standards, and it does little to deter a large firm. Sector regulators exist and work: the Communications Authority of Kenya, the Central Bank of Kenya, and the National Computer and Cybercrimes Co-ordination Committee. We found no enforcement by any of them, on their own sites, of the rules about keeping data in Kenya. The Data Commissioner at the time of writing is Immaculate Kassait. We could not confirm her appointment date or remaining term from the office's own pages.
Sources
- Official sourceOffice of the Data Protection CommissionerODPC determinations issued in 2026 — twenty-two published decisions with named respondents
odpc.go.ke
Link checked 18 August 2026
- Official sourceOffice of the Data Protection CommissionerDetermination ODPC/COMP/0213/2026, Peter Macharia Waithira v LOLC Kenya Microfinance Bank Limited, 14 April 2026
odpc.go.ke
“The Respondent is hereby found liable.”
Link checked 18 August 2026
- Official sourceOffice of the Data Protection CommissionerODPC news — quality management system certification launched 20 July 2026; register of data handlers
odpc.go.ke
Link checked 18 August 2026
How long you must keep it — and when to delete it
Kenya sets a firm limit on how long you may keep data, and almost no minimum. You may keep personal data only for as long as you really need it. Once the purpose is finished you must delete it, strip out the names, or scramble the identifiers. The regulator expects you to have a written retention timetable, to review it regularly, and to justify every period you have chosen. Keeping something 'just in case' is specifically called out as not good enough. The privacy law itself sets no minimum keeping periods. Those come from tax, company and industry rules outside this law. We could not confirm them from a government source, so treat any minimum you rely on as unchecked.
- What you have to do here:
- Delete data after a period · Keep records of how you use data
Section 39 of the Data Protection Act says personal data must be kept 'only as long as may be reasonably necessary'. That is subject to a legal requirement, a lawful purpose, or the person's authorisation. Regulation 19 of the General Regulations, 2021 repeats this. It adds a duty to 'erase, delete anonymise or pseudonymise personal data upon the lapse of the purpose'. The public sector guidance and the health guidance both require a written retention schedule, reviewed from time to time. The health guidance gives one concrete example. A provider keeps the records of dead or non-returning patients for seven years. It then destroys them securely, or removes the names. That is an example of a period you could defend, not a legal minimum. Where a real legal duty to keep data clashes with the duty to delete, section 39 favours keeping it. Keeping data because the law requires it is an express exception.
Sources
- Official sourceOffice of the Data Protection CommissionerData Protection Act, No. 24 of 2019, section 39 — retention
odpc.go.ke
“only as long as may be reasonably necessary”
Link checked 18 August 2026
- Official sourceOffice of the Data Protection CommissionerData Protection (General) Regulations, 2021, regulation 19 — retention and deletion
odpc.go.ke
“erase, delete anonymise or pseudonymise personal data upon the lapse of the purpose”
Link checked 18 August 2026
- Official sourceOffice of the Data Protection CommissionerODPC Guidance Note on the Processing of Health Data — retention must be justified
odpc.go.ke
“must justify a stated retention time and should not preserve any personal data on a 'just-in-case' basis”
Link checked 18 August 2026
What to do: Set an automatic deletion job so data does not sit past its deadline.
Not fully verified — see “What we're not sure about” below.If something goes wrong
Three clocks, and the shortest one is easy to miss. If you are the organisation that decided how the data is used, you must tell the Data Commissioner without delay. In any case you must tell it within seventy-two hours of learning about the breach. If you are a supplier handling data for someone else, you have only forty-eight hours to tell your customer. A supplier who waits for the customer's process has already blown the deadline. You must also tell the people affected, within a reasonably practical period rather than a fixed number of hours. Separately, the national cyber crime body runs an online incident reporting portal. We found no published deadline attached to it.
- What you have to do here:
- Report breaches to the regulator · Tell affected people · Report cyber incidents
Section 43 of the Data Protection Act. The forty-eight hour clock from supplier to customer is the operational trap. It is shorter than the seventy-two hour clock to the regulator, and it starts when the supplier itself learns of the breach. So a global supplier's standard 'notify without undue delay' contract wording is not enough for Kenya. You must tell the affected people where the breach is likely to create a real risk to their rights and freedoms. The National Computer and Cybercrimes Co-ordination Committee runs a reporting form under the Computer Misuse and Cybercrimes Act, 2018. We found no published deadline in hours on its site. That is a deadline we could not find, not a deadline that does not exist.
Sources
- Official sourceOffice of the Data Protection CommissionerData Protection Act, No. 24 of 2019, section 43 — notification of breach
odpc.go.ke
“notify the Data Commissioner without delay, within seventy-two hours of becoming aware of such breach”
Link checked 18 August 2026
- Official sourceNational Computer and Cybercrimes Co-ordination CommitteeNational Computer and Cybercrimes Co-ordination Committee — cyber incident reporting portal
nc4.go.ke
Link checked 18 August 2026
What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.
What catches people out
Five things. One: a child is anyone under eighteen. You need a parent's verifiable consent, profiling a child for marketing is banned outright, and you must build age checks. Two: this is criminal law, not just fines. The regulator has recommended prosecuting company directors, and offences carry up to ten years in prison. Three: registration works like a licence. The certificate lasts twenty-four months, there are fees, and twelve listed activities lose the small-business exemption. Four: for sensitive data such as health or biometrics, a good contract is not enough to send it abroad. You need the person's explicit consent. Five: the rule about keeping data in Kenya was written for the state, but the regulator reads it as catching most telephone and internet companies.
- What you have to do here:
- Get a parent's consent for children · No tracking or ads to children · Register or notify
- What it costs if you get it wrong:
- Criminal liability
(1) Children. The Act defines a child as under eighteen. The General Regulations, 2021, regulation 13 bans profiling a child for direct marketing. The November 2025 children's guidance note requires 'appropriate mechanisms for age verification and consent'. There is no lower digital consent age as in Europe. (2) Criminal exposure. Section 73 sets a fine of up to three million shillings (about 23,000 United States dollars) or imprisonment of up to ten years. The April 2026 microfinance decision shows the office actually recommending prosecution of directors for obstruction under section 61(b). The cap on fines from the regulator, in section 63, is the lower of five million shillings or one per cent of annual turnover. Because it is the lower of the two, the percentage limits large firms rather than exposing them. (3) Registration. Regulation 9 of the Registration Regulations, 2021 gives a twenty-four month certificate. Regulation 13 sets the exemption. The Third Schedule lists twelve activities where the exemption does not apply. They include gambling, financial services, telecommunications, direct marketing, health administration, education, hospitality, property management, transport and genetic data. (4) Sensitive data. Regulation 46 lets sensitive personal data go abroad only with the consent of the person it is about. Safeguards alone will not carry health, biometric or similar data out of Kenya. (5) The protected systems hook. The communications guidance says most service providers are protected computer systems under the Computer Misuse and Cybercrimes Act, and so fall inside regulation 26. The government makes that designation, not you. So the reach of the rule can change without you doing anything.
Sources
- Official sourceOffice of the Data Protection CommissionerODPC Guidance Note for Processing Children's Data, 2025
odpc.go.ke
“Child" means an individual who has not attained the age of eighteen years.”
Link checked 18 August 2026
- Official sourceOffice of the Data Protection CommissionerData Protection Act, No. 24 of 2019, sections 63 and 73 — penalties
odpc.go.ke
“five million shillings, or in the case of an undertaking, up to one per centum of its annual turnover”
Link checked 18 August 2026
- Official sourceOffice of the Data Protection CommissionerDetermination of 14 April 2026 recommending prosecution of directors for obstruction
odpc.go.ke
Link checked 18 August 2026
- Official sourceOffice of the Data Protection CommissionerRegistration Regulations, 2021, regulation 9 and Third Schedule
odpc.go.ke
“valid for a period of twenty-four months from the date of issuance”
Link checked 18 August 2026
What's changing next
One thing is landing now, and three switches could flip at any time. Landing: the regulator put out three draft guidance notes in July 2026. They cover artificial intelligence, emerging technologies, and privacy-enhancing technologies. Comments closed on the seventeenth of August 2026, so final versions are due very soon. The artificial intelligence draft would make organisations register and run risk assessments before high-risk uses. It would keep humans in the loop on serious automated decisions. And it would make you write down how well any country you send data to protects it. The three switches are described below, and none of them needs a new law.
Powers the government already holds, in order of how fast they could hurt. (1) Section 50 of the Act lets the Cabinet Secretary name further categories of data that must stay on Kenyan servers. The Data Commissioner has to recommend it first. The grounds are the strategic interests of the state, or protecting revenue. The revenue ground has never been used. If it were, it would reach ordinary commercial data. (2) The 'protected computer system' designation under the Computer Misuse and Cybercrimes Act, 2018 automatically pulls whatever it touches into regulation 26. The privacy regulator already treats most communications providers as caught. Extending it to other operators needs no change to the data protection rules at all. (3) Regulation 44 lets the Data Commissioner declare countries safe enough and publish the list. We found no published list. That cuts both ways. Nothing is approved, and nothing is blocked. But the office could reshape where you may send data by publishing a narrow list. Also unresolved: the term of office of the current Data Commissioner. We could not confirm it, and it is a natural point where things could change. We found no pending data protection bill on Parliament's own bills listing, checked 18 August 2026.
Sources
- Official sourceOffice of the Data Protection CommissionerODPC draft guidance notes on artificial intelligence, emerging technologies and privacy-enhancing technologies, July 2026, comments closing 17 August 2026
odpc.go.ke
Link checked 18 August 2026
- Official sourceOffice of the Data Protection CommissionerDraft Guidance Note on Artificial Intelligence, July 2026
odpc.go.ke
“Entities shall assess and document the adequacy of data protection in any jurisdiction to which personal data is transferred in connection with AI processing and shall implement contractual or other safeguards.”
Link checked 18 August 2026
- Official sourceOffice of the Data Protection CommissionerData Protection Act, No. 24 of 2019, section 50 — the unused localisation power
odpc.go.ke
Link checked 18 August 2026
- Official sourceParliament of KenyaNational Assembly bills listing — checked for a pending data protection, cybersecurity or gambling bill, none found on the current page
parliament.go.ke
Link checked 18 August 2026
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries3 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Government data needs a copy kept in the country
Official name: The Data Protection (General) Regulations, 2021, regulation 26 — requirement for specified processing to be done in Kenya · Legal Notice No. 263 of 2021, made under section 50 of the Act · Directly binding regulation
Kenya's only rule about where data must be stored. Six state-linked purposes must be handled on a Kenyan server and data centre. The alternative is at least one serving copy held in a Kenyan data centre. It is a mirror rule, not a ban. A second copy may sit abroad. This rule is why Kenya's answer depends on your industry, rather than being simply conditional.
Enforced by Office of the Data Protection Commissioner
How this country controls where data goes: Only approved countries (no country is on the approved list yet) · Accepted routes: Official 'this country is safe' decision, Explicit consent
What you have to do
- Keep the data in the countryYou may run the whole thing on a Kenyan server and data centre. Or you may keep at least one live working copy in a Kenyan data centre. A copy abroad remains lawful. This covers civil registration and legal identity management, running elections, and public finance administration systems. It also covers computer systems declared protected by the government, early childhood and basic education, and primary and secondary health care.
Sources
- Official sourceOffice of the Data Protection CommissionerThe Data Protection (General) Regulations, 2021, regulation 26
odpc.go.ke
“process such personal data through a server and data centre located in Kenya; or store at least one serving copy of the concerned personal data in a data centre located in Kenya”
Link checked 18 August 2026
- Official sourceOffice of the Data Protection CommissionerODPC Guidance Note for the Public Sector, November 2025
odpc.go.ke
“personal data prescribed by the Cabinet Secretary (ICT) as being of strategic interest must have a copy domiciled in Kenya”
Link checked 18 August 2026
Health and social care data needs a copy kept in the country
Official name: ODPC Guidance Note on the Processing of Health Data, read with regulation 26 of the Data Protection (General) Regulations, 2021 · Regulator guideline
Health is the sector where Kenya's rules press hardest on private companies. Providers of primary and secondary care are caught by the rule that keeps state-interest data in Kenya. So a live copy must stay in the country. Health records also count as sensitive. So sending them abroad needs the patient's explicit consent, not just a contract.
Enforced by Office of the Data Protection Commissioner
How this country controls where data goes: Only approved countries (no country is on the approved list yet) · Accepted routes: Explicit consent
What you have to do
- Keep the data in the countryThe binding part: providers of primary and secondary health care fall inside regulation 26 and must keep a serving copy in Kenya. The guidance note itself is not binding, but it states the regulator's expectation more widely.
- Get consentHealth records are sensitive personal data, so a transfer abroad needs the patient's explicit consent, not just a good contract.
- Delete data after a periodNo fixed period. The regulator requires a retention schedule you can justify. It gives seven years for deceased or non-returning patients as an example of a defensible period, not a legal minimum.
Sources
- Official sourceOffice of the Data Protection CommissionerODPC Guidance Note on the Processing of Health Data
odpc.go.ke
“Sensitive personal data can only be transferred with the consent of the data subject”
Link checked 18 August 2026
- Official sourceOffice of the Data Protection CommissionerData Protection (General) Regulations, 2021, regulation 26(2) — primary and secondary health care
odpc.go.ke
Link checked 18 August 2026
Telecoms data needs a copy kept in the country
Official name: ODPC Guidance Note for the Communication Sector, applying regulation 26 through the 'protected computer system' definition in the Computer Misuse and Cybercrimes Act, 2018 · Regulator guideline
Telephone and internet providers are pulled into Kenya's storage rule through a side door. The privacy regulator says most of them count as protected computer systems. That is one of the categories that must be handled on a Kenyan server, or mirrored in a Kenyan data centre. The separate 2025 subscriber registration rules impose no storage-location duty of their own.
Enforced by Office of the Data Protection Commissioner
How this country controls where data goes: Only approved countries (no country is on the approved list yet) · Accepted routes: Official 'this country is safe' decision, Explicit consent
What you have to do
- Keep the data in the countryCaught indirectly. The regulator says most communications service providers are protected computer systems, and those are one of the six purposes inside regulation 26.
- Put a transfer safeguard in placeDo not send data abroad without proof of adequate safeguards or valid consent. That comes from the regulator's own compliance checklist.
Sources
- Official sourceOffice of the Data Protection CommissionerODPC Guidance Note for the Communication Sector
odpc.go.ke
“Most service providers are protected computer systems under the Computer Misuse and Cybercrimes Act.”
Link checked 18 August 2026
- Official sourceCommunications Authority of KenyaKenya Information and Communications (Registration of Telecommunications Services Subscriber) Regulations 2025, Legal Notice No. 90
ca.go.ke
“A person who commits an offence under these Regulations shall be liable upon conviction to a fine not exceeding one million shillings or imprisonment for a term not exceeding six months, or both.”
Link checked 18 August 2026
Applies to every company3 rules
These bind you whatever business you are in, once the country's rules reach you.
Breach reporting rules
Official name: The Data Protection Act, 2019 · No. 24 of 2019, consolidated as Cap. 411C · Act of parliament
Kenya's general privacy law. It reaches foreign companies with no Kenyan office. Most organisations must register and renew every two years. You have seventy-two hours to report a breach. Data may go abroad only on one of four listed bases. Money penalties are modest, but breaking the law can also be a crime.
Enforced by Office of the Data Protection Commissioner
How this country controls where data goes: Only approved countries (no country is on the approved list yet) · Accepted routes: Official 'this country is safe' decision, Explicit consent, Needed for a contract, To save someone’s life
What you have to do
- Register or notify — applies at: Turnover of five million shillings or more, or ten or more employees, or any of twelve listed activities, 2 yearsCertificate lasts twenty-four months. Fees run from 4,000 to 40,000 shillings, roughly 31 to 310 US dollars.
- Get consent
- Tell people what you do
- Let people see their data
- Let people correct their data
- Let people delete their data
- Let people object
- Secure the data
- Report breaches to the regulator — within 72 hours
- Tell affected peopleWithin a reasonably practical period. There is no fixed number of hours.
- Delete data after a periodKeep it only as long as reasonably necessary. Once the purpose ends, delete it, remove the names, or scramble the identifiers.
- Appoint a data protection officerThe Act's wording leaves this to you. It is triggered by regular and systematic monitoring, or by handling sensitive categories of data.
- Assess high-risk projectsRequired where what you plan to do is likely to be high risk. The regulator has published a guidance note on how to do one.
- Written vendor contract
- Get a parent's consent for children — applies at: under 18
What it costs if you get it wrong
- Fixed maximum fine: KES 5,000,000 — about $38 thousandAdministrative penalty; the Act caps it at the LOWER of five million shillings or one per cent of annual turnover
- Percentage of global turnover: 1% of annual turnoverAlternative limb of the administrative penalty, applied only where it produces a lower figure
- Criminal liability: KES 3,000,000 or 10 years imprisonment — about $23 thousandOffences under the Act, including obstruction of the Data Commissioner
- Order to stopEnforcement notice requiring processing to stop or data to be erased
- Claims by individualsCompensation to a data subject who suffers damage
Sources
- Official sourceOffice of the Data Protection CommissionerThe Data Protection Act, No. 24 of 2019
odpc.go.ke
Link checked 18 August 2026
- Official sourceOffice of the Data Protection CommissionerODPC — Kenya's data protection legal framework
odpc.go.ke
Link checked 18 August 2026
General data protection law
Official name: The Data Protection (General) Regulations, 2021 — Part on transfer of personal data outside Kenya · Legal Notice No. 263 of 2021, regulations 39 to 48 · Directly binding regulation
Data may go abroad on one of four bases. Equivalent safeguards. A decision by the Data Commissioner that the country is safe enough. Strict necessity. Or the person's explicit consent. Countries that ratified the African Union data protection convention are treated as safe enough. We found no list of safe countries published by the Commissioner. So almost everyone uses the safeguards route and assesses it themselves.
Enforced by Office of the Data Protection Commissioner
How this country controls where data goes: Only approved countries (no country is on the approved list yet) · Accepted routes: Official 'this country is safe' decision, Approved group rules, Explicit consent, Needed for a contract, Important public interest, Legal claims, To save someone’s life
What you have to do
- Put a transfer safeguard in placeThe main route is a binding legal document that you assess yourself. It must give protection essentially equal to Kenyan law. There is no government contract template, and no filing or approval before you send.
- Keep records of how you use dataWrite down every transfer: the date, the recipient, the reason, and what the data is. Give that paperwork to the Data Commissioner on request.
- Get consentSensitive personal data may only go abroad with the consent of the person it is about. Safeguards alone are not enough.
Sources
- Official sourceOffice of the Data Protection CommissionerThe Data Protection (General) Regulations, 2021, regulations 39 to 48
odpc.go.ke
“a legal instrument containing appropriate safeguards for the protection of personal data binding the intended recipient that is essentially equivalent to the protection under the Act and these Regulations”
Link checked 18 August 2026
General data protection law (2021)
Official name: The Data Protection (Registration of Data Controllers and Data Processors) Regulations, 2021 · Directly binding regulation
A registration system that behaves like a licence. Certificates last twenty-four months and must be renewed. Fees are small, from 4,000 to 40,000 shillings, about 31 to 310 United States dollars. But the twelve listed activities strip away the small-business exemption entirely, and the register is public.
Enforced by Office of the Data Protection Commissioner
What you have to do
- Register or notify — applies at: Exempt only if annual turnover is under five million shillings AND fewer than ten employees, unless in a Third Schedule activity, 2 yearsTwelve activities lose the exemption. They are political canvassing, crime prevention, gambling, educational institutions, health administration and hospitality. Also property management, financial services, telecommunications, direct marketing, transport services and handling genetic data.
What it costs if you get it wrong
- Criminal liabilityProcessing without being registered where registration is mandatory
Sources
- Official sourceOffice of the Data Protection CommissionerData Protection (Registration of Data Controllers and Data Processors) Regulations, 2021
odpc.go.ke
Link checked 18 August 2026
- Official sourceOffice of the Data Protection CommissionerODPC public register of data handlers — active, expired and deregistered
odpc.go.ke
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.
The exact assent and commencement dates of the Data Protection Act, 2019, and the exact commencement date of the 2021 Regulations
We could not confirm the exact commencement dates. Kenya Law, the official statute and gazette publisher, refused our requests. The Act text we used is the copy published by the regulator itself, and it does not show the commencement notice. The Regulations document gives 31 December 2021 as the start date. But that is also the gazette date, so the two may be being run together. The Act is certainly in force, because the regulator is deciding cases under it in 2026. Plan around the earlier of any two candidate dates.
Whether any banking, payments, insurance or securities keeping data in the country rule exists in Kenya
We found no rule requiring data to stay in Kenya. We could not read the Central Bank of Kenya's site in full, and we could not open its outsourcing guideline. We did not reach the insurance and capital markets regulators. Checked 18 August 2026.
Whether Kenya has server-location rules for gambling operators
We could not confirm this. The betting regulator's website is degraded and carries injected commercial links. It lists only the 1966 gambling statute and no current legal texts. Parliament's bills listing showed no gambling bill on the page we could read. Gambling is one of the twelve activities that must register with the privacy regulator, so check this directly.
Whether the Data Commissioner has published any official “this country is safe” decision under regulation 44
The regulation allows a list to be published on the office's website. We found no such list on the pages we could reach, so we treat it as empty. We cannot prove that no list exists. Check the office's website before you rely on this.
Which computer systems have actually been declared 'protected computer systems' by the government
We could not confirm which systems have been declared protected. That designation is what pulls private companies into the rule keeping data in Kenya, and the regulator says it covers most communications providers. We could not find the underlying designations, or the text of the Computer Misuse and Cybercrimes Act, on any government website. So the reach of that rule for telecoms rests on the regulator's guidance note alone.
Minimum retention periods under Kenyan tax and company law
We could not confirm any minimum keeping period. The revenue authority pages we tried returned errors. Kenyan tax and company law is widely understood to require records to be kept for several years. But we could not verify a period from a government source. So we state no minimum here. Check with the revenue authority before you delete anything.
The appointment date and remaining term of the current Data Protection Commissioner
We could not confirm this. The regulator's 'about us' and 'who we are' pages carry no biography and no term of office. The Commissioner's name appears only in the office's news items.
Whether the National Computer and Cybercrimes Co-ordination Committee imposes a cyber incident reporting deadline
We could not confirm whether a deadline exists. The committee's regulations and resources pages returned no documents. Only a reporting portal was visible. A deadline may sit in regulations we could not open, so ask the committee if this matters to you.
Freshness and refresh
Freshness
Checked about 2 months ago, on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.