Skip to the content
Global Data RulesData governance rules, country by country

Kenya

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked yesterday.

The answer

Depends on your industryWork: HighEnforcement: Active

Kenya has a real privacy law and a regulator that genuinely works. Data may leave the country, but only if you can show the destination protects it about as well as Kenya does, or the person has clearly agreed. Some data must stay: anything used for identity records, elections, public money, basic schooling or front-line health care needs at least one live copy on a server inside Kenya.

Data governance in Kenya

The eight things that decide how you handle data about people in Kenya. Same eight on every country page, so you can compare.

Who has to follow these rules

Yes. The law reaches a company with no office and no staff in Kenya, as long as it handles the data of people who are in Kenya. There is no revenue or headcount level that gets you out of the law itself. Size only decides whether you must also put your name on the regulator's public register: you can skip registering if you turn over less than five million Kenyan shillings a year (roughly 38,000 US dollars) and employ fewer than ten people. That let-off disappears if you work in one of twelve listed activities, which include gambling, financial services, telephone and internet services, health, education, transport, direct marketing and anything involving genetic data. Kenya does not make you appoint a local representative.

High confidenceNational rulesRegister or notify

Where the data is allowed to live

Mostly yes, with homework — and then six hard exceptions. In general you may send personal data abroad if you can show the recipient is bound to protect it about as well as Kenya does, or the person has said yes after being told the risks. Sensitive data, such as health or biometric records, needs that explicit yes. But if you process data for identity and civil registration, elections, public finance systems, systems the government has declared protected, early-years and basic schooling, or primary and secondary health care, then a working copy has to live on a server inside Kenya. You can still hold a second copy abroad. Kenya's telephone and internet regulator sector is pulled in through the 'protected systems' door.

High confidenceDepends on your industryA copy must stayYes, with paperworkKeep the data in the country

Sending data out of the country

There are four ways to make a transfer lawful, and you pick one yourself. First, appropriate safeguards: a binding legal document that gives the data protection essentially equal to Kenya's. Second, a decision by the Data Commissioner that the destination country is safe enough — no such decision has been published that we could find. Third, necessity, for a short list of purposes. Fourth, the person's explicit consent after being warned of the risks. Sensitive data can only go on consent. There is no government-issued contract template to copy, no approval to apply for, and no filing to make — but you must write the transfer down and hand the paperwork to the regulator if asked.

High confidenceAllowlistOfficial 'this country is safe' decisionApproved group rulesExplicit consentPut a transfer safeguard in place

The regulator, and whether it actually acts

The Office of the Data Protection Commissioner, and yes, it really works. This is not a paper regulator. In 2026 alone it has published twenty-two decisions naming the companies involved, covering hospitals, schools, lenders, insurance brokers, a water utility and a savings cooperative. In one April 2026 decision it found a microfinance bank liable, ordered the data deleted within fourteen days, and recommended that the company's directors be prosecuted for obstructing the Commissioner. The office also runs a public register of registered organisations with hundreds of entries and took an international quality certification in July 2026. Money penalties are capped low, so orders and criminal referrals do more of the work than fines.

High confidenceActiveCriminal liabilityFixed maximum fine

How long you must keep it — and when to delete it

Kenya sets a firm ceiling and almost no floor. The ceiling: you may keep personal data only for as long as it is genuinely needed, and once the purpose is finished you must delete it, or strip out the names, or scramble the identifiers. The regulator expects you to have a written retention timetable, review it regularly, and be able to justify every period you have chosen — keeping something 'just in case' is specifically called out as not good enough. The privacy law itself sets no minimum keeping periods. Those come from tax, company and sector rules outside this law, and we could not verify them from a government source in this run, so treat any minimum you rely on as unchecked.

Medium confidenceDelete data after a periodKeep records of processing

If something goes wrong

Three clocks, and the shortest one is easy to miss. If you are the organisation that decided how the data is used, you must tell the Data Commissioner without delay and in any case within seventy-two hours of becoming aware of the breach. If you are a supplier processing data for someone else, you have only forty-eight hours to tell your customer — so a supplier who waits for the customer's process has already blown the deadline. You must also tell the affected people, within a reasonably practical period rather than a fixed number of hours. Separately, the national cyber crime body runs an online incident reporting portal; we found no published deadline attached to it.

High confidenceReport breaches to the regulatorTell affected peopleReport cyber incidents

What catches people out

Five things that are not in the summary. One: a child is anyone under eighteen, you need a parent's verifiable consent, and profiling a child for marketing is banned outright — plus you must build age checks. Two: this is criminal law, not just fines. The regulator has recommended prosecuting company directors, and offences carry up to ten years in prison. Three: registration is a licence in disguise — a certificate lasting twenty-four months, with fees, and twelve listed activities that lose the small-business exemption. Four: for sensitive data such as health or biometrics, a good contract is not enough to send it abroad; you need the person's explicit consent. Five: the localisation rule was written for the state but the regulator reads it as catching most telephone and internet companies.

High confidenceGet a parent's consent for childrenNo tracking or ads to childrenCriminal liabilityRegister or notifySensitive personal data

What's changing next

One thing is landing now and three switches could flip at any time. Landing: the regulator put out three draft guidance notes in July 2026, on artificial intelligence, on emerging technologies, and on privacy-enhancing technologies. Comments closed on the seventeenth of August 2026, so final versions are due imminently. The artificial intelligence draft would require organisations to register, to run risk assessments before high-risk uses, to keep humans in the loop on serious automated decisions, and to document how well any country they send data to protects it. The three switches are described below and none of them needs a new law.

High confidenceIn forceArtificial intelligence

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries3 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Government

The Data Protection (General) Regulations, 2021, regulation 26 — requirement for specified processing to be done in Kenya

Directly binding regulation · Legal Notice No. 263 of 2021, made under section 50 of the Act

In forceA copy must stay

Kenya's only hard storage-location rule. Six state-linked purposes must be processed on a Kenyan server and data centre, or have at least one serving copy held in a Kenyan data centre. It is a mirror rule, not a ban — a second copy may sit abroad — and it is the one that makes Kenya's headline answer sectoral rather than simply conditional.

In force since 31 December 2021

Enforced by Office of the Data Protection Commissioner

Transfer model: Allowlist (the list is currently empty) · Accepted routes: Official 'this country is safe' decision, Explicit consent

High confidence
Health and social care

ODPC Guidance Note on the Processing of Health Data, read with regulation 26 of the Data Protection (General) Regulations, 2021

Regulator guideline

In forceA copy must stay

Health is the sector where Kenya's rules bite hardest on private companies. Primary and secondary care providers are caught by the state-interest localisation rule, so a live copy must stay in Kenya, and because health records count as sensitive, sending them abroad needs the patient's explicit consent rather than contractual safeguards alone.

In force since 1 February 2024

Enforced by Office of the Data Protection Commissioner

Transfer model: Allowlist (the list is currently empty) · Accepted routes: Explicit consent

Medium confidence
Telecoms

ODPC Guidance Note for the Communication Sector, applying regulation 26 through the 'protected computer system' definition in the Computer Misuse and Cybercrimes Act, 2018

Regulator guideline

In forceA copy must stay

Telephone and internet providers are pulled into Kenya's localisation rule through a side door. The privacy regulator states that most of them count as protected computer systems, which is one of the categories that must be processed on a Kenyan server or mirrored in a Kenyan data centre. The separate 2025 subscriber registration rules impose no storage-location duty of their own.

In force since 1 February 2024

Enforced by Office of the Data Protection Commissioner

Transfer model: Allowlist (the list is currently empty) · Accepted routes: Official 'this country is safe' decision, Explicit consent

Medium confidence

Applies to every company3 rules

These bind you whatever business you are in, once the country's rules reach you.

The Data Protection Act, 2019

Act of parliament · No. 24 of 2019, consolidated as Cap. 411C

In forceYes, with paperwork

Kenya's general privacy law. It reaches foreign companies with no Kenyan office, requires most organisations to register and renew every two years, sets a seventy-two hour breach clock, and allows transfers abroad only on one of four listed bases. Money penalties are modest but the law is criminal as well as administrative.

Enforced by Office of the Data Protection Commissioner

Transfer model: Allowlist (the list is currently empty) · Accepted routes: Official 'this country is safe' decision, Explicit consent, Needed for a contract, Someone's life is at risk

High confidence

The Data Protection (General) Regulations, 2021 — Part on transfer of personal data outside Kenya

Directly binding regulation · Legal Notice No. 263 of 2021, regulations 39 to 48

In forceYes, with paperwork

Transfers abroad need one of four bases: equivalent safeguards, an adequacy decision by the Data Commissioner, strict necessity, or the person's explicit consent. Countries that ratified the African Union data protection convention are deemed adequate. No adequacy list has been published by the Commissioner that we could find, so in practice almost everyone uses the self-assessed safeguards route.

In force since 31 December 2021

Enforced by Office of the Data Protection Commissioner

Transfer model: Allowlist (the list is currently empty) · Accepted routes: Official 'this country is safe' decision, Approved group rules, Explicit consent, Needed for a contract, Important public interest, Legal claims, Someone's life is at risk

High confidence

The Data Protection (Registration of Data Controllers and Data Processors) Regulations, 2021

Directly binding regulation

In forceYes, with paperwork

A registration regime that behaves like a licence. Certificates last twenty-four months and must be renewed. Fees are small — 4,000 to 40,000 shillings, about 31 to 310 US dollars — but the twelve listed activities strip away the small-business exemption entirely, and the register is public.

In force since 31 December 2021

Enforced by Office of the Data Protection Commissioner

High confidence

Who you would hear from

  • Office of the Data Protection Commissioner (ODPC)

    General privacy law, registration, complaints, determinations, sectoral guidance

    Fully operational and one of the more active data protection regulators in Africa. Twenty-two determinations published in 2026 alone, naming respondents including hospitals, schools, lenders, an insurance broker, a water utility and a savings cooperative. Issues erasure orders, enforcement notices and recommendations for criminal prosecution of directors. Runs a public register of data handlers with hundreds of active entries and launched a quality management certification in July 2026.

  • Telecommunications, broadcasting, subscriber registration, cyber security coordination for the sector

    Active; re-made the subscriber registration rules in 2025. No data-localisation rule of its own was found on its site.

  • Cyber incidents, critical information infrastructure, the Computer Misuse and Cybercrimes Act

    Runs a live incident reporting portal. No published reporting deadline in hours was found on its site, and its regulations and resources pages returned no documents when checked.

  • Banking, payments, digital credit providers

    Active regulator. Its site requires JavaScript and could not be crawled fully; the prudential guidelines index an outsourcing guideline whose text we could not open. No banking or payments localisation rule was found.

  • Digital health systems, health registries, health data exchange

    Website live and describing registries and health data portability, but no legal texts or data-residency rules were published on the pages we could reach.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.

  • The exact assent and commencement dates of the Data Protection Act, 2019, and the exact commencement date of the 2021 Regulations

    Kenya Law, the official statute and gazette publisher, returned an access-denied error to our fetcher throughout this run. The Act text we used is the copy published by the regulator itself, which does not show the commencement notice. The Regulations PDF gave 31 December 2021 as the commencement, but that is also the gazette date, so the two may be being conflated. The Act is unquestionably in force — the regulator is deciding cases under it in 2026 — but plan around the earlier of any two candidate dates.

  • Whether any banking, payments, insurance or securities data-localisation rule exists in Kenya

    Nothing was found on the Central Bank of Kenya's own site, but the site requires JavaScript and its outsourcing guideline text could not be opened. The insurance and capital markets regulators were not reachable within this run's budget. Recorded as no rule found, checked 18 August 2026, not as no rule existing.

  • Whether Kenya has server-location rules for gambling operators

    The betting regulator's website is degraded and contains injected commercial links; it lists only the 1966 gambling statute and no current legal texts. Parliament's bills listing showed no gambling bill on the page we could read. This is a real gap and gambling is one of the twelve activities that must register with the privacy regulator, so it is worth re-checking.

  • Whether the Data Commissioner has published any adequacy decisions under regulation 44

    The regulation allows a list to be published on the office's website. We found no such list on the pages we could reach, so we treat it as empty, but we cannot prove the absence.

  • Which computer systems have actually been declared 'protected computer systems' by the government

    This designation is the trigger that pulls private companies into the localisation rule, and the regulator asserts it covers most communications providers. We could not locate the underlying designations or the Computer Misuse and Cybercrimes Act text on any government domain during this run, so the scope of the localisation rule for telecoms is asserted on the regulator's guidance note alone.

  • Minimum retention periods under Kenyan tax and company law

    The revenue authority pages we tried returned errors. Kenyan tax and company statutes are widely understood to impose multi-year record-keeping floors, but we could not verify any period from a government source today, so no floor is asserted here.

  • The appointment date and remaining term of the current Data Protection Commissioner

    The regulator's own 'about us' and 'who we are' pages do not carry biographical or term-of-office details. The Commissioner's name appears in the office's news items only.

  • Whether the National Computer and Cybercrimes Co-ordination Committee imposes a cyber incident reporting deadline

    Its regulations and resources pages returned no documents when fetched. Only a reporting portal was visible. A deadline may exist in regulations we could not open.

60-day cadence. Kenya is stable in its text but carries three switches that need no new law: the unused power to prescribe further Kenya-only processing on revenue-protection grounds, the 'protected computer system' designation that silently expands the localisation rule, and the unpublished adequacy list. Three guidance notes also closed consultation on 17 August 2026 and will land inside the next window.

Freshness and refresh

Freshness

Checked yesterday — on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

Put this next to another country

Kenya versus

Compare

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.