Skip to the content
Global Data RulesData governance rules, country by country

Kenya

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.

If you collect data about people in Kenya — customers, users, employees — these are the rules you have to follow. Here is the short version.

The short version

Depends on your industryWork: HighEnforcement: Active

Kenya has a real privacy law, and a regulator that really works. Data may leave the country. But you must show the destination protects it about as well as Kenya does, or the person must clearly agree. Some data must stay. Anything used for identity records, elections, public money, basic schooling or front-line health care needs at least one live copy on a server inside Kenya.

Data governance in Kenya

The eight things that decide how you handle data about people in Kenya. Same eight on every country page, so you can compare.

Who has to follow these rules

Yes. The law reaches a company with no office and no staff in Kenya, as long as it handles data about people who are in Kenya. There is no revenue or headcount level that gets you out of the law itself. Size only decides whether you must also put your name on the regulator's public register. You can skip registering if you are small. That means turnover under five million Kenyan shillings a year (roughly 38,000 United States dollars), and fewer than ten staff. That let-off disappears if you work in one of twelve listed activities. Those include gambling, financial services, telephone and internet services, health, education, transport, direct marketing and anything involving genetic data. Kenya does not make you appoint a local representative.

What you have to do here:
Register or notify

Where the data is allowed to live

Mostly yes, with homework. Then there are six exceptions. In general you may send personal data abroad if you can show the recipient is bound to protect it about as well as Kenya does. Or the person can say yes after being told the risks. Sensitive data, such as health or biometric records, always needs that explicit yes. But six purposes are different. They are identity and civil registration, elections, and public finance systems. They also cover systems the government has declared protected, early-years and basic schooling, and primary and secondary health care. For those six, a working copy has to live on a server inside Kenya. You can still hold a second copy abroad. Kenya's telephone and internet companies are pulled in through the 'protected systems' door.

What you have to do here:
Keep the data in the country

What to do: Plan for a database inside Kenya: this data is not allowed to leave.

Sending data out of the country

There are four ways to make a transfer lawful, and you pick one yourself. First, appropriate safeguards: a binding legal document that gives the data protection essentially equal to Kenya's. Second, a decision by the Data Commissioner that the destination country is safe enough. We found no such decision published. Third, necessity, for a short list of purposes. Fourth, the person's explicit consent after being warned of the risks. Sensitive data can only go on consent. There is no government contract template to copy, no approval to apply for, and no filing to make. But you must write the transfer down, and hand the paperwork to the regulator if asked.

What you have to do here:
Put a transfer safeguard in place
Ways to send data out:
Official 'this country is safe' decision · Approved group rules · Explicit consent

The regulator, and whether it actually acts

The Office of the Data Protection Commissioner, and it really works. This is not a paper regulator. In 2026 alone it has published twenty-two decisions naming the companies involved. They cover hospitals, schools, lenders, insurance brokers, a water utility and a savings cooperative. In one April 2026 decision it found a microfinance bank liable. It ordered the data deleted within fourteen days. It also recommended prosecuting the company's directors for obstructing the Commissioner. The office also runs a public register of registered organisations with hundreds of entries, and took an international quality certification in July 2026. Money penalties are capped low, so orders and criminal referrals do more of the work than fines.

What it costs if you get it wrong:
Criminal liability · Fixed maximum fine

How long you must keep it — and when to delete it

Kenya sets a firm limit on how long you may keep data, and almost no minimum. You may keep personal data only for as long as you really need it. Once the purpose is finished you must delete it, strip out the names, or scramble the identifiers. The regulator expects you to have a written retention timetable, to review it regularly, and to justify every period you have chosen. Keeping something 'just in case' is specifically called out as not good enough. The privacy law itself sets no minimum keeping periods. Those come from tax, company and industry rules outside this law. We could not confirm them from a government source, so treat any minimum you rely on as unchecked.

What you have to do here:
Delete data after a period · Keep records of how you use data

What to do: Set an automatic deletion job so data does not sit past its deadline.

Not fully verified — see “What we're not sure about” below.

If something goes wrong

Three clocks, and the shortest one is easy to miss. If you are the organisation that decided how the data is used, you must tell the Data Commissioner without delay. In any case you must tell it within seventy-two hours of learning about the breach. If you are a supplier handling data for someone else, you have only forty-eight hours to tell your customer. A supplier who waits for the customer's process has already blown the deadline. You must also tell the people affected, within a reasonably practical period rather than a fixed number of hours. Separately, the national cyber crime body runs an online incident reporting portal. We found no published deadline attached to it.

What you have to do here:
Report breaches to the regulator · Tell affected people · Report cyber incidents

What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.

What catches people out

Five things. One: a child is anyone under eighteen. You need a parent's verifiable consent, profiling a child for marketing is banned outright, and you must build age checks. Two: this is criminal law, not just fines. The regulator has recommended prosecuting company directors, and offences carry up to ten years in prison. Three: registration works like a licence. The certificate lasts twenty-four months, there are fees, and twelve listed activities lose the small-business exemption. Four: for sensitive data such as health or biometrics, a good contract is not enough to send it abroad. You need the person's explicit consent. Five: the rule about keeping data in Kenya was written for the state, but the regulator reads it as catching most telephone and internet companies.

What you have to do here:
Get a parent's consent for children · No tracking or ads to children · Register or notify
What it costs if you get it wrong:
Criminal liability

What's changing next

One thing is landing now, and three switches could flip at any time. Landing: the regulator put out three draft guidance notes in July 2026. They cover artificial intelligence, emerging technologies, and privacy-enhancing technologies. Comments closed on the seventeenth of August 2026, so final versions are due very soon. The artificial intelligence draft would make organisations register and run risk assessments before high-risk uses. It would keep humans in the loop on serious automated decisions. And it would make you write down how well any country you send data to protects it. The three switches are described below, and none of them needs a new law.

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries3 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Government

Government data needs a copy kept in the country

Official name: The Data Protection (General) Regulations, 2021, regulation 26 — requirement for specified processing to be done in Kenya · Legal Notice No. 263 of 2021, made under section 50 of the Act · Directly binding regulation

In forceA copy must stay

Kenya's only rule about where data must be stored. Six state-linked purposes must be handled on a Kenyan server and data centre. The alternative is at least one serving copy held in a Kenyan data centre. It is a mirror rule, not a ban. A second copy may sit abroad. This rule is why Kenya's answer depends on your industry, rather than being simply conditional.

In force since 31 December 2021

Enforced by Office of the Data Protection Commissioner

How this country controls where data goes: Only approved countries (no country is on the approved list yet) · Accepted routes: Official 'this country is safe' decision, Explicit consent

Health and social care

Health and social care data needs a copy kept in the country

Official name: ODPC Guidance Note on the Processing of Health Data, read with regulation 26 of the Data Protection (General) Regulations, 2021 · Regulator guideline

In forceA copy must stay

Health is the sector where Kenya's rules press hardest on private companies. Providers of primary and secondary care are caught by the rule that keeps state-interest data in Kenya. So a live copy must stay in the country. Health records also count as sensitive. So sending them abroad needs the patient's explicit consent, not just a contract.

In force since 1 February 2024

Enforced by Office of the Data Protection Commissioner

How this country controls where data goes: Only approved countries (no country is on the approved list yet) · Accepted routes: Explicit consent

Not fully verified — see “What we're not sure about” below.
Telecoms

Telecoms data needs a copy kept in the country

Official name: ODPC Guidance Note for the Communication Sector, applying regulation 26 through the 'protected computer system' definition in the Computer Misuse and Cybercrimes Act, 2018 · Regulator guideline

In forceA copy must stay

Telephone and internet providers are pulled into Kenya's storage rule through a side door. The privacy regulator says most of them count as protected computer systems. That is one of the categories that must be handled on a Kenyan server, or mirrored in a Kenyan data centre. The separate 2025 subscriber registration rules impose no storage-location duty of their own.

In force since 1 February 2024

Enforced by Office of the Data Protection Commissioner

How this country controls where data goes: Only approved countries (no country is on the approved list yet) · Accepted routes: Official 'this country is safe' decision, Explicit consent

Not fully verified — see “What we're not sure about” below.

Applies to every company3 rules

These bind you whatever business you are in, once the country's rules reach you.

Breach reporting rules

Official name: The Data Protection Act, 2019 · No. 24 of 2019, consolidated as Cap. 411C · Act of parliament

In forceYes, with paperwork

Kenya's general privacy law. It reaches foreign companies with no Kenyan office. Most organisations must register and renew every two years. You have seventy-two hours to report a breach. Data may go abroad only on one of four listed bases. Money penalties are modest, but breaking the law can also be a crime.

Enforced by Office of the Data Protection Commissioner

How this country controls where data goes: Only approved countries (no country is on the approved list yet) · Accepted routes: Official 'this country is safe' decision, Explicit consent, Needed for a contract, To save someone’s life

General data protection law

Official name: The Data Protection (General) Regulations, 2021 — Part on transfer of personal data outside Kenya · Legal Notice No. 263 of 2021, regulations 39 to 48 · Directly binding regulation

In forceYes, with paperwork

Data may go abroad on one of four bases. Equivalent safeguards. A decision by the Data Commissioner that the country is safe enough. Strict necessity. Or the person's explicit consent. Countries that ratified the African Union data protection convention are treated as safe enough. We found no list of safe countries published by the Commissioner. So almost everyone uses the safeguards route and assesses it themselves.

In force since 31 December 2021

Enforced by Office of the Data Protection Commissioner

How this country controls where data goes: Only approved countries (no country is on the approved list yet) · Accepted routes: Official 'this country is safe' decision, Approved group rules, Explicit consent, Needed for a contract, Important public interest, Legal claims, To save someone’s life

General data protection law (2021)

Official name: The Data Protection (Registration of Data Controllers and Data Processors) Regulations, 2021 · Directly binding regulation

In forceYes, with paperwork

A registration system that behaves like a licence. Certificates last twenty-four months and must be renewed. Fees are small, from 4,000 to 40,000 shillings, about 31 to 310 United States dollars. But the twelve listed activities strip away the small-business exemption entirely, and the register is public.

In force since 31 December 2021

Enforced by Office of the Data Protection Commissioner

Who you would hear from

  • Office of the Data Protection Commissioner (ODPC)

    General privacy law, registration, complaints, determinations, sectoral guidance

    Working, and one of the more active data protection regulators in Africa. It published twenty-two decisions in 2026 alone. Those name hospitals, schools, lenders, an insurance broker, a water utility and a savings cooperative. It issues deletion orders, enforcement notices, and recommendations to prosecute directors. It runs a public register of data handlers with hundreds of active entries, and it launched a quality management certification in July 2026.

  • Telecommunications, broadcasting, subscriber registration, cyber security coordination for the sector

    Active. It re-made the subscriber registration rules in 2025. We found no rule of its own requiring data to stay in Kenya.

  • Cyber incidents, critical information infrastructure, the Computer Misuse and Cybercrimes Act

    It runs a live incident reporting portal. We found no published reporting deadline in hours on its site. Its regulations and resources pages returned no documents.

  • Banking, payments, digital credit providers

    An active regulator. We could not read its site in full. Its prudential guidelines list an outsourcing guideline whose text we could not open. We found no banking or payments rule requiring data to stay in Kenya.

  • Digital health systems, health registries, health data exchange

    We found no legal texts, and no rules about where data must be kept, on the pages we could reach.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.

  • The exact assent and commencement dates of the Data Protection Act, 2019, and the exact commencement date of the 2021 Regulations

    We could not confirm the exact commencement dates. Kenya Law, the official statute and gazette publisher, refused our requests. The Act text we used is the copy published by the regulator itself, and it does not show the commencement notice. The Regulations document gives 31 December 2021 as the start date. But that is also the gazette date, so the two may be being run together. The Act is certainly in force, because the regulator is deciding cases under it in 2026. Plan around the earlier of any two candidate dates.

  • Whether any banking, payments, insurance or securities keeping data in the country rule exists in Kenya

    We found no rule requiring data to stay in Kenya. We could not read the Central Bank of Kenya's site in full, and we could not open its outsourcing guideline. We did not reach the insurance and capital markets regulators. Checked 18 August 2026.

  • Whether Kenya has server-location rules for gambling operators

    We could not confirm this. The betting regulator's website is degraded and carries injected commercial links. It lists only the 1966 gambling statute and no current legal texts. Parliament's bills listing showed no gambling bill on the page we could read. Gambling is one of the twelve activities that must register with the privacy regulator, so check this directly.

  • Whether the Data Commissioner has published any official “this country is safe” decision under regulation 44

    The regulation allows a list to be published on the office's website. We found no such list on the pages we could reach, so we treat it as empty. We cannot prove that no list exists. Check the office's website before you rely on this.

  • Which computer systems have actually been declared 'protected computer systems' by the government

    We could not confirm which systems have been declared protected. That designation is what pulls private companies into the rule keeping data in Kenya, and the regulator says it covers most communications providers. We could not find the underlying designations, or the text of the Computer Misuse and Cybercrimes Act, on any government website. So the reach of that rule for telecoms rests on the regulator's guidance note alone.

  • Minimum retention periods under Kenyan tax and company law

    We could not confirm any minimum keeping period. The revenue authority pages we tried returned errors. Kenyan tax and company law is widely understood to require records to be kept for several years. But we could not verify a period from a government source. So we state no minimum here. Check with the revenue authority before you delete anything.

  • The appointment date and remaining term of the current Data Protection Commissioner

    We could not confirm this. The regulator's 'about us' and 'who we are' pages carry no biography and no term of office. The Commissioner's name appears only in the office's news items.

  • Whether the National Computer and Cybercrimes Co-ordination Committee imposes a cyber incident reporting deadline

    We could not confirm whether a deadline exists. The committee's regulations and resources pages returned no documents. Only a reporting portal was visible. A deadline may sit in regulations we could not open, so ask the committee if this matters to you.

Freshness and refresh

Freshness

Checked about 2 months ago, on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.