Kenya
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked yesterday.
The answer
Kenya has a real privacy law and a regulator that genuinely works. Data may leave the country, but only if you can show the destination protects it about as well as Kenya does, or the person has clearly agreed. Some data must stay: anything used for identity records, elections, public money, basic schooling or front-line health care needs at least one live copy on a server inside Kenya.
Data governance in Kenya
The eight things that decide how you handle data about people in Kenya. Same eight on every country page, so you can compare.
Who has to follow these rules
Yes. The law reaches a company with no office and no staff in Kenya, as long as it handles the data of people who are in Kenya. There is no revenue or headcount level that gets you out of the law itself. Size only decides whether you must also put your name on the regulator's public register: you can skip registering if you turn over less than five million Kenyan shillings a year (roughly 38,000 US dollars) and employ fewer than ten people. That let-off disappears if you work in one of twelve listed activities, which include gambling, financial services, telephone and internet services, health, education, transport, direct marketing and anything involving genetic data. Kenya does not make you appoint a local representative.
Data Protection Act, No. 24 of 2019 (consolidated as Cap. 411C), section 4, applies the Act both to controllers and processors established or ordinarily resident in Kenya and processing personal data in Kenya, and to those 'not established or ordinarily resident in Kenya, but processing personal data of data subjects located in Kenya'. Registration thresholds sit in the Data Protection (Registration of Data Controllers and Data Processors) Regulations, 2021, regulation 13(2) and (4), with the twelve override categories in the Third Schedule. A registration certificate lasts twenty-four months; fees run from 4,000 shillings for a micro or small entity to 40,000 shillings for a large one, with lower renewal fees. Unlike the European Union, the Kenyan regulations contain no local-representative duty for foreign controllers — a genuine gap rather than an oversight we can confirm either way.
Sources
- Official sourceOffice of the Data Protection CommissionerData Protection Act, No. 24 of 2019, section 4 (application)
odpc.go.ke
“not established or ordinarily resident in Kenya, but processing personal data of data subjects located in Kenya”
Link checked 18 August 2026
- Official sourceOffice of the Data Protection CommissionerData Protection (Registration of Data Controllers and Data Processors) Regulations, 2021, regulation 13 and Third Schedule
odpc.go.ke
“annual turnover of below five million shillings or annual revenue of below five million shillings”
Link checked 18 August 2026
Where the data is allowed to live
Mostly yes, with homework — and then six hard exceptions. In general you may send personal data abroad if you can show the recipient is bound to protect it about as well as Kenya does, or the person has said yes after being told the risks. Sensitive data, such as health or biometric records, needs that explicit yes. But if you process data for identity and civil registration, elections, public finance systems, systems the government has declared protected, early-years and basic schooling, or primary and secondary health care, then a working copy has to live on a server inside Kenya. You can still hold a second copy abroad. Kenya's telephone and internet regulator sector is pulled in through the 'protected systems' door.
Headline rating is sectoral, but note that the general baseline is itself conditional, not open — there is always something to put in place before data leaves. The sector walls come from regulation 26 of the Data Protection (General) Regulations, 2021, made under section 50 of the Act. Regulation 26(1) offers a choice: process 'through a server and data centre located in Kenya' OR 'store at least one serving copy of the concerned personal data in a data centre located in Kenya'. That makes these mirror rules, not full bans — a foreign copy stays lawful. Sector-by-sector, verified today: GOVERNMENT AND PUBLIC ADMINISTRATION — mirror (civil registration and legal identity, elections, public finance administration). EDUCATION — mirror, limited to early childhood and basic education. HEALTH — mirror, limited to primary and secondary health care provision; the regulator's own health guidance goes further and states the expectation that health data is stored and processed in Kenya unless the patient explicitly consents to a transfer. TELECOMS AND INTERNET — mirror in practice: the regulator's communications-sector guidance states that most service providers are protected computer systems under the Computer Misuse and Cybercrimes Act and must therefore comply with regulation 26. BANKING AND PAYMENTS — no localisation rule found on the Central Bank's own site, checked 18 August 2026; the Central Bank's prudential guidelines index an outsourcing guideline but we could not open its text. INSURANCE, SECURITIES, GAMBLING, MAPPING AND DEFENCE — no rule found on an official domain, checked 18 August 2026; treat as unresearched rather than clear. Sector telecoms subscriber rules were re-made in 2025 and, notably, contain no storage-location or retention duty at all.
Sources
- Official sourceOffice of the Data Protection CommissionerData Protection (General) Regulations, 2021 (Legal Notice No. 263), regulation 26 — requirement for specified processing to be done in Kenya
odpc.go.ke
“shall (a) process such personal data through a server and data centre located in Kenya; or (b) store at least one serving copy of the concerned personal data in a data centre located in Kenya.”
Link checked 18 August 2026
- Official sourceOffice of the Data Protection CommissionerData Protection Act, No. 24 of 2019, section 50 — the power behind the localisation rule
odpc.go.ke
“through a server or a data centre located in Kenya”
Link checked 18 August 2026
- Official sourceOffice of the Data Protection CommissionerODPC Guidance Note for the Communication Sector — extends the localisation rule to telecoms via 'protected computer systems'
odpc.go.ke
“the service provider must process the data through a server and data centre located in Kenya or store at least one serving copy of the concerned personal data in a data centre located in Kenya.”
Link checked 18 August 2026
- Official sourceOffice of the Data Protection CommissionerODPC Guidance Note on the Processing of Health Data
odpc.go.ke
“personal data is stored and processed in Kenya, except in limited circumstances such as where the data subject has given explicit consent to the transfer”
Link checked 18 August 2026
- Official sourceCommunications Authority of KenyaKenya Information and Communications (Registration of Telecommunications Services Subscriber) Regulations 2025 (Legal Notice No. 90) — checked for localisation and found none
ca.go.ke
Link checked 18 August 2026
Sending data out of the country
There are four ways to make a transfer lawful, and you pick one yourself. First, appropriate safeguards: a binding legal document that gives the data protection essentially equal to Kenya's. Second, a decision by the Data Commissioner that the destination country is safe enough — no such decision has been published that we could find. Third, necessity, for a short list of purposes. Fourth, the person's explicit consent after being warned of the risks. Sensitive data can only go on consent. There is no government-issued contract template to copy, no approval to apply for, and no filing to make — but you must write the transfer down and hand the paperwork to the regulator if asked.
Data Protection (General) Regulations, 2021, Part on transfer outside Kenya. Regulation 40 sets the four bases. Regulation 41 defines appropriate safeguards as 'a legal instrument containing appropriate safeguards for the protection of personal data binding the intended recipient that is essentially equivalent to the protection under the Act and these Regulations', and requires the transfer to be documented and the documentation produced to the Commissioner on request. Regulation 42 deems safeguards adequate where the destination has ratified the African Union Convention on Cyber Security and Personal Data Protection, has a reciprocal data protection arrangement with Kenya, or where binding corporate rules apply. Regulation 43 sets out what binding corporate rules must contain. Regulation 44 allows the Data Commissioner to make and publish adequacy decisions on the office's website; we found no published list, so treat the list as empty. Regulation 46 is the consent route and also states that sensitive personal data may only be transferred with the data subject's consent. Regulation 47 controls onward transfers, and regulation 48 allows cross-border agreements that name permitted destination countries and give the sender audit access. Note a vocabulary limitation: the dominant Kenyan route is a self-assessed contractual safeguard with no government template, which does not map cleanly onto any single transfer-mechanism code in this framework, so the mechanism list below understates the practical route.
Sources
- Official sourceOffice of the Data Protection CommissionerData Protection (General) Regulations, 2021, regulations 40 to 48 — transfer of personal data outside Kenya
odpc.go.ke
“shall before transferring personal data out of Kenya ascertain that the transfer is based on (a) appropriate data protection safeguards; (b) an adequacy decision made by the Data Commissioner; (c) transfer as a necessity; or (d) consent of the data subject.”
Link checked 18 August 2026
- Official sourceOffice of the Data Protection CommissionerData Protection Act, No. 24 of 2019, sections 48 and 49 — transfer outside Kenya
odpc.go.ke
“appropriate safeguards with respect to the security and protection of the personal data”
Link checked 18 August 2026
The regulator, and whether it actually acts
The Office of the Data Protection Commissioner, and yes, it really works. This is not a paper regulator. In 2026 alone it has published twenty-two decisions naming the companies involved, covering hospitals, schools, lenders, insurance brokers, a water utility and a savings cooperative. In one April 2026 decision it found a microfinance bank liable, ordered the data deleted within fourteen days, and recommended that the company's directors be prosecuted for obstructing the Commissioner. The office also runs a public register of registered organisations with hundreds of entries and took an international quality certification in July 2026. Money penalties are capped low, so orders and criminal referrals do more of the work than fines.
Rated active rather than aggressive: the volume and the naming are real, and the office reaches into criminal referral, but the administrative fine ceiling under section 63 is the lower of five million shillings or one per cent of annual turnover — around 38,000 US dollars — which is small by international standards and blunts the deterrent for large firms. Sector regulators exist and function (the Communications Authority of Kenya, the Central Bank of Kenya, the National Computer and Cybercrimes Co-ordination Committee) but we found no data-localisation enforcement by any of them on their own sites during this run. The Data Commissioner at the time of writing is Immaculate Kassait; we could not verify the appointment date or remaining term from the office's own pages.
Sources
- Official sourceOffice of the Data Protection CommissionerODPC determinations issued in 2026 — twenty-two published decisions with named respondents
odpc.go.ke
Link checked 18 August 2026
- Official sourceOffice of the Data Protection CommissionerDetermination ODPC/COMP/0213/2026, Peter Macharia Waithira v LOLC Kenya Microfinance Bank Limited, 14 April 2026
odpc.go.ke
“The Respondent is hereby found liable.”
Link checked 18 August 2026
- Official sourceOffice of the Data Protection CommissionerODPC news — quality management system certification launched 20 July 2026; register of data handlers
odpc.go.ke
Link checked 18 August 2026
How long you must keep it — and when to delete it
Kenya sets a firm ceiling and almost no floor. The ceiling: you may keep personal data only for as long as it is genuinely needed, and once the purpose is finished you must delete it, or strip out the names, or scramble the identifiers. The regulator expects you to have a written retention timetable, review it regularly, and be able to justify every period you have chosen — keeping something 'just in case' is specifically called out as not good enough. The privacy law itself sets no minimum keeping periods. Those come from tax, company and sector rules outside this law, and we could not verify them from a government source in this run, so treat any minimum you rely on as unchecked.
Data Protection Act section 39 requires that personal data be retained 'only as long as may be reasonably necessary', subject to a legal requirement, a lawful purpose, or the data subject's authorisation. Regulation 19 of the General Regulations, 2021 repeats this and adds the duty to 'erase, delete anonymise or pseudonymise personal data upon the lapse of the purpose'. The public sector and health guidance notes both require a documented retention schedule reviewed periodically. One concrete illustration appears in the health guidance: a provider retaining the records of deceased or non-returning patients for seven years before secure destruction or anonymisation — that is an example of a defensible period, not a legal minimum. Where a genuine legal keeping duty conflicts with the delete-when-done rule, section 39 resolves it in favour of the keeping duty, because retention required by law is an express exception.
Sources
- Official sourceOffice of the Data Protection CommissionerData Protection Act, No. 24 of 2019, section 39 — retention
odpc.go.ke
“only as long as may be reasonably necessary”
Link checked 18 August 2026
- Official sourceOffice of the Data Protection CommissionerData Protection (General) Regulations, 2021, regulation 19 — retention and deletion
odpc.go.ke
“erase, delete anonymise or pseudonymise personal data upon the lapse of the purpose”
Link checked 18 August 2026
- Official sourceOffice of the Data Protection CommissionerODPC Guidance Note on the Processing of Health Data — retention must be justified
odpc.go.ke
“must justify a stated retention time and should not preserve any personal data on a 'just-in-case' basis”
Link checked 18 August 2026
If something goes wrong
Three clocks, and the shortest one is easy to miss. If you are the organisation that decided how the data is used, you must tell the Data Commissioner without delay and in any case within seventy-two hours of becoming aware of the breach. If you are a supplier processing data for someone else, you have only forty-eight hours to tell your customer — so a supplier who waits for the customer's process has already blown the deadline. You must also tell the affected people, within a reasonably practical period rather than a fixed number of hours. Separately, the national cyber crime body runs an online incident reporting portal; we found no published deadline attached to it.
Data Protection Act section 43. The forty-eight hour processor-to-controller clock is the operational trap: it is shorter than the seventy-two hour regulator clock and runs from the processor's own awareness, which means a global supplier's standard 'notify without undue delay' contract term is not enough for Kenya. Notification to data subjects is required where the breach is likely to result in real risk to their rights and freedoms. The National Computer and Cybercrimes Co-ordination Committee operates a reporting form under the Computer Misuse and Cybercrimes Act, 2018, and we could not find a published hour-count deadline on its site — recorded as no deadline found rather than no deadline existing.
Sources
- Official sourceOffice of the Data Protection CommissionerData Protection Act, No. 24 of 2019, section 43 — notification of breach
odpc.go.ke
“notify the Data Commissioner without delay, within seventy-two hours of becoming aware of such breach”
Link checked 18 August 2026
- Official sourceNational Computer and Cybercrimes Co-ordination CommitteeNational Computer and Cybercrimes Co-ordination Committee — cyber incident reporting portal
nc4.go.ke
Link checked 18 August 2026
What catches people out
Five things that are not in the summary. One: a child is anyone under eighteen, you need a parent's verifiable consent, and profiling a child for marketing is banned outright — plus you must build age checks. Two: this is criminal law, not just fines. The regulator has recommended prosecuting company directors, and offences carry up to ten years in prison. Three: registration is a licence in disguise — a certificate lasting twenty-four months, with fees, and twelve listed activities that lose the small-business exemption. Four: for sensitive data such as health or biometrics, a good contract is not enough to send it abroad; you need the person's explicit consent. Five: the localisation rule was written for the state but the regulator reads it as catching most telephone and internet companies.
(1) Children: the Act defines a child as under eighteen; the General Regulations, 2021, regulation 13 prohibits profiling a child in relation to direct marketing; the November 2025 children's guidance note requires 'appropriate mechanisms for age verification and consent'. There is no lower digital-consent age as in Europe. (2) Criminal exposure: section 73 provides for a fine up to three million shillings (about 23,000 US dollars) or imprisonment up to ten years; the April 2026 microfinance determination shows the office actually recommending prosecution of directors for obstruction under section 61(b). The administrative cap in section 63 is the lower of five million shillings or one per cent of annual turnover — the 'lower of' drafting means the percentage limits large firms rather than exposing them. (3) Registration: Registration Regulations, 2021, regulation 9 gives a twenty-four month certificate; regulation 13 sets the exemption; the Third Schedule lists twelve activities where the exemption does not apply, including gambling, financial services, telecommunications, direct marketing, health administration, education, hospitality, property management, transport and genetic data. (4) Sensitive data: regulation 46 conditions transfer of sensitive personal data on the data subject's consent, so a safeguards-based route alone will not carry health, biometric or similar data out of Kenya. (5) The protected-systems hook: the communications guidance states that most service providers are protected computer systems under the Computer Misuse and Cybercrimes Act and therefore fall inside regulation 26. That designation sits with the government, not with you, which makes it a live risk rather than a fixed scope.
Sources
- Official sourceOffice of the Data Protection CommissionerODPC Guidance Note for Processing Children's Data, 2025
odpc.go.ke
“Child" means an individual who has not attained the age of eighteen years.”
Link checked 18 August 2026
- Official sourceOffice of the Data Protection CommissionerData Protection Act, No. 24 of 2019, sections 63 and 73 — penalties
odpc.go.ke
“five million shillings, or in the case of an undertaking, up to one per centum of its annual turnover”
Link checked 18 August 2026
- Official sourceOffice of the Data Protection CommissionerDetermination of 14 April 2026 recommending prosecution of directors for obstruction
odpc.go.ke
Link checked 18 August 2026
- Official sourceOffice of the Data Protection CommissionerRegistration Regulations, 2021, regulation 9 and Third Schedule
odpc.go.ke
“valid for a period of twenty-four months from the date of issuance”
Link checked 18 August 2026
What's changing next
One thing is landing now and three switches could flip at any time. Landing: the regulator put out three draft guidance notes in July 2026, on artificial intelligence, on emerging technologies, and on privacy-enhancing technologies. Comments closed on the seventeenth of August 2026, so final versions are due imminently. The artificial intelligence draft would require organisations to register, to run risk assessments before high-risk uses, to keep humans in the loop on serious automated decisions, and to document how well any country they send data to protects it. The three switches are described below and none of them needs a new law.
DORMANT SWITCHES, in order of how fast they could hurt. (1) Section 50 of the Act lets the Cabinet Secretary, on the Data Commissioner's recommendation, prescribe further categories of processing that must stay on Kenyan servers, on the grounds of the strategic interests of the state or the protection of revenue. The revenue ground has never been used and would reach ordinary commercial data if it were. (2) The 'protected computer system' designation under the Computer Misuse and Cybercrimes Act, 2018 automatically pulls whatever it touches into regulation 26 localisation. The privacy regulator already treats most communications providers as caught; extending it to other operators requires no change to the data protection rules at all. (3) Regulation 44 lets the Data Commissioner declare countries adequate and publish the list. No published list was found, which cuts both ways: nothing is blessed, and nothing is blocked, but the office could reshape the transfer map by publishing a narrow list. Also unresolved: the term of office of the current Data Commissioner, which we could not verify and which is a natural point of discontinuity. No pending data protection bill was found on Parliament's own bills listing, checked 18 August 2026.
Sources
- Official sourceOffice of the Data Protection CommissionerODPC draft guidance notes on artificial intelligence, emerging technologies and privacy-enhancing technologies, July 2026, comments closing 17 August 2026
odpc.go.ke
Link checked 18 August 2026
- Official sourceOffice of the Data Protection CommissionerDraft Guidance Note on Artificial Intelligence, July 2026
odpc.go.ke
“Entities shall assess and document the adequacy of data protection in any jurisdiction to which personal data is transferred in connection with AI processing and shall implement contractual or other safeguards.”
Link checked 18 August 2026
- Official sourceOffice of the Data Protection CommissionerData Protection Act, No. 24 of 2019, section 50 — the unused localisation power
odpc.go.ke
Link checked 18 August 2026
- Official sourceParliament of KenyaNational Assembly bills listing — checked for a pending data protection, cybersecurity or gambling bill, none found on the current page
parliament.go.ke
Link checked 18 August 2026
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries3 rules
If your product does one of these things, read this group first — industry rules beat the general position.
The Data Protection (General) Regulations, 2021, regulation 26 — requirement for specified processing to be done in Kenya
Directly binding regulation · Legal Notice No. 263 of 2021, made under section 50 of the Act
Kenya's only hard storage-location rule. Six state-linked purposes must be processed on a Kenyan server and data centre, or have at least one serving copy held in a Kenyan data centre. It is a mirror rule, not a ban — a second copy may sit abroad — and it is the one that makes Kenya's headline answer sectoral rather than simply conditional.
Enforced by Office of the Data Protection Commissioner
Transfer model: Allowlist (the list is currently empty) · Accepted routes: Official 'this country is safe' decision, Explicit consent
What it makes you do
- Keep the data in the countryYou may either run the whole thing on a Kenyan server and data centre, or keep at least one live working copy in a Kenyan data centre. A copy abroad remains lawful. Covers civil registration and legal identity management, running elections, public finance administration systems, computer systems declared protected by the government, early childhood and basic education, and primary and secondary health care.
Sources
- Official sourceOffice of the Data Protection CommissionerThe Data Protection (General) Regulations, 2021, regulation 26
odpc.go.ke
“process such personal data through a server and data centre located in Kenya; or store at least one serving copy of the concerned personal data in a data centre located in Kenya”
Link checked 18 August 2026
- Official sourceOffice of the Data Protection CommissionerODPC Guidance Note for the Public Sector, November 2025
odpc.go.ke
“personal data prescribed by the Cabinet Secretary (ICT) as being of strategic interest must have a copy domiciled in Kenya”
Link checked 18 August 2026
ODPC Guidance Note on the Processing of Health Data, read with regulation 26 of the Data Protection (General) Regulations, 2021
Regulator guideline
Health is the sector where Kenya's rules bite hardest on private companies. Primary and secondary care providers are caught by the state-interest localisation rule, so a live copy must stay in Kenya, and because health records count as sensitive, sending them abroad needs the patient's explicit consent rather than contractual safeguards alone.
Enforced by Office of the Data Protection Commissioner
Transfer model: Allowlist (the list is currently empty) · Accepted routes: Explicit consent
What it makes you do
- Keep the data in the countryBinding limb: providers of primary and secondary health care fall inside regulation 26 and must keep a serving copy in Kenya. The guidance note itself is persuasive, not binding, but states the regulator's expectation more broadly.
- Get consentHealth records are sensitive personal data, so a transfer abroad needs the patient's explicit consent, not just a good contract.
- Delete data after a periodNo fixed period. The regulator requires a justified retention schedule and gives seven years for deceased or non-returning patients as an example of a defensible period, not a legal minimum.
Sources
- Official sourceOffice of the Data Protection CommissionerODPC Guidance Note on the Processing of Health Data
odpc.go.ke
“Sensitive personal data can only be transferred with the consent of the data subject”
Link checked 18 August 2026
- Official sourceOffice of the Data Protection CommissionerData Protection (General) Regulations, 2021, regulation 26(2) — primary and secondary health care
odpc.go.ke
Link checked 18 August 2026
ODPC Guidance Note for the Communication Sector, applying regulation 26 through the 'protected computer system' definition in the Computer Misuse and Cybercrimes Act, 2018
Regulator guideline
Telephone and internet providers are pulled into Kenya's localisation rule through a side door. The privacy regulator states that most of them count as protected computer systems, which is one of the categories that must be processed on a Kenyan server or mirrored in a Kenyan data centre. The separate 2025 subscriber registration rules impose no storage-location duty of their own.
Enforced by Office of the Data Protection Commissioner
Transfer model: Allowlist (the list is currently empty) · Accepted routes: Official 'this country is safe' decision, Explicit consent
What it makes you do
- Keep the data in the countryReached indirectly: the regulator says most communications service providers are protected computer systems, and protected computer systems are one of the six purposes inside regulation 26.
- Put a transfer safeguard in placeNo transfer without proof of adequate safeguards or valid consent, per the regulator's own compliance checklist.
Sources
- Official sourceOffice of the Data Protection CommissionerODPC Guidance Note for the Communication Sector
odpc.go.ke
“Most service providers are protected computer systems under the Computer Misuse and Cybercrimes Act.”
Link checked 18 August 2026
- Official sourceCommunications Authority of KenyaKenya Information and Communications (Registration of Telecommunications Services Subscriber) Regulations 2025, Legal Notice No. 90
ca.go.ke
“A person who commits an offence under these Regulations shall be liable upon conviction to a fine not exceeding one million shillings or imprisonment for a term not exceeding six months, or both.”
Link checked 18 August 2026
Applies to every company3 rules
These bind you whatever business you are in, once the country's rules reach you.
The Data Protection Act, 2019
Act of parliament · No. 24 of 2019, consolidated as Cap. 411C
Kenya's general privacy law. It reaches foreign companies with no Kenyan office, requires most organisations to register and renew every two years, sets a seventy-two hour breach clock, and allows transfers abroad only on one of four listed bases. Money penalties are modest but the law is criminal as well as administrative.
Enforced by Office of the Data Protection Commissioner
Transfer model: Allowlist (the list is currently empty) · Accepted routes: Official 'this country is safe' decision, Explicit consent, Needed for a contract, Someone's life is at risk
What it makes you do
- Register or notify — applies at: Turnover of five million shillings or more, or ten or more employees, or any of twelve listed activities, 2 yearsCertificate lasts twenty-four months. Fees run from 4,000 to 40,000 shillings, roughly 31 to 310 US dollars.
- Get consent
- Tell people what you do
- Let people see their data
- Let people correct their data
- Let people delete their data
- Let people object
- Secure the data
- Report breaches to the regulator — within 72 hours
- Tell affected peopleWithin a reasonably practical period; no fixed hour count.
- Delete data after a periodOnly as long as reasonably necessary; delete, anonymise or pseudonymise once the purpose lapses.
- Appoint a data protection officerDiscretionary in the Act's wording, triggered by regular and systematic monitoring or by processing sensitive categories.
- Assess high-risk projectsRequired where processing is likely to result in high risk; the regulator has published a guidance note on how to do one.
- Written vendor contract
- Get a parent's consent for children — applies at: under 18
What it costs if you get it wrong
- Fixed maximum fine: KES 5,000,000 — about $38 thousandAdministrative penalty; the Act caps it at the LOWER of five million shillings or one per cent of annual turnover
- Percentage of global turnover: 1% of annual turnoverAlternative limb of the administrative penalty, applied only where it produces a lower figure
- Criminal liability: KES 3,000,000 or 10 years imprisonment — about $23 thousandOffences under the Act, including obstruction of the Data Commissioner
- Order to stopEnforcement notice requiring processing to stop or data to be erased
- Claims by individualsCompensation to a data subject who suffers damage
Sources
- Official sourceOffice of the Data Protection CommissionerThe Data Protection Act, No. 24 of 2019
odpc.go.ke
Link checked 18 August 2026
- Official sourceOffice of the Data Protection CommissionerODPC — Kenya's data protection legal framework
odpc.go.ke
Link checked 18 August 2026
The Data Protection (General) Regulations, 2021 — Part on transfer of personal data outside Kenya
Directly binding regulation · Legal Notice No. 263 of 2021, regulations 39 to 48
Transfers abroad need one of four bases: equivalent safeguards, an adequacy decision by the Data Commissioner, strict necessity, or the person's explicit consent. Countries that ratified the African Union data protection convention are deemed adequate. No adequacy list has been published by the Commissioner that we could find, so in practice almost everyone uses the self-assessed safeguards route.
Enforced by Office of the Data Protection Commissioner
Transfer model: Allowlist (the list is currently empty) · Accepted routes: Official 'this country is safe' decision, Approved group rules, Explicit consent, Needed for a contract, Important public interest, Legal claims, Someone's life is at risk
What it makes you do
- Put a transfer safeguard in placeMain route is a self-assessed binding legal instrument giving protection essentially equivalent to Kenyan law. There is no government-published contract template, and no filing or approval before transfer.
- Keep records of processingEvery transfer must be documented — date, recipient, justification, description of the data — and the documentation given to the Data Commissioner on request.
- Get consentSensitive personal data may only be transferred abroad with the data subject's consent. Safeguards alone are not enough.
Sources
- Official sourceOffice of the Data Protection CommissionerThe Data Protection (General) Regulations, 2021, regulations 39 to 48
odpc.go.ke
“a legal instrument containing appropriate safeguards for the protection of personal data binding the intended recipient that is essentially equivalent to the protection under the Act and these Regulations”
Link checked 18 August 2026
The Data Protection (Registration of Data Controllers and Data Processors) Regulations, 2021
Directly binding regulation
A registration regime that behaves like a licence. Certificates last twenty-four months and must be renewed. Fees are small — 4,000 to 40,000 shillings, about 31 to 310 US dollars — but the twelve listed activities strip away the small-business exemption entirely, and the register is public.
Enforced by Office of the Data Protection Commissioner
What it makes you do
- Register or notify — applies at: Exempt only if annual turnover is under five million shillings AND fewer than ten employees, unless in a Third Schedule activity, 2 yearsTwelve activities lose the exemption: political canvassing, crime prevention, gambling, educational institutions, health administration, hospitality, property management, financial services, telecommunications, direct marketing, transport services and processing of genetic data.
What it costs if you get it wrong
- Criminal liabilityProcessing without being registered where registration is mandatory
Sources
- Official sourceOffice of the Data Protection CommissionerData Protection (Registration of Data Controllers and Data Processors) Regulations, 2021
odpc.go.ke
Link checked 18 August 2026
- Official sourceOffice of the Data Protection CommissionerODPC public register of data handlers — active, expired and deregistered
odpc.go.ke
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.
The exact assent and commencement dates of the Data Protection Act, 2019, and the exact commencement date of the 2021 Regulations
Kenya Law, the official statute and gazette publisher, returned an access-denied error to our fetcher throughout this run. The Act text we used is the copy published by the regulator itself, which does not show the commencement notice. The Regulations PDF gave 31 December 2021 as the commencement, but that is also the gazette date, so the two may be being conflated. The Act is unquestionably in force — the regulator is deciding cases under it in 2026 — but plan around the earlier of any two candidate dates.
Whether any banking, payments, insurance or securities data-localisation rule exists in Kenya
Nothing was found on the Central Bank of Kenya's own site, but the site requires JavaScript and its outsourcing guideline text could not be opened. The insurance and capital markets regulators were not reachable within this run's budget. Recorded as no rule found, checked 18 August 2026, not as no rule existing.
Whether Kenya has server-location rules for gambling operators
The betting regulator's website is degraded and contains injected commercial links; it lists only the 1966 gambling statute and no current legal texts. Parliament's bills listing showed no gambling bill on the page we could read. This is a real gap and gambling is one of the twelve activities that must register with the privacy regulator, so it is worth re-checking.
Whether the Data Commissioner has published any adequacy decisions under regulation 44
The regulation allows a list to be published on the office's website. We found no such list on the pages we could reach, so we treat it as empty, but we cannot prove the absence.
Which computer systems have actually been declared 'protected computer systems' by the government
This designation is the trigger that pulls private companies into the localisation rule, and the regulator asserts it covers most communications providers. We could not locate the underlying designations or the Computer Misuse and Cybercrimes Act text on any government domain during this run, so the scope of the localisation rule for telecoms is asserted on the regulator's guidance note alone.
Minimum retention periods under Kenyan tax and company law
The revenue authority pages we tried returned errors. Kenyan tax and company statutes are widely understood to impose multi-year record-keeping floors, but we could not verify any period from a government source today, so no floor is asserted here.
The appointment date and remaining term of the current Data Protection Commissioner
The regulator's own 'about us' and 'who we are' pages do not carry biographical or term-of-office details. The Commissioner's name appears in the office's news items only.
Whether the National Computer and Cybercrimes Co-ordination Committee imposes a cyber incident reporting deadline
Its regulations and resources pages returned no documents when fetched. Only a reporting portal was visible. A deadline may exist in regulations we could not open.
60-day cadence. Kenya is stable in its text but carries three switches that need no new law: the unused power to prescribe further Kenya-only processing on revenue-protection grounds, the 'protected computer system' designation that silently expands the localisation rule, and the unpublished adequacy list. Three guidance notes also closed consultation on 17 August 2026 and will land inside the next window.
Freshness and refresh
Freshness
Checked yesterday — on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.
Put this next to another country
Kenya versus
Compare