Kenya Data Protection Act 2019 (DPA) Act No. 24 of 2019 + assented by President 8 November 2019 + commenced 25 November 2019 + published in Kenya Gazette Supplement No. 181. Foundational comprehensive data protection statute for Republic of Kenya + significantly aligned with EU GDPR + first East African Community member to enact GDPR-style legislation. (1) Statutory Framework: (a) Bill introduced in National Assembly 2018; (b) Act No. 24 of 2019 passed Parliament; (c) Presidential Assent 8 November 2019; (d) Commenced 25 November 2019; (e) Office of the Data Protection Commissioner (ODPC) established + Commissioner Immaculate Kassait appointed 14 November 2020; (f) Implementing Regulations + Operational + Compliance Regulations + Complaints Regulations + Cross-Border Regulations + Registration Regulations promulgated 2021; (g) National Information Communications and Technology (ICT) Policy 2019 alignment. (2) Constitutional Anchor: (a) Constitution of Kenya 2010 Article 31 Right to Privacy - every person has the right to privacy including not to have (i) their person home or property searched; (ii) their possessions seized; (iii) information relating to their family or private affairs unnecessarily required or revealed; (iv) the privacy of their communications infringed; (b) Article 33 Freedom of Expression; (c) Article 35 Access to Information Act 2016 intersection; (d) Bill of Rights Chapter Four. (3) Section 1 Short Title and Commencement: (a) The Data Protection Act 2019; (b) Commencement on 25 November 2019. (4) Section 2 Interpretation - Definitions: (a) Personal data - information relating to identified or identifiable natural person; (b) Sensitive Personal Data per Section 44 - includes data relating to children + race + health + biometric + genetic + sex life + sexual orientation + religion + belief + conscience + ethnicity + tribe + nationality + immigration status + marital status + family details including names of person spouse children parents; (c) Data subject - identified or identifiable natural person; (d) Data controller - person determining purposes and means of processing; (e) Data processor - person processing on behalf of controller; (f) Processing - operations on personal data including collection + recording + organisation + storage + adaptation + retrieval + consultation + use + disclosure + dissemination + alignment + restriction + erasure + destruction; (g) Consent - any manifestation of express + unequivocal + free + specific + informed indication of data subject wishes; (h) Public Authority - state organ; (i) Public Body. (5) Section 3 Object and Purpose: (a) Regulate processing of personal data; (b) Ensure data subject rights; (c) Provide framework for cross-border transfers; (d) Establish data protection commissioner; (e) Provide for collection + protection of personal data. (6) Section 4 Application and Exemptions: (a) Material Scope - applies to processing of personal data within Kenya OR by data controller/processor established in Kenya OR processing of personal data of data subjects in Kenya; (b) Territorial Scope - extraterritorial application similar to GDPR Article 3; (c) Excluded - processing for purely personal or household activity by natural person; (d) Limited exemptions for national security + criminal investigation + journalism + research + statistics per Section 51. (7) Office of the Data Protection Commissioner (ODPC): (a) Established under Section 5 + 6; (b) Independent regulatory body affiliated with Ministry of Information Communications and Technology (MIICT); (c) Commissioner Immaculate Kassait appointed 14 November 2020 first commissioner; (d) Headquartered Britam Tower Nairobi; (e) Branch offices in Mombasa + Eldoret + Kisumu; (f) Inter-ministerial coordination including Ministry of ICT + Ministry of Interior + Ministry of Health. (8) International Coordination: (a) EU GDPR Regulation 2016/679 (significant alignment); (b) Convention 108+ Modernised Council of Europe (Kenya accession candidate); (c) East African Community (EAC) Data Protection initiative; (d) African Union Convention on Cyber Security and Personal Data Protection (Malabo Convention 2014); (e) Bilateral arrangements + cross-border data flow agreements emerging; (f) Common Market for Eastern and Southern Africa (COMESA). (9) Sectoral Coordination: (a) Central Bank of Kenya + banking sector; (b) Communications Authority of Kenya + telecommunications; (c) Insurance Regulatory Authority; (d) Kenya Revenue Authority + Tax Administration; (e) Ministry of Health + Universal Health Coverage; (f) Ministry of Education + Competency Based Curriculum (CBC); (g) Cyber Security Centre under MIICT + National KE-CIRT/CC. (10) Penalties Framework per Sections 56-63: (a) Administrative penalties up to KES 5 million OR 1 percent of annual turnover whichever is higher; (b) Article 63 offences + Civil compensation; (c) Criminal prosecution for serious offences; (d) Director + Officer liability; (e) Operational suspension for licensed entities. Coordinates with EU GDPR + UK DPA 2018 + Convention 108+ + East African Community Data Protection initiative + African Union Convention on Cyber Security and Personal Data Protection (Malabo Convention 2014) + Constitution of Kenya 2010 Article 31 + 33 + 35 + Access to Information Act 2016 + Computer Misuse and Cybercrimes Act 2018 + Kenya Information and Communications Act + Banking Act + Communications Authority of Kenya + Insurance Regulatory Authority + Kenya Revenue Authority + Ministry of Health + Ministry of Education + National KE-CIRT/CC. Kenya Data Protection Act 2019 Scope + Sections 1-4 applies.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.