Kenya Data Protection Act 2019
The Kenya Data Protection Act No. 24 of 2019 establishes Kenya's comprehensive data protection framework. It creates the Office of the Data Protection Commissioner (ODPC) as the supervisory authority. The Act establishes data processing principles, data subject rights, registration requirements for controllers and processors, and provisions for cross-border data transfers. Applies to processing of personal data by controllers and processors within and outside Kenya where data subjects are in Kenya.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (24)
Accountability
| Code | Title |
|---|---|
| KE-DPA-S31 | Records of Processing and DPIA |
Algorithmic
| Code | Title |
|---|---|
| KE-DPA-S35 | Automated Individual Decision Making |
Children
| Code | Title |
|---|---|
| KE-DPA-S33 | Processing of Children's Personal Data |
Enforcement
| Code | Title |
|---|---|
| KE-DPA-S58 | Complaints to the ODPC |
Governance
| Code | Title |
|---|---|
| KE-DPA-S24 | Designation of Data Protection Officer |
Incident Response
| Code | Title |
|---|---|
| KE-DPA-S43 | Notification of Personal Data Breaches |
Lawful Basis
| Code | Title |
|---|---|
| KE-DPA-S30 | Conditions for Lawful Processing |
Marketing
| Code | Title |
|---|---|
| KE-DPA-S37 | Direct Marketing Use of Personal Data |
Part I - Preliminary
| Code | Title |
|---|---|
| Sec. 1 | Short Title and Commencement |
| Sec. 2 | Interpretation |
| Sec. 3 | Scope and Application |
| Sec. 4 | Exemptions |
| Sec. 6 | Establishment of the Commission |
Part II - Office of the Data Protection Commissioner
| Code | Title |
|---|---|
| Sec. 5 | Functions and Duties of Authority |
| Sec. 6 | Establishment of the Commission |
| Sec. 8 | Functions of the Commission |
| Sec. 9 | Direct Marketing Consent |
Part III - Registration of Data Controllers and Processors
| Code | Title |
|---|---|
| Sec. 18 | Right to Correction |
| Sec. 19 | Lawful, Fair and Transparent Processing |
| Sec. 20 | Purpose Limitation |
Part IV - Rights of Data Subjects
| Code | Title |
|---|---|
| Sec. 26 | Notifiable Data Breaches |
| Sec. 27 | Duty to Conduct Assessment |
| Sec. 28 | Duty to Notify |
| Sec. 29 | Data Protection Council |
Part V - Obligations of Data Controllers and Processors
| Code | Title |
|---|---|
| Sec. 30 | Right to Information |
| Sec. 31 | Unauthorised Disclosure |
| Sec. 33 | Unauthorised Re-identification |
| Sec. 35 | Security of Processing |
Part VI - Transfer of Personal Data
| Code | Title |
|---|---|
| Sec. 48 | Establishment of the Office |
| Sec. 49 | Exemptions |
Part VII - Exemptions and Enforcement
| Code | Title |
|---|---|
| Sec. 51 | Exemptions |
| Sec. 56 | Complaints Mechanism |
| Sec. 61 | Offences and Penalties |
Principles
| Code | Title |
|---|---|
| KE-DPA-S25 | Principles of Data Protection |
Processors
| Code | Title |
|---|---|
| KE-DPA-S42 | Use of Data Processors |
Registration
| Code | Title |
|---|---|
| KE-DPA-S18 | Registration of Controllers and Processors |
Retention
| Code | Title |
|---|---|
| KE-DPA-S39 | Retention and Storage Limitation |
Rights
| Code | Title |
|---|---|
| KE-DPA-S26 | Rights of the Data Subject |
Security
| Code | Title |
|---|---|
| KE-DPA-S41 | Security of Personal Data |
Sensitive Data
| Code | Title |
|---|---|
| KE-DPA-S44 | Processing of Sensitive Personal Data |
Transfers
| Code | Title |
|---|---|
| KE-DPA-S48 | Transfer of Personal Data Outside Kenya |
Transparency
| Code | Title |
|---|---|
| KE-DPA-S29 | Information to Data Subjects at Collection |
Your Compliance Coverage
If you comply with Kenya Data Protection Act 2019, you already cover:
Albania Law on Protection of Personal Data (Law No. 9887, 2008, amended 2014)
22%
9 controls mapped
Compare →MiFID II / MiFIR
22%
9 controls mapped
Compare →Turkey Personal Data Protection Law (KVKK - Law No. 6698)
22%
9 controls mapped
Compare →+ 311 more: Uzbekistan Law on Personal Data (No. ZRU-547) (22%), Portugal Law No. 58/2019 - Data Protection Implementation Act (22%)
See all 314 mapped frameworks ↓Maps to 314 other frameworks
Frequently Asked Questions
What is Kenya Data Protection Act 2019?
Kenya Data Protection Act 2019 is a compliance framework from Kenya with 24 domains and 42 controls. The Kenya Data Protection Act No. 24 of 2019 establishes Kenya's comprehensive data protection framework. It creates the Office of the Data Protection Commissioner (ODPC) as the supervisory authority. The Act establishes data processing principles, data subject rights, registration requirements for controllers and processors, and provisions for cross-border data transfers. Applies to processing of personal data by controllers and processors within and outside Kenya where data subjects are in Kenya. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does Kenya Data Protection Act 2019 have?
Kenya Data Protection Act 2019 has 42 controls organised across 24 domains. The largest domains are Part I - Preliminary (5 controls), Part II - Office of the Data Protection Commissioner (4 controls), Part IV - Rights of Data Subjects (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does Kenya Data Protection Act 2019 map to?
Kenya Data Protection Act 2019 maps to 314 other compliance frameworks. The top mapping partners are Albania Law on Protection of Personal Data (Law No. 9887, 2008, amended 2014) (22% coverage), MiFID II / MiFIR (22% coverage), Turkey Personal Data Protection Law (KVKK - Law No. 6698) (22% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with Kenya Data Protection Act 2019 compliance?
Start your Kenya Data Protection Act 2019 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Kenya Data Protection Act 2019 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 42 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 700 frameworks.
Get Started Free →Free forever — no credit card required