Kenya Data Protection Act 2019
The Kenya Data Protection Act No. 24 of 2019 establishes Kenya's comprehensive data protection framework. It creates the Office of the Data Protection Commissioner (ODPC) as the supervisory authority. The Act establishes data processing principles, data subject rights, registration requirements for controllers and processors, and provisions for cross-border data transfers. Applies to processing of personal data by controllers and processors within and outside Kenya where data subjects are in Kenya.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (7)
Part I - Preliminary
| Code | Title |
|---|---|
| Sec. 1 | Short Title and Commencement |
| Sec. 2 | Interpretation |
| Sec. 3 | Scope and Application |
| Sec. 4 | Exemptions |
| Sec. 6 | Establishment of the Commission |
Part II - Office of the Data Protection Commissioner
| Code | Title |
|---|---|
| Sec. 5 | Functions and Duties of Authority |
| Sec. 6 | Establishment of the Commission |
| Sec. 8 | Functions of the Commission |
| Sec. 9 | Direct Marketing Consent |
Part III - Registration of Data Controllers and Processors
| Code | Title |
|---|---|
| Sec. 18 | Right to Correction |
| Sec. 19 | Lawful, Fair and Transparent Processing |
| Sec. 20 | Purpose Limitation |
Part IV - Rights of Data Subjects
| Code | Title |
|---|---|
| Sec. 26 | Notifiable Data Breaches |
| Sec. 27 | Duty to Conduct Assessment |
| Sec. 28 | Duty to Notify |
| Sec. 29 | Data Protection Council |
Part V - Obligations of Data Controllers and Processors
| Code | Title |
|---|---|
| Sec. 30 | Right to Information |
| Sec. 31 | Unauthorised Disclosure |
| Sec. 33 | Unauthorised Re-identification |
| Sec. 35 | Security of Processing |
Part VI - Transfer of Personal Data
| Code | Title |
|---|---|
| Sec. 48 | Establishment of the Office |
| Sec. 49 | Exemptions |
Part VII - Exemptions and Enforcement
| Code | Title |
|---|---|
| Sec. 51 | Exemptions |
| Sec. 56 | Complaints Mechanism |
| Sec. 61 | Offences and Penalties |
Maps to 526 other frameworks
Frequently Asked Questions
What is Kenya Data Protection Act 2019?
Kenya Data Protection Act 2019 is a compliance framework from Kenya with 7 domains and 25 controls. The Kenya Data Protection Act No. 24 of 2019 establishes Kenya's comprehensive data protection framework. It creates the Office of the Data Protection Commissioner (ODPC) as the supervisory authority. The Act establishes data processing principles, data subject rights, registration requirements for controllers and processors, and provisions for cross-border data transfers. Applies to processing of personal data by controllers and processors within and outside Kenya where data subjects are in Kenya. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does Kenya Data Protection Act 2019 have?
Kenya Data Protection Act 2019 has 25 controls organised across 7 domains. The largest domains are Part I - Preliminary (5 controls), Part II - Office of the Data Protection Commissioner (4 controls), Part IV - Rights of Data Subjects (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does Kenya Data Protection Act 2019 map to?
Kenya Data Protection Act 2019 maps to 526 other compliance frameworks. The top mapping partners are Bosnia and Herzegovina Law on Protection of Personal Data (2006, amended 2011) (38% coverage), Albania Law on Protection of Personal Data (Law No. 9887, 2008, amended 2014) (38% coverage), EU Digital Services Act — Minors Protection Provisions (Regulation 2022/2065) (38% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with Kenya Data Protection Act 2019 compliance?
Start your Kenya Data Protection Act 2019 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Kenya Data Protection Act 2019 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 25 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 692 frameworks.
Get Started Free →Free forever — no credit card required