Kenya Data Protection Act
Kenya Data Protection Act 2019 + Data Protection (General) Regulations 2021.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (22)
Assurance
| Code | Title |
|---|---|
| KE-DPA-27 | Audit and Compliance Monitoring |
Automated Processing
| Code | Title |
|---|---|
| KE-DPA-19 | Automated Decision-Making and Profiling |
Awareness
| Code | Title |
|---|---|
| KE-DPA-26 | Training and Awareness |
Consent
| Code | Title |
|---|---|
| KE-DPA-3 | Consent Requirements |
Cross-Border Transfers
| Code | Title |
|---|---|
| KE-DPA-14 | Cross-Border Transfer Conditions |
| KE-DPA-15 | Data Localisation for Strategic Interests |
Data Lifecycle
| Code | Title |
|---|---|
| KE-DPA-23 | Data Minimisation and Retention |
Data Subject Rights
| Code | Title |
|---|---|
| KE-DPA-5 | Data Subject Right of Access |
| KE-DPA-6 | Right to Rectification and Erasure |
| KE-DPA-7 | Right to Object and Restrict Processing |
| KE-DPA-8 | Right to Data Portability |
Enforcement
| Code | Title |
|---|---|
| KE-DPA-24 | Complaints Handling and ODPC Investigations |
| KE-DPA-25 | Administrative Penalties up to KES 5M or 1% Turnover |
Exemptions
| Code | Title |
|---|---|
| KE-DPA-31 | Exemptions for Journalism, Research, and National Security |
Governance
| Code | Title |
|---|---|
| KE-DPA-10 | Records of Processing Activities (ROPA) |
| KE-DPA-18 | Privacy by Design and by Default |
| KE-DPA-32 | Codes of Conduct and Certification |
| KE-DPA-9 | Appointment of Data Protection Officer |
Incident Response
| Code | Title |
|---|---|
| KE-DPA-12 | Breach Notification to ODPC within 72 Hours |
| KE-DPA-13 | Breach Communication to Data Subjects |
Lawful Basis
| Code | Title |
|---|---|
| KE-DPA-2 | Lawful Basis for Processing |
Marketing
| Code | Title |
|---|---|
| KE-DPA-20 | Direct Marketing and Unsolicited Communications |
Registration
| Code | Title |
|---|---|
| KE-DPA-1 | Registration of Data Controllers and Processors with ODPC |
Risk Assessment
| Code | Title |
|---|---|
| KE-DPA-11 | Data Protection Impact Assessment (DPIA) |
Sectoral
| Code | Title |
|---|---|
| KE-DPA-30 | Public Sector and Government Processing |
Security
| Code | Title |
|---|---|
| KE-DPA-17 | Security of Processing |
Sensitive Data
| Code | Title |
|---|---|
| KE-DPA-29 | Health and Biometric Data Processing |
| KE-DPA-4 | Sensitive Personal Data Processing |
Surveillance
| Code | Title |
|---|---|
| KE-DPA-28 | CCTV and Workplace Monitoring |
Third-Party Risk
| Code | Title |
|---|---|
| KE-DPA-16 | Controller-Processor Contracts |
Transparency
| Code | Title |
|---|---|
| KE-DPA-22 | Privacy Notice and Transparency |
Vulnerable Populations
| Code | Title |
|---|---|
| KE-DPA-21 | Children's Data |
Your Compliance Coverage
If you comply with Kenya Data Protection Act, you already cover:
Bahrain PDPL
31%
10 controls mapped
Compare →ISO 27701
31%
10 controls mapped
Compare →CSA CCM v4
31%
10 controls mapped
Compare →+ 580 more: COPPA (31%), Delaware Online Privacy and Protection Act (proposed) (31%)
See all 583 mapped frameworks ↓Maps to 583 other frameworks
Frequently Asked Questions
What is Kenya Data Protection Act?
Kenya Data Protection Act is a compliance framework from Kenya with 22 domains and 32 controls. Kenya Data Protection Act 2019 + Data Protection (General) Regulations 2021. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does Kenya Data Protection Act have?
Kenya Data Protection Act has 32 controls organised across 22 domains. The largest domains are Data Subject Rights (4 controls), Governance (4 controls), Cross-Border Transfers (2 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does Kenya Data Protection Act map to?
Kenya Data Protection Act maps to 583 other compliance frameworks. The top mapping partners are Bahrain PDPL (31% coverage), ISO 27701 (31% coverage), CSA CCM v4 (31% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with Kenya Data Protection Act compliance?
Start your Kenya Data Protection Act compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Kenya Data Protection Act requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 32 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 769 frameworks.
Get Started Free →Free forever — no credit card required