Kenya runs East Africa’s most active privacy regime, and its distinguishing feature is ordinariness in the best sense: real complaints from real people, decided quickly, with penalties that name names. Digital lenders shaming borrowers via scraped contacts, schools posting children’s photos, clubs using patrons’ images in marketing, these are the cases that built the ODPC’s docket, not abstractions. For companies, the signal is that Kenyan exposure is retail: consent failures visible to any complainant, and a registration status anyone can look up.
| Law | Data Protection Act, No. 24 of 2019 |
|---|---|
| Regulator | Office of the Data Protection Commissioner (ODPC) |
| Registration | Threshold-based + mandatory sectors; 24-month certificates |
| Breach clock | 72 hours to ODPC (risk of harm) |
| Transfers | Proof of safeguards, consent, or necessity (s 48) |
| Max penalty | KES 5M or 1% turnover (lower); offenses to 10 years |
Building the Kenya module
Register first; it is public. Check the sector list and thresholds, file, and diarize the 24-month renewal, the register is searchable and gaps invite both the ODPC and complainants.
Fix consent where enforcement lives. Photos, marketing, and any lending-adjacent contact processing are the penalty-producing categories; make consent provable and objections instant.
Paper transfers as proofs, not citations. Section 48 asks you to demonstrate safeguards; per-corridor memos with contractual protections do that better than borrowed EU boilerplate.
Slot Kenya into the African chassis. The same core-plus-annex structure that serves Nigeria and South Africa extends here; the NDPA vs POPIA comparison shows the pattern.
Consent and tracker behavior on Kenya-facing pages is the exact evidence ODPC complaints attach: check yours with a free scan.