Middle East & Africa Kenya

Kenya Data Protection Act 2019: ODPC Compliance Guide

Kenya's Data Protection Act: ODPC registration, lawful bases, data subject rights, transfer restrictions, active enforcement, and fines up to KES 5 million or 1% of turnover.

Regulation

Data Protection Act, No. 24 of 2019, with the 2021 Regulations (General; Registration; Complaints Handling and Enforcement)

Max Penalty

Administrative fines up to KES 5 million or 1% of annual turnover (whichever is lower) per infringement; offenses carry fines up to KES 3 million and/or imprisonment up to 10 years

Enforcing Authority

Office of the Data Protection Commissioner (ODPC)

Official Source

www.odpc.go.ke

Executive Summary

  • Kenya's Data Protection Act (No. 24 of 2019) is a close GDPR adaptation, operationalized by three 2021 regulations and enforced by the Office of the Data Protection Commissioner (ODPC).
  • Controllers and processors above threshold criteria must register with the ODPC (certificates renewable every 24 months), with mandatory registration regardless of thresholds for listed sectors including financial services, telecoms, health, education, and betting.
  • The Act applies extraterritorially to processing of data subjects located in Kenya; lawful bases mirror the GDPR's six, with sensitive data on heightened conditions.
  • The ODPC enforces visibly: penalty notices against digital lenders, schools, clubs, and marketing firms (including the maximum KES 5 million against a digital credit provider and multi-million-shilling penalties over unconsented photo use), plus a steady complaints docket.
  • Transfers outside Kenya require proof of appropriate safeguards or adequacy, with consent and necessity derogations, and sensitive data transfers face extra conditions.

Kenya runs East Africa’s most active privacy regime, and its distinguishing feature is ordinariness in the best sense: real complaints from real people, decided quickly, with penalties that name names. Digital lenders shaming borrowers via scraped contacts, schools posting children’s photos, clubs using patrons’ images in marketing, these are the cases that built the ODPC’s docket, not abstractions. For companies, the signal is that Kenyan exposure is retail: consent failures visible to any complainant, and a registration status anyone can look up.

LawData Protection Act, No. 24 of 2019
RegulatorOffice of the Data Protection Commissioner (ODPC)
RegistrationThreshold-based + mandatory sectors; 24-month certificates
Breach clock72 hours to ODPC (risk of harm)
TransfersProof of safeguards, consent, or necessity (s 48)
Max penaltyKES 5M or 1% turnover (lower); offenses to 10 years

Building the Kenya module

Register first; it is public. Check the sector list and thresholds, file, and diarize the 24-month renewal, the register is searchable and gaps invite both the ODPC and complainants.

Fix consent where enforcement lives. Photos, marketing, and any lending-adjacent contact processing are the penalty-producing categories; make consent provable and objections instant.

Paper transfers as proofs, not citations. Section 48 asks you to demonstrate safeguards; per-corridor memos with contractual protections do that better than borrowed EU boilerplate.

Slot Kenya into the African chassis. The same core-plus-annex structure that serves Nigeria and South Africa extends here; the NDPA vs POPIA comparison shows the pattern.

Consent and tracker behavior on Kenya-facing pages is the exact evidence ODPC complaints attach: check yours with a free scan.

Frequently Asked Questions

Who must register with the ODPC?

The Registration Regulations 2021 set thresholds (annual turnover/revenue above KES 5 million or more than 10 employees) above which controllers and processors must register, and list sectors where registration is mandatory regardless of size: among them financial institutions and digital lenders, telecoms, health providers, education institutions, betting firms, property agents, and CCTV operators. Registration describes processing purposes, categories, transfers, and safeguards; certificates last 24 months and renewals are checked. Operating unregistered where registration is required is an offense, and the ODPC publishes the register, making gaps publicly verifiable.

What rights and clocks apply to data subjects?

GDPR-family rights: information, access, correction, deletion, objection (including to direct marketing and profiling), portability, and rights around automated decisions. The General Regulations set procedures and timelines, requests are generally handled within reasonable statutory periods with the regulations specifying response expectations, and complaints to the ODPC are free and actively processed (the Complaints Regulations govern the pipeline: admission, investigation, determination, with appeals to the High Court). Kenyan practice is notably complaint-driven: individuals use the ODPC readily, and photo/marketing consent complaints have produced repeated penalties.

What has the ODPC actually enforced?

A busy docket by regional standards. Landmarks: the maximum KES 5 million penalty against a digital credit provider (Whitepath) over unconsented contact-list processing, KES 4.55 million against Mulla Pride (another lender) for using borrowers' contacts to shame-debt-collect, penalties against a school and a restaurant/club chain (Casa Vera) for publishing individuals' images without consent, and enforcement notices across education, hospitality, and real estate. Themes: consent for photos and marketing, digital-lending abuses, and CCTV. The ODPC also audits registration status and has ordered compensation to complainants, a remedial power GDPR authorities lack.

How do cross-border transfers work?

Section 48 permits transfers out of Kenya only where the controller provides proof to the ODPC of appropriate safeguards for the data's security and protection (including that the destination has commensurate protection), or with the data subject's consent, or on necessity grounds (contract, legal claims, vital interests, public interest). Sensitive data transfers face additional conditions under Section 49 and the regulations, effectively consent-or-necessity with safeguards. There is no published adequacy whitelist; the operational pattern is contractual safeguards plus a documented transfer assessment retained for ODPC inquiries, with data-center localization mandates limited to specific government datasets rather than general commercial data.

Is GDPR compliance sufficient for Kenya?

Nearly, with four additions: (1) ODPC registration with 24-month renewal tracking, the visible duty with no GDPR equivalent; (2) DPO practice, the Act encourages and the regulations detail designation, and registered entities commonly appoint one though it is not universally mandatory; (3) transfer files reworked to Section 48's proof-of-safeguards framing rather than EU instrument citations; (4) consent hygiene for photos, marketing, and lending-adjacent data, reflecting where Kenyan enforcement concentrates. Notices should reference Kenyan law and the ODPC complaint channel. The rights pipeline, security program, and breach process (notify the ODPC within 72 hours of becoming aware, where there is real risk of harm) port from a GDPR base with addressee changes.

Regulatory Crosswalk

GDPRNigeria NDPAPOPIA

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.