IOC Law / Africa Intelligence / Kenya
Data Protection and Privacy in Kenya
Kenya’s Data Protection Act 2019 applies to controllers and processors in Kenya and can reach overseas organisations processing personal data of people located in Kenya. Controllers and processors must register unless an exemption applies. Specified activities and overseas entities may remain registrable despite general size thresholds. See the ODPC registration FAQ.
Map customer, employee, applicant, vendor, payment, CCTV, cookie and device data. Record purpose, legal basis, sensitivity, recipients, system, destination country, retention and owner. Determine controller and processor roles from actual decisions. A company may be a controller for HR data and a processor for a client’s platform.
Prepare privacy notices, processor agreements, cross-border safeguards, retention rules, rights workflows and incident response. Assess DPIA requirements for high-risk monitoring, biometrics, health, children, profiling or consequential automated decisions. Overseas hosting and remote support must be visible in the transfer map.
Use proportionate security controls: least privilege, multifactor authentication, encryption, secure development, logging, patching, backups, vendor review and training. Test the breach plan before launch. Marketing should separate service communications, direct marketing and cookies and maintain consent and suppression records.
Registration is continuing compliance. Update the position when processing, ownership or system locations change and track certificate renewal. In an acquisition, analyse whether personal data can lawfully be disclosed in diligence and used by the buyer after closing.