Your Business Holds Personal Data. The Law Has Something to Say About That.
Look, every business in Kenya handles personal data. Every single one. The employee payroll. The customer database. The enquiry form on your website. The WhatsApp group where your team shares client updates. The Excel sheet with supplier contacts that has been sitting on a shared drive since 2018.
All of it is personal data. And since the Data Protection Act, No. 24 of 2019 came into force, all of it is regulated.
Honestly, the number of Kenyan businesses that have heard of the Act but have not actually done anything about it is striking. Some assume it only applies to large corporations or tech companies. Others have been meaning to get around to it. A few are not even sure what personal data means in a legal sense.
This article is a plain, practical guide to what the Act requires, who it applies to, what your obligations are as a business, and what happens if you fall short. Read it, share it with your team, and then do something about it.
Contact S&P Advocates ⟶ Talk To Our Team About Data Protection Compliance
What Is the Data Protection Act, 2019?
The Data Protection Act, No. 24 of 2019 is Kenya’s primary legislation governing the collection, use, storage, and disclosure of personal data. It was enacted to give effect to Article 31(c) and (d) of the Constitution of Kenya, 2010, which guarantees every person the right to privacy, including the right not to have information relating to their family or private affairs unnecessarily required or revealed.
The Act established the Office of the Data Protection Commissioner (ODPC), a statutory body with the mandate to oversee compliance, receive complaints, conduct investigations, and impose sanctions on organisations that violate the law.
The Act is supplemented by several regulations, including the:
- Data Protection (General) Regulations, 2021
- Data Protection (Registration of Data Controllers and Data Processors) Regulations, 2021
- Data Protection (Complaints Handling Procedure and Enforcement) Regulations, 2021
Together, these instruments form the full regulatory framework that Kenyan businesses must comply with.
Office of the Data Protection Commissioner (ODPC Kenya) ⟶ www.odpc.go.ke
Who Does the Act Apply To?
This is the question most business owners ask first. And the answer is broader than most people expect.
The Act applies to any person or organisation that collects, processes, stores, uses, or discloses personal data about individuals, where:
- The organisation is established in Kenya, or
- The processing takes place in Kenya, or
- The personal data relates to individuals who are in Kenya
In practical terms, this means the Act applies to:
- Every Kenyan company and business, regardless of size or sector
- Foreign companies that process the personal data of Kenyan residents
- Non-governmental organisations and associations
- Government agencies and public bodies
- Sole traders and individual professionals who handle client or employee data
You know what this means? The small law firm, the mid-sized manufacturing company, the e-commerce startup, the hospital, the school, the SACCO, the church with a membership database; all of them are covered.
Key Definitions You Need to Know
Before getting into obligations, it helps to understand the terminology the Act uses. These definitions matter because your obligations depend on which role you play.
Personal Data
Under Section 2 of the Act, personal data means any information relating to an identified or identifiable natural person. This includes:
- Names, ID numbers, phone numbers, email addresses
- Location data
- Financial information, including bank account details and credit scores
- Health and medical information
- Biometric data, including fingerprints and facial recognition data
- Employment information
- Online identifiers such as IP addresses and cookies
Data Subject
The individual whose personal data is being collected or processed. Your customers, employees, suppliers, and website visitors are all data subjects.
Data Controller
An organisation or person that determines the purposes and means of processing personal data. If your business decides what data to collect and why, you are a data controller.
Data Processor
An organisation or person that processes personal data on behalf of a data controller. Your payroll provider, your cloud storage provider, and your email marketing platform are likely data processors.
Most businesses are data controllers. Some are both data controllers and data processors, depending on the nature of their work.
Step One: Register With the ODPC
The Data Protection (Registration of Data Controllers and Data Processors) Regulations, 2021 require data controllers and data processors to register with the ODPC before processing personal data.
Registration is done through the ODPC’s online portal at www.odpc.go.ke. The registration process requires you to provide information about:
- Your organisation’s identity and contact details
- The categories of personal data you process
- The purposes for which you process personal data
- The categories of data subjects whose data you hold
- Whether you transfer data outside Kenya and to which countries
Registration attracts a fee that varies depending on the size and nature of the organisation.
Failure to register is itself a violation of the Act and can attract penalties.
ODPC Registration Portal (Register With the ODPC) ⟶ www.odpc.go.ke
Your Core Obligations as a Data Controller
Once registered, your obligations under the Act are ongoing and substantial. Here is what the law requires.
1. Collect Data Lawfully and Fairly
Under Section 25 of the Act, personal data must be processed lawfully, fairly, and in a transparent manner. You must have a lawful basis for every piece of personal data you collect. The Act recognises the following lawful bases:
- Consent — the data subject has given clear, informed, and specific consent
- Contract — processing is necessary to perform a contract with the data subject
- Legal obligation — processing is required by law
- Vital interests — processing is necessary to protect someone’s life
- Public interest — processing is necessary for a public interest task
- Legitimate interests — processing is necessary for your legitimate business interests, provided these do not override the data subject’s rights
Consent under the Act must be freely given, specific, informed, and unambiguous. Pre-ticked boxes, vague consent clauses buried in small print, and blanket authorisations do not meet the standard.
2. Collect Only What You Need
The data minimisation principle under Section 25(c) requires that personal data collected must be adequate, relevant, and limited to what is necessary for the purpose. Collecting data “just in case it might be useful later” is not a lawful approach under the Act.
Review every form, every database field, and every data collection process in your business and ask honestly: do we actually need this information for the purpose we have stated?
3. Keep Data Accurate and Up to Date
Under Section 25(d), personal data must be accurate and, where necessary, kept up to date. You must take reasonable steps to ensure that inaccurate personal data is erased or corrected without delay.
4. Keep Data Only as Long as Necessary
The storage limitation principle under Section 25(e) requires that personal data be kept in a form that permits identification of data subjects for no longer than is necessary for the purpose for which it was collected.
This means you need a data retention policy that sets out how long you keep different categories of data and what happens to it at the end of the retention period. Holding onto customer data indefinitely “just in case” is a compliance risk.
5. Keep Data Secure
Section 41 of the Act requires data controllers to implement appropriate technical and organisational measures to ensure the security of personal data, including protection against:
- Unauthorised access
- Accidental loss or destruction
- Unlawful processing or disclosure
What counts as “appropriate” depends on the nature of the data and the risks involved. At a minimum, every business should have:
- Password-protected systems with access controls
- Encrypted storage for sensitive personal data
- Regular software updates and security patches
- Staff training on data security practices
- A clear process for responding to data breaches
6. Respect Data Subject Rights
The Act gives individuals significant rights over their personal data. As a data controller, you must be able to respond to requests from data subjects to exercise these rights.
Right of access
A data subject can request a copy of the personal data you hold about them. You must respond within 21 days.
Right to rectification
A data subject can request correction of inaccurate data. You must respond within 21 days.
Right to erasure
A data subject can request deletion of their personal data in certain circumstances, including where the data is no longer necessary for the original purpose or where consent has been withdrawn.
Right to object
A data subject can object to processing based on legitimate interests. You must stop processing unless you can demonstrate compelling legitimate grounds that override their interests.
Right to data portability
A data subject can request their data in a portable, machine-readable format where processing is based on consent or contract.
Right to withdraw consent
Where you rely on consent as your lawful basis, the data subject has the right to withdraw it at any time, and withdrawal must be as easy as giving it.
7. Appoint a Data Protection Officer (Where Required)
Under the Data Protection (General) Regulations, 2021, certain organisations are required to appoint a Data Protection Officer (DPO). These include:
- Public authorities
- Organisations that process personal data on a large scale
- Organisations that process special categories of data (health data, biometric data, financial data) regularly and systematically
Even where a DPO is not strictly required, appointing one is good practice. The DPO is responsible for overseeing data protection compliance, advising on obligations, and acting as the point of contact with the ODPC.
Special Categories of Personal Data
Some categories of personal data are considered particularly sensitive and attract heightened protection under Section 46 of the Act. These include:
- Health and medical data
- Genetic and biometric data
- Data revealing racial or ethnic origin
- Religious beliefs or political opinions
- Financial data
- Sexual orientation or gender identity
- Criminal records
Processing special category data requires explicit consent from the data subject, unless another specific lawful basis applies. Businesses that handle special category data, including hospitals, financial institutions, HR departments, and schools, must apply additional safeguards.
Transferring Data Outside Kenya
If your business transfers personal data to a country outside Kenya, you must ensure that the receiving country provides an adequate level of data protection comparable to the protections under the Kenyan Act.
Where adequate protection is not guaranteed by the destination country’s laws, you must put in place appropriate safeguards, such as contractual clauses or binding corporate rules, before the transfer takes place.
This is particularly relevant for businesses that:
- Use cloud storage providers based outside Kenya
- Share customer data with international partners or parent companies
- Use foreign-based email marketing, CRM, or HR platforms
Privacy Notices: What You Must Tell People
Transparency is one of the foundational principles of the Act. When you collect personal data, you must provide the data subject with a privacy notice that includes:
- Who you are and how to contact you
- What data you are collecting and why
- The lawful basis for processing
- How long you will keep the data
- Whether you will share it with third parties and who they are
- Whether you will transfer it outside Kenya
- The data subject’s rights and how to exercise them
- Whether the collection is voluntary or mandatory and the consequences of not providing it
Privacy notices must be written in plain language that a reasonable person can understand. Legal jargon and dense paragraphs do not meet the standard.
Data Breaches: What to Do When Things Go Wrong
A data breach is any security incident that results in the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.
Under Section 43 of the Act, data controllers must:
- Notify the ODPC of a breach within 72 hours of becoming aware of it, where the breach is likely to result in a risk to the rights and freedoms of data subjects
- Notify affected data subjects without undue delay where the breach is likely to result in a high risk to their rights and freedoms
This 72-hour window is tight. It means every business needs a data breach response plan before a breach occurs, not after. That plan should identify who is responsible for assessing and reporting breaches, what information needs to be gathered, and how affected individuals will be notified.
What Happens if You Are Not Compliant?
Here is the part that should focus the mind.
Administrative Penalties
Under Section 71 of the Act, the ODPC can impose administrative fines of up to Kshs 5,000,000 or, in the case of an undertaking, up to 1% of annual gross turnover, whichever is higher. These fines apply for contraventions of the Act including failure to register, failure to implement security measures, and failure to comply with data subject rights requests.
Criminal Offences
The Act also creates criminal offences. Under Sections 72 to 74, certain violations can result in:
- Fines of up to Kshs 3,000,000
- Imprisonment of up to 10 years
- Or both
Criminal liability extends to directors, managers, and officers of a company where the offence was committed with their consent or connivance.
Reputational Damage
Beyond the legal consequences, a data breach or a public finding of non-compliance can cause lasting reputational harm. In 2026, customers and business partners take data privacy seriously. A business that mishandles personal data loses trust, and trust is hard to rebuild.
A Practical Data Protection Compliance Checklist for Kenyan Businesses
Here is a working checklist to assess where your business stands:
Registration
- Have you registered with the ODPC as a data controller or data processor?
Data Mapping
- Do you know what personal data your business holds, where it came from, and where it goes?
Lawful Basis
- Have you identified a lawful basis for every category of personal data you process?
Privacy Notice
- Do you have a clear, plain-language privacy notice that tells data subjects how you use their data?
Consent
- Where you rely on consent, is it specific, informed, and freely given? Can data subjects withdraw it easily?
Data Minimisation
- Are you collecting only the data you actually need for the stated purpose?
Retention Policy
- Do you have a written policy setting out how long you keep different categories of data?
Security Measures
- Do you have appropriate technical and organisational measures to protect personal data?
Data Subject Rights
- Do you have a process for handling data subject access requests, correction requests, and erasure requests within 21 days?
Data Breach Response
- Do you have a documented breach response plan that includes ODPC notification within 72 hours?
Third-Party Processors
- Do you have written contracts with your data processors that include data protection obligations?
Cross-Border Transfers
- Have you assessed whether your data transfers outside Kenya are lawful and properly safeguarded?
Staff Training
- Have your employees received training on data protection obligations and your internal policies?
If you answered no to any of these, you have compliance work to do.
Commission A Data Protection Compliance Audit ⟶
Frequently Asked Questions: Kenya Data Protection Act
Yes. The Act does not have a small business exemption. If you process the personal data of any individual in Kenya, the Act applies to you. The scale and nature of your processing affects the specific obligations that apply, but the core principles and registration requirement apply to all.
Processing is broadly defined and covers virtually anything you do with personal data, including collecting, recording, organising, structuring, storing, adapting, using, disclosing, transferring, and deleting it.
No. Consent is one of six lawful bases for processing. Where processing is necessary to perform a contract, to comply with a legal obligation, or for your legitimate business interests, you do not need consent. However, for special category data and for direct marketing, consent or a specific legal basis is required.
A data controller decides why and how personal data is processed. A data processor processes data on behalf of a controller and follows the controller's instructions. Your business is most likely a data controller. The platforms and services you use to handle data, such as your payroll software provider or cloud storage platform, are likely data processors.
Registration is completed online through the ODPC portal at www.odpc.go.ke. You will need your organisation's KRA PIN, contact details, and information about your data processing activities. Registration attracts a fee.
Acknowledge the request promptly and respond within 21 days with a copy of the personal data you hold about the individual. If the request is complex or if you need to verify the requester's identity, you may extend the response period by a further month with notification. Do not ignore data subject requests, failure to respond is a violation of the Act.
Compliance Is Not Optional. But It Is Manageable.
The Data Protection Act, 2019 is here, it is being enforced, and the ODPC is active. The question for Kenyan businesses in 2026 is not whether to comply but how quickly and how well.
The good news is that compliance is achievable for businesses of every size. It requires honest assessment of the data you hold, clear documentation of your practices, proper notice to data subjects, and the security measures and internal processes to back it all up.
At Simiyu and Partners Advocates LLP, we advise businesses across Kenya on data protection compliance, including registration with the ODPC, privacy policy drafting, data protection audits, and responding to regulatory investigations. If you are not sure where your business stands, a legal audit is the fastest way to find out.
Commission A Legal Audit ⟶
Talk To Our Team Today ⟶
Office of the Data Protection Commissioner (ODPC Kenya) ⟶
Data Protection Act No. 24 of 2019 (Kenya Law) ⟶
Data Protection (General) Regulations 2021 (Kenya Law) ⟶
Simiyu and Partners Advocates LLP is a Nairobi-based specialist law firm offering senior-led counsel in dispute resolution, commercial, property, and regulatory law across Kenya and East Africa. This article is for informational purposes only and does not constitute legal advice. For advice specific to your situation, please contact our team directly.