KenyaIn ForceData Protection

Data Protection (General) Regulations, 2021

ke-dpgr-2021 · Regulation

Verified entryReviewed by Ademola Adekunbi · 27 June 2026
Summary

The Data Protection (General) Regulations, 2021 (Legal Notice No. 263 of 2021) are subsidiary legislation made under the Data Protection Act, 2019. Published in the Kenya Gazette Supplement on 14 January 2022 and commencing on the same date, the Regulations provide the detailed operational framework needed to give effect to the Act's core obligations. The Regulations elaborate on the legal requirements for obtaining valid consent: consent must be freely given, specific, informed, and unambiguous. They specify what information must be provided to a data subject before their data is collected, how consent must be recorded, and the process by which it may be withdrawn. On Data Protection Impact Assessments (DPIAs), the Regulations identify the circumstances in which a DPIA is mandatory, covering processing involving new technologies, large-scale processing of sensitive data, systematic monitoring of publicly accessible areas, and profiling that may significantly affect data subjects. Where a DPIA is submitted to the ODPC and no response is received within 60 days, the controller may proceed with processing and the DPIA is deemed approved. The Regulations set out procedures and timeframes for data subjects to exercise their rights under the Act, including the periods within which controllers must respond to access requests, rectification requests, erasure requests, and data portability requests. Data supplied pursuant to a portability request must be in a structured, commonly used, and machine-readable format. Detailed rules on cross-border data transfers are provided: transfers require either an adequacy determination for the destination jurisdiction or the presence of appropriate safeguards, including binding corporate rules, standard contractual clauses, or an approved code of conduct. The Regulations also set out the information that must appear in privacy notices given to data subjects at the point of collection, the record-keeping obligations of data controllers, and the procedures for filing complaints with the ODPC.

Key provisions
  1. Sets out requirements for valid consent, specifying that it must be freely given, specific, informed, and unambiguous, and establishing how consent must be recorded and withdrawn.
  2. Identifies the circumstances requiring a Data Protection Impact Assessment (DPIA), including large-scale processing of sensitive data, profiling with significant effects, and systematic monitoring of publicly accessible areas.
  3. Establishes timelines and detailed procedures for controllers to respond to data subject access, rectification, erasure, restriction, and portability requests.
  4. Requires that data provided in response to portability requests be delivered in a structured, commonly used, and machine-readable format.
  5. Provides rules for cross-border data transfers, recognising binding corporate rules, standard contractual clauses, and approved codes of conduct as appropriate safeguards.
  6. Specifies the mandatory content of privacy notices provided to data subjects at the point of data collection.
  7. Sets out record-keeping obligations for data controllers and data processors, and complaint-filing procedures with the ODPC.
Related instruments
Entry history
Entry history
  1. 23 June 2026
    ATLPF Research Team (AI-assisted)
    Initial draft created from Kenya Law official legislation database and ODPC official resources