Kenya
East Africa
Kenya operates one of East Africa's most developed data protection regimes, documented in ATLPF with both a primary Act and its principal subsidiary regulations. The Data Protection Act, 2019 (Act No. 24 of 2019) commenced on 25 November 2019 and gives legislative effect to the privacy right in Article 31 of the 2010 Constitution. It applies to controllers and processors established in Kenya and extraterritorially to those outside Kenya processing the personal data of individuals located in Kenya, who must appoint a local representative. The Act establishes the Office of the Data Protection Commissioner, requires registration of controllers and processors, sets out six lawful bases, imposes heightened conditions on sensitive data, grants the full suite of data-subject rights, restricts cross-border transfers to adequate jurisdictions or those with appropriate safeguards, requires breach notification within 72 hours, and provides administrative fines up to KES 5 million and criminal penalties up to ten years' imprisonment. The regime is operationalised by the Data Protection (General) Regulations, 2021, which give detailed effect to the Act, elaborating valid consent, the circumstances requiring DPIAs (with a 60-day deemed-approval mechanism), timelines for data-subject requests, portability in machine-readable form, cross-border transfer safeguards, mandatory privacy-notice content, record-keeping, and complaint procedures. This pairing of primary Act plus comprehensive General Regulations is what distinguishes Kenya's documentation from single-statute peers. Enforcement rests with the Office of the Data Protection Commissioner (ODPC), an active, independent supervisory authority that registers controllers and processors, audits, investigates complaints, issues enforcement notices, and imposes fines. With two in-force instruments and an established, active regulator, Kenya is one of the most mature and best-documented regimes on the continent.
| Topic | Instruments | Cases | Coverage |
|---|---|---|---|
| Data Protection | 5 | 4 | ● |
| AI Governance | 1 | 0 | ◐ |
| Fintech | 5 | 1 | ● |
| Cybercrime | 1 | 1 | ● |
| Digital Rights | 3 | 2 | ● |
| Platform Liability | 0 | 0 | ○ |
| Telecoms | 0 | 0 | ○ |
● Covered ◐ Partially covered ○ Not yet covered
Constitution of Kenya, 2010, Article 31 (Right to Privacy, including privacy of communications)
Enacted 27 Aug 2010
Access to Information Act, 2016 (No. 31 of 2016)
Enacted 31 Aug 2016
Computer Misuse and Cybercrimes Act, 2018 (No. 5 of 2018)
Enacted 16 May 2018
E-Money Regulations, 2013
Central Bank of Kenya (Digital Credit Providers) Regulations, 2022
Enacted 18 Mar 2022
Virtual Asset Service Providers Act, 2025
Enacted 15 Oct 2025
National Payment System Regulations, 2014
Enacted 1 Aug 2014
National Payment System Act, 2011
Enacted 2 Dec 2011
Kenya Artificial Intelligence Strategy 2025 - 2030
Enacted 27 Mar 2025
Data Protection Act, 2019
Enacted 8 Nov 2019
Data Protection (General) Regulations, 2021
Enacted 14 Jan 2022
Court of Appeal of Kenya
Decided 6 Mar 2026
Office of the Data Protection Commissioner
Decided 21 Dec 2022
Office of the Data Protection Commissioner
Decided 26 Sept 2023
High Court of Kenya at Nairobi (Judicial Review Division)
Decided 5 May 2025
Office of the Data Protection Commissioner
Decided 26 Sept 2023
Beyond the General Regulations, sector-specific and complaints-handling regulations continue to evolve and are not all separately recorded on file. The framework is otherwise comprehensive and well-documented.