KE

Kenya

East Africa

11Instruments
5Cases
3Regulators
85%Coverage
Overview

Kenya operates one of East Africa's most developed data protection regimes, documented in ATLPF with both a primary Act and its principal subsidiary regulations. The Data Protection Act, 2019 (Act No. 24 of 2019) commenced on 25 November 2019 and gives legislative effect to the privacy right in Article 31 of the 2010 Constitution. It applies to controllers and processors established in Kenya and extraterritorially to those outside Kenya processing the personal data of individuals located in Kenya, who must appoint a local representative. The Act establishes the Office of the Data Protection Commissioner, requires registration of controllers and processors, sets out six lawful bases, imposes heightened conditions on sensitive data, grants the full suite of data-subject rights, restricts cross-border transfers to adequate jurisdictions or those with appropriate safeguards, requires breach notification within 72 hours, and provides administrative fines up to KES 5 million and criminal penalties up to ten years' imprisonment. The regime is operationalised by the Data Protection (General) Regulations, 2021, which give detailed effect to the Act, elaborating valid consent, the circumstances requiring DPIAs (with a 60-day deemed-approval mechanism), timelines for data-subject requests, portability in machine-readable form, cross-border transfer safeguards, mandatory privacy-notice content, record-keeping, and complaint procedures. This pairing of primary Act plus comprehensive General Regulations is what distinguishes Kenya's documentation from single-statute peers. Enforcement rests with the Office of the Data Protection Commissioner (ODPC), an active, independent supervisory authority that registers controllers and processors, audits, investigates complaints, issues enforcement notices, and imposes fines. With two in-force instruments and an established, active regulator, Kenya is one of the most mature and best-documented regimes on the continent.

Topic coverage
TopicInstrumentsCasesCoverage
Data Protection54
AI Governance10
Fintech51
Cybercrime11
Digital Rights32
Platform Liability00
Telecoms00

● Covered  ◐ Partially covered  ○ Not yet covered

Instruments
ke-const-privacy·Act

Constitution of Kenya, 2010, Article 31 (Right to Privacy, including privacy of communications)

KenyaDigital RightsData ProtectionIn Force
Verified

Enacted 27 Aug 2010

ke-ati-2016·Act

Access to Information Act, 2016 (No. 31 of 2016)

KenyaDigital RightsData ProtectionIn Force
Verified

Enacted 31 Aug 2016

ke-cyber-2018·Act

Computer Misuse and Cybercrimes Act, 2018 (No. 5 of 2018)

KenyaCybercrimeData ProtectionDigital RightsIn Force
Verified

Enacted 16 May 2018

ke-emoney-2013·Regulation

E-Money Regulations, 2013

KenyaFintechIn Force
Verified
ke-dcp-2022·Regulation

Central Bank of Kenya (Digital Credit Providers) Regulations, 2022

KenyaFintechIn Force
Verified

Enacted 18 Mar 2022

ke-vaspact-2025·Act

Virtual Asset Service Providers Act, 2025

KenyaFintechIn Force
Verified

Enacted 15 Oct 2025

ke-npsregulations-2014·Regulation

National Payment System Regulations, 2014

KenyaFintechIn Force
Verified

Enacted 1 Aug 2014

ke-npsact-2011·Act

National Payment System Act, 2011

KenyaFintechIn Force
Verified

Enacted 2 Dec 2011

ke-ai-2025·Guidance

Kenya Artificial Intelligence Strategy 2025 - 2030

KenyaAI GovernanceProposed
Verified

Enacted 27 Mar 2025

ke-dpa-2019·Act

Data Protection Act, 2019

KenyaData ProtectionIn Force
Verified

Enacted 8 Nov 2019

ke-dpgr-2021·Regulation

Data Protection (General) Regulations, 2021

KenyaData ProtectionIn Force
Verified

Enacted 14 Jan 2022

Cases
ke-ca-2026-bake-v-ag

Court of Appeal of Kenya

KenyaCybercrimeDigital RightsSupreme Court / Court of Appeal
Verified

Decided 6 Mar 2026

"The Court of Appeal partially allowed BAKE's appeal, declaring sections 22 (false publications) and 23 (publication of false information) of the Computer Misuse and Cybercrimes Act 2018 unconstitutional for vagueness and overbreadth and as unjustified limitations on freedom of expression and the media under Articles 33 and 34 of the Constitution, while upholding the remaining challenged provisions."

ke-odpc-2022-oppo-kenya

Office of the Data Protection Commissioner

KenyaData ProtectionTribunal / Regulatory Body
Verified

Decided 21 Dec 2022

"The ODPC imposed a penalty of KES 5,000,000, the maximum then available under the Act, on Oppo Kenya for using a complainant's photograph on its Instagram account for commercial purposes without consent, contrary to section 37 of the Data Protection Act 2019, and for failing to adopt a data protection policy or internal complaints mechanism despite a prior enforcement notice."

ke-odpc-2023-roma-school

Office of the Data Protection Commissioner

KenyaData ProtectionTribunal / Regulatory Body
Verified

Decided 26 Sept 2023

"The ODPC fined Roma School (Nairobi) KES 4,550,000 for publishing photographs of minor pupils on its social-media platforms for marketing purposes without the consent of their parents or guardians, processing children's personal data without a lawful basis."

ke-hc-2025-worldcoin-katiba

High Court of Kenya at Nairobi (Judicial Review Division)

KenyaData ProtectionDigital RightsHigh Court / Federal High Court
Verified

Decided 5 May 2025

"The High Court held that the collection and processing of Kenyans' iris and facial biometric data by the Worldcoin entities through the "Orb" device contravened the Data Protection Act 2019: consent procured by inducement of cryptocurrency tokens was not valid consent, and the operators had failed to conduct an adequate Data Protection Impact Assessment as required by section 31. The court granted certiorari quashing the processing, mandamus compelling permanent deletion of all biometric data within seven days under the Data Commissioner's supervision, and prohibition restraining further biometric processing absent a lawful DPIA."

ke-odpc-2023-mulla-pride

Office of the Data Protection Commissioner

KenyaData ProtectionFintechTribunal / Regulatory Body
Verified

Decided 26 Sept 2023

"The ODPC fined Mulla Pride Limited, a digital credit provider, KES 2,975,000 for unlawfully obtaining the names and contact details of borrowers' third-party referees from borrowers' phones and using them to make threatening debt-collection calls and messages, processing personal data without a lawful basis and outside the purpose for which it was collected."

Notable gaps

Beyond the General Regulations, sector-specific and complaints-handling regulations continue to evolve and are not all separately recorded on file. The framework is otherwise comprehensive and well-documented.