Kenyan data protection law
Kenya’s Data Protection Act 2019: what it actually requires of a small business
Most guides to the Act stop at 'implement appropriate technical and organisational measures'. The Regulations are far more specific than that — eleven named security elements, a seven-day deadline for access requests, forty-eight hours for a supplier to tell you it has lost your data. This is the version with the details in it.
The short answer
The Act applies to you if you are established or ordinarily resident in Kenya and process personal data here — including on paper, if the paper forms part of a filing system. It requires you to meet eight principles, to put appropriate technical and organisational measures in place, to notify the Data Commissioner within 72 hours of a breach that carries a real risk of harm, and to answer a customer's access request within seven days, free of charge.
Penalties come in two forms. An administrative fine from the Data Commissioner is capped at KES 5,000,000 or 1% of your annual turnover for the preceding financial year, whichever is lower — for most SMEs that is the turnover figure, and it is much lower than the headline. Offences under the Act carry a separate criminal penalty, and a data subject can claim compensation on top.
Does the Act apply to my business?
Section 4 answers it in two parts, and the second one surprises people.
- What. Personal data entered in a record, by or for a controller or processor, by automated or non-automated means — where data processed by non-automated means forms the whole or part of a filing system.
- Who. A controller or processor established or ordinarily resident in Kenya and processing personal data while in Kenya; or one not established in Kenya but processing personal data of data subjects located in Kenya.
So this is not a law about computers. The paper guest register at a reception desk, the patient file in a cabinet, the visitor book at a factory gate, the printed payroll in a drawer — all inside the Act. And an overseas booking platform or cloud clinic system processing data about people in Kenya is inside it too, which is worth remembering when a supplier tells you its obligations are governed elsewhere.
Registration is a separate question with its own thresholds, and being exempt from registering exempts you from none of what follows. Who must register, and what it costs, is the companion guide.
What counts as personal data here?
Personal data is information about an identified or identifiable person. Sensitive personal data is a narrower set the Act protects more strictly — including data revealing race or ethnicity, health, biometric data, religious or philosophical beliefs, marital status and family details, and sexual orientation.
The abstract definition is easy. The list for a real Kenyan business is the useful part.
- A hotel or lodge
- Guest names, phone numbers and ID or passport numbers in the register; card details held in or passed through the booking system; the arrival list forwarded to a WhatsApp group at shift change; lobby and corridor CCTV; staff files and payroll; loyalty and mailing lists.
- A clinic or hospital
- Every patient file, appointment list, lab result and insurer correspondence. Nearly all of it is sensitive personal data, which raises the bar on lawful basis, on security and on what happens after a breach.
- A factory
- Payroll, staff records, the gate register of visitor ID numbers, CCTV — and the fingerprint or face clock-in terminal, which is biometric data by the Act's own definition, and therefore sensitive.
The eight principles, in plain language
Section 25 lists them. They are not aspirational language; they are the standard against which everything else in the Act is measured, and they apply to registered and exempt businesses alike.
| The principle | What it looks like on an ordinary Tuesday |
|---|---|
| Processed in accordance with the data subject's right to privacy | The default question is whether you should hold this at all |
| Lawful, fair and transparent | A lawful basis you could name if asked, and a notice at the point of collection that a guest could actually read |
| Collected for explicit, specified and legitimate purposes, and not further processed incompatibly | Booking data collected to run a stay is not a marketing list because somebody in sales had an idea |
| Adequate, relevant and limited to what is necessary | Stop photocopying passports if the number and the name are what you need; stop keeping the copy afterwards |
| Collected only where a valid explanation is provided whenever information about family or private affairs is required | If a form asks about family, next of kin or private circumstances, the reason has to be given |
| Accurate and kept up to date, with inaccurate data erased or rectified | Somebody owns corrections, and they happen without a chase |
| Kept in identifiable form no longer than necessary | A written retention schedule, and a deletion that actually runs — including in backups and old spreadsheets |
| Not transferred outside Kenya without proof of adequate safeguards or the data subject's consent | Your booking engine, your cloud clinic system and your email provider are all transfers. Know where they are and on what footing |
What does "appropriate security" actually mean?
Section 41 requires appropriate technical and organisational measures, designed to implement the principles effectively and to build the necessary safeguards into the processing itself — at the time you decide how to process, not only when you process. Section 42 adds that in choosing them you must have regard to the state of technology available, the cost, the special risks in the processing and the nature of the data.
That is still fairly abstract. Regulation 32 of the General Regulations 2021 is not: it names eleven elements. This is the closest thing Kenyan law gives a small business to a security checklist, and it is worth reading as one.
| What the Regulations say | What a 30-person business actually does |
|---|---|
| An operative means of managing information-security policies and procedures | One short written policy with a named owner, not a 40-page document nobody opens |
| Assessing risks to personal data and putting measures in place against them | The same table the registration form asks for, kept current |
| Processing robust enough to withstand changes, regulatory demands, incidents and cyber-attacks | Someone has thought about what happens when the booking system is down for a day |
| Only authorised personnel accessing the data their tasks need | Named accounts, no shared reception login, and access removed the week someone leaves |
| Transfers secured against unauthorised access and alteration | Files sent to your accountant or insurer are not passed around in an unprotected attachment |
| Storage secured against use, unauthorised access and alteration | Disk encryption on laptops; the cabinet is locked; the server room is not the store room |
| Back-ups and logs kept to the extent necessary for information security | Backups that have been restored at least once, so you know they work |
| Audit trails and event monitoring as a routine security control | You can answer "who looked at that record, and when" without asking the software vendor |
| Sensitive personal data protected adequately and, where possible, kept separate | Patient data is not in the same shared drive as the marketing folder |
| Routines to detect, handle, report and learn from data breaches | A one-page plan naming who is called, in what order, within the first hour |
| Regularly reviewing and testing software to uncover vulnerabilities of the systems supporting the processing | A dated, repeatable review — and a record of what you fixed after it |
Section 42 also requires that where you use a processor you choose one that offers sufficient guarantees, and that you have a written contract requiring it to act only on your instructions. For most SMEs that means the booking engine, the payroll bureau, the clinic software vendor and the outsourced IT provider — four contracts that are usually silent on exactly this.
What do I do in the first 72 hours of a breach?
When the duty is triggered
Section 43 applies where personal data has been accessed or acquired by an unauthorised person and there is a real risk of harm to the data subject. Regulation 37 removes much of the guesswork by deeming a breach notifiable where it involves the categories of personal data in the Second Schedule to the General Regulations, or where it involves an account held with you together with the credentials used to reach it — a password, a security code, an access code, the answer to a security question, or biometric data.
That Second Schedule is worth knowing, because its contents are so ordinary. It includes salary and other remuneration; credit, charge and debit card numbers; bank account numbers; creditworthiness and outstanding debts; insurance terms and conditions of health; and a set of specific health matters including HIV status, mental disorder and substance abuse. In practice: a leaked payroll file is notifiable. A booking system holding card numbers is notifiable. A clinic's records are notifiable several times over.
The clocks
| Who | Tells whom | By when |
|---|---|---|
| Data controller | The Data Commissioner | Without delay, within 72 hours of becoming aware |
| Data controller | The affected data subject, in writing | Within a reasonably practical period, unless their identity cannot be established |
| Data processor | Its data controller | Without delay and, where reasonably practicable, within 48 hours |
A notification made after 72 hours must be accompanied by the reasons for the delay — so a late notification is contemplated, but an unexplained one is not. And the 48-hour processor clock is the sentence to put in your supplier contracts: it is the only way the 72-hour clock is survivable when the breach happens at your booking engine rather than in your own office.
What the notification has to contain
Regulation 38 lists it, and it doubles as the incident log you should be keeping anyway:
- the date and circumstances in which you first became aware;
- a chronological account of the steps you took after that;
- how the breach occurred, where you know;
- the number of data subjects affected and the classes of personal data involved;
- the potential harm to those affected;
- what you have done or will do to eliminate or mitigate harm, and to fix whatever allowed it;
- how affected people can reduce their own risk;
- contact details for an authorised representative of your business.
Separately, section 43(8) requires you to record the facts of the breach, its effects and the remedial action taken — every time, including when no notification is due.
What rights do customers have, and how fast must I answer?
Section 26 gives a data subject the right to be informed of the use their personal data is put to; to access it; to object to its processing; and to correction and deletion of false or misleading data. The General Regulations put deadlines on the ones that generate work.
| Request | Deadline | Fee |
|---|---|---|
| Access to their personal data | 7 days from the request | Free of charge |
| Rectification of inaccurate data | 14 days, where you are satisfied it is needed | Free of charge |
| Refusal to rectify | 7 days, in writing, with reasons | Free of charge |
| Data portability | 30 days | A prescribed fee, which must be reasonable and not exceed the cost of doing it |
| Restricting further direct marketing by a third party | 7 days from the request | Free of charge |
Seven days is short. It is short enough that "we will look into it" is not a process, and the only way to meet it reliably is to know in advance where personal data about one named person lives — the booking system, the property-management system, the accounting package, the CCTV recorder, the mailing list and the shared drive. Writing that map down is an afternoon's work and it is the single most useful preparation an SME can do.
Do I need a data protection officer or a DPIA?
The officer
Section 24 provides that a controller or processor may designate or appoint a data protection officer where the processing is carried out by a public or private body, where core activities require regular and systematic monitoring of data subjects, or where core activities consist of processing sensitive categories of personal data. The officer may be an existing staff member with other duties, provided those duties do not conflict.
Read the verb carefully — the Act says "may", so it is enabling rather than a flat mandate, and the ODPC's own guidance is where to check what it expects in your sector. But if your core activity is patient care, limb (c) describes you exactly, and having a named person answerable for this is worth doing whether or not you are compelled to.
The impact assessment
Section 31 is not permissive: where a processing operation is likely to result in high risk to the rights and freedoms of a data subject, you shall carry out a data protection impact assessment before you start. Regulation 49 lists the operations treated as high risk. Several are ordinary SME purchases:
- processing biometric or genetic data — the fingerprint clock-in;
- processing sensitive personal data, or data about children or vulnerable groups;
- systematic monitoring of a publicly accessible area on a large scale — cameras;
- large-scale processing of personal data;
- using personal data at scale for a purpose other than the one it was collected for;
- combining or cross-referencing datasets from different sources for different purposes;
- automated decision-making with legal or similarly significant effect, including profiling;
- innovative use of new technological or organisational solutions;
- a change to processing that raises the risk to data subjects;
- processing that prevents a data subject from exercising a right.
What are the penalties, really?
Before imposing a penalty the Data Commissioner must weigh a list of factors set out in the Act — the degree of responsibility given the measures in place, any previous failures, how far you co-operated to remedy the failure, the categories of personal data affected, how the infringement came to light and whether you reported it yourself, adherence to approved codes, and whether the penalty would be effective, proportionate and dissuasive.
That list is the argument for self-reporting and for keeping records. A business that notified promptly, held a written risk assessment and could show what it fixed is in a materially different position from one that was found out.
Section 63 then caps the fine: up to KES 5,000,000 or, in the case of an undertaking, up to one per cent of annual turnover of the preceding financial year, whichever is lower. The word "lower" does a great deal of work.
| Turnover last year | 1% of turnover | Maximum for one infringement |
|---|---|---|
| KES 8,000,000 — a guest house | KES 80,000 | KES 80,000 |
| KES 48,000,000 — a mid-size hotel | KES 480,000 | KES 480,000 |
| KES 300,000,000 — a hospital group | KES 3,000,000 | KES 3,000,000 |
| KES 800,000,000 — a large manufacturer | KES 8,000,000 | KES 5,000,000 |
Below roughly KES 500 million of turnover, the one per cent limb is the one that binds you. That is most of this country's businesses, and it is why we do not quote the five-million headline on its own.
Three things sit outside that cap and are easy to overlook:
- Offences. Section 73 sets a general penalty for offences under the Act: on conviction, a fine not exceeding KES 3,000,000 or imprisonment not exceeding ten years, or both.
- Compensation. Under section 65 a person who suffers damage from a contravention is entitled to compensation from the controller or processor, and "damage" expressly includes distress as well as financial loss. That is a civil claim, uncapped by section 63.
- The cost of the incident itself — the days the plant or the booking system is down, and the customers who go elsewhere while you rebuild.
Enforcement is live. The Data Commissioner publishes determinations; the record includes a KES 5 million penalty against Oppo Kenya in December 2022 and KES 1.85 million against Casa Vera Lounge, a hospitality business, in September 2023, and the Office has announced inspections of the hospitality sector. An appeal against any administrative action lies to the High Court under section 64.
What should a small business do first?
In this order, because each step makes the next one possible.
- Map where personal data lives. Every system, every shared drive, every cabinet, every WhatsApp group. Nothing else works without this.
- Write down why you hold each set, and delete what has no answer.
- Settle registration — Third Schedule or exemption — using the previous guide.
- Fix access. Named accounts, no shared logins, removal on the day someone leaves, and multi-factor authentication on email before anything else.
- Fix your email domain so criminals cannot send invoices as you. It is free, it is DNS-only, and it is the highest-value hour in this list — the how is in the next guide.
- Test one backup restore. An untested backup is a hope, not a control.
- Write the one-page breach plan: who is called, in what order, in the first hour, and where the ODPC's reporting route is.
- Fix the supplier contracts — instructions-only processing, and a 48-hour breach notification to you.
- Prepare for a seven-day access request by knowing where one person's data is held.
- Do a DPIA for the biometric terminal and the cameras if you never did.
What counts as evidence that you did something
Almost every duty above is provable or unprovable depending on whether anybody wrote anything down. Regulation 32(k) asks for software to be reviewed and tested for vulnerabilities regularly; regulation 32(j) asks for routines to detect, handle, report and learn from breaches; the penalty factors reward a business that can show what it did and when. Dates and records are the difference between a control and an intention.
A free exposure snapshot from Reconesys is one dated, external piece of that record. You give us a domain and a work email; a person reads the public records — DNS, mail records, certificate transparency logs and the domain registry — and writes you a plain-language report in one to two business days, with a rating, the three issues that matter most and a 30-day plan. We never connect to your website or servers, never log in, and never test your defences.
It is not a penetration test, it is not monitoring, and it does not make your business compliant with the Act. It is evidence relating to one technical control, which is a real but narrow thing, and we would rather say so here than let you discover it later. Read the sample report and judge it before you give us an email address, or see exactly what the snapshot covers.
Questions
Questions people ask about this
- What is the fine for breaching the Data Protection Act in Kenya?
- For an infringement of the Act, the maximum administrative penalty the Data Commissioner may impose in a penalty notice is up to KES 5,000,000 or, in the case of an undertaking, up to 1% of its annual turnover of the preceding financial year, whichever is lower. For most Kenyan SMEs the turnover limb is far lower than KES 5 million and is the one that binds. Offences under the Act carry a separate criminal penalty, and a data subject may also claim compensation for damage, including distress.
- How long do I have to report a data breach in Kenya?
- Where personal data has been accessed or acquired by an unauthorised person and there is a real risk of harm to the data subject, the data controller must notify the Data Commissioner without delay and within seventy-two hours of becoming aware of the breach. A notification made later must carry the reasons for the delay. The affected data subject must be told in writing within a reasonably practical period. A data processor must notify its data controller without delay and, where reasonably practicable, within forty-eight hours.
- How quickly must I answer a data access request in Kenya?
- Within seven days of the request, and free of charge, under regulation 9 of the Data Protection (General) Regulations, 2021. Rectification of inaccurate data must be done within fourteen days, and a refusal to rectify must be given in writing with reasons within seven days. A data portability request has thirty days and may carry a reasonable fee that does not exceed the cost of fulfilling it.
- Does the Data Protection Act apply to paper records?
- Yes. The Act applies to personal data entered in a record by automated or non-automated means, provided that data processed by non-automated means forms the whole or part of a filing system. A paper guest register at a hotel reception desk and a patient file in a cabinet are both in scope.
- Does buying a security product make my business compliant?
- No. Compliance covers how you collect personal data, what you tell people, your lawful basis, retention, transfers outside Kenya, contracts with suppliers, staff training, breach handling and data-subject rights. A technical control is evidence relating to one part of the security duty. Anyone selling a product as compliance in a box is describing something that does not exist.
Sources
Every legal and statistical claim above traces to one of these. We link to the publisher's own copy rather than to a summary, and name the provision in full so the citation survives a broken link.
Sources
- Data Protection Act, 2019 (No. 24 of 2019) — PDF — Office of the Data Protection Commissioner
Section 4 (application), 24 (data protection officer), 25 (principles), 26 (rights), 31 (impact assessment), 41 and 42 (technical and organisational measures), 43 (breach), 62 to 65 (enforcement, fines, appeal, compensation) and 73 (general penalty).
- Data Protection (General) Regulations, 2021 — Legal Notice No. 263, PDF — Office of the Data Protection Commissioner
Regulations 9 to 11 and 18 (data-subject deadlines), 19 (retention), 24 and 25 (processor contracts), 32 (integrity, confidentiality and availability), 37 and 38 (notifiable breaches and what a notification must contain), 49 (processing requiring an impact assessment), and the Second Schedule.
- Data Protection (Registration of Data Controllers and Data Processors) Regulations, 2021 — Legal Notice No. 265, PDF — Office of the Data Protection Commissioner
Regulation 13, cited for the rule that a business exempt from registration still owes Part IV and Part VI of the Act.
- Data Protection Act (Cap. 411C) — consolidated text — Kenya Law
The National Council for Law Reporting’s consolidated version. Check section numbering here before relying on it: an Act as enacted and an Act as consolidated can differ.
- Determinations — Office of the Data Protection Commissioner
Published penalty decisions, the source for the enforcement figures cited above.
- Report a data breach — Office of the Data Protection Commissioner
The regulator’s own breach-reporting route. Find it before you need it.
- Rights of a data subject — Office of the Data Protection Commissioner
The regulator’s public-facing summary of what your customers can ask you for.