Kenya DPA 2019

The Data Protection Act, 2019 (Act No. 24 of 2019)

Key Facts

Effective Date
November 25, 2019
Enacted
November 8, 2019
Enforcing Authority
Office of the Data Protection Commissioner (ODPC)
Consent Model
Opt-in
Fulfillment Time
90 days
Applies To
All data controllers and processors in Kenya; registration threshold: KES 5M+ annual turnover or 10+ employees

Overview

Kenya's Data Protection Act 2019 (Act No. 24 of 2019) is a comprehensive privacy law enforced by the Office of the Data Protection Commissioner (ODPC). It requires data controllers to register with the ODPC before processing personal data and obtain consent as the primary legal basis. The law is notable for its unusual penalty calculation using "whichever is lower" between KES 5 million or 1% of annual turnover. Criminal penalties of up to 10 years imprisonment also apply.

What This Means for Your Website

If your website collects personal data from users in Kenya, you must register as a data controller with the ODPC, appoint a Data Protection Officer when required, and obtain freely given, specific, and informed consent before collecting any personal data. You also need to conduct Data Protection Impact Assessments for high-risk processing activities and respond to data subject requests within statutory timelines.

Key Requirements

Organizations must register with the ODPC if their annual turnover exceeds KES 5 million or they have more than 10 employees. Consent must be obtained before processing personal data. DPIAs are required for high-risk processing. Breach notifications must be submitted promptly. The ODPC has a 90-day complaint resolution timeline, signaling active enforcement expectations.

How ConsentStack Handles This

ConsentStack provides a compliant consent banner that collects freely given, specific, and informed consent as required by Kenya's DPA. It automatically records consent preferences with timestamps for audit purposes, supports data subject rights workflows, and helps you demonstrate compliance with ODPC registration requirements through detailed consent logs.

Penalties

KES 5,000,000 or 1% of annual turnover (whichever is LOWER); daily penalty KES 10,000 for continuing violations; up to 10 years imprisonment

Maximum Fine
KES5,000,000 aggregate
Revenue-based
1% of annual revenue

Key Requirements

  • Mandatory registration with ODPC for controllers/processors (KES 5M+ turnover or 10+ employees)
  • DPO appointment required for public bodies, large-scale sensitive data, or systematic monitoring
  • Data Protection Impact Assessment required for high-risk processing
  • Consent must be freely given, specific, and informed
  • Data subjects have rights of access, rectification, and erasure
  • 90-day complaint resolution timeline for ODPC

Notable Provisions

  • Penalty cap uses "whichever is LOWER" — unusual globally as most laws use "whichever is higher"
  • Criminal penalties including up to 10 years imprisonment
  • Registration thresholds based on turnover and employee count
  • 90-day complaint resolution requirement

Other Sub-Saharan Africa Regulations

POPIASouth Africa
Africa's most developed and actively enforced data protection law. POPIA establishes eight conditions for lawful processing and grants the Information Regulator broad enforcement powers including criminal sanctions. The inclusion of "online identifiers" in the definition of personal information means cookies are covered, and Section 69's direct marketing consent requirement is directly relevant to consent management.
NDPANigeria
One of Africa's most comprehensive data protection laws, with the GAID providing Africa's most detailed cookie consent framework. Essential cookies are exempt; non-essential cookies require conspicuous accept/reject banners. The NDPC enforces a two-tier penalty structure based on organizational significance.
Ghana Act 843Ghana
Ghana's foundational data protection law requires mandatory registration with the DPC before processing begins, with renewal every 2 years. Criminal penalties include up to 10 years imprisonment for serious violations. A new comprehensive bill is under consultation as of late 2025.
Uganda DPPA 2019Republic of Uganda
Uganda's Data Protection and Privacy Act 2019 establishes the PDPO as an independent office under NITA-U. It prohibits processing personal data without prior consent and mandates accountability, lawful collection, data minimization, and purpose limitation. Criminal penalties of up to 10 years imprisonment make it one of the strictest enforcement regimes in East Africa.
Ivory Coast Law 2013-450Ivory Coast
Ivory Coast's data protection law features an escalating penalty structure with significant increases for repeat offenders — up to 5% of pre-tax sales or XOF 500 million. ARTCI has been active in issuing formal notices against online lending applications. Prior declaration or authorization from ARTCI is required.
Tanzania PDPA 2022United Republic of Tanzania
Tanzania's first comprehensive data protection legislation establishes the Personal Data Protection Commission as the supervisory body. It mandates DPO appointment for all controllers and processors, a broader requirement than most jurisdictions. Personal data must be processed lawfully with consent, and criminal penalties of up to 10 years imprisonment apply for violations.

Frequently Asked Questions

Does Kenya's DPA apply to my website?

Yes, if you collect personal data from users in Kenya, the DPA applies regardless of where your organization is based. Registration with the ODPC may be required.

What are the penalties for non-compliance with Kenya's DPA?

Penalties include KES 5 million or 1% of annual turnover (whichever is lower), daily fines of KES 10,000 for continuing violations, and up to 10 years imprisonment.

Do I need a Data Protection Officer under Kenya's DPA?

A DPO is required for public bodies, organizations processing large-scale sensitive data, or those conducting systematic monitoring of individuals.

How does Kenya's DPA compare to GDPR?

Kenya's DPA shares many GDPR principles including consent requirements, DPIAs, and data subject rights, but uniquely uses a 'whichever is lower' penalty cap and requires mandatory ODPC registration.

Stay compliant with Kenya DPA 2019

ConsentStack helps you implement Opt-in consent for Republic of Kenya automatically.