The Kenya Data Protection Act: What Every Business Owner Must Know
Brian Otieno
Business Advisory Lead, Paper Street
The Kenya Data Protection Act (DPA) came into force in 2019, and the Office of the Data Protection Commissioner (ODPC) has been building enforcement capacity steadily since then. In 2024, the ODPC began issuing formal compliance notices and fines. For small and medium businesses that have been waiting to see whether the law would actually be enforced before taking action, the answer is now clear: it is.
The maximum penalty under the DPA is KES 5 million or imprisonment of up to ten years for criminal offences. Civil penalties for data breaches range from KES 3 million to KES 5 million. This guide explains what your business must do to be compliant.
Does the DPA Apply to Your Business?
The DPA applies to any person or organisation that collects, processes, stores, or shares personal data in Kenya, or that processes data of Kenyan residents from outside the country. There is no minimum size threshold. A one-person consultancy that collects client email addresses is subject to the DPA.
"Personal data" is defined broadly to include any information that can be used to identify an individual, directly or indirectly. This includes names, email addresses, phone numbers, physical addresses, ID numbers, IP addresses, location data, and health information.
Core Obligations Under the DPA
Registration as a Data Controller or Processor
Businesses that collect or process personal data as part of their core activities must register with the ODPC as data controllers or data processors. Registration is done through the ODPC portal and requires payment of a registration fee. Operating without registration when required is itself an offence.
Lawful Basis for Processing
Every time you collect or process personal data, you must have a lawful basis for doing so. The DPA recognises six lawful bases:
- Consent: The individual has given clear, informed, and specific consent to the processing. Consent must be as easy to withdraw as to give.
- Contract: Processing is necessary to perform a contract with the individual or to take steps at their request before entering a contract.
- Legal obligation: Processing is required by law, for example KYC obligations under POCAMLA.
- Vital interests: Processing is necessary to protect the life of the individual.
- Public task: Processing is necessary for a task in the public interest or in the exercise of official authority.
- Legitimate interests: Processing is necessary for the legitimate interests of the controller, provided those interests are not overridden by the individual's rights.
Privacy Notice
Every business that collects personal data must provide individuals with a clear privacy notice at the point of collection. This notice must explain who you are, what data you collect, why you collect it, how long you keep it, who you share it with, and what rights the individual has. A privacy notice on your website, supplemented by a brief notice at the point of data collection (e.g., on a sign-up form), is the standard approach.
Data Subject Rights
Individuals whose data you hold have rights that you must be able to honour within 21 days of a request:
- The right to access a copy of their data.
- The right to correct inaccurate data.
- The right to deletion in certain circumstances.
- The right to object to processing based on legitimate interests.
- The right to data portability (receiving data in a structured, machine-readable format).
Data Breach Notification
If your business suffers a data breach that is likely to result in a risk to individuals, you must notify the ODPC within 72 hours of becoming aware of it. If the breach is likely to result in a high risk to individuals, you must also notify the affected individuals directly without undue delay. Failing to report a notifiable breach is a separate offence.
Practical Steps to Achieve Compliance
- Conduct a data audit: map every category of personal data you collect, where it comes from, what you do with it, who you share it with, and how long you keep it.
- Register with the ODPC as a data controller or data processor.
- Draft and publish a Privacy Policy on your website that is specific to your business, not a generic template.
- Review your consent mechanisms: opt-in tick boxes must be unticked by default and must describe specifically what the individual is consenting to.
- Put a Data Processing Agreement in place with any third party that processes personal data on your behalf, such as your cloud storage provider, payroll software, or email marketing platform.
- Train all staff who handle personal data on their obligations under the DPA.
- Create an internal process for handling data subject requests and data breaches.
Ready to get started?
Establish your professional presence today.
Join businesses and professionals who trust Paper Street for their commercial business address, mail management, and quiet meeting space in Kisumu CBD.
Get a Quote