Controllers/processors established or resident in Kenya, and those outside Kenya processing personal data of data subjects located in Kenya.
Key obligations
Processing principles (s.25) and lawful bases incl. consent (s.30-32); Mandatory registration with ODPC above thresholds (Registration Regulations 2021); DPIA for high-risk processing (s.31); Data subject rights: access, correction, erasure, portability (ss.26, 34-40)
DPO required
Designation is permissive on the text ("may designate or appoint", s.24(1)) for public/private bodies, monitoring-heavy cores, and sensitive-category cores; practice-mandatory gravity via registration forms, s.24(6) publication duty and s.62(2) factors. CORRECTED 2026-08-02 from "Required" (course semantic-pass catch against the s.24 body).
Registration
Yes: mandatory registration with ODPC, thresholds per 2021 Regulations.
Cross-border transfers
Transfers outside Kenya require proof of appropriate safeguards or adequacy, or data-subject consent (ss.48-50); sensitive data transfers further restricted.
Breach notification
Notify ODPC within 72 hours where there is a real risk of harm; communicate to data subject in writing (s.43).
Penalties
Administrative fines up to KES 5,000,000 or 1% of annual turnover, whichever is lower (s.63); compensation orders (s.65); criminal offences for unlawful disclosure.
Authority
Office of the Data Protection Commissioner (ODPC)
Verified 2026-07-06
Data Protection (General) Regulations, 2021 (LN 263 of 2021) IN FORCE