{
 "jurisdiction_id": "KE",
 "jurisdiction": "Kenya",
 "url": "https://dataprotection.gi/jurisdictions/kenya/",
 "generator": "render_jid v13-gdpri-1.0.0",
 "date_modified": "2026-08-05",
 "schema_version": "gdpri-v2",
 "counts": {
  "categories": 10,
  "claims": 46,
  "sub_modules": 57,
  "source_register": 12
 },
 "categories": [
  {
   "code": "regulator_and_framework",
   "name": "Regulator & Framework",
   "traffic_light": "amber",
   "sub_modules": [
    "act_and_instruments",
    "material_scope",
    "regulator_and_authority",
    "regulator_registration_and_filing",
    "territorial_scope"
   ],
   "url": "https://dataprotection.gi/jurisdictions/kenya/#regulator-and-framework-regulator-framework",
   "traffic_light_rationale": "Statute in force and regulator active/enforcing since 2021-2022, but core implementing instruments (SCC-equivalent forms, adequacy decisions) remain absent, and the ODPC's independence/resourcing has been publicly questioned.",
   "claims": [
    {
     "statement": "The Data Protection Commissioner oversees implementation and enforcement of the Act under Section 8, but the office remained unformed until Immaculate Kassait was sworn in as Kenya's first Data Commissioner on 16 November 2020.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/kenya-appoints-its-first-ever-data-protection-commissioner",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Data Protection Act, 2019 came into force on 25 November 2019 and is the primary data protection legislation in Kenya.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/gdpr_v._kenya.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Sensitive personal data under the Act includes race, health status, ethnic/social origin, conscience, belief, genetic data, biometric data, property details, marital status, family details (names of children, parents, spouses), sex and sexual orientation.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/notes/kenya-data-protection-officer-appointment",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Act applies to controllers/processors established or resident in Kenya, and separately to controllers/processors not established or resident in Kenya but who process personal data of data subjects located in Kenya, giving it broader extraterritorial reach than the GDPR's establishment-based test.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/opinion/kenya-data-protection-considerations-ma-deals",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Section 18 provides no person shall act as a data controller or data processor unless registered with the Data Commissioner, who prescribes mandatory-registration thresholds considering industry nature, data volumes processed, and whether sensitive personal data is processed.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/kenya-appoints-its-first-ever-data-protection-commissioner",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Registration Regulations exempt controllers/processors with annual turnover below KES 5 million or fewer than 10 employees from registration, but registration remains mandatory regardless of size for specified high-risk processing activities; online/physical registration opened 14 July 2022.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": null,
     "source_url": null,
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "lawful_processing_and_special_data",
   "name": "Lawful Processing & Special Data",
   "traffic_light": "green",
   "sub_modules": [
    "consent_thresholds",
    "lawful_bases",
    "pseudonymisation_and_anonymisation",
    "special_categories"
   ],
   "url": "https://dataprotection.gi/jurisdictions/kenya/#lawful-processing-and-special-data-lawful-processing-special-data",
   "traffic_light_rationale": "Core lawful-basis and special-category framework is legislated and in force, closely tracking GDPR structure.",
   "claims": [
    {
     "statement": "The GDPR and the Act set out very similar legal bases for processing both personal data and sensitive data, with comparable conditions of consent and exceptions for journalism or artistic purposes.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/gdpr_v._kenya.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Under the Data Protection (General) Regulations, 2021, processing may rely on only one legal basis at a time, which must be established before the processing begins.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": null,
     "source_url": null,
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "There are slight differences between GDPR and the Act regarding withdrawal of consent and consent tied to performance of a contract.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/gdpr_v._kenya.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Section 45 of the Act sets out specific protective requirements for the processing of sensitive personal data.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/gdpr_v._kenya.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The GDPR and the Act both explicitly consider anonymised and pseudonymised data and apply to automated processing, with comparable concepts of personal and sensitive data, though key differences exist in how anonymisation is defined.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/gdpr_v._kenya.pdf",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "data_subject_rights",
   "name": "Data Subject Rights",
   "traffic_light": "amber",
   "sub_modules": [
    "access_right",
    "data_portability",
    "deadlines_and_response_windows",
    "rectification_and_erasure",
    "restriction_and_objection"
   ],
   "url": "https://dataprotection.gi/jurisdictions/kenya/#data-subject-rights-data-subject-rights",
   "traffic_light_rationale": "Rights exist and are being enforced via ODPC orders, but the Act is comparatively thin on granular procedural mechanics/response deadlines for controllers.",
   "claims": [
    {
     "statement": "The Act provides less detailed information than the GDPR on the exercise of data subject rights.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/gdpr_v._kenya.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The ODPC found Platinum Credit Limited violated the Act by using personal data for commercial purposes without consent, ignoring the complainant's objection to marketing messages, and failing to erase the complainant's data, ordering KES 900,000 in compensation.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/news/kenya-odpc-orders-platinum-credit-limited-pay-kes",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The ODPC ordered The Nairobi Hospital to delete unlawfully-used promotional advertisements containing a patient's covertly recorded image and to provide proof of deletion within 14 days, alongside a KES 500,000 fine, for violations of Sections 32(1) and 37 of the Act.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/news/kenya-odpc-orders-nairobi-hospital-pay-kes-500000",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Compliance and Enforcement Regulations require the ODPC to be guided by the Fair Administrative Action Act, 2015, which requires conclusion of complaints within 90 days.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/opinion/kenya-entry-force-2021-regulations",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "controller_processor_duties",
   "name": "Controller/Processor Duties",
   "traffic_light": "amber",
   "sub_modules": [
    "accountability_and_dpia",
    "breach_notification",
    "dpo_requirements",
    "joint_controller_arrangements",
    "retention_and_disposal",
    "ropa_requirements",
    "security_measures"
   ],
   "url": "https://dataprotection.gi/jurisdictions/kenya/#controller-processor-duties-controller-processor-duties",
   "traffic_light_rationale": "Core accountability, DPIA, and breach-notification duties are legislated and enforced, but DPO mandate is non-binding in practice and ROPA/joint-controller mechanics are comparatively underdeveloped versus GDPR.",
   "claims": [
    {
     "statement": "Regulation 49 of the Data Protection (General) Regulations requires a DPIA to be conducted under Section 31 of the Act for processing operations considered to result in high risks to the rights and freedoms of a data subject, including biometric or genetic data processing.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/worldcoin-case-a-watershed-moment-for-data-protection-in-kenya",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Where a controller is required to consult the Data Commissioner on a DPIA, they must do so within 60 days.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/worldcoin-case-a-watershed-moment-for-data-protection-in-kenya",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The General Regulations designate biometric-data processing and automated decision-making with legal or other significant effect using profiling or algorithmic means as DPIA-triggering activities.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/opinion/kenya-entry-force-2021-regulations",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "DPO concepts, tasks, and appointment provisions are similar between GDPR and the Act, but the Act uses permissive terms such as 'may' rather than 'shall', making DPO appointment conditional rather than a strict mandate.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/gdpr_v._kenya.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Where appointed, the DPO's contact details must be communicated to the Commissioner and published on the official website of the data controller or data processor.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/notes/kenya-data-protection-officer-appointment",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Unlike the GDPR, the Act establishes general processing registration/notification requirements rather than explicit internal record-keeping obligations for controllers and processors.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/gdpr_v._kenya.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "There are no legal provisions specifically governing the management of the data controller and data processor relationship under Kenyan sectoral telecoms rules, though service providers must ensure contracted third parties adhere to data-protection provisions.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://free.dataguidance.com/laws/kenya-privacy-and-data-protection-bill-draft/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Act and GDPR have broadly similar security requirements, both establishing principles of privacy by default and by design, operationalised in Kenya via the General Regulations' technical and organisational measures requirements.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/gdpr_v._kenya.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Controllers and processors must notify the Commissioner within 72 hours of any breach where there is a real risk of harm to data subjects, comparable to the GDPR's breach-notification timeline.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://free.dataguidance.com/laws/kenya-privacy-and-data-protection-bill-draft/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Where there is real risk of harm to data subjects from a breach, controllers must notify affected data subjects in writing after first notifying the Commissioner.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://free.dataguidance.com/laws/kenya-privacy-and-data-protection-bill-draft/",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "cross_border_and_adequacy",
   "name": "Cross-Border & Adequacy",
   "traffic_light": "amber",
   "sub_modules": [
    "adequacy_granted",
    "adequacy_received",
    "data_localisation",
    "sccs_and_bcrs",
    "transfer_impact_assessment",
    "transfer_mechanisms"
   ],
   "url": "https://dataprotection.gi/jurisdictions/kenya/#cross-border-and-adequacy-cross-border-adequacy",
   "traffic_light_rationale": "Transfer mechanisms exist in principle but lack a developed adequacy/SCC infrastructure, and sectoral/strategic-interest data localisation mandates add complexity and legal uncertainty (as illustrated by ongoing Worldcoin litigation).",
   "claims": [
    {
     "statement": "Transfer of personal data outside Kenya is restricted to instances involving appropriate data protection safeguards, an ODPC adequacy decision, necessity, or data-subject consent.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/opinion/kenya-entry-force-2021-regulations",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The General Regulations require written cross-border transfer agreements between sending and receiving entities, along with restrictions on further onward transfer of personal data.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/opinion/kenya-entry-force-2021-regulations",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "There is currently no adequacy agreement between Kenya and the United States, or any other country, for personal data transfers, and standard contractual clauses have not been provided under the Act or approved by the ODPC.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/worldcoin-case-a-watershed-moment-for-data-protection-in-kenya",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Act generally requires data controllers or processors to demonstrate to the Data Commissioner that appropriate safeguards exist, unless consent has been obtained, but the Act does not explicitly define what constitutes 'appropriate safeguards'.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/gdpr_v._kenya.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Under Regulation 41(1) of the General Regulations, the appropriate-safeguards basis for transfer requires a legal instrument binding the recipient that is 'essentially equivalent' to protection under the Act, or a robust assessment concluding appropriate safeguards exist.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/worldcoin-case-a-watershed-moment-for-data-protection-in-kenya",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Section 50 of the Act allows the Cabinet Secretary to prescribe, on grounds of strategic interests of the state or protection of revenue, that certain processing be effected only through a server or data centre located in Kenya.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/gdpr_v._kenya.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The General Regulations require controllers/processors handling data for strategic state interests -- including civil registration, elections, public finance, critical infrastructure, basic education, and healthcare -- to process such data via a Kenya-located server/data centre and store at least one servicing copy in Kenya.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/opinion/kenya-entry-force-2021-regulations",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "sectoral_watch",
   "name": "Sectoral Watch",
   "traffic_light": "amber",
   "sub_modules": [
    "credit_and_scoring",
    "education",
    "employment_data",
    "financial_sector_overlay",
    "health_sector_overlay",
    "insurance",
    "telecoms_and_eprivacy"
   ],
   "url": "https://dataprotection.gi/jurisdictions/kenya/#sectoral-watch-sectoral-watch",
   "traffic_light_rationale": "Multiple sectoral overlays exist and interact with the DPA (telecoms, payments, health), but coverage is uneven and some sectors (education, insurance) show no distinct DP overlay in available sources.",
   "claims": [
    {
     "statement": "Financial data in Kenya is regulated under the National Payment System Act, National Payment Regulations, and Prudential Guidelines, in addition to the general Data Protection Act.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://free.dataguidance.com/laws/kenya-privacy-and-data-protection-bill-draft/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Health Information System Policy requires health data not be stored outside Kenyan territory; while not legally binding, it is persuasive and courts are likely to be guided by it absent statutory provision.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://free.dataguidance.com/laws/kenya-privacy-and-data-protection-bill-draft/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Licensed providers under the Kenya Information and Communications Act must obtain and retain SIM-card/subscriber registration information, keep it secure and confidential, and adhere to CA-prescribed retention periods for registration details, call data records and financial information.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://free.dataguidance.com/laws/kenya-privacy-and-data-protection-bill-draft/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Act amends KICA to require licensed providers to process subscriber personal data in accordance with the Act's principles and to implement technical/organisational measures preventing loss, damage, unauthorised destruction/access, or unlawful processing.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://free.dataguidance.com/laws/kenya-privacy-and-data-protection-bill-draft/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Most data collected from employees in the course of employment is protected as personal data and sensitive data under the general Act, as there is no dedicated sectoral employment-data statute.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://free.dataguidance.com/laws/kenya-privacy-and-data-protection-bill-draft/",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "adtech_and_commercial_privacy",
   "name": "AdTech & Commercial Privacy",
   "traffic_light": "amber",
   "sub_modules": [
    "clean_rooms_and_dcr",
    "cookies_and_trackers",
    "cross_context_advertising",
    "dark_patterns",
    "direct_marketing",
    "opt_out_signals"
   ],
   "url": "https://dataprotection.gi/jurisdictions/kenya/#adtech-and-commercial-privacy-adtech-commercial-privacy",
   "traffic_light_rationale": "Direct-marketing consent/opt-out rules are legislated and actively enforced, but Kenya has no distinct cookie/tracker, dark-pattern, or cross-context-advertising regime comparable to EU ePrivacy or US state adtech laws.",
   "claims": [
    {
     "statement": "The General Regulations deem personal data used to advance economic/commercial interests or for direct marketing as 'commercial use', permitted only where the data subject was informed at collection, consented, or was offered and did not exercise a simplified opt-out; use for direct marketing without consent is an offence.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/opinion/kenya-entry-force-2021-regulations",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "algorithmic_biometric_and_surveillance_governance",
   "name": "Algorithmic, Biometric & Surveillance Governance",
   "traffic_light": "amber",
   "sub_modules": [
    "ai_risk_assessments",
    "automated_decision_making_transparency",
    "biometric_regime",
    "genetic_data",
    "profiling_restrictions",
    "state_surveillance_carveouts"
   ],
   "url": "https://dataprotection.gi/jurisdictions/kenya/#algorithmic-biometric-and-surveillance-governance-algorithmic-biometric-surveill",
   "traffic_light_rationale": "Biometric/ADM processing is captured via DPIA triggers and is the subject of active, high-profile enforcement (Worldcoin), but no dedicated AI risk-assessment framework exists and national-security exemptions are broadly drawn.",
   "claims": [
    {
     "statement": "The ODPC revoked Tools For Humanity's registration as a data processor and banned all Worldcoin activities in Kenya for one year, alleging the registration certificate was obtained through misrepresentation or material nondisclosure.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/worldcoin-case-a-watershed-moment-for-data-protection-in-kenya",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Failure to register or deliberately providing misleading information to the Data Commissioner's office is an offence punishable by a fine not exceeding KES 3 million or imprisonment not exceeding 10 years, or both, with courts additionally empowered to order forfeiture of related equipment.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/worldcoin-case-a-watershed-moment-for-data-protection-in-kenya",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Kenya's Miscellaneous Amendments Act of 2020 empowers security services to access personal data from any phone or computer, cited by civil-society analysts as an overly intrusive national-security exemption relative to the DPA framework.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/evaluating-african-nations-comprehensive-privacy-laws-and-their-implementation",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "children_and_vulnerable_groups",
   "name": "Children & Vulnerable Groups",
   "traffic_light": "amber",
   "sub_modules": [
    "age_verification",
    "dependent_adults",
    "education_settings",
    "minor_profiling_bans",
    "parental_consent"
   ],
   "url": "https://dataprotection.gi/jurisdictions/kenya/#children-and-vulnerable-groups-children-vulnerable-groups",
   "traffic_light_rationale": "A children's-data provision exists in statute (Section 33) but lacks the granularity of GDPR Art 8 (no explicit age-of-consent threshold in the Act itself, no age-verification mechanics, no dependent-adult provisions located).",
   "claims": [
    {
     "statement": "Section 33 of the Act provides detailed requirements for processing children's data, although the Act does not specifically define 'child'; Article 260 of the Kenyan Constitution sets the adulthood threshold at 18 years.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/gdpr_v._kenya.pdf",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "enforcement_and_redress",
   "name": "Enforcement & Redress",
   "traffic_light": "amber",
   "sub_modules": [
    "collective_redress_and_class_actions",
    "enforcement_activity_index",
    "private_right_of_action",
    "recent_developments_180d",
    "regulator_funding_and_capacity",
    "regulator_powers_and_penalties"
   ],
   "url": "https://dataprotection.gi/jurisdictions/kenya/#enforcement-and-redress-enforcement-redress",
   "traffic_light_rationale": "Enforcement powers are legislated and actively used (multiple 2025-2026 fines/orders), but resourcing/independence concerns persist and collective-redress/private-right-of-action mechanisms remain undeveloped.",
   "claims": [
    {
     "statement": "The Data Commissioner has powers to conduct investigations on own initiative or on complaint, impose administrative fines for non-compliance, facilitate conciliation/mediation/negotiation, issue summons to witnesses, and require explanations/information/assistance from any person subject to the Act.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/kenya-appoints-its-first-ever-data-protection-commissioner",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The maximum administrative penalty the DPC may impose in a penalty notice for an infringement of the Act is up to KES 5 million, or in the case of an undertaking, up to 1% of its annual turnover of the preceding financial year, whichever is lower.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/kenya-appoints-its-first-ever-data-protection-commissioner",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Under the Compliance and Enforcement Regulations, the ODPC may issue a penalty notice including a daily fine of not more than KES 10,000 per identified breach until the breach is rectified; recipients of an enforcement notice may seek ODPC review or appeal to the High Court within 30 days.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/opinion/kenya-entry-force-2021-regulations",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Civil-society analysis found the ODPC lacks proper independence and recommended the Kenyan government provide adequate resources to ensure the office's effectiveness and functionality.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "International Association of Privacy Professionals",
     "source_url": "https://iapp.org/news/a/protecting-data-protection-rights-in-kenya",
     "source_tier": null,
     "observed_at": null
    }
   ]
  }
 ]
}