🔒 Data Protection Regulatory Intelligence
GDPRI · dataprotection.gi
KE · run data-protection-2026-08-05 v13-gdpri-1.0.0
content: ai_generated 12 sources retrieved model claude-sonnet-5 ·

Kenya

KE schema gdpri-v2 trajectory: not recorded

Last updated · 10 categories · 46 claims · 12 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
46Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)
No categories are currently flagged red.

Jurisdiction brief

No content recorded at this JID path.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Statute in force and regulator active/enforcing since 2021-2022, but core implementing instruments (SCC-equivalent forms, adequacy decisions) remain absent, and the ODPC's independence/resourcing has been publicly questioned.

Primary frameworkData Protection Act, 2019 (Kenya)
Traffic-light rationale — AmberStatute in force and regulator active/enforcing since 2021-2022, but core implementing instruments (SCC-equivalent forms, adequacy decisions) remain absent, and the ODPC's independence/resourcing has been publicly questioned.

Sub-modules (5)

Regulator And AuthorityAmber

The ODPC, headed by the Data Protection Commissioner, oversees implementation and enforcement of the Act under Section 8; the first Commissioner was sworn in November 2020, more than a year after the Act commenced.

Claims: CLM-KE-a1b2c301

Act And InstrumentsGreen

The Data Protection Act, 2019 came into force 25 November 2019 as Kenya's primary DP legislation, supplemented by the Data Protection (General) Regulations, (Registration of Data Controllers and Data Processors) Regulations, and (Compliance and Enforcement) Regulations, all 2021.

Claims: CLM-KE-b2c3d402

Material ScopeGreen

The Act covers processing of 'personal data' and imposes enhanced rules on 'sensitive personal data', defined broadly to include race, health status, ethnic/social origin, conscience, belief, genetic data, biometric data, property details, marital status, family details (including children's/parents'/spouse's names), sex, and sexual orientation.

Claims: CLM-KE-c3d4e503

Territorial ScopeGreen

The Act applies extraterritorially: it covers any controller/processor established or resident in Kenya processing data while in Kenya, and also any controller/processor not established in Kenya but processing personal data of data subjects located in Kenya.

Claims: CLM-KE-d4e5f604

Regulator Registration And FilingAmber

Section 18 prohibits acting as a controller/processor unless registered with the Data Commissioner; the Registration Regulations 2021 set turnover/employee-based exemption thresholds (below KES 5 million turnover or under 10 employees) but registration remains mandatory regardless of size for specified high-risk activities. Registration opened 14 July 2022.

Claims: CLM-KE-e5f60705, CLM-KE-f6071806

Category narrative135 words

Kenya's Data Protection Act, 2019 (DPA) is the primary omnibus instrument, enacted to give effect to the constitutional right to privacy under Article 31(c) and (d) of the Constitution. It closely mirrors GDPR concepts but substitutes GDPR-style record-keeping (Art 30 ROPA) with a mandatory registration/certification regime for controllers and processors. The Office of the Data Protection Commissioner (ODPC) was formally activated only after the first Commissioner, Immaculate Kassait, was sworn in on 16 November 2020 -- over a year after the Act's commencement -- and the operative subsidiary regulations (General, Registration, and Compliance & Enforcement Regulations) were only finalised in 2021 with registration opening in July 2022. The regime is therefore treated as in_transition: the statute and ODPC are operative and actively enforcing, but several implementing mechanisms (e.g. approved SCC-equivalents, formal adequacy determinations) remain undeveloped.

Sources and claims (6)
  1. ConfirmedInternational Association of Privacy ProfessionalsThe Data Protection Commissioner oversees implementation and enforcement of the Act under Section 8, but the office remained unformed until Immaculate Kassait was sworn in as Kenya's first Data Commissioner on 16 November 2020.
  2. ConfirmedOneTrust DataGuidanceThe Data Protection Act, 2019 came into force on 25 November 2019 and is the primary data protection legislation in Kenya.
  3. ConfirmedOneTrust DataGuidanceSensitive personal data under the Act includes race, health status, ethnic/social origin, conscience, belief, genetic data, biometric data, property details, marital status, family details (names of children, parents, spouses), sex and sexual orientation.
  4. ConfirmedOneTrust DataGuidanceThe Act applies to controllers/processors established or resident in Kenya, and separately to controllers/processors not established or resident in Kenya but who process personal data of data subjects located in Kenya, giving it broader extraterritorial reach than the GDPR's establishment-based test.
  5. ConfirmedInternational Association of Privacy ProfessionalsSection 18 provides no person shall act as a data controller or data processor unless registered with the Data Commissioner, who prescribes mandatory-registration thresholds considering industry nature, data volumes processed, and whether sensitive personal data is processed.
  6. Confirmedsource not recorded — The Registration Regulations exempt controllers/processors with annual turnover below KES 5 million or fewer than 10 employees from registration, but registration remains mandatory regardless of size for specified high-risk processing activities; online/physical registration opened 14 July 2022.

#

Core lawful-basis and special-category framework is legislated and in force, closely tracking GDPR structure.

Primary frameworkData Protection Act, 2019 (Kenya); Data Protection (General) Regulations, 2021
Traffic-light rationale — GreenCore lawful-basis and special-category framework is legislated and in force, closely tracking GDPR structure.

Sub-modules (4)

Lawful BasesGreen

The Act sets out legal bases for processing personal and sensitive data broadly similar to GDPR Art 6/9; the General Regulations 2021 require reliance on only one legal basis, established before processing begins.

Claims: CLM-KE-g708190a, CLM-KE-h8091b0b

Special CategoriesGreen

Section 45 imposes specific requirements for processing sensitive personal data, with protective measures required and a broader sensitive-data definition than GDPR (e.g., including family members' names).

Claims: CLM-KE-c3d4e503, CLM-KE-j03bd10d

Pseudonymisation And AnonymisationGreen

Both the Act and GDPR explicitly recognise anonymised and pseudonymised data and apply comparable concepts to automated processing, though definitional nuances differ (e.g., what counts as identifying data).

Claims: CLM-KE-k14ce20e

Category narrative79 words

The Act sets out lawful bases for both ordinary and sensitive personal data broadly comparable to GDPR Art 6/9, and the General Regulations 2021 require that processing rely on a single legal basis established prior to processing. Section 45 imposes enhanced protective requirements for sensitive personal data. Consent standards and journalism/artistic-purpose exceptions mirror GDPR, though withdrawal-of-consent and contract-performance nuances differ. Anonymisation/pseudonymisation are recognised concepts, similar to GDPR, though defined with some differences (e.g. family-member names counted as personal data).

Sources and claims (5)
  1. ConfirmedOneTrust DataGuidanceThe GDPR and the Act set out very similar legal bases for processing both personal data and sensitive data, with comparable conditions of consent and exceptions for journalism or artistic purposes.
  2. Confirmedsource not recorded — Under the Data Protection (General) Regulations, 2021, processing may rely on only one legal basis at a time, which must be established before the processing begins.
  3. ProbableOneTrust DataGuidanceThere are slight differences between GDPR and the Act regarding withdrawal of consent and consent tied to performance of a contract.
  4. ConfirmedOneTrust DataGuidanceSection 45 of the Act sets out specific protective requirements for the processing of sensitive personal data.
  5. ConfirmedOneTrust DataGuidanceThe GDPR and the Act both explicitly consider anonymised and pseudonymised data and apply to automated processing, with comparable concepts of personal and sensitive data, though key differences exist in how anonymisation is defined.

#

Rights exist and are being enforced via ODPC orders, but the Act is comparatively thin on granular procedural mechanics/response deadlines for controllers.

Primary frameworkData Protection Act, 2019 (Kenya)
Traffic-light rationale — AmberRights exist and are being enforced via ODPC orders, but the Act is comparatively thin on granular procedural mechanics/response deadlines for controllers.

Sub-modules (5)

Access RightAmber

The Act provides an access right but with less detailed procedural guidance than GDPR on the exercise of data subject rights.

Claims: CLM-KE-l25df30f

Rectification And ErasureAmber

ODPC enforcement action confirms an operative erasure/rectification expectation: Platinum Credit was found to have failed to erase a complainant's data on request, and Nairobi Hospital was ordered to delete unlawfully obtained promotional recordings within 14 days.

Claims: CLM-KE-m36e0410, CLM-KE-n47f0511

Restriction And ObjectionAmber

The right to object to processing (particularly direct marketing) is enforced in practice; Platinum Credit was sanctioned for ignoring a complainant's objection to marketing messages.

Claims: CLM-KE-m36e0410

Data PortabilityRed

No specific enforcement action or detailed portability mechanic was identified in available sources beyond the Act's general rights framework.

Absence provenance: not recorded. Searched: Kenya Data Protection Act data portability right mechanics.

Deadlines And Response WindowsAmber

No explicit statutory controller-response deadline for subject access/rectification/erasure requests (analogous to GDPR's one-month rule) was located; the only concrete procedural deadline identified is the ODPC's own 90-day complaint-resolution timeline under the Compliance and Enforcement Regulations, guided by the Fair Administrative Action Act 2015.

Absence provenance: not recorded. Searched: Kenya Data Protection Act subject access request response deadline, Data Protection General Regulations 2021 response window.

Claims: CLM-KE-o580c612

Category narrative70 words

The Act provides data subject rights but with less procedural detail than the GDPR. Enforcement practice (e.g. the Platinum Credit and Nairobi Hospital decisions) shows the ODPC actively enforcing objection-to-marketing and erasure/consent rights. No explicit statutory SAR response-window analogous to GDPR's one-month rule was located in available sources; the clearest procedural deadline identified relates to ODPC's own complaint resolution (90 days) rather than a controller's response to a data-subject request.

Sources and claims (4)
  1. ProbableOneTrust DataGuidanceThe Act provides less detailed information than the GDPR on the exercise of data subject rights.
  2. ConfirmedOneTrust DataGuidanceThe ODPC found Platinum Credit Limited violated the Act by using personal data for commercial purposes without consent, ignoring the complainant's objection to marketing messages, and failing to erase the complainant's data, ordering KES 900,000 in compensation.
  3. ConfirmedOneTrust DataGuidanceThe ODPC ordered The Nairobi Hospital to delete unlawfully-used promotional advertisements containing a patient's covertly recorded image and to provide proof of deletion within 14 days, alongside a KES 500,000 fine, for violations of Sections 32(1) and 37 of the Act.
  4. ConfirmedOneTrust DataGuidanceThe Compliance and Enforcement Regulations require the ODPC to be guided by the Fair Administrative Action Act, 2015, which requires conclusion of complaints within 90 days.

#

Core accountability, DPIA, and breach-notification duties are legislated and enforced, but DPO mandate is non-binding in practice and ROPA/joint-controller mechanics are comparatively underdeveloped versus GDPR.

Primary frameworkData Protection Act, 2019 (Kenya); Data Protection (General) Regulations, 2021
Traffic-light rationale — AmberCore accountability, DPIA, and breach-notification duties are legislated and enforced, but DPO mandate is non-binding in practice and ROPA/joint-controller mechanics are comparatively underdeveloped versus GDPR.

Sub-modules (7)

Accountability And DpiaGreen

Section 31 requires DPIAs for processing operations likely to result in high risk to data subjects, including biometric or genetic data processing and profiling/algorithmic ADM with legal or significant effect; where Commissioner consultation is required, it must occur within 60 days.

Claims: CLM-KE-p691d713, CLM-KE-q7a2e814, CLM-KE-r8b3f915

Dpo RequirementsAmber

The Act's DPO provisions mirror GDPR concepts and tasks but use permissive ('may') rather than mandatory ('shall') language, meaning appointment depends on the controller/processor's specific conditions and activities; where appointed, DPO contact details must be communicated to the Commissioner and published on the controller/processor's website.

Claims: CLM-KE-s9c40a16, CLM-KE-t0d51b17

Ropa RequirementsAmber

Unlike the GDPR's Article 30 record-keeping obligation, the Act substitutes a registration/notification regime with the Data Commissioner rather than requiring internal records of processing activities.

Claims: CLM-KE-u1e62c18

Joint Controller ArrangementsRed

No specific statutory provisions were identified governing the management of joint controller/processor relationships; service providers are only required to ensure contracted third parties adhere to data-protection provisions generally.

Claims: CLM-KE-v2f73d19

Security MeasuresGreen

The Act and General Regulations establish privacy-by-design/by-default principles broadly similar to GDPR, requiring embedded technical and organisational measures.

Claims: CLM-KE-w3084e1a

Breach NotificationGreen

Controllers must notify the Commissioner within 72 hours of a breach presenting real risk of harm to data subjects, and must subsequently notify affected data subjects in writing; the General Regulations set out categories of notifiable breaches and required notification content.

Claims: CLM-KE-x4195f1b, CLM-KE-y52a601c

Retention And DisposalRed

No explicit statutory retention-period schedule or disposal-duty provision specific to Kenya was located in available sources beyond general storage-limitation principles implied by the Act's data protection principles.

Absence provenance: not recorded. Searched: Kenya Data Protection Act retention period disposal obligations, Kenya General Regulations 2021 data retention.

Category narrative69 words

Kenya's General Regulations 2021 operationalise accountability via privacy-by-design/default obligations, mandatory DPIAs for high-risk processing (including biometric/genetic data and profiling-based ADM), and 72-hour breach notification to the ODPC. DPO appointment exists conceptually but is framed permissively ('may' rather than 'shall'), making it conditional rather than a hard threshold-based mandate. The Act substitutes formal ROPA/record-keeping with a registration regime, and a documented gap exists in statutory provisions governing controller-processor contractual relationships.

Sources and claims (10)
  1. ConfirmedInternational Association of Privacy ProfessionalsRegulation 49 of the Data Protection (General) Regulations requires a DPIA to be conducted under Section 31 of the Act for processing operations considered to result in high risks to the rights and freedoms of a data subject, including biometric or genetic data processing.
  2. ConfirmedInternational Association of Privacy ProfessionalsWhere a controller is required to consult the Data Commissioner on a DPIA, they must do so within 60 days.
  3. ProbableOneTrust DataGuidanceThe General Regulations designate biometric-data processing and automated decision-making with legal or other significant effect using profiling or algorithmic means as DPIA-triggering activities.
  4. ProbableOneTrust DataGuidanceDPO concepts, tasks, and appointment provisions are similar between GDPR and the Act, but the Act uses permissive terms such as 'may' rather than 'shall', making DPO appointment conditional rather than a strict mandate.
  5. ProbableOneTrust DataGuidanceWhere appointed, the DPO's contact details must be communicated to the Commissioner and published on the official website of the data controller or data processor.
  6. ConfirmedOneTrust DataGuidanceUnlike the GDPR, the Act establishes general processing registration/notification requirements rather than explicit internal record-keeping obligations for controllers and processors.
  7. ProbableOneTrust DataGuidanceThere are no legal provisions specifically governing the management of the data controller and data processor relationship under Kenyan sectoral telecoms rules, though service providers must ensure contracted third parties adhere to data-protection provisions.
  8. ConfirmedOneTrust DataGuidanceThe Act and GDPR have broadly similar security requirements, both establishing principles of privacy by default and by design, operationalised in Kenya via the General Regulations' technical and organisational measures requirements.
  9. ConfirmedOneTrust DataGuidanceControllers and processors must notify the Commissioner within 72 hours of any breach where there is a real risk of harm to data subjects, comparable to the GDPR's breach-notification timeline.
  10. ConfirmedOneTrust DataGuidanceWhere there is real risk of harm to data subjects from a breach, controllers must notify affected data subjects in writing after first notifying the Commissioner.

#

Transfer mechanisms exist in principle but lack a developed adequacy/SCC infrastructure, and sectoral/strategic-interest data localisation mandates add complexity and legal uncertainty (as illustrated by ongoing Worldcoin litigation).

Primary frameworkData Protection Act, 2019 (Kenya), Part VII; Data Protection (General) Regulations, 2021
Traffic-light rationale — AmberTransfer mechanisms exist in principle but lack a developed adequacy/SCC infrastructure, and sectoral/strategic-interest data localisation mandates add complexity and legal uncertainty (as illustrated by ongoing Worldcoin litigation).

Sub-modules (6)

Transfer MechanismsAmber

Cross-border transfer of personal data is permitted based on appropriate safeguards, an ODPC adequacy decision, necessity, or data-subject consent; written cross-border transfer agreements and restrictions on further onward transfer are also required.

Claims: CLM-KE-z63b711d, CLM-KE-a74c821e

Adequacy ReceivedRed

No information was identified indicating any jurisdiction has issued an adequacy decision recognising Kenya's regime as adequate.

Absence provenance: not recorded. Searched: Kenya adequacy decision received EU UK, Kenya DPA adequacy status.

Adequacy GrantedRed

There is currently no adequacy agreement between Kenya and the U.S. or any other country for personal data transfers, and the ODPC has not issued formal adequacy decisions for outbound transfers to specific jurisdictions.

Claims: CLM-KE-b85d931f

Sccs And BcrsRed

Unlike the GDPR, standard contractual clauses have not been provided under the Act or approved by the ODPC; the Act instead relies on the Commissioner-assessed 'appropriate safeguards' concept, which is undefined in the statute itself.

Claims: CLM-KE-b85d931f, CLM-KE-c96ea420

Transfer Impact AssessmentAmber

Regulation 41(1) of the General Regulations requires demonstrating that a legal instrument binding the recipient provides protection 'essentially equivalent' to the Act, or that a robust assessment of transfer circumstances concludes appropriate safeguards exist -- a GDPR-TIA-like exercise, though without a codified formal TIA methodology.

Claims: CLM-KE-d07fb521

Data LocalisationAmber

Section 50 empowers the Cabinet Secretary to mandate that certain processing (on strategic-interest or revenue-protection grounds) occur only via a server/data centre located in Kenya; the General Regulations extend this to specified sectors (civil registration, elections, public finance, critical infrastructure, education, healthcare), requiring at least one servicing data copy be stored in Kenya.

Claims: CLM-KE-e18c1622, CLM-KE-f29d2723

Category narrative76 words

Kenya has no adequacy agreement with any other jurisdiction and has not published approved SCC-equivalent forms; transfers instead rely on ODPC-assessed 'appropriate safeguards' (an 'essentially equivalent' protection standard under Regulation 41(1) of the General Regulations), necessity, or consent. The Cabinet Secretary retains power under Section 50 to mandate in-country server/data-centre processing for strategic-interest or revenue-protection purposes, and the General Regulations impose data-localisation duties on specified public-interest sectors (civil registration, elections, public finance, critical infrastructure, education, healthcare).

Sources and claims (7)
  1. ConfirmedOneTrust DataGuidanceTransfer of personal data outside Kenya is restricted to instances involving appropriate data protection safeguards, an ODPC adequacy decision, necessity, or data-subject consent.
  2. ConfirmedOneTrust DataGuidanceThe General Regulations require written cross-border transfer agreements between sending and receiving entities, along with restrictions on further onward transfer of personal data.
  3. ConfirmedInternational Association of Privacy ProfessionalsThere is currently no adequacy agreement between Kenya and the United States, or any other country, for personal data transfers, and standard contractual clauses have not been provided under the Act or approved by the ODPC.
  4. ConfirmedOneTrust DataGuidanceThe Act generally requires data controllers or processors to demonstrate to the Data Commissioner that appropriate safeguards exist, unless consent has been obtained, but the Act does not explicitly define what constitutes 'appropriate safeguards'.
  5. ConfirmedInternational Association of Privacy ProfessionalsUnder Regulation 41(1) of the General Regulations, the appropriate-safeguards basis for transfer requires a legal instrument binding the recipient that is 'essentially equivalent' to protection under the Act, or a robust assessment concluding appropriate safeguards exist.
  6. ConfirmedOneTrust DataGuidanceSection 50 of the Act allows the Cabinet Secretary to prescribe, on grounds of strategic interests of the state or protection of revenue, that certain processing be effected only through a server or data centre located in Kenya.
  7. ConfirmedOneTrust DataGuidanceThe General Regulations require controllers/processors handling data for strategic state interests -- including civil registration, elections, public finance, critical infrastructure, basic education, and healthcare -- to process such data via a Kenya-located server/data centre and store at least one servicing copy in Kenya.

#

Multiple sectoral overlays exist and interact with the DPA (telecoms, payments, health), but coverage is uneven and some sectors (education, insurance) show no distinct DP overlay in available sources.

Primary frameworkData Protection Act, 2019 (Kenya); Kenya Information and Communications Act, 1998; National Payment System Act
Traffic-light rationale — AmberMultiple sectoral overlays exist and interact with the DPA (telecoms, payments, health), but coverage is uneven and some sectors (education, insurance) show no distinct DP overlay in available sources.

Sub-modules (7)

Financial Sector OverlayAmber

Financial data is regulated under the National Payment System Act, National Payment Regulations, and Prudential Guidelines, layered atop general DPA obligations.

Claims: CLM-KE-g30e3824

Health Sector OverlayAmber

The (non-binding but persuasive) Health Information System Policy requires that health data not be stored outside Kenyan territory.

Claims: CLM-KE-h41f3925

Telecoms And EprivacyGreen

Licensed providers under KICA must obtain/retain subscriber and SIM-card registration information, keep records secure and confidential, adhere to CA-prescribed retention periods, and ensure processing complies with DPA principles including breach notification to customers for network-security risks.

Claims: CLM-KE-i5203a26, CLM-KE-j6314b27

Employment DataAmber

Most employee data is protected as personal/sensitive data under the general Act; no dedicated sectoral employment-data statute was identified, though the cross-cutting Consumer Protection Act provisions may also apply.

Claims: CLM-KE-k7425c28

Credit And ScoringAmber

The ODPC has actively enforced against credit/lending firms for unlawful marketing and data-erasure failures, as evidenced by the Platinum Credit Limited decision (KES 900,000 compensation order, January 2025).

Claims: CLM-KE-m36e0410

EducationRed

No education-sector-specific data protection overlay was identified in available sources.

Absence provenance: not recorded. Searched: Kenya education sector data protection overlay, Kenya student data protection regulations.

InsuranceRed

No insurance-sector-specific data protection overlay was identified in available sources.

Absence provenance: not recorded. Searched: Kenya insurance sector data protection regulations, Kenya IRA data protection overlay.

Category narrative88 words

Telecoms are regulated under the Kenya Information and Communications Act (KICA) and its Consumer Protection/SIM-Card Registration Regulations, overlaying the DPA for licensed providers. Financial data is separately regulated under the National Payment System Act, National Payment Regulations, and Prudential Guidelines. A non-binding Health Information System Policy discourages storing health data outside Kenya. No dedicated employment-sector statute exists; employee data instead falls under the Act's general personal/sensitive-data provisions. Credit-sector enforcement (e.g., Platinum Credit) demonstrates active ODPC oversight of consumer-lending data practices. No education- or insurance-sector-specific DP overlays were identified.

Sources and claims (5)
  1. ConfirmedOneTrust DataGuidanceFinancial data in Kenya is regulated under the National Payment System Act, National Payment Regulations, and Prudential Guidelines, in addition to the general Data Protection Act.
  2. ProbableOneTrust DataGuidanceThe Health Information System Policy requires health data not be stored outside Kenyan territory; while not legally binding, it is persuasive and courts are likely to be guided by it absent statutory provision.
  3. ConfirmedOneTrust DataGuidanceLicensed providers under the Kenya Information and Communications Act must obtain and retain SIM-card/subscriber registration information, keep it secure and confidential, and adhere to CA-prescribed retention periods for registration details, call data records and financial information.
  4. ConfirmedOneTrust DataGuidanceThe Act amends KICA to require licensed providers to process subscriber personal data in accordance with the Act's principles and to implement technical/organisational measures preventing loss, damage, unauthorised destruction/access, or unlawful processing.
  5. ProbableOneTrust DataGuidanceMost data collected from employees in the course of employment is protected as personal data and sensitive data under the general Act, as there is no dedicated sectoral employment-data statute.

#

Direct-marketing consent/opt-out rules are legislated and actively enforced, but Kenya has no distinct cookie/tracker, dark-pattern, or cross-context-advertising regime comparable to EU ePrivacy or US state adtech laws.

Primary frameworkData Protection (General) Regulations, 2021
Traffic-light rationale — AmberDirect-marketing consent/opt-out rules are legislated and actively enforced, but Kenya has no distinct cookie/tracker, dark-pattern, or cross-context-advertising regime comparable to EU ePrivacy or US state adtech laws.

Sub-modules (6)

Cookies And TrackersRed

No cookie- or tracker-specific consent regime distinct from the general lawful-basis framework was identified for Kenya.

Absence provenance: not recorded. Searched: Kenya cookie consent law, Kenya ePrivacy equivalent tracker regulation.

Dark PatternsRed

No dark-pattern prohibition specific to Kenyan data protection law was identified.

Absence provenance: not recorded. Searched: Kenya dark patterns data protection prohibition.

Opt Out SignalsAmber

No recognition of technical opt-out signals (e.g., Global Privacy Control, DAA) was identified in Kenyan sources; the General Regulations instead require a 'simplified opt out mechanism' for direct marketing.

Claims: CLM-KE-l8425d29

Clean Rooms And DcrRed

No clean-room or data-collaboration-room rules were identified for Kenya.

Absence provenance: not recorded. Searched: Kenya data clean room regulation.

Cross Context AdvertisingRed

Kenya's Act has no CPRA-style 'sale' or 'share' concept for cross-context behavioural advertising.

Absence provenance: not recorded. Searched: Kenya cross-context advertising sale share concept data protection.

Direct MarketingAmber

Direct marketing constitutes 'commercial use' of personal data under the General Regulations, requiring the data subject be informed at collection or have consented, with a mandatory simplified opt-out; use for direct marketing without consent is an offence. ODPC enforcement against Platinum Credit (unsolicited marketing) and Nairobi Hospital (unauthorised promotional use of a patient recording) demonstrates active enforcement.

Claims: CLM-KE-l8425d29, CLM-KE-m36e0410, CLM-KE-n47f0511

Category narrative82 words

The General Regulations 2021 create a direct-marketing consent/opt-out regime: commercial use of data (including direct marketing) requires either that the data subject was informed at collection, that consent was obtained, or that a simplified opt-out is offered and not exercised; using data for direct marketing without consent is an offence. ODPC enforcement (Platinum Credit, Nairobi Hospital) confirms active application of these rules. No cookie/tracker-specific ePrivacy-style regime, dark-pattern prohibition, Global-Privacy-Control-style opt-out signal recognition, clean-room rules, or CPRA-style 'sale'/'share' concept was identified for Kenya.

Sources and claims (1)
  1. ConfirmedOneTrust DataGuidanceThe General Regulations deem personal data used to advance economic/commercial interests or for direct marketing as 'commercial use', permitted only where the data subject was informed at collection, consented, or was offered and did not exercise a simplified opt-out; use for direct marketing without consent is an offence.

#

Biometric/ADM processing is captured via DPIA triggers and is the subject of active, high-profile enforcement (Worldcoin), but no dedicated AI risk-assessment framework exists and national-security exemptions are broadly drawn.

Primary frameworkData Protection Act, 2019 (Kenya); Data Protection (General) Regulations, 2021
Traffic-light rationale — AmberBiometric/ADM processing is captured via DPIA triggers and is the subject of active, high-profile enforcement (Worldcoin), but no dedicated AI risk-assessment framework exists and national-security exemptions are broadly drawn.

Sub-modules (6)

Profiling RestrictionsAmber

Profiling-based automated decision-making with legal or significant effect is captured as a DPIA-triggering activity, though no standalone Article-22-style restriction/opt-out right distinct from the DPIA requirement was identified.

Claims: CLM-KE-r8b3f915

Automated Decision Making TransparencyRed

No explicit ADM-transparency/explanation right distinct from the general DPIA obligation was identified for Kenya.

Absence provenance: not recorded. Searched: Kenya automated decision-making transparency explanation right.

Ai Risk AssessmentsRed

No AI-specific risk-assessment framework (analogous to the EU AI Act) was identified for Kenya; DPIA obligations under the DPA are the closest functional equivalent for high-risk automated processing.

Absence provenance: not recorded. Searched: Kenya AI Act risk assessment law, Kenya artificial intelligence regulation data protection.

Biometric RegimeAmber

Biometric data is treated as sensitive personal data and triggers mandatory DPIA; the Worldcoin case (registration revocation, one-year activity ban, and unresolved cross-border transfer legality for iris-scan data) is the leading enforcement precedent.

Claims: CLM-KE-p691d713, CLM-KE-o691f230, CLM-KE-p7a2031

Genetic DataAmber

Genetic data is classified as sensitive personal data and, like biometric data, triggers mandatory DPIA under Regulation 49.

Claims: CLM-KE-p691d713

State Surveillance CarveoutsRed

The Miscellaneous Amendments Act, 2020 empowers security services to access personal data from any phone or computer, an exemption criticised by civil society as an overly intrusive national-security carve-out relative to constitutional privacy protections.

Claims: CLM-KE-q8b3142

Category narrative89 words

Kenya lacks a dedicated AI-specific statute, but the General Regulations mandate DPIAs for biometric-data processing and for automated decision-making with legal or significant effect using profiling or algorithmic means. The ongoing Worldcoin/Tools For Humanity litigation is Kenya's most significant test case for biometric governance, involving alleged registration-certificate misrepresentation, DPIA adequacy questions, and unresolved cross-border transfer legality for iris-scan biometric data. Separately, the Miscellaneous Amendments Act, 2020 grants security services broad access to personal data from any phone or computer, a state-surveillance carve-out that has drawn criticism as overly intrusive.

Sources and claims (3)
  1. ConfirmedInternational Association of Privacy ProfessionalsThe ODPC revoked Tools For Humanity's registration as a data processor and banned all Worldcoin activities in Kenya for one year, alleging the registration certificate was obtained through misrepresentation or material nondisclosure.
  2. ConfirmedInternational Association of Privacy ProfessionalsFailure to register or deliberately providing misleading information to the Data Commissioner's office is an offence punishable by a fine not exceeding KES 3 million or imprisonment not exceeding 10 years, or both, with courts additionally empowered to order forfeiture of related equipment.
  3. ProbableInternational Association of Privacy ProfessionalsKenya's Miscellaneous Amendments Act of 2020 empowers security services to access personal data from any phone or computer, cited by civil-society analysts as an overly intrusive national-security exemption relative to the DPA framework.

#

A children's-data provision exists in statute (Section 33) but lacks the granularity of GDPR Art 8 (no explicit age-of-consent threshold in the Act itself, no age-verification mechanics, no dependent-adult provisions located).

Primary frameworkData Protection Act, 2019 (Kenya), Section 33
Traffic-light rationale — AmberA children's-data provision exists in statute (Section 33) but lacks the granularity of GDPR Art 8 (no explicit age-of-consent threshold in the Act itself, no age-verification mechanics, no dependent-adult provisions located).

Sub-modules (5)

Age VerificationRed

No dedicated age-verification mechanism was identified in the Act or its regulations.

Absence provenance: not recorded. Searched: Kenya Data Protection Act age verification mechanism children.

Minor Profiling BansRed

No explicit ban on profiling of minors distinct from the general children's-data provision was identified.

Absence provenance: not recorded. Searched: Kenya minor profiling ban data protection.

Education SettingsRed

No education-setting-specific children's-data provision was identified beyond the general Section 33 requirements.

Absence provenance: not recorded. Searched: Kenya education setting children data protection specific rules.

Dependent AdultsRed

No dependent-adult (elderly/mentally-incapacitated) specific data protection provision was identified in available sources.

Absence provenance: not recorded. Searched: Kenya dependent adults vulnerable persons data protection provisions.

Category narrative58 words

Section 33 of the Act provides detailed requirements for processing children's data, though the Act itself does not define 'child'; Article 260 of the Constitution sets the age of adulthood at 18, which is generally read across as the operative threshold. No further education-setting-specific or dependent-adult-specific provisions, minor-profiling bans, or dedicated age-verification mechanisms were identified in available sources.

Sources and claims (1)
  1. ConfirmedOneTrust DataGuidanceSection 33 of the Act provides detailed requirements for processing children's data, although the Act does not specifically define 'child'; Article 260 of the Kenyan Constitution sets the adulthood threshold at 18 years.

#

Enforcement powers are legislated and actively used (multiple 2025-2026 fines/orders), but resourcing/independence concerns persist and collective-redress/private-right-of-action mechanisms remain undeveloped.

Primary frameworkData Protection Act, 2019 (Kenya); Data Protection (Compliance and Enforcement) Regulations, 2021
Traffic-light rationale — AmberEnforcement powers are legislated and actively used (multiple 2025-2026 fines/orders), but resourcing/independence concerns persist and collective-redress/private-right-of-action mechanisms remain undeveloped.

Sub-modules (6)

Regulator Powers And PenaltiesGreen

The DPC has powers to investigate (own-initiative or complaint-based), impose administrative fines, facilitate conciliation/mediation/negotiation, issue summons, and require explanations/information; maximum administrative penalty is KES 5 million or 1% of annual turnover (whichever lower), with additional daily fines of up to KES 10,000 per unrectified breach.

Claims: CLM-KE-s0d5364, CLM-KE-t1e6475, CLM-KE-u2f7586

Enforcement Activity IndexAmber

The ODPC issued multiple published enforcement decisions through 2025-2026, including fines against Platinum Credit Limited (KES 900,000, Jan 2025) and The Nairobi Hospital (KES 500,000, Dec 2025), alongside the Worldcoin/Tools For Humanity registration revocation and one-year activity ban.

Claims: CLM-KE-m36e0410, CLM-KE-n47f0511, CLM-KE-o691f230

Regulator Funding And CapacityAmber

Civil-society analysis (Access Now) found the ODPC lacks proper independence and recommended the Kenyan government provide adequate resources to ensure the office's effectiveness and functionality.

Claims: CLM-KE-v3g8697

Collective Redress And Class ActionsRed

No dedicated collective-redress or class-action mechanism specific to data protection claims was identified in available sources.

Absence provenance: not recorded. Searched: Kenya Data Protection Act class action collective redress mechanism.

Private Right Of ActionAmber

Redress in practice runs through the ODPC's administrative complaint process (which can order compensation, as in the Platinum Credit and Nairobi Hospital decisions); a distinct standalone civil private right of action outside the ODPC/High-Court judicial-review route was not clearly identified in available sources.

Absence provenance: not recorded. Searched: Kenya Data Protection Act private right of action civil suit.

Claims: CLM-KE-m36e0410

Recent Developments 180DAmber

Within the last 180 days, the ODPC issued its Nairobi Hospital decision (16 December 2025, KES 500,000 for unauthorised promotional use of a patient recording) and continued to pursue the Worldcoin/Tools For Humanity matter, including registration revocation and a one-year activity ban following allegations of registration-certificate misrepresentation.

Claims: CLM-KE-n47f0511, CLM-KE-o691f230

Category narrative124 words

The ODPC has broad investigative and administrative-fine powers under the Act and Compliance and Enforcement Regulations 2021, including own-initiative or complaint-based investigations, conciliation/mediation facilitation, and issuance of enforcement/penalty notices. Maximum administrative penalty for a general infringement is KES 5 million or 1% of the preceding year's annual turnover (whichever is lower), separate from criminal offence penalties (e.g., up to KES 3 million or 10 years' imprisonment for registration fraud). Enforcement activity has intensified through 2025-2026, with multiple published decisions (Platinum Credit, Nairobi Hospital, and others) and the high-profile Worldcoin registration revocation/one-year ban. Civil-society commentary (Access Now) has flagged concerns about ODPC's institutional independence and resourcing. No dedicated collective-redress/class-action mechanism or standalone private right of action distinct from the ODPC's administrative complaint process was identified.

Sources and claims (4)
  1. ConfirmedInternational Association of Privacy ProfessionalsThe Data Commissioner has powers to conduct investigations on own initiative or on complaint, impose administrative fines for non-compliance, facilitate conciliation/mediation/negotiation, issue summons to witnesses, and require explanations/information/assistance from any person subject to the Act.
  2. ConfirmedInternational Association of Privacy ProfessionalsThe maximum administrative penalty the DPC may impose in a penalty notice for an infringement of the Act is up to KES 5 million, or in the case of an undertaking, up to 1% of its annual turnover of the preceding financial year, whichever is lower.
  3. ConfirmedOneTrust DataGuidanceUnder the Compliance and Enforcement Regulations, the ODPC may issue a penalty notice including a daily fine of not more than KES 10,000 per identified breach until the breach is rectified; recipients of an enforcement notice may seek ODPC review or appeal to the High Court within 30 days.
  4. ProbableInternational Association of Privacy ProfessionalsCivil-society analysis found the ODPC lacks proper independence and recommended the Kenyan government provide adequate resources to ensure the office's effectiveness and functionality.
No categories match.

Filters combine as OR inside a group and AND across groups.

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Kenya
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewernot recorded
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-05. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 46 claim(s), 12 source(s) in the cumulative register.