Data Protection Atlas

Kenya

Tier 3 Comprehensive law Africa

Principal framework: Data Protection Act 2019 (2019). Regulator: ODPC. The 2019 Act is actively enforced — penalty notices have covered spam marketing, CCTV and biometric misuse — and Kenya is regularly cited as an EU adequacy candidate.

At a glance

Principal law
Data Protection Act, 2019 (No. 24 of 2019)
Regulator
Office of the Data Protection Commissioner (ODPC)
Breach notification
72 hours to the ODPC where a real risk of harm; subjects without delay
Maximum penalty
Up to KES 5m or 1% of annual turnover, whichever is lower
DPO required
Required in defined cases; controllers and processors register with the ODPC
Digital consent age
Parental consent for children
Extraterritorial reach
Yes — data subjects located in Kenya

Structure

Structural pattern
Not assessed
Sub-jurisdictions
None — no sub-national axis
ISO code
KE

A Pattern 4 jurisdiction has no sub-national layer to model. Devolution elsewhere in the legal system does not imply it here — check each Act rather than reasoning from the country.

Transfers and adequacy

EU member
No
EEA member
No

Instruments

No instrument profiled yet.

Sources

Never independently verified — seeded from the prototype.