Kenya
Tier 3 Comprehensive law AfricaPrincipal framework: Data Protection Act 2019 (2019). Regulator: ODPC. The 2019 Act is actively enforced — penalty notices have covered spam marketing, CCTV and biometric misuse — and Kenya is regularly cited as an EU adequacy candidate.
At a glance
- Principal law
- Data Protection Act, 2019 (No. 24 of 2019)
- Regulator
- Office of the Data Protection Commissioner (ODPC)
- Breach notification
- 72 hours to the ODPC where a real risk of harm; subjects without delay
- Maximum penalty
- Up to KES 5m or 1% of annual turnover, whichever is lower
- DPO required
- Required in defined cases; controllers and processors register with the ODPC
- Digital consent age
- Parental consent for children
- Extraterritorial reach
- Yes — data subjects located in Kenya
Structure
- Structural pattern
- Not assessed
- Sub-jurisdictions
- None — no sub-national axis
- ISO code
- KE
A Pattern 4 jurisdiction has no sub-national layer to model. Devolution elsewhere in the legal system does not imply it here — check each Act rather than reasoning from the country.
Transfers and adequacy
- EU member
- No
- EEA member
- No
Instruments
No instrument profiled yet.
Sources
Never independently verified — seeded from the prototype.