Skip to content

Evidence request lists

Kenya Data Protection Act

Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

KE DPA Breach Notification

KE-DPA-Breach-Notification-Sections43-72-Hour-ODPC-Affected-Subjects-Mitigation-Documentation
Kenya DPA Personal Data Breach Notification + Section 43 + 72-Hour ODPC + Affected Data Subjects High Risk + Mitigation + Documentation + Processor Notification Chain + Cross-Border Coordination

Section 43 of the Kenya DPA establishes the Personal Data Breach Notification framework. (1) Section 43(1) Personal Data Breach Definition: (a) Breach of security leading to accidental or unlawful (i) destruction; (ii) loss; (iii) alteration; (iv) unauthorised disclosure; (v) access to personal data; (b) Covers all data states - at rest + in transit + in use; (c) Covers both technical (cyber) + human (insider + negligence) + physical (theft + loss); (d) Covers controller + processor breaches. (2) Section 43(2) ODPC Notification: (a) Notification required to ODPC without undue delay; (b) Where feasible within 72 HOURS of becoming aware; (c) If delayed beyond 72 hours - reasons must accompany notification; (d) Phased notification allowed if full information not available; (e) Ongoing updates as investigation progresses. (3) Section 43(3) Notification Information Required: (a) Nature of the

Artefacts an auditor will ask for
  • Breach detection + SIEM/DLP/EDR/insider + records + per incident + audit trail
  • ODPC notification + 72-hour + Section 43 + records + per breach + phased updates
  • Subject notification + high-risk + Section 43(4) + records + per breach + English + Kiswahili
  • Breach documentation + ALL breaches + Section 43(6) + records + audit-ready
  • Processor notification + Section 42 + records + per sub-processor + escalation
Where this commonly fails
  • Breach detection passive (manual reports only)
  • ODPC notification beyond 72 hours without explanation
  • Subject notification skipped (high-risk underestimated)
  • Documentation only for notified breaches
  • Processor notification absent in contracts

KE DPA Complaints + Penalties

KE-DPA-Complaints-Enforcement-Sections56-63-Penalties-KES-5M-1-Percent-Turnover-Whichever-Higher
Kenya DPA Complaints + Enforcement + Sections 56-63 + Administrative Penalties + KES 5 Million OR 1 Percent Annual Turnover Whichever Higher + Civil Compensation + Criminal Offences + Director/Officer Liability + Reasonable Care Defence

Sections 56-63 of the Kenya DPA establish the complaints + enforcement + penalty framework. (1) Section 56 Right to Complain: (a) Data subject may complain to ODPC against controller or processor; (b) Anonymous complaints accepted at ODPC discretion; (c) Civil society + NGO complaints accepted with subject consent; (d) Commissioner may initiate investigation on own motion. (2) Section 57-58 Investigation + Hearing: (a) Preliminary review + admissibility; (b) Controller/processor invited to respond; (c) Formal investigation with information gathering; (d) Interim orders if urgent; (e) Interview of witnesses; (f) Production of documents; (g) Inspection of premises; (h) Cooperation requirement; (i) Privacy of investigation balanced with transparency. (3) Section 59 Determination + Orders: (a) Finding of non-compliance + nature; (b) Compliance orders; (c) Cessation orders; (d) Corrective mea

Artefacts an auditor will ask for
  • Complaint handling + Section 56 + records + per complaint + audit trail
  • ODPC cooperation + Section 57-58 + records + per inquiry + document production
  • Penalty risk + Section 61-62 + KES 5M/1% turnover + records + quantified
  • Reasonable care defence + Section 63 + records + per control + audit trail
  • Training + annual mandatory + English + Kiswahili + records + completion
Where this commonly fails
  • Complaint handling reactive (no proactive procedure)
  • ODPC cooperation reluctant (defensive)
  • Penalty risk not quantified (Board unaware of KES exposure)
  • Reasonable care defence undocumented
  • Training generic + completed once only

KE DPA Cross-Border + Data Localisation

KE-DPA-Cross-Border-Transfer-Section48-50-Adequacy-Consent-Public-Interest-Performance-Localisation-Strategic
Kenya DPA Cross-Border Transfer + Sections 48-50 + Adequacy + Consent + Public Interest + Performance + Localisation for Strategic Interests + EAC Coordination + African Union Convention + Cabinet Secretary Approval

Sections 48-50 of the Kenya DPA govern cross-border transfers of personal data outside Kenya territory. (1) Section 48 General Framework: Cross-border transfer permitted only on specific grounds (a) Adequacy Determination by Cabinet Secretary; (b) Subject consent (express written for sensitive data + specific for transfer); (c) Performance of contract to which subject is party; (d) Vital interests of subject; (e) Public interest as defined by law; (f) Statutory authority; (g) Cabinet Secretary approval for specific transfer mechanism. (2) Section 49 Adequacy Determinations: (a) Cabinet Secretary determines third country provides adequate level of protection; (b) Consideration includes (i) rule of law + respect for human rights; (ii) data protection legislation + enforcement; (iii) supervisory authority independence; (iv) international commitments; (v) Convention 108+ accession; (c) Recip

Artefacts an auditor will ask for
  • Transfer map + per destination + records + per data flow + per category
  • Lawful mechanism + Adequacy/SCC/BCR + records + per transfer + per recipient
  • Section 50 localisation + strategic data + records + per data class + Kenya-primary
  • TIA + per transfer + records + per destination + periodic review
  • Cabinet Secretary approval + records + per material transfer + per mechanism
Where this commonly fails
  • Transfers without mapping (cloud sprawl)
  • Lawful mechanism not chosen per transfer
  • Section 50 localisation ignored for strategic data
  • TIA absent (Schrems II analysis ignored)
  • Cabinet Secretary approval absent or expired

KE DPA Data Subject Rights

KE-DPA-Data-Subject-Rights-Sections26-Access-Correction-Erasure-Object-Portability-Restriction-30-Days
Kenya DPA Data Subject Rights + Section 26 + Right to be Informed + Access + Correction + Erasure + Object + Restriction + Portability + Automated Decision-Making + 30-Day Response + Free for First Request + Refusal Grounds Limited

Section 26 of the Kenya DPA establishes comprehensive data subject rights closely modelled on EU GDPR. (1) Section 26 Seven Data Subject Rights: (a) Right to be Informed of use of personal data; (b) Right of Access - request access to personal data; (c) Right of Correction (Rectification) - correct false or misleading data; (d) Right of Erasure (Right to be Forgotten) - request deletion or destruction of personal data; (e) Right to Object - object to processing including profiling for direct marketing + legitimate interests + public interest task; (f) Right of Restriction - restrict processing in specific circumstances; (g) Right to Data Portability - structured + commonly used + machine-readable format. (2) Section 27 Right of Access Detail: (a) Confirmation whether processing personal data; (b) Copy of personal data; (c) Supplementary information (purposes + categories + recipients + r

Artefacts an auditor will ask for
  • DSAR portal + Section 26 + 30-day SLA + records + per request + English + Kiswahili
  • Rights implementation + Section 26 + 7 rights + records + per type
  • Identity verification + Huduma Namba + records + per DSAR + per access level
  • Downstream propagation + recipients + records + per action + audit trail
  • DPO oversight + escalation + records + per request + decisions
Where this commonly fails
  • DSAR portal absent (email-only handling)
  • 30-day SLA frequently missed
  • Rights implementation incomplete (portability + restriction)
  • Identity verification weak (impersonation risk)
  • Downstream propagation absent (siloed responses)

KE DPA Lawful Basis + Notice

KE-DPA-Lawful-Basis-Section30-Consent-Contract-Legal-Vital-Public-Interest-Legitimate-Section29-Notice
Kenya DPA Lawful Basis + Section 30 + Consent + Contract Performance + Legal Obligation + Vital Interests + Public Interest + Legitimate Interests + Section 29 Notice + Express Unequivocal Consent + Withdrawal Right

Section 30 of the Kenya DPA establishes the lawful basis framework + Section 29 establishes information notice requirements. (1) Section 30 Lawful Basis - 7 Grounds: (a) Consent of data subject; (b) Performance of contract to which data subject is party + or pre-contractual steps requested by data subject; (c) Compliance with legal obligation; (d) Protection of vital interests of data subject or another natural person; (e) Performance of task carried out in public interest or in exercise of official authority; (f) Legitimate interests of controller or third party (subject to balancing against data subject interests); (g) Historical + statistical + journalistic + literary + artistic expression purposes (subject to safeguards). (2) Section 25 Consent Definition: (a) Any manifestation of express + unequivocal + free + specific + informed indication of data subject wishes; (b) Pre-ticked box

Artefacts an auditor will ask for
  • Lawful basis register + per processing + Section 30 + records + per activity
  • Consent records + Section 25/32 + documented + withdrawal + records + per subject
  • Privacy notice + Section 29 + records + per touchpoint + English + Kiswahili
  • Sensitive data express consent + Section 44 + written + records + per category
  • Parental consent + Section 33 + records + per child + verification mechanism
Where this commonly fails
  • Lawful basis selected after processing
  • Consent records weak (bundled + pre-ticked)
  • Privacy Notice English-only (no Kiswahili)
  • Sensitive data without Section 44 express consent
  • Children's consent absent

KE DPA Registration + ODPC

KE-DPA-Registration-Section18-19-Mandatory-ODPC-Controllers-Processors-Annual-Renewal
Kenya DPA Mandatory Registration with ODPC + Sections 18-19 + Controllers + Processors + Annual Renewal + Registration Categories + Material Change Notification + Exemptions + Public Register

Sections 18-19 of the Kenya DPA establish the mandatory registration framework administered by the Office of the Data Protection Commissioner (ODPC). (1) Section 18 Mandatory Registration: (a) Every data controller AND data processor must be registered with ODPC before processing personal data; (b) Penalty for non-registration - administrative penalty + cessation of processing order; (c) ODPC maintains public register of registered controllers + processors; (d) Annual renewal required. (2) Registration Categories: (a) Public sector controllers - government ministries + counties + state corporations; (b) Private sector controllers - SMEs + large businesses + multinationals; (c) Processors - service providers + cloud providers + outsourcing partners; (d) Joint controllers; (e) Foreign entities processing Kenya data subjects. (3) Registration Application Content per Section 19: (a) Identity

Artefacts an auditor will ask for
  • Registration + ODPC + Section 18 + records + per entity + Certificate
  • Annual renewal + records + per year + fees paid + audit trail
  • Material change + 30-day + records + per change + notification
  • Public register + listing + records + per verification + transparency
  • Vendor/processor registration + verification + records + per engagement
Where this commonly fails
  • Registration absent (processing illegal)
  • Annual renewal lapsed
  • Material changes not notified
  • Vendors operating without registration verification
  • Registration scope incomplete

KE DPA Scope + Application

KE-DPA-Scope-Application-Sections1-3-Act-No-24-2019-8-November-2019-25-November-Effective-Article-31-Constitution-ODPC
Kenya Data Protection Act 2019 Scope + Application + Sections 1-3 + Act No. 24 of 2019 + Assented 8 November 2019 + Effective 25 November 2019 + Article 31 Constitution Right to Privacy + Office of Data Protection Commissioner (ODPC) + GDPR-Aligned + EU Adequacy Candidacy

Kenya Data Protection Act 2019 (DPA) Act No. 24 of 2019 + assented by President 8 November 2019 + commenced 25 November 2019 + published in Kenya Gazette Supplement No. 181. Foundational comprehensive data protection statute for Republic of Kenya + significantly aligned with EU GDPR + first East African Community member to enact GDPR-style legislation. (1) Statutory Framework: (a) Bill introduced in National Assembly 2018; (b) Act No. 24 of 2019 passed Parliament; (c) Presidential Assent 8 November 2019; (d) Commenced 25 November 2019; (e) Office of the Data Protection Commissioner (ODPC) established + Commissioner Immaculate Kassait appointed 14 November 2020; (f) Implementing Regulations + Operational + Compliance Regulations + Complaints Regulations + Cross-Border Regulations + Registration Regulations promulgated 2021; (g) National Information Communications and Technology (ICT) Poli

Artefacts an auditor will ask for
  • Scope assessment + per processing + records + per business unit + per system
  • Territorial application + per Kenya data subject + records + per market
  • Definitions mapping + Section 2 + records + per system + per data flow
  • Article 31 Constitution + records + per activity + privacy by design
  • ODPC engagement + records + per inquiry + cooperation + transparency
Where this commonly fails
  • Scope misjudged (foreign processors with Kenya data subjects)
  • Extraterritorial application unrecognised
  • Definitions not mapped (sensitive personal data per Section 44 unflagged)
  • Article 31 Constitution not considered in privacy program
  • ODPC engagement absent

KE DPA Sensitive Data + Children

KE-DPA-Sensitive-Personal-Data-Section44-46-Children-Section33-Health-Genetic-Biometric-Religious-Sex-Marital
Kenya DPA Sensitive Personal Data + Sections 44-46 + Children Section 33 + Health + Genetic + Biometric + Religious + Sex Life + Sexual Orientation + Marital Status + Ethnicity + Tribe + Immigration + Family Details + Heightened Consent + Special Conditions

Sections 44-46 of the Kenya DPA establish enhanced protections for Sensitive Personal Data + Section 33 for children's personal data. (1) Section 2 Sensitive Personal Data Definition (broader than GDPR): (a) Race + ethnic origin + tribe (Kenya-specific tribal categorization concern); (b) Health + including reproductive health + mental health + disability; (c) Biometric data (fingerprint + facial recognition + iris + voice + behavioural); (d) Genetic data (DNA + heritable conditions + ancestry); (e) Sex life + sexual orientation; (f) Religion + belief + conscience; (g) Marital status (broader than most jurisdictions); (h) Family details including names of spouse + children + parents (unique Kenya inclusion reflecting communal society); (i) Citizenship + immigration status; (j) Children's personal data (Section 33). (2) Section 44 Sensitive Data Processing Conditions - PROHIBITED unless: (

Artefacts an auditor will ask for
  • Sensitive data inventory + Section 44 + categories + records + per system
  • Lawful basis sensitive + Section 44 + records + per processing + per condition
  • Express consent + written + records + per subject + per category + audit
  • Children's parental consent + Section 33 + records + per child + verification
  • Family/marital/tribe + records + per disclosure + sensitivity awareness
Where this commonly fails
  • Sensitive data uncategorised (broader 11-category Kenya scope unrecognised)
  • Lawful basis sensitive same as general (Section 44 not applied)
  • Express consent same as general consent
  • Children's age verification absent (under 18 standard)
  • Family/marital data not recognised as sensitive
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.