Kenya Data Protection Act
Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
KE DPA Breach Notification
Section 43 of the Kenya DPA establishes the Personal Data Breach Notification framework. (1) Section 43(1) Personal Data Breach Definition: (a) Breach of security leading to accidental or unlawful (i) destruction; (ii) loss; (iii) alteration; (iv) unauthorised disclosure; (v) access to personal data; (b) Covers all data states - at rest + in transit + in use; (c) Covers both technical (cyber) + human (insider + negligence) + physical (theft + loss); (d) Covers controller + processor breaches. (2) Section 43(2) ODPC Notification: (a) Notification required to ODPC without undue delay; (b) Where feasible within 72 HOURS of becoming aware; (c) If delayed beyond 72 hours - reasons must accompany notification; (d) Phased notification allowed if full information not available; (e) Ongoing updates as investigation progresses. (3) Section 43(3) Notification Information Required: (a) Nature of the
- Breach detection + SIEM/DLP/EDR/insider + records + per incident + audit trail
- ODPC notification + 72-hour + Section 43 + records + per breach + phased updates
- Subject notification + high-risk + Section 43(4) + records + per breach + English + Kiswahili
- Breach documentation + ALL breaches + Section 43(6) + records + audit-ready
- Processor notification + Section 42 + records + per sub-processor + escalation
- Breach detection passive (manual reports only)
- ODPC notification beyond 72 hours without explanation
- Subject notification skipped (high-risk underestimated)
- Documentation only for notified breaches
- Processor notification absent in contracts
KE DPA Complaints + Penalties
Sections 56-63 of the Kenya DPA establish the complaints + enforcement + penalty framework. (1) Section 56 Right to Complain: (a) Data subject may complain to ODPC against controller or processor; (b) Anonymous complaints accepted at ODPC discretion; (c) Civil society + NGO complaints accepted with subject consent; (d) Commissioner may initiate investigation on own motion. (2) Section 57-58 Investigation + Hearing: (a) Preliminary review + admissibility; (b) Controller/processor invited to respond; (c) Formal investigation with information gathering; (d) Interim orders if urgent; (e) Interview of witnesses; (f) Production of documents; (g) Inspection of premises; (h) Cooperation requirement; (i) Privacy of investigation balanced with transparency. (3) Section 59 Determination + Orders: (a) Finding of non-compliance + nature; (b) Compliance orders; (c) Cessation orders; (d) Corrective mea
- Complaint handling + Section 56 + records + per complaint + audit trail
- ODPC cooperation + Section 57-58 + records + per inquiry + document production
- Penalty risk + Section 61-62 + KES 5M/1% turnover + records + quantified
- Reasonable care defence + Section 63 + records + per control + audit trail
- Training + annual mandatory + English + Kiswahili + records + completion
- Complaint handling reactive (no proactive procedure)
- ODPC cooperation reluctant (defensive)
- Penalty risk not quantified (Board unaware of KES exposure)
- Reasonable care defence undocumented
- Training generic + completed once only
KE DPA Cross-Border + Data Localisation
Sections 48-50 of the Kenya DPA govern cross-border transfers of personal data outside Kenya territory. (1) Section 48 General Framework: Cross-border transfer permitted only on specific grounds (a) Adequacy Determination by Cabinet Secretary; (b) Subject consent (express written for sensitive data + specific for transfer); (c) Performance of contract to which subject is party; (d) Vital interests of subject; (e) Public interest as defined by law; (f) Statutory authority; (g) Cabinet Secretary approval for specific transfer mechanism. (2) Section 49 Adequacy Determinations: (a) Cabinet Secretary determines third country provides adequate level of protection; (b) Consideration includes (i) rule of law + respect for human rights; (ii) data protection legislation + enforcement; (iii) supervisory authority independence; (iv) international commitments; (v) Convention 108+ accession; (c) Recip
- Transfer map + per destination + records + per data flow + per category
- Lawful mechanism + Adequacy/SCC/BCR + records + per transfer + per recipient
- Section 50 localisation + strategic data + records + per data class + Kenya-primary
- TIA + per transfer + records + per destination + periodic review
- Cabinet Secretary approval + records + per material transfer + per mechanism
- Transfers without mapping (cloud sprawl)
- Lawful mechanism not chosen per transfer
- Section 50 localisation ignored for strategic data
- TIA absent (Schrems II analysis ignored)
- Cabinet Secretary approval absent or expired
KE DPA Data Subject Rights
Section 26 of the Kenya DPA establishes comprehensive data subject rights closely modelled on EU GDPR. (1) Section 26 Seven Data Subject Rights: (a) Right to be Informed of use of personal data; (b) Right of Access - request access to personal data; (c) Right of Correction (Rectification) - correct false or misleading data; (d) Right of Erasure (Right to be Forgotten) - request deletion or destruction of personal data; (e) Right to Object - object to processing including profiling for direct marketing + legitimate interests + public interest task; (f) Right of Restriction - restrict processing in specific circumstances; (g) Right to Data Portability - structured + commonly used + machine-readable format. (2) Section 27 Right of Access Detail: (a) Confirmation whether processing personal data; (b) Copy of personal data; (c) Supplementary information (purposes + categories + recipients + r
- DSAR portal + Section 26 + 30-day SLA + records + per request + English + Kiswahili
- Rights implementation + Section 26 + 7 rights + records + per type
- Identity verification + Huduma Namba + records + per DSAR + per access level
- Downstream propagation + recipients + records + per action + audit trail
- DPO oversight + escalation + records + per request + decisions
- DSAR portal absent (email-only handling)
- 30-day SLA frequently missed
- Rights implementation incomplete (portability + restriction)
- Identity verification weak (impersonation risk)
- Downstream propagation absent (siloed responses)
KE DPA Lawful Basis + Notice
Section 30 of the Kenya DPA establishes the lawful basis framework + Section 29 establishes information notice requirements. (1) Section 30 Lawful Basis - 7 Grounds: (a) Consent of data subject; (b) Performance of contract to which data subject is party + or pre-contractual steps requested by data subject; (c) Compliance with legal obligation; (d) Protection of vital interests of data subject or another natural person; (e) Performance of task carried out in public interest or in exercise of official authority; (f) Legitimate interests of controller or third party (subject to balancing against data subject interests); (g) Historical + statistical + journalistic + literary + artistic expression purposes (subject to safeguards). (2) Section 25 Consent Definition: (a) Any manifestation of express + unequivocal + free + specific + informed indication of data subject wishes; (b) Pre-ticked box
- Lawful basis register + per processing + Section 30 + records + per activity
- Consent records + Section 25/32 + documented + withdrawal + records + per subject
- Privacy notice + Section 29 + records + per touchpoint + English + Kiswahili
- Sensitive data express consent + Section 44 + written + records + per category
- Parental consent + Section 33 + records + per child + verification mechanism
- Lawful basis selected after processing
- Consent records weak (bundled + pre-ticked)
- Privacy Notice English-only (no Kiswahili)
- Sensitive data without Section 44 express consent
- Children's consent absent
KE DPA Registration + ODPC
Sections 18-19 of the Kenya DPA establish the mandatory registration framework administered by the Office of the Data Protection Commissioner (ODPC). (1) Section 18 Mandatory Registration: (a) Every data controller AND data processor must be registered with ODPC before processing personal data; (b) Penalty for non-registration - administrative penalty + cessation of processing order; (c) ODPC maintains public register of registered controllers + processors; (d) Annual renewal required. (2) Registration Categories: (a) Public sector controllers - government ministries + counties + state corporations; (b) Private sector controllers - SMEs + large businesses + multinationals; (c) Processors - service providers + cloud providers + outsourcing partners; (d) Joint controllers; (e) Foreign entities processing Kenya data subjects. (3) Registration Application Content per Section 19: (a) Identity
- Registration + ODPC + Section 18 + records + per entity + Certificate
- Annual renewal + records + per year + fees paid + audit trail
- Material change + 30-day + records + per change + notification
- Public register + listing + records + per verification + transparency
- Vendor/processor registration + verification + records + per engagement
- Registration absent (processing illegal)
- Annual renewal lapsed
- Material changes not notified
- Vendors operating without registration verification
- Registration scope incomplete
KE DPA Scope + Application
Kenya Data Protection Act 2019 (DPA) Act No. 24 of 2019 + assented by President 8 November 2019 + commenced 25 November 2019 + published in Kenya Gazette Supplement No. 181. Foundational comprehensive data protection statute for Republic of Kenya + significantly aligned with EU GDPR + first East African Community member to enact GDPR-style legislation. (1) Statutory Framework: (a) Bill introduced in National Assembly 2018; (b) Act No. 24 of 2019 passed Parliament; (c) Presidential Assent 8 November 2019; (d) Commenced 25 November 2019; (e) Office of the Data Protection Commissioner (ODPC) established + Commissioner Immaculate Kassait appointed 14 November 2020; (f) Implementing Regulations + Operational + Compliance Regulations + Complaints Regulations + Cross-Border Regulations + Registration Regulations promulgated 2021; (g) National Information Communications and Technology (ICT) Poli
- Scope assessment + per processing + records + per business unit + per system
- Territorial application + per Kenya data subject + records + per market
- Definitions mapping + Section 2 + records + per system + per data flow
- Article 31 Constitution + records + per activity + privacy by design
- ODPC engagement + records + per inquiry + cooperation + transparency
- Scope misjudged (foreign processors with Kenya data subjects)
- Extraterritorial application unrecognised
- Definitions not mapped (sensitive personal data per Section 44 unflagged)
- Article 31 Constitution not considered in privacy program
- ODPC engagement absent
KE DPA Sensitive Data + Children
Sections 44-46 of the Kenya DPA establish enhanced protections for Sensitive Personal Data + Section 33 for children's personal data. (1) Section 2 Sensitive Personal Data Definition (broader than GDPR): (a) Race + ethnic origin + tribe (Kenya-specific tribal categorization concern); (b) Health + including reproductive health + mental health + disability; (c) Biometric data (fingerprint + facial recognition + iris + voice + behavioural); (d) Genetic data (DNA + heritable conditions + ancestry); (e) Sex life + sexual orientation; (f) Religion + belief + conscience; (g) Marital status (broader than most jurisdictions); (h) Family details including names of spouse + children + parents (unique Kenya inclusion reflecting communal society); (i) Citizenship + immigration status; (j) Children's personal data (Section 33). (2) Section 44 Sensitive Data Processing Conditions - PROHIBITED unless: (
- Sensitive data inventory + Section 44 + categories + records + per system
- Lawful basis sensitive + Section 44 + records + per processing + per condition
- Express consent + written + records + per subject + per category + audit
- Children's parental consent + Section 33 + records + per child + verification
- Family/marital/tribe + records + per disclosure + sensitivity awareness
- Sensitive data uncategorised (broader 11-category Kenya scope unrecognised)
- Lawful basis sensitive same as general (Section 44 not applied)
- Express consent same as general consent
- Children's age verification absent (under 18 standard)
- Family/marital data not recognised as sensitive
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.