Kenya's Data Protection Act, 2019 governs the collection, use, and storage of personal data. It grants rights to access, correct, and delete your data, and requires organisations to appoint a Data Protection Officer.
The Data Protection Act, 2019 (No. 24 of 2019) establishes the legal framework for personal data protection in Kenya, operationalising Article 31 of the Constitution (right to privacy). Key rights: **Right of access**: You may request confirmation that an organisation holds your personal data and obtain a copy. **Right to rectification**: You may require correction of inaccurate or incomplete data. **Right to erasure**: You may request deletion of data processed without lawful basis. **Right to object**: You may object to processing for direct marketing or profiling. Organisations (data controllers and processors) must: obtain your consent for processing in most cases; collect only data that is adequate, relevant, and necessary; and notify you of the purpose of processing. Data controllers with large-scale processing activities must register with the Office of the Data Protection Commissioner (ODPC). Complaints about violations can be lodged with the ODPC. Penalties for violations can reach KES 5 million or up to 3 years' imprisonment for wilful breaches.
A bank sells a customer's phone number to a marketing firm without consent. The customer files a complaint with the ODPC. The bank is required to stop the processing, delete the data, and may face a fine of up to KES 3 million.
The Advocate covers Kenyan law and Scripture — 389 real scenarios across 7 countries with exact rebuttals and law references. Free to start.
Explore Kenyan Rights — Free