Skip to content
Esta es una traduccion de conveniencia. La version en ingles es la version oficial y legalmente vinculante. Ver version en ingles
KEMEDIUM coverage1 enforcement action

Kenya Data Protection Act 2019: AI Compliance Requirements

Kenya's Data Protection Act No. 24 of 2019 entered into force November 8, 2019, with the Data Protection (General) Regulations and other subsidiary legislation issued in 2021. The Office of the Data Protection Commissioner (ODPC) enforces the Act. The Act applies to all organizations processing personal data of Kenyan residents (or where processing takes place in Kenya) — including foreign organizations. AI-relevant provisions: Section 33 provides data subjects the right to object to automated decision-making that produces legal effects or significantly affects them, and the right to request human review. Data controllers using AI for profiling or automated decisions must conduct Privacy Impact Assessments. Biometric data (increasingly used in AI systems) is classified as sensitive and requires explicit consent.

Summary of publicly-available regulatory text as of 2026-08-22. Verify against current official sources before relying on this for compliance decisions. Not legal advice.

Key Facts

Effective Date

November 8, 2019

Maximum Penalty

CYCLE 20 CORRECTION (2026-08-22): the prior flat "KES 5,000,000 or up to 10 years imprisonment" framing omitted the actual administrative-penalty-notice mechanism ODPC uses in every real enforcement case in this entry's own enforcementActions (Platinum Credit, Oppo Kenya). Verified via the Act's own text (kenyalaw.org) and the Data Protection (Complaints Handling and Enforcement) Regulations: under ss. 62-63, the Data Commissioner may issue a penalty notice of up to KES 5,000,000 OR 1% of the undertaking's annual turnover for the preceding financial year, WHICHEVER IS LOWER (not a flat KES 5M ceiling for larger organizations) — plus a continuing daily fine of up to KES 10,000 per unrectified breach until compliance. Separately, willful/criminal offenses under the Act (e.g. unlawful disclosure) can carry imprisonment up to 10 years and/or a fine, a distinct criminal track from the administrative penalty-notice regime. ODPC enforces both tracks.

What Your Business Must Do

3 compliance requirements identified. Critical requirements carry the highest risk of enforcement action.

Automated Decision Rights (Section 33)

Critical

Kenya DPA Section 33: data subjects have the right to object to automated processing — including AI profiling — that produces decisions with legal or significant effects. Provide: (1) Disclosure in privacy notice when AI drives significant decisions. (2) A process to submit objections and request human review. (3) Response and human review within a reasonable timeframe. Document your automated decision systems and objection handling procedures.

Deadline: November 8, 2019

Kenya DPA 2019, s. 33

Privacy Impact Assessment for AI

High Priority

Kenya DPA requires Privacy Impact Assessments for high-risk processing including automated decision-making, large-scale profiling, and processing of sensitive data categories. Before deploying AI systems that process Kenyan residents' personal data, conduct and document a PIA. Submit to the ODPC if required (ODPC may request PIAs for high-risk deployments).

Deadline: November 8, 2019

Kenya DPA 2019 + Data Protection (General) Regulations 2021

Data Controller/Processor Registration with ODPC

Medium Priority

Organizations processing personal data of Kenyan residents must register as data controllers and/or data processors with the ODPC (odpc.go.ke). This includes foreign organizations. Registration must be renewed. Failure to register is a separate offense from data protection violations.

Deadline: November 8, 2019

Kenya DPA 2019

Who Does This Apply To?

Applies to: any data controller or data processor that processes the personal data of data subjects resident in Kenya, or where the processing takes place in Kenya — including foreign organisations targeting the Kenyan market (the Act has extraterritorial reach). Organisations must register as data controllers and/or processors with the Office of the Data Protection Commissioner (ODPC); registration is a distinct obligation from the processing rules, and certain thresholds (annual turnover/number of data subjects) determine who must register. AI-relevant triggers: Section 33 gives data subjects the right to object to automated processing — including AI profiling — that produces decisions with legal or significant effects, with a right to request human review; and Privacy Impact Assessments are required before high-risk processing such as automated decision-making, large-scale profiling, or processing of sensitive data. Biometric data used in AI systems is sensitive and requires explicit consent. Enforced by the ODPC.

Recent Enforcement Actions

Office of the Data Protection Commissioner (ODPC)2025-12Source verified· as of 2026-08-22

Against: Platinum Credit Limited

Recent Regulatory Guidance

guidance2024

Kenya Data Protection Act 2019 + ODPC AI-awareness guidance; draft rules issued for consultation (Dec 2024)

Obligations for AI processing of Kenyan residents' personal data derive from the Data Protection Act 2019, not from a standalone AI guidelines instrument: automated decisions with legal effects engage the DPA's right to object and to request human review; Data Protection Impact Assessments are required before deploying AI for profiling or automated decision-making; biometric data used in AI requires explicit consent; controllers/processors must register with the ODPC. The ODPC has published AI-data-protection awareness guidance and, in December 2024, issued draft rules for public consultation.

guidance2026-07

ODPC — Draft Guidance Note on Artificial Intelligence (July 2026) — DRAFT, comment period closed 2026-08-17

The ODPC circulated a draft Guidance Note on AI (July 2026, 36 pages) mapping the Data Protection Act onto seven AI-system lifecycle stages (problem definition through model-weight deletion), including a 72-hour breach-notification clock and an explicit statement that public availability of data does NOT by itself make it lawful AI-training material — directly relevant to any organization training or fine-tuning models on scraped Kenyan-resident data. The public-comment deadline was 2026-08-17; as of this cycle (2026-08-22) it remains a DRAFT, not yet formally adopted/finalized. Do not treat as binding until finalized.

guidance2026-07

Kenya Artificial Intelligence and Other Emerging Technologies Policy (Draft, July 2026) — State Dept for ICT, NOT YET ADOPTED

A separate draft national AI policy (distinct from the ODPC's guidance note above) published by the State Department for ICT and the Digital Economy for public consultation in July 2026, following Kenya's National AI Strategy 2025-2030. Policy-level, not a data-protection-specific instrument; not yet adopted as of this cycle.

guidance2026

Pending legislation — Artificial Intelligence Bill 2026 (Senate) + Data Protection (Amendment) Bill 2025

The Artificial Intelligence Bill 2026, a Senate Bill establishing a risk-based AI regulatory regime modeled in part on the EU AI Act (would create an AI Commissioner office with penalties reportedly up to KES 5,000,000 for offenders), was pending legislative consideration as of this cycle — NOT enacted. Separately, the Data Protection (Amendment) Bill 2025 proposes new statutory obligations specifically around AI, cross-border data-sharing, and enhanced penalties under the existing DPA 2019 framework — also NOT enacted. Monitor both; neither is a current obligation.

Frequently Asked Questions

Does Kenya Data Protection Act 2019 apply to my business?

Kenya's Data Protection Act No. 24 of 2019 entered into force November 8, 2019, with the Data Protection (General) Regulations and other subsidiary legislation issued in 2021. The Office of the Data Protection Commissioner (ODPC) enforces the Act.… Use Aegis Firma's free scanner to get a personalized assessment in under 5 minutes.

What is the penalty for non-compliance?

The maximum penalty under Kenya Data Protection Act 2019 is: CYCLE 20 CORRECTION (2026-08-22): the prior flat "KES 5,000,000 or up to 10 years imprisonment" framing omitted the actual administrative-penalty-notice mechanism ODPC uses in every real enforcement case in this entry's own enforcementActions (Platinum Credit, Oppo Kenya). Verified via the Act's own text (kenyalaw.org) and the Data Protection (Complaints Handling and Enforcement) Regulations: under ss. 62-63, the Data Commissioner may issue a penalty notice of up to KES 5,000,000 OR 1% of the undertaking's annual turnover for the preceding financial year, WHICHEVER IS LOWER (not a flat KES 5M ceiling for larger organizations) — plus a continuing daily fine of up to KES 10,000 per unrectified breach until compliance. Separately, willful/criminal offenses under the Act (e.g. unlawful disclosure) can carry imprisonment up to 10 years and/or a fine, a distinct criminal track from the administrative penalty-notice regime. ODPC enforces both tracks.. Fines are typically scaled by company size, severity of violation, and whether violations were willful or accidental.

How do I comply with Kenya Data Protection Act 2019?

The 3 requirements above cover the core obligations. The fastest path to compliance is: (1) conduct an AI risk assessment, (2) document your AI systems, (3) implement transparency disclosures where required. Aegis Firma generates all required documents automatically.

Official Source

https://www.odpc.go.ke/data-protection-act/

Last updated: 2026-08-22 — verify at source before relying on this information.

Don't leave compliance to chance

Aegis Firma scans your AI tools, tells you exactly which regulations apply, and generates all required documents — in 30 minutes.

Start your free compliance scan