MP Muchangi Patrick& Associates Advocates
Talk to an Expert
Practice Areas Case Digest Knowledge Centre Insights About Contact Talk to an Expert
Home / Practice Areas / Data Protection & Privacy
Flagship Practice Area · Kenya Data Protection Act, 2019

Data Protection & Privacy.

The Data Protection Act, 2019 touches almost everything a modern business or individual does — from a shop collecting a phone number to an AI model trained on customer records. This page is the most complete resource we publish on it: every data-subject right explained, every issue we advise on, real Kenyan case law, and a way to ask a specific question and get a real answer. Read it, then talk to counsel.

33Kenyan Case Notes
11Parts of the Act, Mapped
14Legal Issues We Advise On
72hrsStatutory Breach Window
The Full Menu

Every issue that falls under data protection & privacy.

Whether you are a data subject asking what your rights are, or an organisation that has to comply with them, these are the issues we advise on most.

01

Data-subject rights & complaints

Access, correction, deletion and objection requests — helping data subjects exercise their rights, and helping organisations respond to them lawfully.

02

ODPC registration

Assessing whether you must register as a data controller or processor, and preparing and filing the application.

03

Privacy notices & policies

Drafting the notices, policies and terms the Act requires you to give data subjects before you collect their data.

04

Consent & lawful basis

Working out which of the Act's eight lawful bases actually applies to your processing — consent is only one of them, and often not the right one.

05

Data Protection Impact Assessments

Running the Section 31 assessment before high-risk processing begins, and preparing the ODPC consultation where the risk is genuinely high.

06

Breach response & notification

Containment, the 72-hour ODPC notification, and the data-subject communication the Act requires — advised on in the first hours, not after.

07

Cross-border data transfers

Structuring transfers of personal data outside Kenya so they meet the safeguards and necessity grounds in Sections 48–50.

08

Children's & sensitive personal data

Age-verification and parental consent mechanisms, and the narrower grounds that apply to health, biometric and other sensitive data.

09

Automated decisions & AI

Advising on profiling and automated decision-making under Section 35, and the wider legal exposure of training or deploying AI on personal data.

10

Vendor & data-processing agreements

The contracts between controllers and processors the Act requires, and the due diligence that should sit behind them.

11

Employee & workplace data

Monitoring, HR systems and staff records — where employer interests and employee data rights meet.

12

Retention & deletion policies

Setting retention schedules that satisfy Section 39, and defensible deletion or anonymisation once the purpose has ended.

13

Marketing & direct communication

Consent and opt-out mechanisms for direct marketing under Section 37, including commercial use of customer data.

14

Representation before the ODPC & courts

Complaints, investigations, determinations, appeals to the High Court, and compensation claims under Section 65.

Data Protection Act, 2019 · Parts IV–VI, Paraphrased

Your rights, in plain language.

This is not the statute reproduced — it is what the statute actually means for you, section by section. For the legal text itself, see Kenya Law's consolidated Data Protection Act, Cap. 411C ↗.

Section 26 · Right to be informed

You must be told your data is being collected.

Before an organisation collects your data, it must — so far as practicable — tell you why it's being collected, who else might receive it, how it's kept secure, and what happens if you don't provide it. This is set out fully in Section 29.

Section 26 · Right to access

You can see what an organisation holds on you.

Any data controller or processor can be asked what personal data they hold about you, and you are entitled to see it — subject to limited exemptions in Part VII of the Act.

Section 26 & 36 · Right to object

You can object to your data being processed.

An organisation can only continue if it can show a compelling legitimate interest that overrides your interests, or that the processing is needed to establish or defend a legal claim.

Section 26 & 40 · Right to correction & erasure

Wrong data must be fixed. Unlawful data must go.

You can have inaccurate, outdated or misleading data corrected without undue delay, and have data erased that the controller is no longer authorised to keep, or that was obtained unlawfully.

Section 35 · Automated decisions

A machine can't make the final call on you alone.

You have the right not to be subject to a decision based solely on automated processing — including AI profiling — that produces legal effects or significantly affects you, unless it's necessary for a contract, authorised by law, or based on your consent. Where it does apply, you can ask for the decision to be reconsidered by a person.

Section 38 · Data portability

You can take your data with you.

You can ask for your personal data in a structured, machine-readable format, and — where technically possible — have it sent directly to another provider. Organisations have thirty days to comply.

Section 32 · Consent

The burden of proving consent is on them, not you.

Where consent is the lawful basis relied on, the organisation must be able to prove you gave it freely, specifically and with full information — and you can withdraw it at any time, without affecting what was already done lawfully before you withdrew it.

Section 43 · Breach notification

72 hours. That's the clock.

If a breach creates a real risk of harm to you, the controller must notify the ODPC within 72 hours of becoming aware of it, and tell you directly in writing within a reasonable period, unless you genuinely cannot be identified.

Section 31 · Impact assessments

High-risk processing needs a risk assessment first.

Before starting processing likely to create a high risk to your rights, an organisation must carry out a Data Protection Impact Assessment — and consult the ODPC beforehand if that assessment shows the risk is genuinely high.

Section 33 · Children's data

A child's data needs a parent's consent.

Personal data relating to a child can only be processed with consent from a parent or guardian, and organisations must build age-verification into how they collect it — proportionate to the risk involved.

Part V · Sensitive personal data

Some data gets extra protection.

Race, health, ethnicity, religion, genetic and biometric data, property details, family and marital details, and sexual orientation are all "sensitive personal data" — processed only on narrower grounds, and health data specifically only by, or under the responsibility of, a healthcare provider.

Part VI · Cross-border transfers

Your data can't just leave the country.

A transfer of your personal data outside Kenya needs proven safeguards in the receiving jurisdiction, or must fit a specific necessity ground — and if it's sensitive personal data, your explicit consent is required too.

This page paraphrases Parts IV, V and VI of the Data Protection Act, 2019 (Cap. 411C) for general understanding — it is not legal advice, and doesn't cover every exemption or circumstance in the Act. If a specific right has been denied to you, or you are unsure how it applies to your situation, speak to counsel — the right answer often depends on facts a summary can't capture.
Ask Wakili

Have a specific question? Ask it.

"Wakili" is Swahili for lawyer. This isn't a generic chatbot — every answer below is pre-written and checked against the Data Protection Act and our own case work, so you get an accurate answer instead of a guess.

Ask Wakili

Instant, vetted answers on Kenyan data protection law

Try a question above, or type your own — for example, "can my employer read my WhatsApp messages?"

Ask Wakili gives general information on Kenyan data protection law, not legal advice on your specific situation.

Still not sure? Talk to counsel
How We Help

From first question to resolution.

Whether you're a data subject or an organisation, the process starts the same way — understanding exactly what happened.

01

Understand

We establish the facts: what data, what happened, and which provisions of the Act are actually engaged.

02

Assess

We test the legal position against the Act, the Regulations, and how the ODPC and courts have actually applied them.

03

Advise

You get a plain answer on your options, the realistic risk, and what we'd recommend doing next.

04

Act

Where instructed, we draft, file, negotiate or represent you — through the ODPC, or before the courts.

Case Law

What Kenyan courts have actually decided.

These are real cases from our Case Digest — the holding, not just the headline.

How to read these. Each case note separates the material facts from the outcome and why it matters, and is checked against the published judgment. This is commentary for understanding, not a substitute for the judgment itself.
[2026] KEHC 5928

Kipchirchir v Hornbill Rongai Limited

What happened

An advocate's photograph was used to advertise a business without her consent.

Outcome

The court awarded KES 1.5 million in damages.

Why it matters: Using someone's image for commercial purposes without consent is unlawful processing of personal data — and the damages can be substantial.

Read the full case note →
[2026] KEHC 8819

Mwaniki v Safaricom PLC

What happened

A dispute over the High Court's jurisdiction to hear a data protection claim before the ODPC's own complaint process had run its course.

Outcome

The suit was struck out for non-exhaustion of the statutory complaint mechanism.

Why it matters: The High Court's data protection jurisdiction is "staggered," not absent — go to the ODPC first, in most cases.

Read the full case note →
Case Digest

Savla v Maralal Energy Limited & 2 Others

What happened

A family business kept using a relative's KRA PIN without ongoing authorisation.

Outcome

Declarations were granted against the continued, unauthorised use.

Why it matters: A PIN, ID number or other identifier is personal data too — consent to use it isn't indefinite or automatic.

Read the full case note →
Case Digest

Republic v Office of Data Protection Commissioner; HS & 2 Others

What happened

The ODPC had gone silent on a complaint for 90 days with no determination.

Outcome

The court issued an order of mandamus compelling the ODPC to act.

Why it matters: The regulator's own statutory deadlines are enforceable — silence is not a lawful response to a complaint.

Read the full case note →

33 cases. One searchable library.

Filter by category, search by name or citation, and export a proper citation for any case you need to reference.

Open the Case Digest
Frequently Asked

Questions we hear most.

What are my rights as a data subject in Kenya?

Under Section 26, you have the right to be informed, to access your data, to object to processing, to correction, and to deletion of false or misleading data — plus further rights covered in the section above.

How long does an organisation have to report a data breach?

Where the breach creates real risk of harm, 72 hours to notify the ODPC (Section 43), and a reasonable period after that to notify you directly, unless you can't be identified.

Do I need to consent before a company can process my personal data?

Not always — consent is one of eight lawful bases under Section 30. Others include performing a contract with you or the organisation's legitimate interests.

Can my personal data be transferred outside Kenya?

Only with proven safeguards or under specific necessity grounds (Sections 48–50) — and sensitive personal data additionally needs your consent.

What should I bring to a first consultation?

Whatever you have — correspondence, notices, screenshots, the ODPC complaint if one exists. We'll tell you what's still needed.

Now you know the law. Let's talk about your situation.

Every situation turns on facts a summary can't capture. A short conversation with counsel is the fastest way to find out where you actually stand.

Enquire Now