Section 26 · Right to be informedYou must be told your data is being collected.
Before an organisation collects your data, it must — so far as practicable — tell you why it's being collected, who else might receive it, how it's kept secure, and what happens if you don't provide it. This is set out fully in Section 29.
Section 26 · Right to accessYou can see what an organisation holds on you.
Any data controller or processor can be asked what personal data they hold about you, and you are entitled to see it — subject to limited exemptions in Part VII of the Act.
Section 26 & 36 · Right to objectYou can object to your data being processed.
An organisation can only continue if it can show a compelling legitimate interest that overrides your interests, or that the processing is needed to establish or defend a legal claim.
Section 26 & 40 · Right to correction & erasureWrong data must be fixed. Unlawful data must go.
You can have inaccurate, outdated or misleading data corrected without undue delay, and have data erased that the controller is no longer authorised to keep, or that was obtained unlawfully.
Section 35 · Automated decisionsA machine can't make the final call on you alone.
You have the right not to be subject to a decision based solely on automated processing — including AI profiling — that produces legal effects or significantly affects you, unless it's necessary for a contract, authorised by law, or based on your consent. Where it does apply, you can ask for the decision to be reconsidered by a person.
Section 38 · Data portabilityYou can take your data with you.
You can ask for your personal data in a structured, machine-readable format, and — where technically possible — have it sent directly to another provider. Organisations have thirty days to comply.
Section 32 · ConsentThe burden of proving consent is on them, not you.
Where consent is the lawful basis relied on, the organisation must be able to prove you gave it freely, specifically and with full information — and you can withdraw it at any time, without affecting what was already done lawfully before you withdrew it.
Section 43 · Breach notification72 hours. That's the clock.
If a breach creates a real risk of harm to you, the controller must notify the ODPC within 72 hours of becoming aware of it, and tell you directly in writing within a reasonable period, unless you genuinely cannot be identified.
Section 31 · Impact assessmentsHigh-risk processing needs a risk assessment first.
Before starting processing likely to create a high risk to your rights, an organisation must carry out a Data Protection Impact Assessment — and consult the ODPC beforehand if that assessment shows the risk is genuinely high.
Section 33 · Children's dataA child's data needs a parent's consent.
Personal data relating to a child can only be processed with consent from a parent or guardian, and organisations must build age-verification into how they collect it — proportionate to the risk involved.
Part V · Sensitive personal dataSome data gets extra protection.
Race, health, ethnicity, religion, genetic and biometric data, property details, family and marital details, and sexual orientation are all "sensitive personal data" — processed only on narrower grounds, and health data specifically only by, or under the responsibility of, a healthcare provider.
Part VI · Cross-border transfersYour data can't just leave the country.
A transfer of your personal data outside Kenya needs proven safeguards in the receiving jurisdiction, or must fit a specific necessity ground — and if it's sensitive personal data, your explicit consent is required too.
This page paraphrases Parts IV, V and VI of the Data Protection Act, 2019 (Cap. 411C) for general understanding — it is not legal advice, and doesn't cover every exemption or circumstance in the Act. If a specific right has been denied to you, or you are unsure how it applies to your situation,
speak to counsel — the right answer often depends on facts a summary can't capture.