Data Protection Act
This Act may be cited as the Data Protection Act.
- Jurisdiction
- Kenya
- Instrument
- Act or statute
- Citation
- Cap. 411C
- Version
- 31 Dec 2022
- Language
- en
- Official source
- View official record ↗
Source attribution: Source: Kenya Law
Statute overview
About this statute
This Act may be cited as the Data Protection Act. States that a 'Section' is processed by equipment operating automatically in response to instructions given for that purpose. The provision states the object and purpose of the Act is to regulate the processing of personal data. Personal data may be entered in a record by or for a data controller or processor using automated or non-automated means; if processed non-automatedly the recorded personal data forms a whole or part of a filing system. The Data Commissioner may delegate any power under this Act or other written law to a regulator established by an Act of Parliament, subject to conditions the Commissioner may impose.
Search within this statute
Search all stored provisions in this version.
Legal text
Provisions of Data Protection Act
Showing 74 of 74
Part I
PRELIMINARY
- 1 Verify source ↗
PRELIMINARY - 1. Short title
This Act may be cited as the Data Protection Act.
Section 1. Short title Section This Act may be cited as the Data Protection Act. - 2 Verify source ↗
PRELIMINARY - 2. Interpretation
States that a 'Section' is processed by equipment operating automatically in response to instructions given for that purpose.
Section 2. Interpretation Section is processed by means of equipment operating automatically in response to instructions given for that purpose; - 3 Verify source ↗
PRELIMINARY - 3. Object and purpose of this Act
The provision states the object and purpose of the Act is to regulate the processing of personal data.
Section 3. Object and purpose of this Act Section to regulate the processing of personal data; - 4 Verify source ↗
PRELIMINARY - 4. Application
Personal data may be entered in a record by or for a data controller or processor using automated or non-automated means; if processed non-automatedly the recorded personal data forms a whole or part of a filing system.
Section 4. Application Section entered in a record, by or for a data controller or processor, by making use of automated or non-automated means: Provided that when the recorded personal data is processed by non-automated means, it forms a whole or part of a filing system;
Part II
ESTABLISHMENT OF THE OFFICE OF DATA PROTECTION COMMISSIONER
- 10 Verify source ↗
ESTABLISHMENT OF THE OFFICE OF DATA PROTECTION COMMISSIONER - 10. Delegation by the Data Commissioner
The Data Commissioner may delegate any power under this Act or other written law to a regulator established by an Act of Parliament, subject to conditions the Commissioner may impose.
Section 10. Delegation by the Data Commissioner Section The Data Commissioner may, subject to such conditions as the Data Commissioner may impose, delegate any power conferred under this Act or any other written law to a regulator established through an Act of Parliament. - 11 Verify source ↗
ESTABLISHMENT OF THE OFFICE OF DATA PROTECTION COMMISSIONER - 11. Vacancy in the Office of the Data Commissioner
Section 11 is titled "Vacancy in the Office of the Data Commissioner."
Section 11. Vacancy in the Office of the Data Commissioner Section dies; - 12 Verify source ↗
ESTABLISHMENT OF THE OFFICE OF DATA PROTECTION COMMISSIONER - 12. Removal of the Data Commissioner
A person seeking removal of the Data Commissioner may present a complaint to the Public Service Commission setting out the alleged facts for the ground.
Section 12. Removal of the Data Commissioner Section 12(1) A person desiring the removal of Data Commissioner on any ground specified under section 11 (d) may present a complaint to the Public Service Commission setting out the alleged facts constituting that ground. Section 12(2)(a) investigate the matter expeditiously; Section 12(2)(b) report on the facts; and Section 12(2)(c) make a recommendation to the Cabinet Secretary. Section 12(3)(a) informed, in writing, of the reasons for the intended removal; and Section 12(3)(b) offered an opportunity to put in a defence against any such allegations. - 13 Verify source ↗
ESTABLISHMENT OF THE OFFICE OF DATA PROTECTION COMMISSIONER - 13. Staff of the Office
The Data Commissioner must, in consultation with the Public Service Commission, appoint the number of staff necessary to discharge the Office's functions under this Act or any other relevant law.
Section 13. Staff of the Office Section The Data Commissioner shall in consultation with the Public Service Commission, appoint such number of staff as may be necessary for the proper and efficient discharge of the functions under this Act or any other relevant law. - 14 Verify source ↗
ESTABLISHMENT OF THE OFFICE OF DATA PROTECTION COMMISSIONER - 14. Remuneration of the Data Commissioner and staff
The Data Commissioner and the Office staff are to be paid remuneration or allowances; the Salaries and Remuneration Commission may advise on those amounts.
Section 14. Remuneration of the Data Commissioner and staff Section The Data Commissioner and staff of the Office shall be paid such remuneration or allowances as the Salaries and Remuneration Commission may advise. - 15 Verify source ↗
ESTABLISHMENT OF THE OFFICE OF DATA PROTECTION COMMISSIONER - 15. Oath of office
The Data Commissioner must take the oath set out in the First Schedule upon appointment.
Section 15. Oath of office Section The Data Commissioner shall take the oath set out in the First Schedule on appointment. - 16 Verify source ↗
ESTABLISHMENT OF THE OFFICE OF DATA PROTECTION COMMISSIONER - 16. Confidentiality agreement
The Data Commissioner and Office staff must not disclose information obtained for the purposes of this Act except with lawful authority.
Section 16. Confidentiality agreement Section The Data Commissioner, or any staff of the Office, shall not, unless with lawful authority, disclose any information obtained for the purposes of this Act. - 17 Verify source ↗
ESTABLISHMENT OF THE OFFICE OF DATA PROTECTION COMMISSIONER - 17. Protection from personal liability
The Data Commissioner and staff of the Office are protected from personal liability for performing their functions in good faith and in accordance with the Act.
Section 17. Protection from personal liability Section The Data Commissioner or any staff of the Office shall not be held liable for having performed any of their functions in good faith and in accordance with this Act. - 5 Verify source ↗
ESTABLISHMENT OF THE OFFICE OF DATA PROTECTION COMMISSIONER - 5. Establishment of the Office
Establishes the Office of the Data Protection Commissioner, its composition, powers to act legally and hold property, and duties including ensuring access and creating directorates.
Section 5. Establishment of the Office Section 5(1)(a) suing and being sued; Section 5(1)(b) taking, purchasing or otherwise acquiring, holding, charging or disposing of movable and immovable property; Section 5(1)(c) entering into contracts; and Section 5(1)(d) doing such other legal acts necessary for the proper performance of the functions of the Office. Section 5(2) The Office is designated as a State Office in accordance with Article 260(q) of the Constitution. Section 5(3) The Office shall comprise the Data Commissioner as its head and accounting officer, and other staff appointed by the Data Commissioner. Section 5(4) The Office shall ensure reasonable access to its services in all parts of the Republic. Section 5(5) The Data Commissioner shall in consultation with the Cabinet Secretary, establish such directorates as may be necessary for the better carrying of the functions of the Office. - 6 Verify source ↗
ESTABLISHMENT OF THE OFFICE OF DATA PROTECTION COMMISSIONER - 6. Appointment of the Data Commissioner
When there is a vacancy for the Data Commissioner, the Public Service Commission must start recruitment; it must invite applications and shortlist, interview and nominate three candidates for the President to forward for appointment, and the President, with approval of the National Assembly, appoints the Data Commissioner.
Section 6. Appointment of the Data Commissioner Section 6(1) The Public Service Commission shall, whenever a vacancy arises in the position of the Data Commissioner, initiate the recruitment process. Section 6(2) The Public Service Commission shall, within seven days of being notified of a vacancy under subsection (1), invite applications from persons who qualify for nomination and appointment for the position of the Data Commissioner. Section 6(3)(a) consider the applications received to determine their compliance with this Act; Section 6(3)(b) shortlist qualified applicants; Section 6(3)(c) publish and publicise the names of the applicants and the shortlisted applicants; Section 6(3)(d) conduct interviews of the shortlisted persons in an open and transparent process; Section 6(3)(e) nominate three qualified applicants in the order of merit for the position of Data Commissioner; and Section 6(3)(f) submit the names of the persons nominated under paragraph (e) to the President. Section 6(4) The President shall nominate and, with approval of the National Assembly, appoint the Data Commissioner. - 7 Verify source ↗
ESTABLISHMENT OF THE OFFICE OF DATA PROTECTION COMMISSIONER - 7. Qualifications of Data Commissioner
Sets qualifications for the Data Commissioner (education and experience) and provides appointment term of six years with no re-appointment.
Section 7. Qualifications of Data Commissioner Section 7(1)(a) data science; Section 7(1)(a)(i) data science; Section 7(1)(a)(ii) law; Section 7(1)(a)(iii) information technology; or Section 7(1)(a)(iv) any other related field; Section 7(1)(b) has knowledge and relevant experience of not less than ten years; Section 7(1)(c) meets the requirements of Chapter Six of the Constitution; and Section 7(1)(d) holds a Master's degree. Section 7(2) The Data Commissioner shall be appointed for a single term of six years and shall not be eligible for a re-appointment. - 8 Verify source ↗
ESTABLISHMENT OF THE OFFICE OF DATA PROTECTION COMMISSIONER - 8. Functions of the Office
Sets out the functions of the Office of the Data Commissioner, including oversight, registration, inspections, investigations, promotion of self-regulation, public awareness, research, international cooperation, and other prescribed functions; allows collaboration with national security organs and requires the Data Commissioner to act independently.
Section 8. Functions of the Office Section 8(1)(a) oversee the implementation of and be responsible for the enforcement of this Act; Section 8(1)(b) establish and maintain a register of data controllers and data processors; Section 8(1)(c) exercise oversight on data processing operations, either of own motion or at the request of a data subject, and verify whether the processing of data is done in accordance with this Act; Section 8(1)(d) promote self-regulation among data controllers and data processors; Section 8(1)(e) conduct an assessment, on its own initiative of a public or private body, or at the request of a private or public body for the purpose of ascertaining whether information is processed according to the provisions of this Act or any other relevant law; Section 8(1)(f) receive and investigate any complaint by any person on infringements of the rights under this Act; Section 8(1)(g) take such measures as may be necessary to bring the provisions of this Act to the knowledge of the general public; Section 8(1)(h) carry out inspections of public and private entities with a view to evaluating the processing of personal data; Section 8(1)(i) promote international cooperation in matters relating to data protection and ensure country's compliance on data protection obligations under international conventions and agreements; Section 8(1)(j) undertake research on developments in data processing of personal data and ensure that there is no significant risk or adverse effect of any developments on the privacy of individuals; and Section 8(1)(k) perform such other functions as may be prescribed by any other law or as necessary for the promotion of object of this Act. Section 8(2) The Office of the Data Commissioner may, in the performance of its functions collaborate with the national security organs. Section 8(3) The Data Commissioner shall act independently in exercise of powers and carrying out of functions under this Act. - 9 Verify source ↗
ESTABLISHMENT OF THE OFFICE OF DATA PROTECTION COMMISSIONER - 9. Powers of the Office
The Data Commissioner may enter into association with other bodies or organisations within and outside Kenya to further the object of the Act.
Section 9. Powers of the Office Section 9(1)(a) conduct investigations on own initiative, or on the basis of a complaint made by a data subject or a third party; Section 9(1)(b) obtain professional assistance, consultancy or advice from such persons or organisations whether within or outside public service as considered appropriate; Section 9(1)(c) facilitate conciliation, mediation and negotiation on disputes arising from this Act; Section 9(1)(d) issue summons to a witness for the purposes of investigation; Section 9(1)(e) require any person that is subject to this Act to provide explanations, information and assistance in person and in writing; Section 9(1)(f) impose administrative fines for failures to comply with this Act; Section 9(1)(g) undertake any activity necessary for the fulfilment of any of the functions of the Office; and Section 9(1)(h) exercise any powers prescribed by any other legislation. Section 9(2) The Data Commissioner may enter into association with other bodies or organisations within and outside Kenya as appropriate in furtherance of the object of this Act.
Part III
REGISTRATION OF DATA CONTROLLERS AND DATA PROCESSORS
- 18 Verify source ↗
REGISTRATION OF DATA CONTROLLERS AND DATA PROCESSORS - 18. Registration of data controllers and data processors
No person may act as a data controller or data processor unless registered with the Data Commissioner.
Section 18. Registration of data controllers and data processors Section 18(1) Subject to subsection (2), no person shall act as a data controller or data processor unless registered with the Data Commissioner. Section 18(2)(a) the nature of industry; Section 18(2)(b) the volumes of data processed; Section 18(2)(c) whether sensitive personal data is being processed; and Section 18(2)(d) any other criteria the Data Commissioner may specify. - 19 Verify source ↗
REGISTRATION OF DATA CONTROLLERS AND DATA PROCESSORS - 19. Application for registration
Data controllers or processors required to register must apply to the Data Commissioner, provide specified registration details, notify changes, and may face offences for false information or failure to comply; the Data Commissioner must issue certificates and amend the Register on notification.
Section 19. Application for registration Section 19(1) A data controller or data processor required to register under section 18 shall apply to the Data Commissioner. Section 19(2)(a) a description of the personal data to be processed by the data controller or data processor; Section 19(2)(b) a description of the purpose for which the personal data is to be processed; Section 19(2)(c) the category of data subjects, to which the personal data relates; Section 19(2)(d) contact details of the data controller or data processor; Section 19(2)(e) a general description of the risks, safeguards, security measures and mechanisms to ensure the protection of personal data; Section 19(2)(f) any measures to indemnify the data subject from unlawful use of data by the data processor or data controller; and Section 19(2)(g) any other details as may be prescribed by the Data Commissioner. Section 19(3) A data controller or data processor who knowingly supplies any false or misleading detail under subsection (1) commits an offence. Section 19(4) The Data Commissioner shall issue a certificate of registration where a data controller or data processor meets the requirements for registration. Section 19(5) A data controller or data processor shall notify the Data Commissioner of a change in any particular outlined under subsection (2). Section 19(6) On receipt of a notification under subsection (5), the Data Commissioner shall amend the respective entry in the Register. Section 19(7) A data controller or data processor who fails to comply with the provisions of this section commits an offence. - 20 Verify source ↗
REGISTRATION OF DATA CONTROLLERS AND DATA PROCESSORS - 20. Duration of the registration certificate
The holder of a registration certificate may apply to renew the certificate after it expires.
Section 20. Duration of the registration certificate Section A registration certificate issued under section 19 shall be valid for a period determined at the time of the application after taking into account the need for the certificate, and the holder may apply for a renewal of the certificate after expiry of the certificate. - 21 Verify source ↗
REGISTRATION OF DATA CONTROLLERS AND DATA PROCESSORS - 21. Register of data controllers and data processors
The Data Commissioner must keep a register of registered data controllers and data processors; the Commissioner may remove ceased entries on request; the register is a public document available for inspection by any person; a person may request a certified copy of any entry.
Section 21. Register of data controllers and data processors Section 21(1) The Data Commissioner shall keep and maintain a register of the registered data controllers and data processors. Section 21(2) The Data Commissioner may, at the request of a data controller or data processor, remove any entry in the register which has ceased to be applicable. Section 21(3) The register shall be a public document and available for inspection by any person. Section 21(4) A person may request the Data Commissioner for a certified copy of any entry in the register. - 22 Verify source ↗
REGISTRATION OF DATA CONTROLLERS AND DATA PROCESSORS - 22. Cancellation or variation of the certificate
Cancellation or variation of the certificate where any information given by the applicant is false or misleading.
Section 22. Cancellation or variation of the certificate Section any information given by the applicant is false or misleading; or - 23 Verify source ↗
REGISTRATION OF DATA CONTROLLERS AND DATA PROCESSORS - 23. Compliance and audit
The Data Commissioner may carry out periodical audits of the processes and systems of data controllers and data processors to ensure compliance with the Act.
Section 23. Compliance and audit Section The Data Commissioner may carry out periodical audits of the processes and systems of the data controllers or data processors to ensure compliance with this Act. - 24 Verify source ↗
REGISTRATION OF DATA CONTROLLERS AND DATA PROCESSORS - 24. Designation of the Data Protection Officer
Specifies when and how data protection officers may be designated and lists DPO duties; controllers/processors must publish DPO contact details and inform the Data Commissioner, who must make them available on the official website.
Section 24. Designation of the Data Protection Officer Section 24(1)(a) the processing is carried out by a public body or private body, except for courts acting in their judicial capacity; Section 24(1)(b) the core activities of the data controller or data processor consist of processing operations which, by virtue of their nature, their scope or their purposes, require regular and systematic monitoring of data subjects; or Section 24(1)(c) the core activities of the data controller or the data processor consist of processing of sensitive categories of personal data. Section 24(2) A data protection officer may be a staff member of the data controller or data processor and may fulfil other tasks and duties provided that any such tasks and duties do not result in a conflict of interest. Section 24(3) A group of entities may appoint a single data protection officer provided that such officer is accessible by each entity. Section 24(4) Where a data controller or a data processor is a public body, a single data protection officer may be designated for several such public bodies, taking into account their organisational structures. Section 24(5) A person may be designated or appointed as a data protection officer, if that person has relevant academic or professional qualifications which may include knowledge and technical skills in matters relating to data protection. Section 24(6) A data controller or data processor shall publish the contact details of the data protection officer on the website and communicate them to the Data Commissioner who shall ensure that the same information is available on the official website. Section 24(7)(a) advise the data controller or data processor and their employees on data processing requirements provided under this Act or any other written law; Section 24(7)(b) ensure on behalf of the data controller or data processor that this Act is complied with; Section 24(7)(c) facilitate capacity building of staff involved in data processing operations; Section 24(7)(d) provide advice on data protection impact assessment; and Section 24(7)(e) co-operate with the Data Commissioner and any other authority on matters relating to data protection.
Part IV
PRINCIPLES AND OBLIGATIONS OF PERSONAL DATA PROTECTION
- 25 Verify source ↗
PRINCIPLES AND OBLIGATIONS OF PERSONAL DATA PROTECTION - 25. Principles of data protection
Personal data must be processed in accordance with the right to privacy of the data subject.
Section 25. Principles of data protection Section processed in accordance with the right to privacy of the data subject; - 26 Verify source ↗
PRINCIPLES AND OBLIGATIONS OF PERSONAL DATA PROTECTION - 26. Rights of a data subject
Data subjects are entitled to be informed about the use to which their personal data will be put.
Section 26. Rights of a data subject Section to be informed of the use to which their personal data is to be put; - 27 Verify source ↗
PRINCIPLES AND OBLIGATIONS OF PERSONAL DATA PROTECTION - 27. Exercise of rights of data subjects
Where the data subject is a minor, the rights are to be exercised by a person who has parental authority or by a guardian.
Section 27. Exercise of rights of data subjects Section where the data subject is a minor, by a person who has parental authority or by a guardian; - 28 Verify source ↗
PRINCIPLES AND OBLIGATIONS OF PERSONAL DATA PROTECTION - 28. Collection of personal data
Data controllers or processors must collect personal data directly from the data subject, and may only collect, store or use personal data for lawful, specific and explicitly defined purposes.
Section 28. Collection of personal data Section 28(1) A data controller or data processor shall collect personal data directly from the data subject. Section 28(2)(a) the data is contained in a public record; Section 28(2)(b) the data subject has deliberately made the data public; Section 28(2)(c) the data subject has consented to the collection from another source; Section 28(2)(d) the data subject has an incapacity, the guardian appointed has consented to the collection from another source; Section 28(2)(e) the collection from another source would not prejudice the interests of the data subject; Section 28(2)(f) for the prevention, detection, investigation, prosecution and punishment of crime; Section 28(2)(f)(i) for the prevention, detection, investigation, prosecution and punishment of crime; Section 28(2)(f)(ii) for the enforcement of a law which imposes a pecuniary penalty; or Section 28(2)(f)(iii) for the protection of the interests of the data subject or another person. Section 28(3) A data controller or data processor shall collect, store or use personal data for a purpose which is lawful, specific and explicitly defined. - 29 Verify source ↗
PRINCIPLES AND OBLIGATIONS OF PERSONAL DATA PROTECTION - 29. Duty to notify
Duty to notify
Section 29. Duty to notify Section the rights of data subject specified under section 26 ; - 30 Verify source ↗
PRINCIPLES AND OBLIGATIONS OF PERSONAL DATA PROTECTION - 30. Lawful processing of personal data
Lists lawful bases for processing personal data and states that a data controller who contravenes subsection (1) commits an offence.
Section 30. Lawful processing of personal data Section 30(1)(a) the data subject consents to the processing for one or more specified purposes; or Section 30(1)(b) for the performance of a contract to which the data subject is a party or in order to take steps at the request of the data subject before entering into a contract; Section 30(1)(b)(i) for the performance of a contract to which the data subject is a party or in order to take steps at the request of the data subject before entering into a contract; Section 30(1)(b)(ii) for compliance with any legal obligation to which the controller is subject; Section 30(1)(b)(iii) in order to protect the vital interests of the data subject or another natural person; Section 30(1)(b)(iv) for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller; Section 30(1)(b)(v) the performance of any task carried out by a public authority; Section 30(1)(b)(vi) for the exercise, by any person in the public interest, of any other functions of a public nature; Section 30(1)(b)(vii) for the legitimate interests pursued by the data controller or data processor by a third party to whom the data is disclosed, except if the processing is unwarranted in any particular case having regard to the harm and prejudice to the rights and freedoms or legitimate interests of the data subject; or Section 30(1)(b)(viii) for the purpose of historical, statistical, journalistic, literature and art or scientific research. Section 30(2) Further processing of personal data shall be in accordance with the purpose of collection. Section 30(3) A data controller who contravenes the provisions of subsection (1) commits an offence. - 31 Verify source ↗
PRINCIPLES AND OBLIGATIONS OF PERSONAL DATA PROTECTION - 31. Data protection impact assessment
When processing is likely to create high risk to individuals, a data controller or processor must carry out a data protection impact assessment before processing; if that assessment shows high risk they must consult the Data Commissioner; assessment reports must be submitted sixty days before processing.
Section 31. Data protection impact assessment Section 31(1) Where a processing operation is likely to result in high risk to the rights and freedoms of a data subject, by virtue of its nature, scope, context and purposes, a data controller or data processor shall, prior to the processing, carry out a data protection impact assessment. Section 31(2)(a) a systematic description of the envisaged processing operations and the purposes of the processing, including, where applicable, the legitimate interest pursued by the data controller or data processor; Section 31(2)(b) an assessment of the necessity and proportionality of the processing operations in relation to the purposes; Section 31(2)(c) an assessment of the risks to the rights and freedoms of data subjects; Section 31(2)(d) the measures envisaged to address the risks and the safeguards, security measures and mechanisms to ensure the protection of personal data and to demonstrate compliance with this Act, taking into account the rights, and legitimate interests of data subjects and other persons concerned. Section 31(3) The data controller or data processor shall consult the Data Commissioner prior to the processing if a data protection impact assessment prepared under this section indicates that the processing of the data would result in a high risk to the rights and freedoms of a data subject. Section 31(4) For the purposes of this section, a "data protection impact assessment" means an assessment of the impact of the envisaged processing operations on the protection of personal data. Section 31(5) The data impact assessment reports shall be submitted sixty days prior to the processing of data. Section 31(6) The Data Commissioner shall set out guidelines for carrying out an impact assessment under this section. - 32 Verify source ↗
PRINCIPLES AND OBLIGATIONS OF PERSONAL DATA PROTECTION - 32. Conditions of consent
Data controllers or processors must prove a data subject's consent; data subjects may withdraw consent at any time.
Section 32. Conditions of consent Section 32(1) A data controller or data processor shall bear the burden of proof for establishing a data subject's consent to the processing of their personal data for a specified purpose. Section 32(2) Unless otherwise provided under this Act, a data subject shall have the right to withdraw consent at any time. Section 32(3) The withdrawal of consent under subsection (2) shall not affect the lawfulness of processing based on prior consent before its withdrawal. Section 32(4) In determining whether consent was freely given, account shall be taken of whether, among others, the performance of a contract, including the provision of a service, is conditional on consent to the processing of personal data that is not necessary for the performance of that contract. - 33 Verify source ↗
PRINCIPLES AND OBLIGATIONS OF PERSONAL DATA PROTECTION - 33. Processing of personal data relating to a child
Data controllers or processors must include age-verification and consent mechanisms to process personal data of a child; certain child-protection counselling providers may not need parental consent.
Section 33. Processing of personal data relating to a child Section 33(1)(a) consent is given by the child's parent or guardian; and Section 33(1)(b) the processing is in such a manner that protects and advances the rights and best interests of the child. Section 33(2) A data controller or data processor shall incorporate appropriate mechanisms for age verification and consent in order to process personal data of a child. Section 33(3)(a) available technology; Section 33(3)(b) volume of personal data processed; Section 33(3)(c) proportion of such personal data likely to be that of a child; Section 33(3)(d) possibility of harm to a child arising out of processing of personal data; and Section 33(3)(e) such other factors as may be specified by the Data Commissioner. Section 33(4) A data controller or data processor that exclusively provides counselling or child protection services to a child may not be required to obtain parental consent as set out under subsection (1). - 34 Verify source ↗
PRINCIPLES AND OBLIGATIONS OF PERSONAL DATA PROTECTION - 34. Restrictions on processing
Data controllers must inform the data subject before withdrawing a restriction on processing; data controllers or data processors must implement mechanisms to ensure time limits for rectification, erasure, restriction or periodic review of stored personal data are observed.
Section 34. Restrictions on processing Section 34(1)(a) accuracy of the personal data is contested by the data subject, for a period enabling the data controller to verify the accuracy of the data; Section 34(1)(b) personal data is no longer required for the purpose of the processing, unless the data controller or data processor requires the personal data for the establishment, exercise or defence of a legal claim; Section 34(1)(c) processing is unlawful and the data subject opposes the erasure of the personal data and requests the restriction of their use instead; or Section 34(1)(d) data subject has objected to the processing, pending verification as to whether the legitimate interests of the data controller or data processor overrides those of the data subject. Section 34(2)(a) the personal data shall, unless the data is being stored, only be processed with the data subject's consent or for the establishment, exercise or defence of a legal claim, the protection of the rights of another person or for reasons of public interest; and Section 34(2)(b) the data controller shall inform the data subject before withdrawing the restriction on processing of the personal data. Section 34(3) The data controller or data processor shall implement mechanisms to ensure that time limits established for the rectification, erasure or restriction of processing of personal data, or for a periodic review of the need for the storage of the personal data, is observed. - 35 Verify source ↗
PRINCIPLES AND OBLIGATIONS OF PERSONAL DATA PROTECTION - 35. Automated individual decision making
Every data subject has a right not to be subject to a decision based solely on automated processing, including profiling, except where allowed for contract necessity, law authorisation with safeguards, or consent; controllers/processors must notify and either reconsider or make a new non-automated decision; the Cabinet Secretary may make Regulations to provide safeguards.
Section 35. Automated individual decision making Section 35(1) Every data subject has a right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning or significantly affects the data subject. Section 35(2)(a) necessary for entering into, or performing, a contract between the data subject and a data controller; Section 35(2)(b) authorised by a law to which the data controller is subject and which lays down suitable measures to safeguard the data subject's rights, freedoms and legitimate interests; or Section 35(2)(c) based on the data subject's consent. Section 35(3)(a) the data controller or data processor must, as soon as reasonably practicable, notify the data subject in writing that a decision has been taken based solely on automated processing; and Section 35(3)(b) reconsider the decision; or Section 35(3)(b)(i) reconsider the decision; or Section 35(3)(b)(ii) take a new decision that is not based solely on automated processing. Section 35(4)(a) consider the request, including any information provided by the data subject that is relevant to it; Section 35(4)(b) comply with the request; and Section 35(4)(c) the steps taken to comply with the request; and Section 35(4)(c)(i) the steps taken to comply with the request; and Section 35(4)(c)(ii) the outcome of complying with the request. Section 35(5) The Cabinet Secretary may by Regulations make such further provision to provide suitable measures to safeguard a data subject's rights, freedoms and legitimate interests in connection with the taking of decisions based solely on automated processing. - 36 Verify source ↗
PRINCIPLES AND OBLIGATIONS OF PERSONAL DATA PROTECTION - 36. Objecting to processing
A data subject has a right to object to the processing of their personal data unless the controller or processor shows a compelling legitimate interest that overrides the data subject's interests, or when needed to establish, exercise or defend a legal claim.
Section 36. Objecting to processing Section A data subject has a right to object to the processing of their personal data, unless the data controller or data processor demonstrates compelling legitimate interest for the processing which overrides the data subject's interests, or for the establishment, exercise or defence of a legal claim. - 37 Verify source ↗
PRINCIPLES AND OBLIGATIONS OF PERSONAL DATA PROTECTION - 37. Commercial use of data
Data controllers or processors using personal data commercially must, where possible, anonymise the data so the data subject is no longer identifiable; the Cabinet Secretary may, with the Data Commissioner, prescribe practice guidelines.
Section 37. Commercial use of data Section 37(1)(a) has sought and obtained express consent from a data subject; or Section 37(1)(b) is authorised to do so under any written law and the data subject has been informed of such use when collecting the data from the data subject. Section 37(2) A data controller or data processor that uses personal data for commercial purposes shall, where possible, anonymise the data in such a manner as to ensure that the data subject is no longer identifiable. Section 37(3) The Cabinet Secretary, in consultation with the Data Commissioner, may prescribe practice guidelines for commercial use of personal data in accordance with this Act. - 38 Verify source ↗
PRINCIPLES AND OBLIGATIONS OF PERSONAL DATA PROTECTION - 38. Right to data portability
Gives data subjects rights to receive, transmit, and (where technically possible) have personal data transmitted directly between controllers/processors; controllers/processors must comply with portability requests at reasonable cost within thirty days; the Data Commissioner may determine technical capacity when direct transfer is declined; processing necessary for public interest or that adversely affects others may limit portability.
Section 38. Right to data portability Section 38(1) A data subject has the right to receive personal data concerning them in a structured, commonly used and machine-readable format. Section 38(2) A data subject has the right to transmit the data obtained under subsection (1), to another data controller or data processor without any hindrance. Section 38(3) Where technically possible, the data subject shall have the right to have the personal data transmitted directly from one data controller or processor to another. Section 38(4) Where data controller or data processor declines to comply with a request under subsection (3), the Data Commissioner may make a determination on the technical capacity of the data controller or data processor. Section 38(5)(a) processing may be necessary for the performance of a task carried out in the public interest or in the exercise of an official authority; or Section 38(5)(b) it may adversely affect the rights and freedoms of others. Section 38(6) A data controller or data processor shall comply with data portability requests, at reasonable cost and within a period of thirty days. Section 38(7) Where the portability request is complex or numerous, the period under subsection (6) may be extended for a further period as may be determined in consultation with the Data Commissioner. - 39 Verify source ↗
PRINCIPLES AND OBLIGATIONS OF PERSONAL DATA PROTECTION - 39. Limitation to retention of personal data
Data controllers and processors must delete, erase, anonymise or pseudonymise personal data that is not necessary to retain under subsection (1), in a manner that may be specified, at the expiry of the retention period.
Section 39. Limitation to retention of personal data Section 39(1)(a) required or authorised by law; Section 39(1)(b) reasonably necessary for a lawful purpose; Section 39(1)(c) authorised or consented by the data subject; or Section 39(1)(d) for historical, statistical, journalistic literature and art or research purposes. Section 39(2) A data controller or data processor shall delete, erase, anonymise or pseudonymise personal data not necessary to be retained under subsection (1) in a manner as may be specified at the expiry of the retention period. - 40 Verify source ↗
PRINCIPLES AND OBLIGATIONS OF PERSONAL DATA PROTECTION - 40. Right of rectification and erasure
Data controllers and data processors must promptly rectify inaccurate, out-dated, incomplete or misleading personal data and must erase or destroy personal data they are not authorised to retain; if the data is required for evidence they must restrict processing and inform the data subject within a reasonable time.
Section 40. Right of rectification and erasure Section 40(1)(a) to rectify without undue delay personal data in its possession or under its control that is inaccurate, out-dated, incomplete or misleading; or Section 40(1)(b) to erase or destroy without undue delay personal data that the data controller or data processor is no longer authorised to retain, irrelevant, excessive or obtained unlawfully. Section 40(2)(a) the rectification of such personal data in their possession or under their control that is inaccurate, out-dated, incomplete or misleading; or Section 40(2)(b) the erasure or destruction of such personal data that the data controller is no longer authorised to retain, irrelevant, excessive or obtained unlawfully. Section 40(3) Where a data controller or data processor is required to rectify or erase personal data under subsection (1), but the personal data is required for the purposes of evidence, the data controller or data processor shall, instead of erasing or rectifying, restrict its processing and inform the data subject within a reasonable time. - 41 Verify source ↗
PRINCIPLES AND OBLIGATIONS OF PERSONAL DATA PROTECTION - 41. Data protection by design or by default
Requires implementing data protection principles and integrating necessary safeguards into processing, and lists factors and safeguards to consider (e.g. amount of data, extent of processing, storage period, accessibility, costs, pseudonymisation, encryption, and restoration ability).
Section 41. Data protection by design or by default Section 41(1)(a) to implement the data protection principles in an effective manner; and Section 41(1)(b) to integrate necessary safeguards for that purpose into the processing. Section 41(2) The duty under subsection (1) applies both at the time of the determination of the means of processing the data and at the time of the processing. Section 41(3)(a) the amount of personal data collected; Section 41(3)(b) the extent of its processing; Section 41(3)(c) the period of its storage; Section 41(3)(d) its accessibility; and Section 41(3)(e) the cost of processing data and the technologies and tools used. Section 41(4)(a) to identify reasonably foreseeable internal and external risks to personal data under the person's possession or control; Section 41(4)(b) to establish and maintain appropriate safeguards against the identified risks; Section 41(4)(c) to the pseudonymisation and encryption of personal data; Section 41(4)(d) to the ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident; Section 41(4)(e) to verify that the safeguards are effectively implemented; and Section 41(4)(f) to ensure that the safeguards are continually updated in response to new risks or deficiencies. - 42 Verify source ↗
PRINCIPLES AND OBLIGATIONS OF PERSONAL DATA PROTECTION - 42. Particulars of determining organisational measures
Section 42 requires controllers to choose processors with sufficient organisational-security guarantees, requires controllers and processors to have a written contract specifying that processors act only on controller instructions and are bound by the controller's obligations, and requires controllers or processors to take reasonable steps to ensure staff and agents comply with security measures.
Section 42. Particulars of determining organisational measures Section 42(1)(a) the state of technological development available; Section 42(1)(b) the cost of implementing any of the security measures; Section 42(1)(c) the special risks that exist in the processing of the data; and Section 42(1)(d) the nature of the data being processed. Section 42(2)(a) the data controller shall opt for a data processor who provides sufficient guarantees in respect of organisational measures for the purpose of complying with section 41 (1); and Section 42(2)(b) the data controller and the data processor shall enter into a written contract which shall provide that the data processor shall act only on instructions received from the data controller and shall be bound by obligations of the data controller. Section 42(3) Where a data processor processes personal data other than as instructed by the data controller, the data processor shall be deemed to be a data controller in respect of that processing. Section 42(4) A data controller or data processor shall take all reasonable steps to ensure that any person employed by or acting under the authority of the data controller or data processor, complies with the relevant security measures. - 43 Verify source ↗
PRINCIPLES AND OBLIGATIONS OF PERSONAL DATA PROTECTION - 43. Notification and communication of breach
Requires prompt notification of personal data breaches to the Data Commissioner (within 72 hours) and, subject to conditions, written communication to affected data subjects; sets processor-to-controller timing (48 hours), required content elements, allowed phased disclosure, a limited exemption when adequate safeguards like encryption exist, and permitted delay for criminal investigation purposes.
Section 43. Notification and communication of breach Section 43(1)(a) notify the Data Commissioner without delay, within seventy-two hours of becoming aware of such breach; and Section 43(1)(b) subject to subsection (3), communicate to the data subject in writing within a reasonably practical period, unless the identity of the data subject cannot be established. Section 43(2) Where the notification to the Data Commissioner is not made within seventy-two hours, the notification shall be accompanied by reasons for the delay. Section 43(3) Where a data processor becomes aware of a personal data breach, the data processor shall notify the data controller without delay and where reasonably practicable, within forty-eight hours of becoming aware of such breach. Section 43(4) The data controller may delay or restrict communication referred to under subsection (1)(b) as necessary and proportionate for purposes of prevention, detection or investigation of an offence by the concerned relevant body. Section 43(5)(a) description of the nature of the data breach; Section 43(5)(b) description of the measures that the data controller or data processor intends to take or has taken to address the data breach; Section 43(5)(c) recommendation on the measures to be taken by the data subject to mitigate the adverse effects of the security compromise; Section 43(5)(d) where applicable, the identity of the unauthorised person who may have accessed or acquired the personal data; and Section 43(5)(e) the name and contact details of the data protection officer where applicable or other contact point from whom more information could be obtained. Section 43(6) The communication of a breach to the data subject shall not be required where the data controller or data processor has implemented appropriate security safeguards which may include encryption of affected personal data. Section 43(7) Where and to the extent that it is not possible to provide all the information mentioned in subsection (5) at the same time, the information may be provided in phases without undue delay. Section 43(8)(a) the facts relating to the breach; Section 43(8)(b) its effects; and Section 43(8)(c) the remedial action taken.
Part IX
FINANCIAL PROVISIONS
- 67 Verify source ↗
FINANCIAL PROVISIONS - 67. Funds of the Office
Monies are allocated by the National Assembly for purposes of the Office.
Section 67. Funds of the Office Section monies allocated by the National Assembly for purposes of the Office; - 68 Verify source ↗
FINANCIAL PROVISIONS - 68. Annual estimates
The Data Commissioner must prepare annual estimates of the Office's revenue and expenditure at least three months before each financial year starts.
Section 68. Annual estimates Section 68(1) At least three months before the commencement of each financial year, the Data Commissioner shall cause to be prepared estimates of the revenue and expenditure of the Office for that year. Section 68(2)(a) the payment of salaries, allowances and other charges in respect of the staff of the Office; Section 68(2)(b) the payment of pensions, gratuities and other charges in respect of retirement benefits which are payable out of the finances of the Office; Section 68(2)(c) the acquisition, maintenance, repair and replacement of the equipment and other movable property of the Office; Section 68(2)(d) funding of training, research and development of activities of the Office; Section 68(2)(e) the creation of such reserve funds to meet future or contingent liabilities or in respect of such other matters as the Data Commissioner may deem fit; and Section 68(2)(f) any other expenditure for the purposes of this Act. Section 68(3) The annual estimates shall be submitted to the Cabinet Secretary for tabling in the National Assembly. - 69 Verify source ↗
FINANCIAL PROVISIONS - 69. Accounts and Audit
The Office must have its annual accounts prepared, audited and reported in accordance with Articles 226 and 229 of the Constitution, the Public Finance Management Act (Cap. 412A), or any other law relating to audit of public entities.
Section 69. Accounts and Audit Section The annual accounts of the Office shall be prepared, audited and reported in accordance with the provisions of Articles 226 and 229 of the Constitution, the Public Finance Management Act (Cap. 412A), or any other law relating to audit of public entities. - 70 Verify source ↗
FINANCIAL PROVISIONS - 70. Annual reports
The Data Commissioner must prepare and submit an annual report to the Cabinet Secretary within three months after the end of each financial year; the Cabinet Secretary must submit that report to the National Assembly within three months of receipt.
Section 70. Annual reports Section 70(1) The Data Commissioner shall, within three months after the end of each financial year, prepare and submit to the Cabinet Secretary a report of the operations of the Office for the immediately preceding year. Section 70(2) The Cabinet Secretary shall submit the annual report before the National Assembly within three months of receipt of the report under subsection (1). Section 70(3)(a) the financial statements and description of activities of the Office; Section 70(3)(b) such other statistical information as the Data Commissioner may consider appropriate relating to the Data Commissioner's functions; Section 70(3)(c) the impact of the exercise of any of Data Commissioner's mandate or function; Section 70(3)(d) any impediments to the achievements of the object and purpose of this Act or any written law; and Section 70(3)(e) any other information relating to its functions that the Data Commissioner may consider necessary.
Part V
GROUNDS FOR PROCESSING OF SENSITIVE PERSONAL DATA
- 44 Verify source ↗
GROUNDS FOR PROCESSING OF SENSITIVE PERSONAL DATA - 44. Processing of sensitive personal data
Sensitive personal data must not be processed unless section 25 applies to that processing.
Section 44. Processing of sensitive personal data Section No category of sensitive personal data shall be processed unless section 25 applies to that processing. - 45 Verify source ↗
GROUNDS FOR PROCESSING OF SENSITIVE PERSONAL DATA - 45. Permitted grounds for processing sensitive personal data
Permitted grounds: processing relates solely to the members of the body or to persons who have regular contact with it in connection with its purposes.
Section 45. Permitted grounds for processing sensitive personal data Section the processing relates solely to the members of the body or to persons who have regular contact with it in connection with its purposes; and - 46 Verify source ↗
GROUNDS FOR PROCESSING OF SENSITIVE PERSONAL DATA - 46. Personal data relating to health
Section 46 lists grounds for processing personal data relating to health: by or under the responsibility of a health care provider; by a person subject to professional secrecy; when necessary for public health; or by another person who owes a duty of confidentiality.
Section 46. Personal data relating to health Section 46(1)(a) by or under the responsibility of a health care provider; or Section 46(1)(b) by a person subject to the obligation of professional secrecy under any law. Section 46(2)(a) is necessary for reasons of public interest in the area of public health; or Section 46(2)(b) is carried out by another person who in the circumstances owes a duty of confidentiality under any law. - 47 Verify source ↗
GROUNDS FOR PROCESSING OF SENSITIVE PERSONAL DATA - 47. Further categories of sensitive personal data
The Data Commissioner may prescribe or specify additional categories of personal data as sensitive and may consider listed factors when doing so.
Section 47. Further categories of sensitive personal data Section 47(1) The Data Commissioner may prescribe further categories of personal data which may be classified as sensitive personal data. Section 47(2)(a) to the risk of significant harm that may be caused to a data subject by the processing of such category of personal data; Section 47(2)(b) to the expectation of confidentiality attached to such category of personal data; Section 47(2)(c) to whether a significantly discernible class of data subjects may suffer significant harm from the processing of such category of personal data; and Section 47(2)(d) to the adequacy of protection afforded by ordinary provisions applicable to personal data. Section 47(3) The Data Commissioner may specify other categories of personal data, which may require additional safeguards or restrictions.
Part VI
TRANSFER OF PERSONAL DATA OUTSIDE KENYA
- 48 Verify source ↗
TRANSFER OF PERSONAL DATA OUTSIDE KENYA - 48. Conditions for transfer out of Kenya
The data controller or data processor must give proof to the Data Commissioner of appropriate safeguards for security and protection of personal data before transfer out of Kenya.
Section 48. Conditions for transfer out of Kenya Section the data controller or data processor has given proof to the Data Commissioner on the appropriate safeguards with respect to the security and protection of the personal data; - 49 Verify source ↗
TRANSFER OF PERSONAL DATA OUTSIDE KENYA - 49. Safeguards prior to transfer of personal data out of Kenya
Section 49 gives the Data Commissioner powers to request evidence about security safeguards for transfers and to prohibit, suspend or condition transfers to protect data subjects; transfer of sensitive personal data out of Kenya requires consent and confirmation of appropriate safeguards.
Section 49. Safeguards prior to transfer of personal data out of Kenya Section 49(1) The processing of sensitive personal data out of Kenya shall only be effected upon obtaining consent of a data subject and on obtaining confirmation of appropriate safeguards. Section 49(2) The Data Commissioner may request a person who transfers data to another country to demonstrate the effectiveness of the security safeguards or the existence of compelling legitimate interests. Section 49(3) The Data Commissioner may, in order to protect the rights and fundamental freedoms of data subjects, prohibit, suspend or subject the transfer to such conditions as may be determined. - 50 Verify source ↗
TRANSFER OF PERSONAL DATA OUTSIDE KENYA - 50. Processing through a data server or data centre in Kenya
The Cabinet Secretary may prescribe that certain types of processing must be done only using a server or data centre located in Kenya.
Section 50. Processing through a data server or data centre in Kenya Section The Cabinet Secretary may prescribe, based on grounds of strategic interests of the state or protection of revenue, certain nature of processing that shall only be effected through a server or a data centre located in Kenya.
Part VII
EXEMPTIONS
- 51 Verify source ↗
EXEMPTIONS - 51. General exemptions
Data controllers and data processors are not exempt from complying with data protection principles, except for personal/household processing, national security/public interest, or court- or law-required disclosures.
Section 51. General exemptions Section 51(1) Nothing in this Part shall exempt any data controller or data processor from complying with data protection principles relating to lawful processing, minimisation of collection, data quality, and adopting security safeguards to protect personal data. Section 51(2)(a) it relates to processing of personal data by an individual in the course of a purely personal or household activity; Section 51(2)(b) if it is necessary for national security or public interest; or Section 51(2)(c) disclosure is required by or under any written law or by an order of the court. - 52 Verify source ↗
EXEMPTIONS - 52. Journalism, literature and art
The Data Commissioner must prepare a code of practice giving practical guidance on processing personal data for journalism, literature and art.
Section 52. Journalism, literature and art Section 52(1)(a) processing is undertaken by a person for the publication of a literary or artistic material; Section 52(1)(b) data controller reasonably believes that publication would be in the public interest; and Section 52(1)(c) data controller reasonably believes that, in all the circumstances, compliance with the provision is incompatible with the special purposes. Section 52(2) Subsection (1)(b) shall only apply where it can be demonstrated that the processing is in compliance with any self-regulatory or issued code of ethics in practice and relevant to the publication in question. Section 52(3) The Data Commissioner shall prepare a code of practice containing practical guidance in relation to the processing of personal data for purposes of Journalism, Literature and Art. - 53 Verify source ↗
EXEMPTIONS - 53. Research, history and statistics
Further processing of personal data for research, history or statistics must be compatible with the original purpose; data controllers/processors must ensure such processing is solely for those purposes and not published identifiably; they must take safeguards to prevent other uses; the Data Commissioner must prepare a code of practice.
Section 53. Research, history and statistics Section 53(1) The further processing of personal data shall be compatible with the purpose of collection if the data is used for historical, statistical or research purposes and the data controller or data processor shall ensure that the further processing is carried out solely for such purposes and will not be published in an identifiable form. Section 53(2) The data controller or data processor shall take measures to establish appropriate safeguards against the records being used for any other purposes. Section 53(3)(a) data is processed in compliance with the relevant conditions; and Section 53(3)(b) results of the research or resulting statistics are not made available in a form which identifies the data subject or any of them. Section 53(4) The Data Commissioner shall prepare a code of practice containing practical guidance in relation to the processing of personal data for purposes of Research, History and Statistics. - 54 Verify source ↗
EXEMPTIONS - 54. Exemptions by the Data Commissioner
The Data Commissioner may prescribe additional instances where compliance with certain provisions of the Act may be exempted.
Section 54. Exemptions by the Data Commissioner Section The Data Commissioner may prescribe other instances where compliance with certain provisions of this Act may be exempted. - 55 Verify source ↗
EXEMPTIONS - 55. Data-sharing code
The Commissioner must prepare a data-sharing code that provides practical guidance on sharing personal data and other guidance to promote good practice, and must specify lawful exchange of personal data between government departments or public sector agencies.
Section 55. Data-sharing code Section 55(1)(a) practical guidance in relation to the sharing of personal data in accordance with the requirements of the data protection legislation; and Section 55(1)(b) such other guidance as the Commissioner considers appropriate to promote good practice in the sharing of personal data. Section 55(2) The data sharing code under subsection (1) shall specify on the lawful exchange of personal data between government departments or public sector agencies.
Part VIII
ENFORCEMENT PROVISIONS
- 56 Verify source ↗
ENFORCEMENT PROVISIONS - 56. Complaints to the Data Commissioner
A data subject aggrieved by a decision may complain to the Data Commissioner; a person intending to complain shall do so orally or in writing; orally made complaints must be recorded in writing; the Data Commissioner may prescribe procedures for handling complaints.
Section 56. Complaints to the Data Commissioner Section 56(1) A data subject who is aggrieved by a decision of any person under this Act may lodge a complaint with the Data Commissioner in accordance with this Act. Section 56(2) A person who intends to lodge a complaint under this Act shall do so orally or in writing. Section 56(3) Where a complaint made under subclause (1) is made orally, the Data Commissioner shall cause the complaint to be recorded in writing and the complaint shall be dealt with in accordance with such procedures as the Data Commissioner may prescribe. Section 56(4) A complaint lodged under subclause (1) shall contain such particulars as the Data Commissioner may prescribe. Section 56(5) A complaint made to the Data Commissioner shall be investigated and concluded within ninety days. - 57 Verify source ↗
ENFORCEMENT PROVISIONS - 57. Investigation of complaints
The Data Commissioner may require production or access to material stored in mechanical or electronic devices; a person who, without reasonable excuse, fails to comply with a notice or gives the Commissioner information they know to be false or misleading commits an offence.
Section 57. Investigation of complaints Section 57(1)(a) attend at a specified time and place for the purpose of being examined orally in relation to the complaint; Section 57(1)(b) produce such book, document, record or article as may be required with respect to any matter relevant to the investigation, which the person is not prevented by any other enactment from disclosing; or Section 57(1)(c) furnish a statement in writing made under oath or on affirmation setting out all information which may be required under the notice. Section 57(2) Where material to which an investigation relates consists of information stored in any mechanical or electronic device, the Data Commissioner may require the person named to produce or give access to it in a form in which it can be taken away and in which it is visible and legible. Section 57(3) A person who, without reasonable excuse, fails or refuses to comply with a notice, or who furnishes to the Data Commissioner any information which the person knows to be false or misleading, commits an offence. - 58 Verify source ↗
ENFORCEMENT PROVISIONS - 58. Enforcement notices
The Data Commissioner may serve an enforcement notice requiring a person to take specified steps within a period (not less than 21 days) and stating a right of appeal; failing without reasonable excuse is an offence punishable by a fine up to five million shillings or imprisonment up to two years, or both.
Section 58. Enforcement notices Section 58(1) Where the Data Commissioner is satisfied that a person has failed, or is failing, to comply with any provision of this Act, the Data Commissioner may serve an enforcement notice on that person requiring that person to take such steps and within such period as may be specified in the notice. Section 58(2)(a) specify the provision of this Act which has been, is being or is likely to be, contravened; Section 58(2)(b) specify the measures that shall be taken to remedy or eliminate the situation which makes it likely that a contravention will arise; Section 58(2)(c) specify a period which shall not be less than twenty-one days within which those measures shall be implemented; and Section 58(2)(d) state any right of appeal. Section 58(3) Any person who, without reasonable excuse, fails to comply with an enforcement notice commits an offence and is liable on conviction to a fine not exceeding five million shillings or to imprisonment for a term not exceeding two years, or to both. - 59 Verify source ↗
ENFORCEMENT PROVISIONS - 59. Power to seek assistance
The Data Commissioner may seek assistance from persons or authorities to gather information or carry out investigations under the Act when reasonably necessary.
Section 59. Power to seek assistance Section For the purpose of gathering information or for any investigation under this Act, the Data Commissioner may seek the assistance of such person or authority as they deem fit and as is reasonably necessary to assist the Data Commissioner in the discharge of their functions. - 60 Verify source ↗
ENFORCEMENT PROVISIONS - 60. Power of entry and search
The Data Commissioner may, on a court warrant, enter and search any premises to discharge functions or exercise powers under the Act.
Section 60. Power of entry and search Section The Data Commissioner, upon obtaining a warrant from a Court, may enter and search any premises for the purpose of discharging any function or exercising any power under this Act. - 61 Verify source ↗
ENFORCEMENT PROVISIONS - 61. Obstruction of Data Commissioner
Obstruction or impediment of the Data Commissioner in the exercise of their powers is addressed.
Section 61. Obstruction of Data Commissioner Section obstructs or impedes the Data Commissioner in the exercise of their powers; - 62 Verify source ↗
ENFORCEMENT PROVISIONS - 62. Penalty notices
If the Data Commissioner is satisfied that a person has failed as described in section 58, the Data Commissioner may issue a penalty notice requiring the person to pay an amount specified in the notice; the Commissioner must consider a list of factors when determining the amount.
Section 62. Penalty notices Section 62(1) If the Data Commissioner is satisfied that a person has failed or is failing as described in section 58 , the Data Commissioner may issue a penalty notice requiring the person to pay to the Office of the Data Commissioner an amount specified in the notice. Section 62(2)(a) to the nature, gravity and duration of the failure; Section 62(2)(b) to the intentional or negligent character of the failure; Section 62(2)(c) to any action taken by the data controller or data processor to mitigate the damage or distress suffered by data subjects; Section 62(2)(d) to the degree of responsibility of the data controller or data processor, taking into account technical and organisational measures; Section 62(2)(e) to any relevant previous failures by the data controller or data processor; Section 62(2)(f) to the degree of co-operation with the Data Commissioner, in order to remedy the failure and mitigate the possible adverse effects of the failure; Section 62(2)(g) to the categories of personal data affected by the failure; Section 62(2)(h) to the manner in which the infringement became known to the Data Commissioner, including whether, and if so to what extent, the data controller or data processor notified the Data Commissioner of the failure; Section 62(2)(i) to the extent to which the data controller or data processor has complied with previous enforcement notices or penalty notices; Section 62(2)(j) to adherence to approved codes of conduct or certification mechanisms; Section 62(2)(k) to any other aggravating or mitigating factor applicable to the case, including financial benefits gained, or losses avoided, as a result of the failure (whether directly or indirectly); Section 62(2)(l) to whether the penalty would be effective, proportionate and dissuasive. - 63 Verify source ↗
ENFORCEMENT PROVISIONS - 63. Administrative fines
The Data Commissioner may impose administrative fines up to five million shillings, or for an undertaking up to one per centum of its annual turnover of the preceding financial year, whichever is lower.
Section 63. Administrative fines Section In relation to an infringement of a provision of this Act, the maximum amount of the penalty that may be imposed by the Data Commissioner in a penalty notice is up to five million shillings, or in the case of an undertaking, up to one per centum of its annual turnover of the preceding financial year, whichever is lower. - 64 Verify source ↗
ENFORCEMENT PROVISIONS - 64. Right of appeal
A person who is subject to an administrative action by the Data Commissioner may appeal to the High Court.
Section 64. Right of appeal Section A person against whom any administrative action is taken by the Data Commissioner, including in enforcement and penalty notices, may appeal to the High Court. - 65 Verify source ↗
ENFORCEMENT PROVISIONS - 65. Compensation to a data subject
A person who suffers damage because of a contravention of this Act is entitled to compensation from the data controller or data processor; controllers/processors are liable for damage caused by processing unless they prove they are not responsible.
Section 65. Compensation to a data subject Section 65(1) A person who suffers damage by reason of a contravention of a requirement of this Act is entitled to compensation for that damage from the data controller or the data processor. Section 65(2)(a) a data controller involved in processing of personal data is liable for any damage caused by the processing; and Section 65(2)(b) has not complied with an obligation under the Act specifically directed at data processors; or Section 65(2)(b)(i) has not complied with an obligation under the Act specifically directed at data processors; or Section 65(2)(b)(ii) has acted outside, or contrary to, the data controller's lawful instructions. Section 65(3) A data controller or data processor is not liable in the manner specified in subsection (2) if the data controller or data processor proves that they are not in any way responsible for the event giving rise to the damage. Section 65(4) In this section, "damage" includes financial loss and damage not involving financial loss, including distress. - 66 Verify source ↗
ENFORCEMENT PROVISIONS - 66. Preservation Order
The Data Commissioner may apply to a court for a preservation order to preserve personal data, including traffic data, when there are reasonable grounds to believe the data is at risk of loss or modification.
Section 66. Preservation Order Section The Data Commissioner may apply to a court for a preservation order for the expeditious preservation of personal data including traffic data, where there is reasonable ground to believe that the data is vulnerable to loss or modification.
Part X
PROVISIONS ON DELEGATED POWERS
- 71 Verify source ↗
PROVISIONS ON DELEGATED POWERS - 71. Regulations
The Cabinet Secretary may make regulations to give effect to the Act and may prescribe specified matters (listed in subsections) including requirements for controllers/processors, certification mechanisms, notices/registrations, information to data subjects, fees, safeguards, local data server processing, codes of practice, and other matters deemed fit.
Section 71. Regulations Section 71(1) The Cabinet Secretary may, make regulations generally for giving effect to this Act, and for prescribing anything required or necessary to be prescribed by or under this Act. Section 71(2)(a) the requirements which are imposed on a data controller or data processor when processing personal data; Section 71(2)(b) mechanisms of conducting certification program; Section 71(2)(c) the contents which a notice or registration by a data controller or data processor should contain; Section 71(2)(d) information to be provided to a data subject and how such information shall be provided; Section 71(2)(e) the levying of fees and taking of charges; Section 71(2)(f) the measures to safeguard a data subject's rights, freedoms and legitimate interests; Section 71(2)(g) the processing of data through a data server or data centre in Kenya; Section 71(2)(h) issuing and approval of codes of practice and guidelines; or Section 71(2)(i) any other matter that the Cabinet Secretary may deem fit. Section 71(3)(a) the purpose and objective of the delegation under this section is to enable the Cabinet Secretary to make regulations for better carrying into effect the provisions of this Act; Section 71(3)(b) the authority of the Cabinet Secretary to make regulations under this Act will be limited to bringing into effect the provisions of this Act and fulfilment of the objectives specified under this section. Section 71(4)(a) the Statutory Instruments Act (Cap. 2A); Section 71(4)(b) the Interpretation and General Provisions Act ( Cap. 2 ); Section 71(4)(c) the general rules of international law as specified under Article 2(5) of the Constitution; and Section 71(4)(d) any treaty and convention ratified by Kenya under Article 2(6) of the Constitution.
Part XI
MISCELLANEOUS PROVISIONS
- 72 Verify source ↗
MISCELLANEOUS PROVISIONS - 72. Offences of unlawful disclosure of personal data
Makes it an offence for data controllers, data processors, and other persons to unlawfully disclose or offer to sell personal data, with an exception for employees or agents acting within their mandate.
Section 72. Offences of unlawful disclosure of personal data Section 72(1) A data controller who, without lawful excuse, discloses personal data in any manner that is incompatible with the purpose for which such data has been collected commits an offence. Section 72(2) A data processor who, without lawful excuse, discloses personal data processed by the data processor without the prior authority of the data controller commits an offence. Section 72(3)(a) obtains access to personal data, or obtains any information constituting such data, without prior authority of the data controller or data processor by whom the data is kept; or Section 72(3)(b) discloses personal data to third party, commit an offence. Section 72(4) Subsection (3) shall not apply to a person who is an employee or agent of a data controller or data processor acting within the scope of such mandate. Section 72(5) A person who offers to sell personal data where such personal data has been obtained in breach of subsection (1) commits an offence. Section 72(6) For the purposes of subsection (5), an advertisement indicating that personal data is or may be for sale constitutes an offer to sell the personal data. - 73 Verify source ↗
MISCELLANEOUS PROVISIONS - 73. General penalty
A person convicted of an offence under this Act for which no specific penalty is provided shall be liable to a fine not exceeding three million shillings or to imprisonment for up to ten years, or both.
Section 73. General penalty Section 73(1) A person who commits an offence under this Act for which no specific penalty is provided or who otherwise contravenes this Act shall, on conviction, be liable to a fine not exceeding three million shillings or to an imprisonment term not exceeding ten years, or to both. Section 73(2)(a) order the forfeiture of any equipment or any article used or connected in any way with the commission of an offence; or Section 73(2)(b) order or prohibit the doing of any act to stop a continuing contravention. - 74 Verify source ↗
MISCELLANEOUS PROVISIONS - 74. Codes, guidelines and certification
Section 74 directs issuance of guidelines, certification standards and sector-specific guidance, and states that certification does not remove controllers' or processors' responsibility for compliance.
Section 74. Codes, guidelines and certification Section 74(1)(a) issue guidelines or codes of practice for the data controllers, data processors and data protection officers; Section 74(1)(b) offer data protection certification standards and data protection seals and marks in order to encourage compliance of processing operations with this Act; Section 74(1)(c) require certification or adherence to code of practice by a third party; Section 74(1)(d) develop sector specific guidelines in consultation with relevant stakeholders in areas such as health, financial services, education, social Protection and any other area as the Data Commissioner may determine. Section 74(2) A certification issued under this section shall not alter the responsibility of the data controller or data processor for compliance with this Act.
Provision text is displayed from LexChat’s stored statute record. Use the official source links to verify amendments, commencement, and current legal force.
Ask AI about this statute
Data Protection Act
Sign in to ask AI about this statute
Sign in to start authenticated, citation-grounded statute research.
Sign inLexChat organizes source-backed legal information for research. Verify amendments, commencement, and current legal force with the official publisher before relying on it.