DPA 2019 is in force. Most companies still treat it like a future problem.
Kenya's Data Protection Act, 2019 is in force. Yet most companies I talk to still treat it like a future problem.
Here's the reality:
The Act applies to every entity — company, NGO, SACCO, fintech, hospital — that processes the personal data of any person residing in Kenya. It doesn't matter if you're incorporated in Nairobi or Delaware. If you hold Kenyan data, the Act applies.
ODPC (Office of the Data Protection Commissioner) is the regulator. They run the data controllers/processors register. They publish enforcement notices publicly. They can investigate on complaint or on their own motion.
Section 33 of the Act sets the penalty ceiling. We're talking fines up to KES 5 million for serious breaches. "Serious" isn't a high bar.
Three things every Kenyan data controller must do right now:
- Register with ODPC (mandatory under the Act)
- Appoint or designate someone accountable for data protection
- Maintain a Register of Data Processing Activities
None of this is optional. None of this is "for later."
Run a free 5-minute compliance check → assessment.bitverse.co.ke