
REPUBLIC OF KENYA
# KENYA GAZETTE SUPPLEMENT
ACTS, 2019
NAIROBI, 11th November, 2019
CONTENT
Act-
PAGE
The Data Protection Act, 2019.. ..901
NATIONAL COUNCIL FOR LAW REPORTING RECEIVED
18 NOV 2019
MO. Dax 10448- 06106 NAIROBI, KENYA TEL: 2719231 FAX: 2712694
PRINTED AND PUBLISHED BY THE GOVERNMENT PRINTER, NAIROBI
# THE DATA PROTECTION ACT
# No. 24 of 2019
Date of Assent: 8th November, 2019
Date of Commencement: 25th November, 2019
ARRANGEMENT OF SECTIONS
# Sections
# PART I—PRELIMINARY
- —Short title.
- -Interpretation.
- —Object and purpose of this Act.
- —Application.
# PART II—ESTABLISHMENT OF THE OFFICE OFTHE DATA PROTECTION COMMISSIONER
- —Establishment of the Office.
- — Appointment of the Data Commissioner.
- —Qualifications of the Data Commissioner.
- —Functions of the Data Commissioner.
. —Powers of the Office. 10. —Delegation by the Data Commissioner. 11. — Vacancy in the Office of the Data Commissioner. 12. —Removal of the Data Commissioner from office. 13. —Staff of the Office. 14. —Remuneration of the Data Commissioner and staff. 15. —Oath of Office. 1.Confidentiality agreements. 17.—Protection from personal liability.
# PART III—REGISTRATION OF DATA CONTROLLERS AND DATA PROCESSORS
- —Registration of data controllers and data Processors.
- —Application for registration.
- —Duration of the registration certificate.
Register of data controllers and data processors.
- —Cancellation or variation of the certificate.
- —Compliance and audit.
- —Designation of the Data Protection Officer.
# PART IV-PRINCIPLES AND OBLIGATIONS OF PERSONAL DATA PROTECTION
- —Principles of personal data protection.
- —Rights of a data subject.
- —Exercise of rights by data subject.
- —Collection of personal data.
- — Duty to notify.
- —Lawful processing of personal data.
- —Data protection impact assessment.
- —Conditions for consent.
- —Processing of personal data relating to a child.
- —Restriction on processing.
- —Automated individual decision making.
- —Objecting to processing.
- —processing for direct marketing.
- —Right to data portability.
- —Limitation to retention of personal data.
- —Right of rectification and erasure.
- —Data protection by design or default.
- —Particulars of determining organisational measures.
- —Notification and communication of breach.
# PART V—GROUNDS FOR PROCESSING OF SENSITIVE PERSONAL DATA
- —Processing of sensitive personal data.
- -Permitted grounds for processing sensitive personal data.
- —Personal data relating to health.
- —Further categories of sensitive personal data.
# PART VI—TRANSFER OF PERSONAE DATA OUTSIDE KENYA
- —Conditions for transfer out of Kenya.
- —Safeguards prior to transfer of personal data out of Kenya.
- —Processing through a data server or centre in Kenya.
# PART VII—EXEMPTIONS
- —General exemptions.
- —Journalism, literature and art.
- —Research, history and statistics.
- —Exemptions by the Data Commissioner.
- —Data-sharing code.
# PART VIII—ENFORCEMENT PROVISIONS
- —Complaints to the Data Commissioner.
- —Investigation of complaints.
- —Enforcement notices.
- —Power to seek assistance.
- — Power of entry and search.
- —Obstruction of the Data Commissioner.
- —Penalty notices.
- —Administrative fines.
- Right of appeal.
- —Compensation of data subject.
- —Preservation Order.