NATIONAL COUNCIL FOR LAW REPORTING LIBRARY
SPECIAL ISSUE
Kenya Gazette Supplement No. 181 (Acts No. 24)
!img-0.jpeg
REPUBLIC OF KENYA
# KENYA GAZETTE SUPPLEMENT
ACTS, 2019
NAIROBI, 11th November, 2019
CONTENT
Act—
PAGE
The Data Protection Act, 2019...901
NATIONAL COUNCIL FOR LAW REPORTING RECEIVED 18 NOV 2019 P.O. Box 10448-00108 NAIROBI, KENYA TEL: 2719231 FAX: 2712694
PRINTED AND PUBLISHED BY THE GOVERNMENT PRINTER, NAIROBI
901
# THE DATA PROTECTION ACT
No. 24 of 2019
Date of Assent: 8th November, 2019
Date of Commencement: 25th November, 2019
# ARRANGEMENT OF SECTIONS
Sections
PART I—PRELIMINARY
- —Short title.
- —Interpretation.
- —Object and purpose of this Act.
- —Application.
PART II—ESTABLISHMENT OF THE OFFICE OF THE DATA PROTECTION COMMISSIONER
- —Establishment of the Office.
- —Appointment of the Data Commissioner.
- —Qualifications of the Data Commissioner.
- —Functions of the Data Commissioner.
- —Powers of the Office.
- —Delegation by the Data Commissioner.
- —Vacancy in the Office of the Data Commissioner.
- —Removal of the Data Commissioner from office.
- —Staff of the Office.
- —Remuneration of the Data Commissioner and staff.
- —Oath of Office.
- —Confidentiality agreements.
- —Protection from personal liability.
PART III—REGISTRATION OF DATA CONTROLLERS AND DATA PROCESSORS
- —Registration of data controllers and data Processors.
- —Application for registration.
- —Duration of the registration certificate.
- —Register of data controllers and data processors.
902
No. 24
Data Protection
- —Cancellation or variation of the certificate.
- —Compliance and audit.
- —Designation of the Data Protection Officer.
PART IV—PRINCIPLES AND OBLIGATIONS OF PERSONAL DATA PROTECTION
- —Principles of personal data protection.
- —Rights of a data subject.
- —Exercise of rights by data subject.
- —Collection of personal data.
- —Duty to notify.
- —Lawful processing of personal data.
- —Data protection impact assessment.
- —Conditions for consent.
- —Processing of personal data relating to a child.
- —Restriction on processing.
- —Automated individual decision making.
- —Objecting to processing.
- —processing for direct marketing.
- —Right to data portability.
- —Limitation to retention of personal data.
- —Right of rectification and erasure.
- —Data protection by design or default.
- —Particulars of determining organisational measures.
- —Notification and communication of breach.
PART V—GROUNDS FOR PROCESSING OF SENSITIVE PERSONAL DATA
- —Processing of sensitive personal data.
- —Permitted grounds for processing sensitive personal data.
- —Personal data relating to health.
- —Further categories of sensitive personal data.
903
2019
Data Protection
No. 24
# PART VI—TRANSFER OF PERSONAL DATA OUTSIDE KENYA
- —Conditions for transfer out of Kenya.
- —Safeguards prior to transfer of personal data out of Kenya.
- —Processing through a data server or centre in Kenya.
# PART VII—EXEMPTIONS
- —General exemptions.
- —Journalism, literature and art.
- —Research, history and statistics.
- —Exemptions by the Data Commissioner.
- —Data-sharing code.
# PART VIII—ENFORCEMENT PROVISIONS
- —Complaints to the Data Commissioner.
- —Investigation of complaints.
- —Enforcement notices.
- —Power to seek assistance.
- —Power of entry and search.