Skip to content
Menu ▾
Patent pending

Regulayer  /  The 146 laws  /  Privacy law

Kenya · Data Protection Act 2019

Security safeguards & 72-hour breach notice.

Applies to: Controllers under Kenya's DPA. Built · in force

What the signed record shows

Breach records, accountability signals, and DPIA references.

The proof is a signed, tamper-evident record. Anyone can check it, free, without an account, and nothing has to leave the building to make it. Evidence, not a promise.

Citation: DPA 2019 (Act No. 24) s.25/31/41/43

In the same family

What to do about it

Seven days free, then $349 a month.

A signed record of which AI you used and what you checked, sealed to the exact file you deliver, made on your own machine and checkable free by anyone you send it to.

Start the free weekOr verify a real record, free →

Part of the Regulayer proof catalogue: 146 laws and standards, one sealed engine. This page is a product description, not legal advice.

What the statute requires, section by section

The Data Protection Act, 2019 (Kenya), Act No. 24 of 2019. Regulator: the Office of the Data Protection Commissioner (ODPC). Provisions addressed:

s. 43
Notification of breach to the Data Commissioner without delay, within
72 hours of becoming aware, and to affected data subjects; a processor notifies the controller within 48 hours.
s. 41
Security safeguards / data protection by design and default.
s. 25
Principles of data protection (lawfulness, purpose limitation, data minimization, accuracy, storage limitation, integrity/confidentiality, accountability).
s. 31
Data Protection Impact Assessment (DPIA) for high-risk processing. Commenced 25 November 2019.

Taken from the Regulayer entry for this instrument, which is built against the primary text.