Author: KNAdvocates

KNlegalassociates > Articles by: KNAdvocates

What Are the 7 Data Protections?

The Data Protection Act 2019 established seven core principles that govern how Kenyan organizations handle personal data. They mirror international laws like the GDPR and aim to safeguard individual privacy through lawful, transparent, and accountable processing. Collect data only on a valid legal basis and inform data subjects how it will be used.Compliance tips: create […]

Read More

Data Protection Impact Assessment Kenya

Introduction A Data Protection Impact Assessment (DPIA) is a structured process used to identify and minimize data protection risks before starting high-risk data processing activities. Under data protection Kenya regulations, conducting a DPIA is a crucial part of ensuring compliance with the Data Protection Act 2019 and safeguarding individuals’ privacy rights. Kenyan organizations must now […]

Read More
Privacy rights in the workplace

Right to Privacy in Kenya: Constitutional Protections, Laws, and Practical Issues

INTRODUCTION The right to privacy is one of the most important guarantees in the Constitution of Kenya. Enshrined in Article 31, this right protects individuals from unwarranted intrusion into their personal lives, communications, and data. In today’s digital and interconnected society, questions about privacy have become central to law, policy, and daily life. From surveillance […]

Read More

Safaricom Accused of Disclosing Moi University Student’s Data to Police Without Court Order

A Safaricom officer has admitted in court that the telecom firm shared a student’s call details, location, and other personal data with police without a judicial warrant, triggering concern over privacy rights and legal compliance. Kenya Insights+2lawguide.co.ke+2 In September 2025, at Nairobi’s Milimani Law Courts, a Safaricom security investigator confirmed that the company furnished the […]

Read More

Why Healthcare Investors Must Prioritize Data Protection in Kenya

Executive SummaryKenya’s healthcare sector offers significant investment opportunities, particularly in digital health and healthtech. Yet healthcare investors cannot afford to overlook data protection. Compliance with the Data Protection Act, 2019 and related regulations is not just a legal requirement; it is a business necessity that shapes market access, reputation, and patient trust. Background: Healthcare Market […]

Read More
Kenya cross-border data transfer

Cross-Border Data Transfers Under Kenya’s Data Protection Act: What Multinationals Must Know

The Global Data DilemmaModern corporations depend on international data flows whether through shared HR systems, cloud platforms, or cross-border customer services. For multinationals entering Kenya, the question is not if data will cross borders, but how. Kenya’s Legal FrameworkSection 48 of the Data Protection Act restricts transfers of personal data outside Kenya unless specific safeguards […]

Read More
Kenya data protection compliance

The Essential Data Protection Compliance Checklist for Foreign Subsidiaries in Kenya

Why Registration MattersKenya’s Data Protection Act requires any entity handling personal data of Kenyan residents even subsidiaries of foreign companies to register with the ODPC. Many companies assume compliance is automatic if they follow global standards like GDPR. This is a mistake. Local adaptation is essential. The 5-Step Checklist for Foreign Subsidiaries Practical Takeaways ConclusionFor […]

Read More
Kenya digital economy

Why Kenya Is the Next Digital Economy Hub and What Investors Must Know About Data Protection

Kenya’s Digital Growth StoryKenya has established itself as a leader in Africa’s digital transformation. From pioneering mobile money through M-Pesa to attracting global tech firms, the country has created fertile ground for digital businesses. According to the Communications Authority of Kenya, internet penetration exceeds 40 million users, and digital services account for a significant portion […]

Read More
data-protection-act-kenya-2019-summary

Kenya’s Data Protection Act 2019: What Businesses Must Know

The Data Protection Act, 2019 (DPA 2019) is one of the most important pieces of legislation for businesses in Kenya today. It established a legal framework that protects the privacy of individuals while setting out obligations for organizations that collect and process personal data. For businesses, this law is not just about legal compliance. It […]

Read More
Kenya Data Protection Penalties & Fines

Penalties for Data Protection Breaches in Kenya

Data protection in Kenya has taken center stage since the enactment of the Data Protection Act, 2019 (DPA 2019). Businesses across all sectors from fintech and banking to healthcare and edtech are under increasing scrutiny from the Office of the Data Protection Commissioner (ODPC). Failure to comply is not just a technical misstep; it can […]

Read More