NEXIO.
Cybersecurity

The Kenya Data Protection Act: What Your Website Must Do

Cookie consent, privacy policies, form data and registration — the practical website obligations under Kenya's Data Protection Act.

Nexio Editorial TeamDigital strategists, Nairobi7 min read

The short answer

Under Kenya's Data Protection Act 2019, any website collecting personal data must publish a clear privacy notice, collect data only for a stated lawful purpose, obtain consent for non-essential cookies and marketing, secure the data it holds, and let people access or delete their records. Some data controllers must also register with the ODPC.

Your minimum website obligations

These are the items an audit will look for first.

  • A privacy notice in plain language, linked in the footer
  • A stated lawful basis for every collection point
  • Cookie consent for analytics and marketing scripts
  • A named contact for data requests
  • A route for access, correction and deletion requests

Forms and marketing lists

Pre-ticked opt-in boxes are not consent. Separate the enquiry from the marketing permission, keep a record of when and how consent was given, and honour unsubscribes promptly.

Registration with the ODPC

Data controllers and processors above the prescribed thresholds must register with the Office of the Data Protection Commissioner. Check your turnover and headcount against the current regulations rather than assuming exemption.

Frequently asked

Do small Kenyan websites need a privacy policy?

If you collect any personal data — including a contact form or analytics — you need a privacy notice. Size does not remove the obligation.

Do I need a cookie banner in Kenya?

You need consent before setting non-essential cookies such as analytics and advertising, which in practice means a banner with a genuine reject option.

Next step

Ready to put this into practice?

We'll audit your current site for free and show you exactly what to fix first.

  • Free strategy call
  • Fixed-price proposal
  • 30 days free support