The Kenya Data Protection Act: What Your Website Must Do
Cookie consent, privacy policies, form data and registration — the practical website obligations under Kenya's Data Protection Act.
The short answer
Under Kenya's Data Protection Act 2019, any website collecting personal data must publish a clear privacy notice, collect data only for a stated lawful purpose, obtain consent for non-essential cookies and marketing, secure the data it holds, and let people access or delete their records. Some data controllers must also register with the ODPC.
Your minimum website obligations
These are the items an audit will look for first.
- ✓A privacy notice in plain language, linked in the footer
- ✓A stated lawful basis for every collection point
- ✓Cookie consent for analytics and marketing scripts
- ✓A named contact for data requests
- ✓A route for access, correction and deletion requests
Forms and marketing lists
Pre-ticked opt-in boxes are not consent. Separate the enquiry from the marketing permission, keep a record of when and how consent was given, and honour unsubscribes promptly.
Security is a legal requirement, not a nice-to-have
The Act requires appropriate technical measures. In practice: HTTPS everywhere, strong admin authentication, least-privilege access, encrypted backups and a documented breach response.
Registration with the ODPC
Data controllers and processors above the prescribed thresholds must register with the Office of the Data Protection Commissioner. Check your turnover and headcount against the current regulations rather than assuming exemption.
Frequently asked
Do small Kenyan websites need a privacy policy?
If you collect any personal data — including a contact form or analytics — you need a privacy notice. Size does not remove the obligation.
Do I need a cookie banner in Kenya?
You need consent before setting non-essential cookies such as analytics and advertising, which in practice means a banner with a genuine reject option.