AI LAW RADAR · Daily Last verified 16 Aug 2026

Jurisdiction dossier

Kenya: AI regulation & deadlines

No AI-specific statute in force: the binding constraint is s. 35 of the Data Protection Act, which gives a data subject the right not to be subject to a decision based solely on automated processing including profiling that produces legal effects or significantly affects them, requires written notification when such a decision is taken, and lets the data subject demand reconsideration or a new decision not based solely on automated processing. The Kenya National AI Strategy 2025–2030 is non-binding. 1 obligation tracked — 1 in force.

Binding — Binding sectoral Flagship law: Data Protection Act s. 35 (No. 24 of 2019)

No AI-specific statute in force: the binding constraint is s. 35 of the Data Protection Act, which gives a data subject the right not to be subject to a decision based solely on automated processing including profiling that produces legal effects or significantly affects them, requires written notification when such a decision is taken, and lets the data subject demand reconsideration or a new decision not based solely on automated processing. The Kenya National AI Strategy 2025–2030 is non-binding.

checked 16 Aug 2026 primary source ↗

The Register

1 obligation
Kenya Binding

Data Protection Act s. 35 — right against solely-automated decisions, with written notification and a right to reconsideration

Binds Data controllers and data processors within the scope of s. 4, that is those established or ordinarily resident in Kenya and processing personal data while in Kenya, and those not so established or resident but processing personal data of data subjects located in Kenya. Registration with the Office of the Data Protection Commissioner under ss. 18 and 19 is a precondition of acting as a controller or processor, subject to the thresholds set by the Data Protection (Registration of Data Controllers and Data Processors) Regulations. The s. 35 duties bind any controller or processor that takes a solely-automated decision with legal or significant effect. Impact tier: all entities.. Section 35 of the Data Protection Act No. 24 of 2019 gives every data subject a right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning or significantly affects the data subject (s. 35(1)). The right does not apply where the decision is necessary for entering into or performing a contract between the data subject and a data controller, is authorised by a law to which the controller is subject and which lays down suitable measures to safeguard the data subject's rights, freedoms and legitimate interests, or is based on the data subject's consent (s. 35(2)). Where a controller or processor does take such a decision, s. 35(3) imposes two duties: it must as soon as reasonably practicable notify the data subject in writing that a decision has been taken based solely on automated processing, and the data subject may then, after a reasonable period from receipt of that notification, request the controller or processor to reconsider the decision or to take a new decision that is not based solely on automated processing. On receipt of such a request the controller or processor must within a reasonable period consider the request including any relevant information the data subject provides, comply with it, and inform the data subject in writing of the steps taken in compliance and of the outcome (s. 35(4)). Section 35(5) empowers the Cabinet Secretary to make further provision by Regulations. Section 31 separately makes a data protection impact assessment mandatory where a processing operation is likely to result in high risk to the rights and freedoms of a data subject.

Commencement is stated on the face of the published Act: the gazetted text of the Data Protection Act No. 24 of 2019 records a Date of Assent of 8 November 2019 and a Date of Commencement of 25 November 2019, and s. 35 carries no deferred or separately-appointed commencement. The Office of the Data Protection Commissioner was constituted in November 2020 and has exercised its enforcement powers since; the section itself has been operative from 25 November 2019. Kenya is the tracker's second African jurisdiction, added in the same sweep as za-popia-s71. Section 35 follows the GDPR Art. 22 shape more closely than the South African provision does: it grants an express right to demand a new decision that is not based solely on automated processing, which POPIA s. 71 does not, and it attaches an affirmative written-notification duty on the controller rather than leaving disclosure to a request. It stops short of the Korean kr-pipa-art37-2-adm model in that it confers no standalone right to an explanation of the criteria used. Text read in the official copy of the Act published by the Office of the Data Protection Commissioner, the supervisory authority established by Part II of the Act; new.kenyalaw.org and kenyalaw.org return HTTP 403 to non-browser clients, so the ODPC copy is cited.

Stated maximum penalty — Section 63 caps the administrative penalty the Data Commissioner may impose by penalty notice, in relation to an infringement of a provision of the Act, at five million Kenyan shillings, or in the case of an undertaking one per centum of its annual turnover of the preceding financial year, whichever is lower; s. 62 governs the penalty notice and s. 58 the enforcement notice that ordinarily precedes it. Section 65 gives a person who suffers damage by reason of a contravention a right to compensation from the controller or processor. Section 73 provides a general penalty, for offences under the Act for which no specific penalty is prescribed, of a fine not exceeding three million shillings or imprisonment for a term not exceeding ten years, or both. Appeals against administrative action lie to the High Court under s. 64.

In force · 25 Nov 2019 checked 16 Aug 2026 Data Protection Act s. 35 (No. 24 of 2019) ↗ high confidence

Questions & answers

From the data

When does Data Protection Act s. 35 (No. 24 of 2019) take effect in Kenya?

Data Protection Act s. 35 (No. 24 of 2019) is already in force, with obligations live since November 25, 2019. No AI-specific statute in force: the binding constraint is s. 35 of the Data Protection Act, which gives a data subject the right not to be subject to a decision based solely on automated processing including profiling that produces legal effects or significantly affects them, requires written notification when such a decision is taken, and lets the data subject demand reconsideration or a new decision not based solely on automated processing. The Kenya National AI Strategy 2025–2030 is non-binding.

Who must comply with AI rules in Kenya?

Current obligations bind, among others, Data controllers and data processors within the scope of s. 4, that is those established or ordinarily resident in Kenya and processing personal data while in Kenya, and those not so established or resident but processing personal data of data subjects located in Kenya. Registration with the Office of the Data Protection Commissioner under ss. 18 and 19 is a precondition of acting as a controller or processor, subject to the thresholds set by the Data Protection (Registration of Data Controllers and Data Processors) Regulations. The s. 35 duties bind any controller or processor that takes a solely-automated decision with legal or significant effect. Impact tier: all entities.. Scope and thresholds vary per instrument — see each row's source for the legal text.

What are the penalties for AI non-compliance in Kenya?

Stated statutory maxima include: Data Protection Act s. 35 (No. 24 of 2019) — Section 63 caps the administrative penalty the Data Commissioner may impose by penalty notice, in relation to an infringement of a provision of the Act, at five million Kenyan shillings, or in the case of an undertaking one per centum of its annual turnover of the preceding financial year, whichever is lower; s. 62 governs the penalty notice and s. 58 the enforcement notice that ordinarily precedes it. Section 65 gives a person who suffers damage by reason of a contravention a right to compensation from the controller or processor. Section 73 provides a general penalty, for offences under the Act for which no specific penalty is prescribed, of a fine not exceeding three million shillings or imprisonment for a term not exceeding ten years, or both. Appeals against administrative action lie to the High Court under s. 64.. These are the maximum amounts in the instruments; actual enforcement is at the regulator's discretion.