loaderimg
What
image
  • Banking & Finance
  • Civil Litigation
  • Corporate
  • Criminal Defence
  • Data Protection
  • Debt Recovery
  • Dispute Resolution
  • Divorce & Family
  • Employment
  • Estate Planning
  • Full-Service
  • Human Rights
  • Immigration
  • Insurance
  • IP & Tech
  • Maritime
  • Medical Malpractice
  • Personal Injury / Accident
  • Real Estate
  • Tax
Where
image
image

Data Protection Lawyers

DATA PROTECTION & CYBER SECURITY LAWYERS

Data Protection & Cyber Security Lawyers in Kenya

Find and compare verified data protection and cyber security lawyers across Kenya. Get help with Data Protection Act compliance, ODPC registration, data breaches, and privacy disputes.

FEATURED LISTINGS

Featured Data Protection & Cyber Security Lawyers in Kenya

Verified data protection and cyber security law firms with complete profiles, confirmed practice areas, and direct contact details.

  • Confirm the lawyer is a registered advocate with the Law Society of Kenya
  • Choose a lawyer with genuine, current experience in data protection law and ODPC practice
  • Address compliance proactively: the ODPC is actively enforcing the Act and fines are real
  • In a breach situation, instruct a lawyer immediately to manage the 72-hour notification deadline
  • Ask how they charge and get a written fee agreement before work begins
  • Nairobi
  • Mombasa
  • Kisumu
  • Nakuru
  • Eldoret
  • Thika
  • Ruiru
  • Nyeri
  • Meru
  • Machakos
  • Kiambu
  • Kisii
  • Kakamega
  • Kericho
  • Naivasha
  • Malindi
  • Kilifi

Find a Data Protection Lawyer in Your Town

Choose your town to find verified data protection and cyber security lawyers near you.

BROWSE MORE

More Data Protection Law Firms in Kenya

Browse more verified data protection and cyber security law firms across Kenya.

No Listings Found

Common Questions

Frequently Asked Questions

Everything you need to know about data protection law in Kenya.

The Data Protection Act, 2019 requires organisations that collect, store, process, or share personal data in Kenya to do so lawfully, fairly, and transparently. Core obligations include having a lawful basis for processing, complying with the data processing principles set out in Section 25 of the Act (including purpose limitation, data minimisation, accuracy, and storage limitation), respecting the rights of data subjects, registering with the ODPC where required, appointing a Data Protection Officer where required, notifying the ODPC of data breaches within 72 hours, and storing at least one copy of personal data on a server in Kenya. A data protection lawyer can assess your organisation's obligations and build a compliance programme. This is general information rather than advice on your particular case.
Possibly. Registration with the Office of the Data Protection Commissioner is required for organisations that meet any of several thresholds: annual turnover above KES 5 million, more than ten employees, processing sensitive personal data, processing the personal data of ten thousand or more data subjects within a year, or operating in regulated sectors such as financial services, healthcare, education, or telecommunications. Registration is done online through the ODPC portal. Operating as a data controller or processor without registering when required is an offence. A data protection lawyer can confirm whether your organisation is required to register and assist with the process. This is general information rather than advice on your particular case.
A Data Protection Officer (DPO) is a person appointed to oversee an organisation's data protection compliance, monitor adherence to the Data Protection Act, conduct or oversee Data Protection Impact Assessments, train staff, and serve as the contact point for the ODPC. The Act requires a DPO to be appointed by public bodies, by organisations that process sensitive personal data on a large scale, and by organisations whose core activities involve large-scale systematic monitoring of data subjects. The DPO must have sufficient knowledge of data protection law and practice. A data protection lawyer can advise on whether your organisation is required to appoint a DPO and what the role involves. This is general information rather than advice on your particular case.
Act immediately. You must notify the ODPC within 72 hours of becoming aware of the breach. If a data processor is involved, they must notify the data controller within 48 hours. Where the breach is likely to result in a high risk to the rights and freedoms of the affected individuals, those data subjects must also be notified without undue delay. The notification to the ODPC must describe the nature of the breach, the categories and approximate number of data subjects affected, the likely consequences, and the measures taken or proposed to address it. Failing to notify in time is itself an offence. In a breach situation, instructing a data protection lawyer immediately is strongly advisable to manage the notification, the ODPC response, and any consequent enforcement or compensation claims. This is general information rather than advice on your particular case.
The ODPC can impose administrative fines of up to KES 5 million or one per cent of the organisation's annual turnover for the preceding financial year, whichever is lower. For continuing violations, a daily fine of KES 10,000 applies for each day the breach is not remedied. The ODPC can also issue enforcement notices, issue orders to cease processing, and make compensation orders to affected data subjects. Criminal penalties for offences under the Act include fines of up to KES 3 million or imprisonment of up to ten years, or both. The ODPC has imposed fines exceeding KES 26 million through September 2024, including a KES 10 million fine against Regus Kenya and Whitepath in 2023. This is general information rather than advice on your particular case.
Data subjects in Kenya have the right to know what personal data is being processed about them and why, the right to access their data, the right to correct inaccurate data, the right to have their data erased where it is no longer necessary or was unlawfully processed, the right to restrict or object to processing, and the right to data portability. Organisations must have procedures in place to respond to data subject requests within the timelines set by the Act. Where an organisation fails to respect these rights, the data subject can lodge a complaint with the ODPC, which can investigate and award compensation. A data protection lawyer can advise organisations on managing data subject rights requests. This is general information rather than advice on your particular case.
Yes, but with conditions. Cross-border transfers of personal data are permitted only where you can demonstrate to the ODPC that adequate safeguards are in place, such as the receiving country having comparable data protection laws, contractual clauses, or binding corporate rules. Transfers of sensitive personal data abroad additionally require the explicit consent of the data subject. Section 50 also imposes a data localisation obligation: at least one serving copy of all personal data must be stored on a server or data centre within Kenya. Organisations using international cloud providers must ensure their infrastructure includes Kenya-based storage to comply. A data protection lawyer can advise on the specific requirements for your data transfer arrangements. This is general information rather than advice on your particular case.
A Data Protection Impact Assessment (DPIA) is a process to identify and minimise the data protection risks of a new project or processing activity. The Data Protection Act requires a DPIA before carrying out processing that is likely to result in a high risk to the rights and freedoms of data subjects, such as large-scale processing of sensitive personal data, automated decision-making with significant effects, or systematic monitoring. Where the DPIA reveals that the processing would result in a high risk that cannot be mitigated, the organisation must consult the ODPC at least sixty days before the processing begins. A data protection lawyer can advise on when a DPIA is required and help conduct it. This is general information rather than advice on your particular case.
A data subject whose rights under the Data Protection Act have been infringed can lodge a written complaint with the ODPC. Only natural persons (individuals, not companies) can lodge complaints with the ODPC, as confirmed by the High Court in 2023. The ODPC investigates the complaint, may attempt to resolve it through alternative dispute resolution, and can issue a determination. Where a violation is confirmed, the ODPC can issue enforcement notices, order compensation to be paid to the data subject, and impose financial penalties on the offending organisation. The ODPC had resolved 357 determinations and issued 184 compensation orders as of 2025. A data protection lawyer can represent you whether you are the complainant or the organisation under investigation. This is general information rather than advice on your particular case.
Yes, in certain circumstances. The Data Protection Act has extraterritorial reach and applies to entities outside Kenya where they process the personal data of Kenyan residents in connection with offering goods or services to those residents, or monitoring their behaviour. This mirrors the approach of the GDPR and means that foreign businesses targeting the Kenyan market, or processing the data of Kenyan users, must comply with the Act regardless of where the business is based. A data protection lawyer can advise on whether the Act applies to your operations and what compliance requires. This is general information rather than advice on your particular case.
The Data Protection Act identifies specific categories of data as sensitive, including data revealing racial or ethnic origin, political opinion, religious or philosophical beliefs, health or medical data, genetic or biometric data, and data concerning sexual orientation. Processing sensitive personal data is subject to stricter conditions than ordinary personal data: you generally need the explicit consent of the data subject or another specific lawful basis, and organisations that process sensitive data on a large scale are required to register with the ODPC and appoint a DPO. A data protection lawyer can advise on the lawful bases available for your specific sensitive data processing. This is general information rather than advice on your particular case.
Employee personal data, including names, contact details, payroll information, performance records, health data, and biometric data used for access control, is subject to the Data Protection Act in the same way as customer data. Employers must have a lawful basis for processing employee data, typically the performance of the employment contract or legal obligations, and must process it in accordance with the Act's principles. Employees have the same data subject rights as other individuals. Biometric data used in HR systems (fingerprint scanners, facial recognition) is sensitive data requiring a specific lawful basis. A data protection lawyer can advise on HR data compliance. This is general information rather than advice on your particular case.
You can find verified data protection and cyber security lawyers by town using the links on this page. Before instructing anyone, confirm they are a registered advocate, the formal term for a lawyer in Kenya, using the Law Society of Kenya's advocates search, reached by searching "LSK advocates." Enter the lawyer's full name; if registered, the portal shows their photo, firm, practising year, address, and status. A practising certificate runs from 1 January to 31 December, so check theirs is current before you instruct them. This is general information rather than advice on your particular case.

Are you a data protection or cyber security lawyer in Kenya?

Add your firm to Kenya’s dedicated legal directory and get found by clients searching for data protection and cyber security lawyers.