Law / Kenya

Data Protection Act, 2019, sensitive personal data

Data Protection Act, 2019 (No. 24 of 2019), Part V (ss. 44-47)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force since 25 November 2019.

A sensitive categories rule binding public and private bodies.

As of 4 September 2026.

What it requires

  • Do not process biometric, genetic, health or other sensitive personal data unless a specific ground under section 45 applies, in addition to the Act's general lawful-basis requirement.
  • Do not process health data unless you are a health-care provider or a person bound by professional secrecy.

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Sensitive personal data, defined to include biometric data, genetic data, health status and several other categories, may only be processed on a specific permitted ground: legitimate not-for-profit activity with appropriate safeguards, data manifestly made public by the data subject, or necessity for a legal claim or to protect vital interests. Health data may only be processed by or under a health-care provider or a person bound by professional secrecy.

The Data Commissioner may prescribe further categories of sensitive personal data and the grounds on which they may be processed.

When LexLint raises it

  • processes_biometrics
  • processes_voice

Read the law

official consolidated Act text, Kenya Law (National Council for Law Reporting)

Back to the example  ·  Lint your app