Data Protection Act, 2019, personal data breach notification
Data Protection Act, 2019 (No. 24 of 2019), s. 43 (notification and communication of breach)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force since 25 November 2019.
A breach notification rule binding public and private bodies.
As of 4 September 2026.
What it requires
- Notify the Data Commissioner within seventy-two hours of becoming aware of a personal data breach that carries a real risk of harm, giving reasons if you notify later.
- As a data processor, notify the data controller within forty-eight hours of becoming aware of a breach.
- Communicate the breach to the affected data subject in writing within a reasonably practical period, unless their identity cannot be established.
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Where personal data has been accessed or acquired by an unauthorised person and there is a real risk of harm, a data controller must notify the Data Commissioner without delay, and in any event within seventy-two hours of becoming aware of the breach, giving reasons for any later notification.
A data processor that becomes aware of a breach must notify the data controller within forty-eight hours where reasonably practicable, and the controller must communicate the breach to the affected data subject in writing within a reasonably practical period unless their identity cannot be established.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbot
Read the law
official consolidated Act text, Kenya Law (National Council for Law Reporting)