The Data Protection Act, 2019 is the law that governs the collection, use, storage, and processing of personal data in Kenya. The Act aims to protect the privacy and personal data of individuals and regulate the handling of such data by both public and private entities.
Under the Data Protection Act, personal data is defined as any information relating to an identified or identifiable individual. This includes information such as a person's name, address, phone number, email address, date of birth, ID number, and any other information that can be used to identify a person.
The Act establishes the office of the Data Protection Commissioner, which is responsible for overseeing and enforcing compliance with the Act. The Commissioner has the power to investigate and impose penalties on entities that violate the provisions of the Act.
The Act requires entities to obtain the consent of individuals before collecting their personal data, and to use such data only for the purposes for which it was collected. Entities are also required to ensure the security and confidentiality of personal data, and to notify individuals in the event of a data breach.