The Kenya Data Protection Act 2019 (DPA) sets out obligations for organisations that process personal data. When that processing happens in the cloud, several practical questions appear immediately:
- Where does the data reside?
- Who can access it?
- How is consent or other legal basis recorded?
- What happens in a breach?
- Can the organisation demonstrate accountability?
A useful checklist includes:
Governance
- Appoint a Data Protection Officer where required.
- Maintain a record of processing activities.
- Conduct Data Protection Impact Assessments for high-risk processing.
Technical
- Prefer regions that support your residency requirements.
- Encrypt data in transit and at rest.
- Apply least-privilege identity and access management.
- Log administrative and data-access events.
Contracts
- Ensure processor agreements exist with cloud providers and sub-processors.
- Clarify international transfer mechanisms if data leaves Kenya.
This article is informational and does not constitute legal advice. Organisations should obtain counsel for their specific circumstances.
Fox Height designs cloud architectures with DPA considerations as a default constraint rather than a later retrofit.
security
Kenya Data Protection Act 2019 — Cloud Compliance Checklist
Complete checklist to ensure your cloud infrastructure complies with Kenya's Data Protection Act 2019. Legal, technical, and governance requirements.
2026-05-20 · 10 min read
dpa
compliance
kenya
security
privacy