Under Kenya’s Data Protection Act, 2019 (DPA), “personal data” is defined broadly, mirroring international standards like the GDPR. Here’s what it encompasses:
Definition
Personal data means any information relating to an identified or identifiable natural person. A person is “identifiable” if they can be identified, directly or indirectly, by reference to an identifier such as:
- A name
- An identification number (e.g., national ID, KRA PIN)
- Location data
- An online identifier (e.g., IP address, email address)
- Factors specific to their physical, physiological, genetic, mental, economic, cultural, or social identity
Sensitive Personal Data
The Act also singles out a special category called “sensitive personal data”, which requires higher protection due to its potential for harm or discrimination if misused. This includes data revealing:
- Race or ethnic origin
- Political opinions
- Religious or philosophical beliefs
- Health status (including mental health)
- Genetic and biometric data
- Property details
- Marital status
- Family details, including names of children, parents, spouse(s), or their address(es)
- Sex or sexual orientation of the data subject
- Criminal record/allegations of criminal conduct
Processing sensitive personal data generally requires explicit consent or another clear legal basis, along with stricter safeguards.
Scope of “Processing” Personal data protections apply to “processing,” which is defined very broadly to include collecting, recording, organizing, storing, adapting, retrieving, using, disclosing, or even erasing data whether done manually or via automated means.
Key Principle
The DPA emphasizes that personal data must be processed in a manner that respects the privacy of the data subject, and that data subjects retain rights over their data even after providing it to a third party (e.g., right to access, correct, or request deletion).
This definition is intentionally broad to capture the wide range of ways personal data can be collected and used in the modern digital economy.
