LegalEase templates are professionally drafted legal documents and are intended as starting points only.   ·   They do not constitute legal advice. For jurisdiction-specific compliance or complex transactions, please consult a qualified legal practitioner in your jurisdiction.       
Business Setup

Privacy Policy

A Privacy Policy discloses how your business collects, uses, and protects personal data. Required under the Kenya Data Protection Act 2019 for any website or app handling user data.

This template is a professionally drafted legal document. It does not constitute legal advice. LegalEase accepts no liability beyond the cost of the document purchased. For complex transactions, we recommend review by a qualified legal practitioner.
Generate this document

Legally sound

Drafted to comply with Kenyan law and international common law standards.

Ready in seconds

Fill in your details and get a complete, professional document instantly.

Fully customisable

Every clause is tailored to your specific situation and requirements.

Who needs this document

You need a privacy policy if your website, app, or business collects, stores, or processes any personal data — names, email addresses, payment details, location data, or any other information that identifies or can identify a person. It is legally required under the Kenya Data Protection Act 2019.

What this document covers

Data controller details
Types of personal data collected
Purpose and legal basis for processing
Data retention periods
Third-party data sharing
User rights (access, correction, deletion)
Cookie policy
Cross-border data transfers if any
Contact details for data requests
Compliance with Kenya Data Protection Act 2019

Frequently Asked Questions

Is a privacy policy legally required in Kenya?
Yes. The Kenya Data Protection Act 2019 requires any person or organisation that collects, processes, or stores personal data to have a privacy notice explaining what data is collected, why, how it is used, how long it is retained, and what rights data subjects have. Failure to comply can result in penalties from the Office of the Data Protection Commissioner.
Does Kenya's Data Protection Act apply to international websites with Kenyan users?
Yes. The KDPA applies to any processing of personal data of Kenyan residents, regardless of where the data processor is based. An international website targeting Kenyan users must comply with the KDPA, similar to how GDPR applies to any site processing EU users' data.
Is a privacy policy required in common law countries?
Most common law countries have data protection or privacy legislation requiring a privacy policy: the UK GDPR (post-Brexit), Australia's Privacy Act, India's Digital Personal Data Protection Act 2023, and Nigeria's NDPR. A well-drafted privacy policy addressing these frameworks reduces compliance risk across multiple jurisdictions.
What rights do Kenyan users have under the Data Protection Act 2019?
Under the Kenya Data Protection Act 2019, data subjects have the right to: access their personal data, correct inaccurate data, object to processing, request deletion ('right to be forgotten' in limited circumstances), receive data in a portable format, and withdraw consent at any time. Your privacy policy must inform users of these rights.
When must I register as a data controller in Kenya?
Under the KDPA 2019 and the Data Protection (Registration of Data Controllers and Data Processors) Regulations 2021, organisations that process personal data must register with the Office of the Data Protection Commissioner (ODPC). Registration is required before or promptly after commencing data processing activities. Failure to register can attract fines.
Does my privacy policy need to mention cookies in Kenya?
Yes. Cookies that collect personal data (such as tracking or analytics cookies) require disclosure and, in many cases, user consent under the KDPA 2019. Your privacy policy should explain what cookies are used, why, and how users can manage or disable them.
Is a Kenya privacy policy compliant with UK GDPR?
The KDPA 2019 is broadly aligned with GDPR principles but is not identical. For websites with UK users, UK GDPR (retained post-Brexit) requires specific disclosures including a lawful basis for processing, data retention periods, and UK-specific rights. A policy drafted only for the KDPA may not fully satisfy UK GDPR — consider dual compliance if you have significant UK traffic.