Back to DPPC

Trust & compliance

East Africa Data Protection

A clear view of the privacy framework DPPC applies in Kenya and how we approach additional obligations across East Africa.

Effective and last reviewed: 27 September 2026

Kenya is our primary legal baseline. Uganda, Tanzania, Rwanda, Burundi and South Sudan each require a separate, fact-specific assessment when their rules apply.

Our compliance approach

DPPC uses Kenya’s Data Protection Act, 2019 and its principles of lawful, fair and transparent processing, purpose limitation, data minimisation, accuracy, storage limitation, security and accountability as its baseline.

Country-specific law may additionally apply depending on where an individual is located, the processing means used, and the engagement. There is no single binding East African Community privacy regulation that replaces national law. Read the practical handling details in our Privacy Policy.

Controls and accountability

  • Collect only information reasonably needed for the stated service, application or legal duty.
  • Limit access to authorised people and service providers with a business need.
  • Review higher-risk processing, including sensitive recruitment information and new technologies, and perform a data protection impact assessment where required.
  • Maintain proportionate security, response and deletion procedures, and notify regulators or affected people of qualifying breaches within applicable legal timeframes.
  • Assess processor terms and cross-border safeguards rather than assuming that regional operation alone permits a transfer.

Kenya

The primary framework is the Data Protection Act, 2019, supported by the 2021 General, Registration, and Complaints Handling and Enforcement Procedures Regulations. The regulator is the Office of the Data Protection Commissioner (ODPC).

DPPC assesses its controller and processor registration, data protection officer, impact assessment and breach-reporting duties against the applicable thresholds and processing activities. This page does not claim a registration or exemption status that has not been independently confirmed.

Uganda

Where its scope applies, DPPC seeks to align processing with Uganda’s Data Protection and Privacy Act, 2019 and 2021 Regulations. The supervisory office is the Personal Data Protection Office. Applicable access, correction, deletion, objection and cross-border requirements are assessed for the engagement.

Tanzania

Where its scope applies, DPPC seeks to align with Tanzania’s Personal Data Protection Act, 2022 and current requirements of the Personal Data Protection Commission, including assessing whether local registration or transfer requirements apply.

Rwanda

Where processing targets or uses means in Rwanda, DPPC seeks to align with Law No. 058/2021 relating to the Protection of Personal Data and Privacy and guidance from Rwanda’s Data Protection Office under the National Cyber Security Authority.

Burundi

Burundi adopted Law No. 1/03 on the Protection of Personal Data on 10 March 2026. This is a new and developing framework, and the status of its independent supervisory arrangements should be verified for each engagement. DPPC applies its Kenyan baseline while assessing any Burundian requirements that are in force.

South Sudan

As at this review date, South Sudan does not have a comprehensive data protection statute in force. Constitutional privacy and other applicable rules may still apply. DPPC therefore applies its Kenyan baseline and contractual safeguards to South Sudan-related processing and will review this statement if local legislation is enacted.

Rights, complaints and cross-border data

Depending on applicable law, individuals may request information, access, correction, deletion, objection or restriction, withdrawal of consent, portability, and review of solely automated decisions. Email support@dppc.co.ke to exercise a right; we may verify identity and explain any lawful limitation.

You may also complain to the regulator in the jurisdiction that applies: ODPC in Kenya, PDPO in Uganda, PDPC in Tanzania, or Rwanda’s Data Protection Office. For cross-border processing, DPPC seeks an allowed basis and safeguards appropriate to the destination, purpose and sensitivity.

Important compliance boundary

This statement describes DPPC’s intended compliance programme; publishing it does not certify or guarantee compliance. Effective compliance also depends on actual practices, regulator registrations, retention schedules, impact assessments, contracts, security controls and staff training.

Regional frameworks change. DPPC will review this statement periodically and should obtain qualified local legal advice for material or high-risk multi-country engagements.

Questions or rights requests? Email support@dppc.co.ke or call +254 720 695 231.