Back to all articles

How much is the fine for a data breach in Kenya?

Kenya's data breach fine caps at KES 5 million or 1% of turnover under the Data Protection Act, 2019. Criminal penalties and civil claims explained for 2026.

LEContent TeamSep 4, 2026 — 8 min read
How much is the fine for a data breach in Kenya?

Kenya's data breach fine tops out at KES 5 million, or 1% of the company's annual turnover from the preceding financial year — whichever figure is lower — under Section 62 of the Data Protection Act, 2019. That administrative cap is only part of the bill: a director or employee found criminally responsible for the breach can face a separate fine of up to KES 3 million or up to 10 years in prison, or both, and the affected individuals can still sue for damages on top of whatever the Office of the Data Protection Commissioner (ODPC) imposes.

TL;DR
  • The administrative fine for a data breach in Kenya caps at KES 5 million or 1% of annual turnover, whichever is lower.
  • Criminal liability under the Data Protection Act, 2019 can add a fine of up to KES 3 million or 10 years imprisonment for the person responsible.
  • Breach notification to the ODPC is required within 72 hours under the Data Protection (General) Regulations, 2021.
  • Civil damages from a lawsuit brought by affected individuals sit outside the fine entirely and have no statutory cap.
  • The ODPC sets the actual fine case by case; the KES 5 million figure is a ceiling, not a starting point.
Data breach penalties in Kenya
KES 5,000,000
Max administrative fine
Data Protection Act, 2019, Section 62
1%
Or turnover cap, if lower
KES 3,000,000
Max criminal fine
For the individual responsible
72 hours
Breach notification deadline

Why this matters

A lot of business owners assume a data breach fine works like a traffic ticket — one fixed number, applied uniformly. It doesn't. The ODPC has discretion over the actual figure, and the administrative and criminal penalties stack on top of each other rather than replacing one another.

If you run a company that collects customer data — an online store, a SACCO, a clinic, an HR platform — the exposure isn't just the fine itself. It's also the possibility that a customer whose data leaked can sue a company for a data breach separately, in civil court, for damages that have no statutory ceiling at all.

How much is the fine for a data breach in Kenya?

Three separate exposures apply in 2026, and they don't cancel each other out.

Penalty typeMaximum amountWho paysLegal basis
Administrative fineKES 5,000,000 or 1% of annual turnover, whichever is lowerThe data controller or processor (the company)Data Protection Act, 2019, Section 62
Criminal fineKES 3,000,000, or imprisonment up to 10 years, or bothThe individual found responsibleData Protection Act, 2019, general penalty provisions
Civil damagesNo statutory capThe company, paid to affected individualsOrdinary civil claim, brought separately in court

The administrative fine is the one most companies actually face. The criminal penalty applies where the ODPC or a prosecutor establishes individual wrongdoing — deliberate misuse of data, obstruction of an investigation, or unlawful disclosure — rather than a straightforward failure of security controls.

Administrative fine: up to KES 5 million or 1% of turnover

This is the ODPC's primary enforcement tool and the number most people mean when they ask about the fine for a data breach in Kenya. It is a ceiling, not a default. The 1% turnover test matters for smaller entities: where 1% of last year's turnover is less than KES 5 million, that lower figure becomes the cap.

A company facing an ODPC investigation in 2026 wants a compliance advocate involved before responding to any notice, not after. Getting that response wrong — denying the breach, missing deadlines, or filing an incomplete incident report — tends to push the ODPC toward the higher end of its discretion. A regulatory compliance lawyer in Kenya can help structure that response before the fine is set.

Criminal penalty: up to KES 3 million or 10 years imprisonment

The criminal route targets the person, not the company. It applies where someone — a system administrator, a manager, a third-party processor — deliberately mishandled personal data, disclosed it without authorization, or obstructed the ODPC's investigation. This penalty runs independently of the administrative fine; a business can be fined under Section 62 while an employee is separately prosecuted under the Act's general penalty provisions.

Civil damages: no fixed cap

Beyond both fines, anyone whose personal data was compromised can bring a civil claim for damages. Kenyan courts don't apply a statutory cap to this figure the way the Data Protection Act caps the administrative fine — the amount depends on the harm proven in that specific case.

Why the fine amount varies

The ODPC does not apply the KES 5 million ceiling automatically. Several factors push the actual fine up or down:

  • Severity and scale of the breach — the number of individuals affected and the sensitivity of the data. Health records and financial data weigh heavier than a leaked mailing list.
  • Whether the breach was reported within 72 hours — the Data Protection (General) Regulations, 2021 require notification to the ODPC within that window. Late or missing notification is an aggravating factor.
  • Prior compliance history — a first-time lapse from a company with a documented data protection policy is treated differently from a repeat offender.
  • Cooperation during the investigation — companies that respond promptly and transparently generally fare better than those that stonewall.
  • Turnover of the company — the 1% test means larger companies can face fines closer to the KES 5 million ceiling, while smaller entities are capped lower by the same rule.
  • Evidence of remedial action — fixing the underlying security gap and notifying affected individuals directly can factor into how the ODPC sets the final number.

Talk to an advocate before you respond

A 15-minute video consultation with an LSK-verified advocate on data breach exposure.

What counts as a data breach under Kenyan law?

A data breach under the Data Protection Act, 2019 covers any unauthorized access, loss, disclosure, or alteration of personal data — whether it happens through a hack, a misconfigured database, an employee sending information to the wrong person, or a lost device holding customer records. The Act does not require the breach to be malicious for liability to attach. Negligent handling of personal data is enough to trigger ODPC scrutiny in 2026.

Do I have to report a data breach to the ODPC?

Yes, notification to the ODPC is required within 72 hours of becoming aware of a breach under the Data Protection (General) Regulations, 2021. Where the breach is likely to cause harm to the people affected, the company also has to notify those individuals directly, separate from the regulatory filing.

Can I sue a company for a data breach in Kenya?

Yes, and a civil claim for damages sits entirely outside the ODPC's administrative fine, with no statutory cap. If your personal data was exposed through a company's negligence, you can pursue damages in addition to any regulatory penalty the ODPC imposes on that company.

Lex Africa connects people in Kenya and the diaspora with LSK-verified advocates for paid 15-minute video consultations — the practical option when you need someone to read the facts of a breach before you decide whether to file or how to respond. This page is general information, not legal advice.

FAQ

How much is the fine for a data breach in Kenya in 2026?

The administrative fine caps at KES 5 million, or 1% of the company's annual turnover from the preceding financial year, whichever is lower. A separate criminal fine of up to KES 3 million or 10 years imprisonment can apply to the individual responsible.

Who enforces data breach fines in Kenya?

The Office of the Data Protection Commissioner (ODPC) investigates breaches and sets administrative fines under the Data Protection Act, 2019. Criminal penalties are pursued through the courts once liability is established.

Is the KES 5 million fine per breach or per company?

It applies per enforcement action against the data controller or processor, not per affected individual. The 1% turnover test can lower that ceiling depending on the company's size.

Does a small business face the same fine as a large company?

No. The 1% of annual turnover test generally caps a small business below the KES 5 million flat figure, because 1% of a smaller turnover produces a smaller number.

Can a company be fined and sued at the same time for the same breach?

Yes. The ODPC's administrative fine and a civil damages claim from affected individuals run independently of each other. Paying the fine does not settle a civil claim.

What happens if a company does not report a breach within 72 hours?

Late or missing notification under the Data Protection (General) Regulations, 2021 is treated as an aggravating factor by the ODPC. It generally pushes the eventual fine toward the higher end of the regulator's discretion.

Can an individual employee go to prison for a data breach?

Yes. Someone found criminally responsible for unlawful disclosure or obstruction can face up to 10 years imprisonment, a fine of up to KES 3 million, or both, separate from any fine against the company.

Do I need an advocate to respond to an ODPC notice?

Not legally, but the response shapes the fine. An advocate who handles regulatory compliance work can review the incident report before it is filed with the ODPC.

One last thing

The KES 5 million figure is a maximum, not a starting point, and cooperation with the ODPC's investigation moves the outcome more than most companies expect. The larger risk in 2026 usually is not the administrative fine at all — it is the civil claim that follows once affected customers learn their data was exposed, because that number has no cap.

You might also like