If your website uses Google Analytics, a Facebook pixel or any marketing tag, you are processing personal data. Here is what the Data Protection Act 2019 expects from your cookie banner, in plain English.
Updated October 2026 · general information, not legal advice
Kenya’s Data Protection Act 2019 does not mention cookies by name. But cookies and tracking pixels collect identifiers such as IP addresses and device IDs, and the Act treats those as personal data. So the general rules apply: you need a lawful basis for processing (section 30), you must follow the data protection principles (section 25), and where you rely on consent, that consent must meet the standard in section 32.
Strictly necessary cookies, such as those that keep a shopping cart working, can usually run without consent. Analytics, advertising and social media tracking generally rely on consent, which means they should not load until the visitor has agreed.
Enforcement is real. The Office of the Data Protection Commissioner (ODPC) issued its first fine in December 2022: KES 5 million against Oppo Kenya, after a person’s photo was used on social media without consent. The Act allows fines of up to KES 5 million or 1% of annual turnover, whichever is lower.
These steps reflect the Act’s consent requirements and widely accepted good practice; your lawyer can confirm what applies to your business.
Run a free scanAnalytics and marketing tags stay off until the visitor clicks Accept. Scrolling or continuing to browse is not consent.
A clear Decline button on the first screen, as visible as Accept, so refusing is a real choice.
Let visitors accept analytics but refuse marketing, rather than all-or-nothing.
Say what you collect, why, who receives it (for example Google or Meta) and how to withdraw consent, in plain language.
A “Cookie settings” link in the footer so visitors can change their mind at any time.
Keep a record of what each visitor agreed to and when, so you can show the ODPC if asked.
Work through these in order. Most small business sites can complete them in an afternoon.
| Step | What to do |
|---|---|
| 1. Find your trackers | List every script, cookie and pixel your site loads, including ones added by plugins |
| 2. Classify them | Mark each as strictly necessary, analytics or marketing |
| 3. Block until consent | Stop analytics and marketing tags loading until the visitor accepts |
| 4. Add a fair banner | Accept and Decline with equal prominence, plus category choices |
| 5. Publish a privacy notice | Explain what you collect, why, who receives it and visitors’ rights |
| 6. Add a settings link | Let visitors change or withdraw consent from the footer |
| 7. Check registration | Confirm whether your business must register with the ODPC as a data controller |
General information, not legal advice. Registration thresholds and exemptions are set out in the Data Protection (Registration of Data Controllers and Data Processors) Regulations, 2021.
If your online store sells to customers in Europe, the UK or California, their laws can apply too. GDPR and UK GDPR take a similar opt-in approach to Kenya, while US state laws such as CCPA focus on the right to opt out of selling or sharing data. A banner that only satisfies one law can fall short of another.
This is why many online stores show different notices to visitors from different regions, while keeping the strictest settings as the default.
Scans are free during launch, so you can see what your site loads today before deciding anything.
There is no cookie-specific law, but the Data Protection Act 2019 applies to cookies and trackers that collect personal data. Where you rely on consent, it must be freely given, specific, informed and unambiguous.
Analytics cookies are not strictly necessary, so the safest approach is to load Google Analytics only after the visitor accepts, and to explain in your privacy notice that data is shared with Google.
Generally no. Consent should be an active choice, such as clicking Accept, with a real option to decline. Continuing to browse is not a clear affirmative action.
The ODPC can impose fines of up to KES 5 million or 1% of annual turnover, whichever is lower, and can issue enforcement notices. Its first fine, in December 2022, was KES 5 million.
Many businesses that process personal data must register as data controllers or processors, subject to thresholds and exemptions in the 2021 registration regulations. Check with the ODPC or a lawyer.
Run a free Lexiscript scan. It lists every cookie, tracker and pixel your site loads and maps each one to the laws that apply.
Run a free Lexiscript scan and get a list of every tracker on your site, mapped to the Kenya DPA and seven other privacy laws.