Children’s Data Protection in Kenya: Consent and Best Interests

Children now hand over personal data years before they understand what data is , to schools, learning apps, games and social platforms. Kenyan law treats their information with particular care: the Data Protection Act 2019 singles out children’s data and conditions its processing on consent and on the child’s best interests. Organisations serving under-eighteens need to know what that means in practice.

Kenyatta International Convention Centre in Nairobi
Photo: Francis Akuka for the Wikimedia Foundation (CC0), via Wikimedia Commons

What does the Data Protection Act say about children?

The Act defines a child as an individual who has not attained the age of eighteen years. Where processing rests on consent, that consent must come from the child’s parent or guardian. Beyond consent, the Act directs that children’s data be handled in a manner that respects the child’s best interests, and processing that targets or significantly affects children invites closer scrutiny. The statute is on Kenya Law, and the Data Protection (General) Regulations 2021 add procedural detail.

What does verifiable parental consent involve?


Verification should be proportionate to the risk of the processing. For a low-risk educational service, a verified parent account may suffice; for a service exposing children to contact with strangers or public sharing, stronger verification is expected. Two traps recur: collecting more data to verify age than the service itself needs, and treating a click-through statement as verification where the service clearly attracts underage users.

What does this mean for schools, platforms and edtech?

  • Privacy notices written so that children and their parents can genuinely understand them
  • Particular restraint on targeted advertising and profiling directed at minors
  • Data protection impact assessments for products and tools used by children
  • Security and access controls suited to environments where users cannot assess risk themselves
  • Staff and teacher training where schools collect data on behalf of providers

Complaints reach the Office of the Data Protection Commissioner from parents directly, and enforcement has shown little patience for services that knew their users included children and planned for nothing.

Where should an organisation start?


With a data map that identifies which products and records involve under-eighteens, followed by a gap review of notices, consent flows and assessments. Our governance and advisory practice conducts such reviews for schools, platforms and employers, and our practice areas page describes the firm’s wider compliance work.

For guidance on your specific situation, contact CS Advocates LLP , call, WhatsApp, or book a confidential consultation at our Westlands, Nairobi office.

Leave a Comment

Your email address and phone number are for verification only and will never be published. Comments appear after approval by the firm. Ask a question anonymously if you prefer.

+254 728 293 000 Email us +254 20 80 93 000 Confidential consultation