Genetic data sits inside Kenya’s Data Protection Act as a named category of sensitive personal data, but the Act never defines it separately from the DNA-based biometric data it overlaps with. A genomic testing provider or research entity operating in Kenya has to work from that thin, overlapping framework, and from one regulation that does single out genetic data directly: the mandatory impact assessment.
Genetic Data Is Named but Never Defined
Section 2 of the Data Protection Act 2019 lists genetic data among the categories making up sensitive personal data, alongside health status, alongside other protected categories, but the Act does not go on to define what counts as genetic data on its own terms. The same section separately defines biometric data to include data resulting from technical processing of a natural person’s biological characteristics, which on its face also captures DNA-derived data. The practical effect is that a genomic testing provider handling raw sequencing output, variant calls, or a family history intake form is very likely handling both a named sensitive-data category and biometric data at the same time, without a single provision in the Act clarifying which specific obligations attach to genetic data as distinct from biometric data generally. Our companion piece on registering as a data handler with the ODPC covers the baseline registration and data protection officer obligations that apply to any entity processing this category, obligations a genomic testing provider must satisfy in addition to the genetic-specific points below.
The One Provision That Actually Singles Out Genetic Data: The Mandatory DPIA
Regulation 49(1)(c) of the Data Protection (General) Regulations 2021, Legal Notice No. 263 of 2021, requires a data protection impact assessment specifically where processing involves biometric or genetic data. This is the clearest genetic-specific obligation in Kenya’s data protection framework, and it is a real procedural requirement, not a general recommendation: section 31(5) of the Act requires the DPIA report to be submitted to the Data Commissioner at least 60 days before processing begins. A genomic testing provider planning to launch a new testing service, or expand an existing one to a new data category, needs to build that 60-day lead time into its launch timeline, and needs to actually produce the DPIA report rather than treating the assessment as an internal checklist exercise.
Cross-Border Transfer of Genetic Data Needs Specific Consent
Section 49(1) of the Act and regulation 46(2) of the same 2021 Regulations require explicit consent from the data subject specifically for cross-border transfer of sensitive personal data, a category genetic data falls within under section 2. This matters directly for genomic testing, where sequencing is frequently outsourced to a laboratory outside Kenya, or where a testing provider uses an overseas reference database or interpretation service. General consent to processing at intake is not the same as the specific transfer consent regulation 46(2) requires; a provider needs a separate, clear consent step covering the transfer itself before sending a sample or its sequencing data abroad. Regulation 42 sets out an alternative path where the destination country offers appropriate safeguards, including recognition under the Malabo Convention, a reciprocal data protection agreement, or binding corporate rules, but a provider relying on that route rather than consent should confirm the specific safeguard actually applies to its transfer, rather than assuming a destination country qualifies.
Research Use Sits Outside the Commercial Framework
Genomic and genetic research conducted for scientific purposes in Kenya runs through a separate track from commercial genetic testing. The National Commission for Science, Technology and Innovation issues biomedical research ethics guidelines, and the Kenya Medical Research Institute’s Scientific and Ethics Review Unit reviews and approves research protocols involving human genetic material. This research-ethics framework governs academic and institutional research use of genetic data; it does not license or regulate a commercial genetic-testing provider selling sequencing or interpretation services directly to consumers or clinicians, and a provider should not assume that NACOSTI or KEMRI/SERU approval of a research protocol substitutes for the Data Protection Act obligations that apply to its commercial processing activity.
A Constitutional Gap Worth Flagging to Clients
Article 27(4) of the Constitution prohibits discrimination on the ground of health status, among other listed grounds, but does not list genetic status as a separate protected ground. Kenya has legislated a sector-specific non-discrimination protection before, in the HIV and AIDS Prevention and Control Act 2006, which addresses discrimination on the basis of actual or perceived HIV status directly. No equivalent statute yet extends that kind of explicit protection to genetic status or predictive genetic information, such as a genetic predisposition disclosed through testing. A genomic testing provider or an employer considering genetic screening should treat this as an open legal gap rather than an area with settled statutory protection, and should build in contractual and policy safeguards against discriminatory use of genetic results rather than relying on an constitutional or statutory provision that does not yet exist for this specific ground.
What This Means for a Genomic Testing Provider
A provider operating in Kenya should register under the Data Protection Act and designate a data protection officer as the baseline step, then treat the DPIA under regulation 49(1)(c) as a mandatory, time-sensitive filing rather than optional documentation, submitted at least 60 days before any new genetic data processing activity begins. Cross-border transfers need their own explicit consent step under regulation 46(2), separate from general processing consent, unless a specific regulation 42 safeguard genuinely applies. Research collaborations should be checked against NACOSTI and KEMRI/SERU requirements separately from, not instead of, Data Protection Act compliance, and any genetic screening programme should account for the absence of an explicit statutory non-discrimination protection specific to genetic status.
How We Can Help
Clay & Associates Advocates advises genomic testing providers and life sciences research entities on Data Protection Act compliance for genetic and biometric data, including impact assessments and cross-border transfer consent. Our guide to registering as a data handler with the ODPC is a useful companion covering the registration and data protection officer requirements that apply alongside the genetic-specific points here. Contact our Life Sciences & Healthcare practice to prepare a data protection impact assessment for a genetic data processing activity.
Sources: Data Protection Act 2019, sections 2, 31(5), and 49(1); Data Protection (General) Regulations 2021, Legal Notice No. 263 of 2021, regulations 42, 46(2), and 49(1)(c); Constitution of Kenya 2010, Article 27(4); HIV and AIDS Prevention and Control Act 2006; National Commission for Science, Technology and Innovation, biomedical research ethics guidelines; Kenya Medical Research Institute, Scientific and Ethics Review Unit.
Frequently asked questions
Does the Data Protection Act define genetic data separately from biometric data?
No. Section 2 names genetic data as a category of sensitive personal data but does not define it separately, and its definition of biometric data also captures DNA-derived data, so the two categories overlap in practice.
Do I need a data protection impact assessment before offering a new genetic test?
Yes. Regulation 49(1)(c) makes a DPIA mandatory for processing involving biometric or genetic data, and section 31(5) requires the report to be submitted to the Data Commissioner at least 60 days before processing begins.
Can I send a client’s sample or sequencing data to a laboratory outside Kenya?
Only with explicit consent to that specific cross-border transfer, under section 49(1) and regulation 46(2), unless a regulation 42 safeguard such as Malabo Convention recognition or binding corporate rules genuinely applies to the destination.
Does NACOSTI or KEMRI ethics approval cover my commercial testing service?
No. The NACOSTI and KEMRI/SERU frameworks govern research use of genetic material, not commercial genetic testing services, which remain separately subject to the Data Protection Act’s registration and processing requirements.



