Back to news
Data ProtectionAug 3, 20266 min read

Why Many Kenyan Businesses Need to Register with the Office of the Data Protection Commissioner

Victor Assanga

Victor Assanga

Technical Lead

Why Many Kenyan Businesses Need to Register with the Office of the Data Protection Commissioner

As businesses increasingly rely on customer information to deliver products and services, compliance with Kenya's data protection laws has become a legal necessity rather than an option. Many organizations remain unaware that they may be required to register with the Office of the Data Protection Commissioner (ODPC), exposing themselves to regulatory action, financial penalties, and reputational damage.

Understanding the Law

The Data Protection Act, 2019 was enacted to safeguard the privacy rights of individuals by regulating how personal data is collected, stored, processed, shared, and disposed of. The law established the Office of the Data Protection Commissioner (ODPC) as the authority responsible for overseeing compliance and enforcing data protection requirements in Kenya.

One of the key obligations under the law is the registration of certain data controllers and data processors.

Who Should Register?

Not every business is required to register. However, organizations that process personal data in significant quantities or handle sensitive personal information are generally required to do so.

Examples of businesses and organizations that may need to register include:

  • Banks, SACCOs, and microfinance institutions
  • Insurance companies
  • Hospitals, clinics, pharmacies, and medical laboratories
  • Schools, colleges, universities, and training institutions
  • Telecommunications and Internet Service Providers
  • E-commerce businesses and online marketplaces
  • Human Resource and recruitment agencies
  • Security companies using CCTV or biometric systems
  • Hotels and hospitality establishments
  • Digital marketing agencies
  • Software companies and SaaS providers
  • Cloud service providers
  • Courier and logistics companies
  • Property management companies
  • NGOs, charities, and faith-based organizations maintaining donor or beneficiary databases
  • Manufacturers and retailers operating customer loyalty programmes
  • Employers maintaining employee records

In general, if your organization routinely collects information such as names, phone numbers, national identification numbers, email addresses, biometric information, financial details, health records, or location data, it should assess whether registration is mandatory.

What Is Personal Data?

Personal data refers to any information that can identify an individual either directly or indirectly.

Examples include:

  • Full names
  • National ID or passport numbers
  • Mobile phone numbers
  • Email addresses
  • Residential addresses
  • Bank account details
  • Photographs
  • Vehicle registration linked to an individual
  • Biometric information such as fingerprints or facial recognition
  • Health records
  • GPS location data

Sensitive personal data attracts even higher levels of protection under Kenyan law.

Data Controller vs Data Processor

Many businesses confuse these two important legal terms.

Data Controller

A data controller is the organization that decides:

  • Why personal data is collected.
  • What personal data is collected.
  • How it will be used.
  • How long it will be retained.
  • A hospital collecting patient records.
  • A bank maintaining customer accounts.
  • A school keeping student records.
  • A retailer operating a customer loyalty programme.

The controller bears primary responsibility for ensuring compliance with the Data Protection Act.

Data Processor

A data processor processes personal data on behalf of a data controller.

They do not decide why the data is collected but simply process it according to instructions.

Examples include:

  • Payroll processing companies
  • Cloud hosting providers
  • IT outsourcing firms
  • Email marketing platforms
  • Call centres handling customer information
  • Document archiving companies

For example, if a hospital stores patient records in a cloud platform, the hospital remains the data controller while the cloud hosting provider acts as the data processor.

Some organizations perform both roles depending on the services they provide.

Why Registration Matters

Registration demonstrates that an organization acknowledges its legal responsibilities regarding personal data.

It also promotes:

  • Accountability
  • Transparency
  • Better information governance
  • Improved cybersecurity practices
  • Customer confidence
  • Stronger business reputation

Increasingly, clients, government agencies, and international partners are requesting evidence of data protection compliance before entering into contracts.

For organizations seeking international business opportunities, demonstrating compliance can become a competitive advantage.

Consequences of Not Registering

Failure to register where required can have serious consequences.

Potential implications include:

  • Regulatory investigations by the Office of the Data Protection Commissioner.
  • Enforcement notices requiring corrective action.
  • Administrative penalties as provided under the Data Protection Act and applicable regulations.
  • Suspension or restriction of data processing activities.
  • Increased exposure to civil claims from affected individuals.
  • Loss of customer trust and reputational damage.
  • Difficulties participating in government procurement or contracts requiring evidence of compliance.

Beyond legal sanctions, organizations that fail to comply may find themselves at a disadvantage as customers become increasingly aware of their privacy rights.

Registration Is Only the Beginning

Registration alone does not make an organization compliant.

Businesses should also implement comprehensive privacy and security measures, including:

  • A Data Protection Policy.
  • Employee awareness and training.
  • Privacy notices for customers and staff.
  • Data processing agreements with service providers.
  • Appropriate technical and organizational security controls.
  • Procedures for responding to data breaches.
  • Mechanisms for handling requests from individuals exercising their data protection rights.
  • Regular audits and reviews of data processing activities.

Compliance should be viewed as an ongoing governance process rather than a one-time administrative exercise.

A Growing Priority for Kenyan Businesses

Kenya's digital economy continues to expand rapidly, with businesses collecting more personal data than ever before. Whether operating a physical shop, an online platform, a healthcare facility, a financial institution, or a technology company, organizations have a responsibility to protect the information entrusted to them.

Understanding whether your organization is a data controller, a data processor, or both is an important first step. Where registration is required, timely compliance not only helps avoid regulatory action but also demonstrates a commitment to protecting customers, employees, and business partners.

As data privacy becomes an increasingly important aspect of doing business, compliance with Kenya's Data Protection Act is no longer simply a legal obligation—it is a hallmark of responsible and trustworthy business practice.

Victor Assanga

Victor Assanga

Technical Lead

Find News that Meet WithYour Needs