Sector · hotels, lodges and restaurants
The regulator is already looking at hospitality.
Hospitality firms are named in the Third Schedule of the 2021 Registration Regulations. Registration with the ODPC is mandatory regardless of size — a six-room guest house is covered on the same basis as a chain — and unlike most sectors, there is already an enforcement record to read.
01 The duty
The KES 5,000,000 in the first paragraph is a turnover threshold for the exemption, not a fine. Two different figures, and they are easy to blur.
Longer version, with the fees and the process: ODPC registration in Kenya.
Size is not a defence in this sector
Outside the listed sectors a Kenyan business is exempt from registration only if its annual turnover is below KES 5,000,000 and it has fewer than ten employees — both conditions. Hospitality is a listed sector, so that test does not apply to you at all. Registration costs between KES 4,000 and KES 40,000 depending on your size, and the certificate runs for 24 months.
Registration is the beginning of it. The Act also expects security safeguards, audit trails and event monitoring, regular review and testing of your software for weaknesses, and notification of a breach within 72 hours.
02 Enforcement
We will not quote the statutory ceiling on its own to make a sale. It is a real cap, and it is the wrong number for almost every business reading this page — which is why the figure never appears here without the clause that limits it.
This is not a hypothetical risk
In September 2023 the ODPC fined Casa Vera Lounge, a hospitality business, KES 1.85 million. In December 2022 it fined Oppo Kenya KES 5 million. The regulator has since announced inspections of the hospitality sector.
An infringement can cost up to KES 5,000,000 or 1% of annual turnover, whichever is lower, per infringement. For a property of the size we usually work with, that means the turnover figure rather than the headline one — still a number worth avoiding, and the honest way to state it.
03 What you hold
You carry more personal data than most businesses your size
-
Guest identity documents
Names, passport and national ID details, taken at check-in, often photographed, often kept far longer than the stay.
-
Card and payment data
Through your booking system, your terminal and your reservations inbox.
-
A booking channel you do not control
Reservations arrive through platforms and agents whose systems are not yours, on email threads that are.
-
Seasonal staffing
High turnover makes shared logins and forgotten accounts the norm rather than the exception.
04 The attack that lands
Those three settings are published in your own DNS, so anyone can read them — you included. Whatever they say today, correcting them is configuration rather than procurement.
How to set them, in order: SPF, DKIM and DMARC explained.
An email from your address, asking for payment to a different account
The thing that actually costs hotels money is not exotic. It is a convincing message to a guest, a corporate client or a supplier, appearing to come from your domain, asking them to pay somewhere else. The victim pays. They then tell everybody that your hotel took their money, because as far as they can tell, it did.
Whether that message can be sent convincingly depends on three public settings on your domain: SPF, DKIM and DMARC. They are readable by anyone — including us, and including whoever is considering sending that email. Checking them costs nothing and takes minutes, and the fix is a change to public DNS records rather than software you have to buy.
05 Where to start
Honest qualification: reading DNS means asking whichever name servers answer for your domain, which may be run by you or by your hosting provider. That single lookup is the only contact a free snapshot involves.
The free snapshot, then a dated record of what you fixed
We read public records — DNS, mail records, certificate transparency logs and the domain registry. We never connect to your website or servers, never log in, and never test your defences. Nothing touches your property management system, your booking engine or your card terminal.
A person reads what those records show, ranks the three issues that matter most for a hospitality business, and writes it in language you can hand to your IT provider or act on yourself. It arrives by email in one to two business days.
If an inspection does come, a dated external exposure report and a record of what you changed afterwards is the kind of documentation the Act's "review and test regularly" duty expects. It is not compliance, and we will not tell you it is. It is evidence about one control, which is more than most properties this size can currently produce.
Fixing what the report finds has a published fixed price. Ongoing managed cover for a property or a group is quoted after a scoping conversation and carries no published figure — a six-room guest house and a five-property group are not the same job, and a price covering both would be an invention.
One free snapshot per domain every 30 days. We read public records — DNS, mail records, certificate transparency logs and the domain registry. We never connect to your website or servers, never log in, and never test your defences. This is not a penetration test.
Check what a stranger can see about your property
One domain, read from public records, written up by a person and emailed to you in one to two business days. Free, and nothing connects to your booking or payment systems.