Kenyan data protection law

ODPC registration in Kenya: who must register, what it costs, and how

Registration is not a formality you can leave until the regulator writes to you, and for two of Kenya's largest SME sectors it does not depend on your size at all. Here is who must register, what it costs, what the form actually asks for, and what happens if you skip it.

The short answer

If your business processes personal data for any of the twelve purposes in the Third Schedule of the Registration Regulations 2021 — they include health administration and the provision of patient care, hospitality firms, education, financial services, property management and transport — registration with the Office of the Data Protection Commissioner is mandatory regardless of your size. A six-room guest house is covered on the same basis as a chain.

Outside those twelve purposes you are exempt only if your annual turnover is below KES 5,000,000 and you have fewer than ten employees — both conditions, not either. Registration costs KES 4,000 for a micro or small organisation, KES 16,000 for a medium one and KES 40,000 for a large one. Applications go through the ODPC's electronic portal, and a certificate is valid for 24 months.

Who has to register at all?

Section 18 of the Data Protection Act, 2019 creates the duty; the Data Protection (Registration of Data Controllers and Data Processors) Regulations, 2021 — Legal Notice No. 265 — set out how it works. The first question is not whether you register but as what, because that decides how many registrations you make and how many fees you pay.

Data controller
You determine the purpose and the means of processing. A hotel that decides to keep scans of guests' passports, a clinic that decides what goes in a patient file, an employer that runs payroll — all controllers.
Data processor
You process personal data on behalf of a controller, under a contract, with no decision-making power over the purpose or the means. A payroll bureau, an outsourced call centre, a booking-engine vendor. Employees of the controller are expressly excluded — your own staff are not processors.
Both
Common, and the Regulations provide for it: a controller may apply to register as both a controller and a processor, and pays the fee applicable to each. A clinic that also runs billing for two visiting consultants is in this position.

One trap worth knowing. If a processor uses personal data for anything other than what the controller instructed, it is treated as a controller for that processing, and carries a controller's liability for it. The same rule appears in section 42(3) of the Act and in regulation 4(4). A supplier who quietly reuses your customer list for their own marketing has not just breached your contract; they have changed their own legal position.

Which businesses must register regardless of size?

The Third Schedule to the Registration Regulations is headed "thresholds for mandatory registration" and lists twelve processing purposes. If you process personal data for one of them, you register — whatever your turnover, whatever your headcount.

Third Schedule — purposes requiring registration at any size
Purpose, as listed Who this usually means
Canvassing political support among the electorate Parties, campaigns, canvassing and voter-contact firms
Crime prevention and prosecution of offenders, including operating security CCTV systems Security firms — and the Schedule names CCTV explicitly, which reaches a great many ordinary businesses that run cameras
Gambling Betting shops, online betting and gaming operators
Operating an educational institution Schools, colleges, universities, training providers
Health administration and provision of patient care Hospitals, clinics, dental and diagnostic practices, medical labs
Hospitality industry firms, but excluding tour guides Hotels, lodges, guest houses, restaurants, bars, conference venues
Property management, including the selling of land Agents, land-selling companies, managing agents holding tenant files
Provision of financial services Banks, SACCOs, microfinance, insurers, lenders, payment businesses
Telecommunications network or service providers Operators, ISPs, resellers
Businesses wholly or mainly in direct marketing Agencies and list operators whose core business is marketing contact
Transport services firms, including online passenger hailing applications Bus and matatu operators, logistics firms, ride-hailing platforms
Businesses that process genetic data Genetic testing and research operations

Read the left column against what you do, not against what your industry is called. The Schedule is drafted by purpose, so a factory with a staffed gatehouse and cameras, or a landlord holding tenant files, may be inside it while thinking of itself as neither a security firm nor a property company. Where it is genuinely arguable, that is a question for your own legal advice rather than for a website.

Am I exempt because my business is small?

Regulation 13(2) sets the exemption, and the word that carries it is and. A controller or processor is exempt from mandatory registration where it has an annual turnover or revenue below KES 5,000,000 and fewer than ten employees. Meet one test and not the other and you are not exempt.

Two worked cases

  • An eight-room guest house on the coast, KES 3.1 million turnover, four staff. It meets both limbs of the exemption — and it registers anyway, because hospitality is in the Third Schedule and regulation 13(4) removes the exemption for Third-Schedule purposes.
  • A four-person design studio in Nairobi, KES 4.2 million turnover, no Third-Schedule purpose. Exempt from mandatory registration.

And then the part most summaries leave out. Regulation 13(3) provides that a business exempt from registration must still comply with Part IV of the Act (the principles and obligations of personal data protection) and Part VI (transfer of personal data outside Kenya). The design studio owes the principles, the security duty, the 72-hour breach notification and its clients' access rights exactly as the hotel does. It simply does not pay a fee or hold a certificate. What those duties look like in practice is the subject of the next guide.

What does it cost, and how long does it last?

The Second Schedule sets the fees. They are payable per data controller or data processor, which is why registering as both costs both.

Second Schedule — registration and renewal fees
Category Definition in the Regulations Registration Renewal, every 2 years
Micro and small 1 to 50 employees and annual turnover or revenue of at most KES 5,000,000 KES 4,000 KES 2,000
Medium 51 to 99 employees and annual turnover or revenue between KES 5,000,001 and KES 50,000,000 KES 16,000 KES 9,000
Large More than 99 employees and annual turnover or revenue above KES 50,000,000 KES 40,000 KES 25,000
Public entities Offering government functions, regardless of employees or turnover KES 4,000 KES 2,000
Charities and religious entities Offering charity or religious functions, regardless of turnover KES 4,000 KES 2,000

A certificate of registration is valid for twenty-four months from the date it is issued.

What does the registration form ask for?

Form DPR1, in the First Schedule, is seven sections. Knowing them in advance turns the application from an afternoon of hunting into about an hour.

  1. Basic details. Whether you are registering as a controller or a processor; name, postal address, telephone, email, county and country; your sector; and your legal establishment. Public bodies also name their state or county department.
  2. Personal data. A table: the categories of data subjects (employee, client, student, supplier, shareholder), a description of the personal data processed (name, address, identification number) and the purpose of each (payroll, invoicing, know your customer, registration).
  3. Sensitive personal data. Whether it applies and, if so, which categories: racial or ethnic origin, political opinion or adherence, religious or philosophical beliefs, marital status and family details, physical or mental health or condition, sexual orientation, and biometric data — each with its purpose. Every clinic is answering "applicable" here.
  4. Transfer of data outside Kenya. Whether it applies, and which countries. A hotel using an overseas booking platform, or a clinic using cloud software hosted abroad, is transferring data outside Kenya even if nobody in the business thinks of it in those words.
  5. Measures for protection of personal data. A five-row table: identify the risks to personal data — unauthorised access or disclosure, theft — and, against each, the safeguards, security measures and mechanisms you have implemented.
  6. Number of employees, by band.
  7. Previous year's annual turnover, by band.

Regulation 5(2) adds the attachments: a copy of your establishment documents, particulars and contact details of the controller or processor, a description of the purposes for which personal data is processed, and a description of the categories of personal data.

How do I actually apply?

  1. Apply electronically. Regulation 17 requires applications to be submitted through the electronic means provided on the Office's website. Start from the ODPC's own site rather than an intermediary — the portal and the payment channel have both changed since the Regulations came into force, and a two-year-old blog post may send you somewhere that no longer exists.
  2. The Data Commissioner verifies what you supplied (regulation 7). This is not a rubber stamp.
  3. If satisfied, the Commissioner issues the certificate within fourteen days and enters your particulars in the register (regulation 8).
  4. If refused, you are told in writing, with reasons, within twenty-one days (regulation 10). The grounds are insufficient particulars, a failure to provide appropriate safeguards for the privacy of data subjects, or being in violation of the Act or the Regulations. You may apply afresh once you have complied with the refusal notice.

The register is public. Under regulation 14(2), the Office publishes a list of registered controllers and processors on its official website every thirty days, so a customer, a corporate client's procurement team or an insurer can check whether you are on it. That cuts both ways, and it is one of the more practical reasons to register early rather than last.

Renewing, and telling the ODPC when things change

  • Renewal. A certificate runs for twenty-four months. Renewal is applied for after expiry on Form DPR2 with the renewal fee. Where the renewal covers a distinct purpose or categories of data other than those you registered for, the Commissioner runs the verification process again.
  • Changes of particulars. Regulation 15 requires you to notify the Data Commissioner in writing within fourteen days of a change to your particulars — a new contact address, a new processing purpose, a change of data protection officer. Failing to do so is itself an offence.

Put the expiry date in a calendar on the day the certificate arrives, and put the reminder a month earlier. Continuing to process personal data after your certificate has expired, without renewing, is one of the three offences the Regulations name.

What happens if I do not register?

Two separate exposures, and they are routinely confused with each other.

A criminal offence, under the Regulations

Regulation 18 makes it an offence to process personal data without registering, to give false or misleading information for the purpose of registration, or to fail to renew and keep processing after the certificate expires. The penalty is the general penalty in section 73 of the Act: on conviction, a fine not exceeding KES 3,000,000 or imprisonment for a term not exceeding ten years, or both.

An administrative fine, from the Data Commissioner

Separately, section 63 provides that for an infringement of the Act the maximum penalty the Data Commissioner may impose in a penalty notice is up to KES 5,000,000 or, in the case of an undertaking, up to one per cent of its annual turnover of the preceding financial year, whichever is lower.

None of this is theoretical. The Data Commissioner publishes determinations, and the enforcement record already includes a KES 5 million penalty against Oppo Kenya in December 2022 and a KES 1.85 million penalty against Casa Vera Lounge, a hospitality business, in September 2023. The Office has also announced inspections of the hospitality sector. Compensation to data subjects under section 65 sits on top of any of this, and is not capped by section 63 at all.

Does registering make my business compliant?

No — and be careful of anyone who says otherwise, ourselves included. Registration is an entry in a register and a certificate on a wall. The substantive duties live in Part IV of the Act and in the General Regulations 2021, and regulation 13(3) applies them to exempt businesses too: the eight principles, appropriate technical and organisational measures, notifying the Data Commissioner of a qualifying breach within seventy-two hours, and answering a data subject's access request within seven days, free of charge.

Registration is the cheapest and most visible of those duties. It is not the hardest one, and it is not the one a regulator will spend most of its time on.

What order should a small business do this in?

  1. Decide your role: controller, processor, or both. Everything else follows from it.
  2. Check the Third Schedule against what you actually do, purpose by purpose.
  3. If you are outside the Schedule, test the exemption honestly — turnover below KES 5 million and fewer than ten employees.
  4. Write down your processing: categories of data subjects, what data, why. Section 2 of the form asks for it, and section 5 is unanswerable without it.
  5. Write down your risks and the safeguards against each, before you open the form.
  6. Gather your establishment documents.
  7. Work out your fee band from both employees and turnover; ask the ODPC if you straddle.
  8. Apply through the ODPC's electronic route, and keep the receipt and the certificate.
  9. Diarise the 24-month expiry and remember the 14-day duty to notify changes.
  10. Then do the substantive security work — because that is the part the certificate does not cover, and the part a breach will test.

Where an exposure report fits

Section 5 of the registration form, and regulation 32(k) of the General Regulations 2021 — "regularly reviewing and testing software to uncover vulnerabilities of the systems supporting the processing" — both expect you to be able to say what you did about security, not what you intended to do. A dated, external review of what your domain publishes to the world is evidence for one part of that, and only that part.

That is the free snapshot Reconesys offers. You give us a domain and a work email, a person reads the public records, and you get a plain-language report in one to two business days. We read public records — DNS, mail records, certificate transparency logs and the domain registry. We never connect to your website or servers, never log in, and never test your defences. It is not a penetration test, it includes no monitoring or alerting, and it does not make your business compliant with the Act.

Questions

Questions people ask about this

Is ODPC registration mandatory for a small hotel in Kenya?
Yes. Hospitality industry firms are one of the twelve purposes listed in the Third Schedule of the Data Protection (Registration of Data Controllers and Data Processors) Regulations, 2021, and registration for a Third-Schedule purpose is mandatory regardless of turnover or number of employees. The Regulations state expressly that the small-business exemption does not apply to a business processing personal data for a Third-Schedule purpose. Tour guides are the one exclusion named in that entry.
How much does ODPC registration cost in Kenya?
KES 4,000 for a micro or small organisation (1 to 50 employees and annual turnover up to KES 5,000,000), KES 16,000 for a medium one (51 to 99 employees and turnover between KES 5,000,001 and KES 50,000,000), and KES 40,000 for a large one (more than 99 employees and turnover above KES 50,000,000). Public entities and charitable or religious entities pay KES 4,000 regardless of size. The fee is payable per data controller or data processor, so an organisation registering as both pays both.
How long is an ODPC registration certificate valid?
Twenty-four months from the date it is issued. Renewal is applied for after expiry on Form DPR2 with the renewal fee — KES 2,000, KES 9,000 or KES 25,000 depending on size. Continuing to process personal data after the certificate has expired, without renewing, is one of the offences the Regulations name.
What is the penalty for not registering with the ODPC?
There are two, and they are separate. Processing personal data without registering is an offence under the Registration Regulations, carrying the general penalty in section 73 of the Act: on conviction, a fine not exceeding KES 3,000,000 or imprisonment not exceeding ten years, or both. Separately, the Data Commissioner may impose an administrative fine of up to KES 5,000,000 or 1% of the annual turnover of the preceding financial year, whichever is lower, per infringement.
Do I have to register if my turnover is under KES 5 million?
Only if your processing falls outside the Third Schedule. The exemption requires both an annual turnover below KES 5,000,000 and fewer than ten employees — both conditions, not either — and it does not apply at all to processing for a Third-Schedule purpose. An exempt business also still has to comply with Part IV and Part VI of the Act, so exemption from registering is not exemption from the law.

Sources

Every legal and statistical claim above traces to one of these. We link to the publisher's own copy rather than to a summary, and name the provision in full so the citation survives a broken link.

Sources

  1. Data Protection Act, 2019 (No. 24 of 2019) — PDF — Office of the Data Protection Commissioner

    Sections 18 to 22 (registration), section 63 (administrative fines) and section 73 (general penalty).

  2. Data Protection (Registration of Data Controllers and Data Processors) Regulations, 2021 — Legal Notice No. 265, PDF — Office of the Data Protection Commissioner

    Regulations 4, 5, 7 to 11, 13 to 15, 17 and 18; First Schedule (Form DPR1), Second Schedule (fees), Third Schedule (thresholds for mandatory registration).

  3. Data Protection (General) Regulations, 2021 — Legal Notice No. 263, PDF — Office of the Data Protection Commissioner

    Regulation 9 (data access requests, seven days, free of charge) and regulation 32 (integrity, confidentiality and availability), cited for what registration does not cover.

  4. Determinations — Office of the Data Protection Commissioner

    The published penalty decisions, issued under regulation 14 of the Data Protection (Complaints Handling Procedure and Enforcement) Regulations, 2021 — the source for the enforcement record described above.

  5. Register of data handlers — Office of the Data Protection Commissioner

    The public register, republished every thirty days under regulation 14(2).

  6. ODPC data portal — Office of the Data Protection Commissioner

    The electronic route regulation 17 requires applications to be submitted through. Start from the regulator rather than an intermediary; the route and the payment channel have both changed since the Regulations came into force.

Read next

Read next