ODPC Registration: Does Your Business Actually Need to Register?
Whether your business must register with Kenya's Office of the Data Protection Commissioner, how the exemption works, why "we're small" is not an answer, and what registration actually requires.
ODPC Registration: Does Your Business Actually Need to Register?
Of all the duties created by Kenya's Data Protection Act, registration with the Office of the Data Protection Commissioner is the one organisations most often miss — and the one easiest for a regulator to check. There is a register. You are either on it or you are not.
It is missed for a specific and understandable reason. Kenya's Act is closely modelled on the European GDPR, so teams with European compliance experience assume their knowledge transfers. Mostly it does. But GDPR has no general registration requirement, so nothing in that experience teaches you to look for one.
The exemption is not simply "we are small"
The Data Protection (Registration of Data Controllers and Data Processors) Regulations exempt certain smaller entities from mandatory registration, based on turnover and headcount thresholds.
If you stopped reading there, you would reach the wrong conclusion, because the exemption falls away where processing personal data is a core part of what the organisation does. And that carve-out captures far more businesses than owners expect.
It reaches organisations operating in health, education, financial services, recruitment and telecommunications. It reaches anyone conducting large-scale monitoring of individuals — which includes far more CCTV and workforce-tracking deployments than most directors realise. It reaches anyone processing sensitive personal data at scale: health records, biometrics, data revealing ethnicity or religious belief.
So a thirty-person medical practice may be required to register while a considerably larger manufacturer may not. Headcount is a threshold, not a principle. The principle is what you do with personal data.
Because the thresholds and the exemption criteria are set out in regulations that are periodically updated, we assess them against the current text rather than a remembered rule of thumb — and we would advise you to verify the position for your own organisation on odpc.go.ke, or to have it assessed, rather than rely on any article, including this one.
Controller, processor, or both?
Registration distinguishes the two roles, and organisations frequently misidentify themselves.
A data controller determines why and how personal data is processed. If you decide what to collect from your customers and what to do with it, you are the controller. You hold the primary legal obligations, and you cannot discharge them by pointing at a supplier.
A data processor processes personal data on a controller's behalf, on their instructions — a cloud host, a payroll bureau, a software company operating a system for a client.
Many organisations are both, in different relationships. A software firm is a processor for its clients' data and a controller of its own employees' and prospects' data. That is not a contradiction, and both roles may need to be reflected.
What registration involves
Registration is an application to the Data Commissioner describing your organisation and the nature of its processing: what personal data you handle, the purposes, the categories of data subject, whether you transfer data outside Kenya. Certificates are issued for a defined period and must be renewed, and material changes to your processing must be reflected.
The application itself is not difficult. What makes it difficult is that most organisations cannot honestly answer the questions, because they have never mapped where personal data actually lives.
Which is the real point
Here is what we have learned from doing this work: the registration form is not the project. The data mapping is the project.
You cannot describe your processing to a regulator until you know what personal data you hold, where it sits, why you are lawfully permitted to hold it, who you have shared it with, and how quickly you could delete it if someone exercised their right to erasure. Almost no organisation can answer those questions on demand at the start of an engagement.
Personal data is never only where the org chart implies. It is in a shadow spreadsheet on a laptop. It is in a marketing tool someone signed up for with a company card. It is in backups with no retention schedule. It is in a WhatsApp group. It is in a former employee's mailbox that was never deprovisioned.
That is why our data protection programmes begin with data mapping rather than with a privacy policy. A privacy notice written before the mapping is a work of fiction, and it is a work of fiction you have published, which is worse than not having one.
What happens if you should have registered and did not
The Act empowers the Data Commissioner to issue enforcement notices and to impose administrative penalties, calculated against a statutory ceiling or a percentage of annual turnover, whichever is lower. Data subjects hold a separate right to compensation for damage suffered.
We will not quote a figure here, because the specific ceilings sit in statute, enforcement practice continues to develop, and a number lifted from a blog post is exactly the kind of thing that gets repeated until it is wrong. If you want to understand your exposure, have it assessed against your actual processing.
In practice, though, the fine is rarely the largest cost. A published enforcement notice tells every customer and every prospective enterprise client that you did not do the basic thing. That is more expensive, and it lasts longer.
Where to start
Establish whether you are a controller, a processor, or both, in each of your relationships. Map where personal data actually lives — genuinely, not in theory. Establish and document a lawful basis for each processing activity. Then determine whether registration is required, and register if it is.
If that sounds like more than a form, it is. It is also the work that makes the form answerable.
Frequently asked questions
Does every business in Kenya have to register with the ODPC?
No. The registration regulations exempt certain smaller entities based on turnover and headcount thresholds. However, the exemption does not apply where processing personal data is a core activity — which captures organisations in health, education, financial services, recruitment and telecommunications, plus anyone conducting large-scale monitoring or processing sensitive personal data at scale. Size alone does not settle it. Because the thresholds are set in regulations that are periodically updated, verify the current position on odpc.go.ke or have your actual processing activities assessed.
We already comply with GDPR. Do we still need to register in Kenya?
Yes, if you meet the criteria. This is the most common error we see in foreign-owned and GDPR-fluent organisations. A GDPR programme gives you most of the substance — principles, data-subject rights, impact assessments, breach procedures — but GDPR has no general registration requirement, so nothing in it teaches you to look for Kenya's. It also will not have established a valid basis under Kenyan law for transferring personal data out of the country. Those two gaps are the easiest for a regulator to check.
Can we be both a data controller and a data processor?
Yes, and most organisations are, in different relationships. A software company is a processor when it operates a system holding its client's customer data, and a controller of its own employees', suppliers' and prospects' personal data. The roles describe a relationship, not an organisation. Identify them relationship by relationship, because the obligations differ.
What are the penalties for failing to register?
The Act allows the Data Commissioner to issue enforcement notices and impose administrative penalties, calculated against a statutory ceiling or a percentage of annual turnover, whichever is lower, and data subjects may separately claim compensation for damage suffered. We would rather assess your actual exposure than publish a figure that gets repeated out of context. In our experience the reputational cost of a published enforcement notice exceeds the financial penalty.
How long does it take to become compliant?
For a mid-sized organisation, a focused programme typically runs three to six months. Registration itself is fast once the groundwork is done. Data mapping is the long pole and the phase organisations consistently underestimate, because personal data lives in places nobody documented — shadow spreadsheets, unapproved SaaS tools, backups with no retention schedule. Building the operational machinery so compliance survives after the consultants leave takes the remainder.