Expert Guide

How to Register With the ODPC as a Data Controller or Processor in Kenya (2026)

How to Register With the ODPC

Kenya's Data Protection Act, 2019 requires organisations that collect and use personal data - customer names, phone numbers, ID numbers, health records, staff files - to protect it, and many must register with the Office of the Data Protection Commissioner (ODPC) as data controllers or data processors.

Controller or Processor?

  • A data controller decides why and how personal data is processed - for example, a school, clinic, SACCO or online shop collecting customer data.
  • A data processor processes data on behalf of a controller - for example, a payroll bureau, IT provider or call centre.

Many businesses are both.

Who Must Register

Registration is mandatory for organisations that process personal data, except those with an annual turnover below KES 5 million and fewer than 10 employees - unless they operate in sectors where registration is mandatory regardless of size. Those sectors include health, education, financial services, telecommunications, real estate, transport, hospitality, political parties, and businesses whose core activity is processing personal data. Check the current list on odpc.go.ke.

Registration Fees

CategoryRegistration feeRenewal fee
Micro and small (up to 50 staff, turnover up to KES 5 million)KES 4,000KES 2,000
Medium (51 to 99 staff, turnover KES 5 million to 50 million)KES 16,000KES 9,000
Large (over 99 staff, turnover above KES 50 million)KES 40,000KES 25,000
Public bodies, charities and religious organisationsKES 4,000KES 2,000

Registration certificates are valid for 24 months and must then be renewed.

What You Need

  • Business registration documents and KRA PIN
  • Details of the types of personal data you process and why
  • Categories of data subjects (customers, staff, patients, students)
  • Who you share data with, and any transfers outside Kenya
  • Your security measures for protecting data
  • Contact details of the person responsible for data protection

Step-by-Step

  1. Visit the ODPC registration portal through odpc.go.ke.
  2. Create an account and choose to register as a data controller, data processor, or both.
  3. Fill in the organisation details and the data processing information.
  4. Upload the required documents.
  5. Pay the fee for your category.
  6. Submit and track the application. Once approved, download your certificate of registration.

Beyond Registration

Registration is only the start. The Act also expects you to:

  • Collect only the data you need, with a lawful basis such as consent
  • Tell people how their data is used (a privacy notice)
  • Keep data secure - strong passwords, two-step sign-in and encrypted systems
  • Respond to requests from people to access or delete their data
  • Report serious data breaches to the ODPC within the required time
  • Conduct data protection impact assessments for high-risk processing

Failure to comply can lead to enforcement notices and fines. Choosing secure systems for email and customer data - see how Tifamail secures business email - makes compliance much easier.

Examples of Who Must Register

BusinessWhy registration applies
Private clinic or pharmacyHealth sector - mandatory regardless of size
School or collegeEducation sector - mandatory regardless of size
SACCO or microfinance lenderFinancial services - mandatory regardless of size
Real estate agencyReal estate sector - mandatory regardless of size
Online shop with turnover above KES 5 millionProcesses customer data above the threshold
Payroll bureau or IT support companyProcesses data on behalf of clients as a data processor
Small consultancy below KES 5 million and under 10 staffMay be exempt, unless in a listed sector

Data Protection Basics for Small Businesses

  • Know your data: list what personal data you collect, where it is stored and who can see it.
  • Collect less: ask only for what you need. Do not photocopy IDs unless required.
  • Get consent for marketing: do not add customers to SMS or email marketing without their agreement, and give an easy way to opt out.
  • Secure your systems: strong passwords, two-step sign-in, encrypted email and devices, and access only for staff who need it.
  • Train staff: most breaches start with a careless click or a shared password.
  • Have a retention policy: delete data you no longer need.

Responding to Data Subject Requests

People can ask to see the data you hold about them, correct it, object to its use, or have it deleted in certain cases. Have a simple process: a contact email, an identity check, and a response within the time required under the Act.

Handling a Data Breach

If personal data is lost, stolen or exposed, act quickly: contain the breach, assess the risk, notify the ODPC within the required timeline where the breach is likely to harm people, and inform affected individuals where necessary. Keep a record of what happened and what you changed.

Frequently Asked Questions

What is the penalty for not registering? The ODPC can issue enforcement notices and impose penalties under the Data Protection Act. It has also publicly named and fined organisations for violations.

Do I need a Data Protection Officer? Organisations whose core activities involve large-scale or sensitive data processing are expected to designate a data protection officer. Smaller organisations should still assign someone responsible.

Is a privacy policy on my website enough? No. A privacy notice is required, but registration, security measures and proper handling of data are separate obligations.

How long does registration take? Online applications are processed by the ODPC after submission; approval time varies, so apply well before any deadline or tender requirement.