The Office of the Data Protection Commissioner has shifted from awareness-building to monetary penalties and compensation orders. A privacy policy on your website is no longer a defence.

For the first few years after the Data Protection Act, 2019 came into force, compliance in Kenya was largely a registration exercise. Organisations registered as data controllers or processors, published a privacy notice, and moved on. That period has ended.

What the regulator is actually doing

The Office of the Data Protection Commissioner now issues determinations on individual complaints, and those determinations carry financial consequences. Alongside determinations, the ODPC has issued enforcement notices, penalty notices and compensation orders, and the cumulative value of fines has grown substantially.

The regulator has also shown willingness to escalate. Where a controller obstructs an investigation, the ODPC has recommended criminal prosecution. And where a complaint involves an entity outside Kenya, it has sought assistance from counterpart regulators in other jurisdictions rather than treating the matter as beyond reach.

Determinations are enforceable. In one matter, a lodge that had been ordered to pay compensation for using an individual's images without consent removed the images but did not pay, and the resulting judicial review application came before the High Court in January 2025.

Consent is where most organisations fail

The clearest theme in the ODPC's reasoning concerns consent, and it is unforgiving.

  • The burden sits with the controller. If you cannot demonstrate how and when consent was obtained, the regulator treats it as never having been obtained. Absence of evidence is treated as absence of consent.
  • Verbal consent is insufficient unless it was documented at the time. An assurance that the customer agreed on a phone call, with nothing recorded, will not carry.
  • Consent is purpose-specific. Consent given for one processing purpose does not extend to a materially different one. Data collected for service delivery cannot be repurposed for marketing on the strength of the original consent.

The penalty exposure

Under section 63 of the Act, the ODPC may impose an administrative penalty of up to KES 5 million or 1% of annual turnover, whichever is lower. There is a separate exposure for continuing violations, calculated on a daily basis for each day a breach remains unrectified.

Data subjects may additionally pursue civil claims for compensation in court, and constitutional petitions grounded in the Article 31 right to privacy fall within the High Court's jurisdiction. Regulatory penalty is therefore not the ceiling of your exposure.

Breach notification timelines

A controller must notify the ODPC of a personal data breach within 72 hours of becoming aware of it, and must notify affected data subjects where there is a real risk of harm to them. Processors must notify their controller within 48 hours. Where an organisation falls within the critical information infrastructure rules, the reporting window is shorter still.

Seventy-two hours is not long. Organisations that have not decided in advance who declares a breach, who drafts the notification and who signs it will spend most of that window deciding.

Our view

The gap we see most often is between policy compliance and operational compliance. Many Kenyan organisations have a privacy policy, a registration certificate and a data protection clause in their standard contracts — and no auditable record of consent, no trained staff, no process for responding to data subject requests within statutory timelines, and no oversight of the third-party processors who hold their data.

The ODPC's determinations consistently probe the second category, not the first. We recommend that organisations move to evidence-based compliance: contemporaneous consent records, a documented breach response process with named roles, a register of processors with written terms, and a request-handling log. If a complaint reaches the regulator, those records are your defence. Without them, the policy alone will not help you.

Note. This article is general commentary on Kenyan law as at the date of publication and is not legal advice. The law in these areas changes, and several of the matters discussed remain subject to appeal. For advice on your own circumstances, please contact us.
Njiule M. Wakoli, DPO

Njiule M. Wakoli, DPO

Partner — Data Protection and Advisory

Njiule leads the firm and practises across intellectual property, data protection, corporate governance, mergers and acquisitions, regulatory compliance and dispute resolution.

← Previous article Next article →
Mitchelson Law LLP AdvocatesMitchelson Law LLP AdvocatesMitchelson Law LLP AdvocatesMitchelson Law LLP AdvocatesMitchelson Law LLP AdvocatesMitchelson Law LLP Advocates