
The perception that the Data Protection Act, 2019 (Kenya) is a law with limited enforcement is no longer accurate as of 2026.
The Office of the Data Protection Commissioner (ODPC) now operates as an active enforcement regulator. The ODPC issues penalty notices that have been upheld by the High Court, orders compensation for data subjects, conducts unannounced compliance audits, and in recent matters, has recommended prosecution of company directors who obstruct investigations.
For Kenyan businesses, data protection compliance is now a legal and operational necessity. It constitutes a significant board-level risk. This article outlines the principal enforcement trends in 2026 and the practical implications for businesses operating in Kenya.
The ODPC's Enforcement Record: The Numbers Tell the Story
The clearest evidence that enforcement has matured is in the regulator's own statistics. Since it became operational, the ODPC has:
- Handled more than 9,000 complaints by data subjects;
- Issued over 350 formal determinations, with the pace roughly doubling in 2025 compared to the previous year;
- Served 134 enforcement notices requiring organisations to remedy violations;
- Issued 20 penalty notices, with administrative fines reaching the statutory maximum;
- Ordered compensation for 184 complainants whose personal data was mishandled — one of the strongest enforcement moves under the Act to date.
More than half of all complaints in the regulator's initial years concerned digital credit providers, which remain a priority for enforcement. In a significant case, the ODPC fined Mulla Pride (operating KeCredit and Faircash) KES 2.975 million for improper debt-collection practices involving third-party data. The High Court upheld this penalty on appeal, confirming that ODPC penalties are enforceable where due process is observed.
Lesson 1: Treat the ODPC as an active regulator, not a formality
Businesses that did not allocate resources for data protection compliance on the assumption that enforcement was unlikely are now subject to enforcement notices. Compliance with data protection law should be regarded as an ongoing statutory obligation with significant financial consequences.
Trend 1: Penalties Are Real, and They Are Being Upheld in Court
Under Section 63 of the Data Protection Act, the Data Commissioner may impose an administrative fine of up to KES 5 million or 1% of annual turnover for the preceding financial year, whichever is lower. Separately, offences under the Act can attract criminal fines of up to KES 3 million, imprisonment of up to ten years, or both. The ODPC may also impose daily fines for continuing non-compliance.
The principal change in 2026 is the increased credibility of penalties. Entities that previously believed they could avoid liability through litigation are now finding that the courts are upholding well-founded penalty notices.
Businesses should also watch the Data Protection (Amendment) Bill, which was pending before Parliament as of early 2026. Among its proposals are higher financial penalties, expanded categories of sensitive personal data (including political opinions and trade union membership), and an obligation on data controllers to demonstrate compliance on an ongoing basis and not simply claim it.
Lesson 2: Budget for compliance now, because the cost of non-compliance is rising
The disparity between the cost of implementing a compliance programme and the potential costs of penalty notices, compensation orders, legal fees, and reputational harm continues to increase. Early investment in compliance remains the most cost-effective approach.
Trend 2: ODPC Registration Is Being Actively Policed
ODPC registration for data controllers and data processors has been mandatory since 2022, with over 15,000 entities now registered. As of 2026, registration is a fundamental compliance requirement and is the first aspect reviewed by the regulator upon receipt of a complaint.
Who must register? Broadly, an entity is exempt only if it has both an annual turnover below KES 5 million and fewer than ten employees. Even then, businesses in designated sectors, including financial services, telecommunications, health, education, insurance, hospitality, gaming, direct marketing, and CCTV operation, must register regardless of size.
Lesson 3: Verify your registration status today
It is necessary to confirm that your business, and any related entities, are registered in the appropriate category as a data controller, data processor, or both. Registration must be renewed and kept accurate, as an outdated registration may be as problematic as a lack of registration.
Trend 3: The 72-Hour Breach Notification Clock Is Strictly Enforced
Kenya's data breach notification rules require a data controller to notify the ODPC within 72 hours of becoming aware of a personal data breach, and to inform affected data subjects where there is a real risk of harm. For operators designated as critical information infrastructure under the 2024 cybersecurity regulations, the reporting window is 24 hours.
Enforcement decisions now examine not only the occurrence of a breach but also the adequacy of the organisation's response. An organisation that promptly detects, investigates, notifies within the prescribed period, and mitigates harm is treated more favourably than one that conceals or delays notification.
Lesson 4: Build and rehearse a breach response plan
Seventy-two hours is a limited timeframe for organisations that have not prepared in advance. A breach response plan should specify the individuals responsible for declaring a breach, drafting the ODPC notification, communicating with affected individuals, and engaging external counsel. This plan should be tested through a tabletop exercise prior to any actual incident.
Trend 4: Consent Standards Have Hardened
A consistent theme in recent ODPC determinations is the rejection of implied or informal consent. The regulator expects data controllers to demonstrate precisely how and when explicit consent was obtained, particularly for direct marketing, data sharing with third parties, and processing of sensitive personal data.
Businesses that rely on pre-ticked boxes, concealed consent clauses, or contact lists acquired from third parties have been found non-compliant. In practice, marketing departments are among the highest-risk areas within organisations.
Lesson 5: Audit your consent trail
For each marketing database, customer list, and data-sharing arrangement, it is necessary to determine whether evidence of valid consent could be produced if requested by the ODPC. If such evidence is lacking, remedial action should be taken without delay.
Trend 5: Compliance Audits and Personal Accountability Are Expanding
Two developments deserve particular attention in 2026:
First, ODPC compliance audits. Under the Data Protection (Conduct of Compliance Audit) Regulations, 2024, the ODPC's compliance and inspection teams may audit organisations by reviewing their records and scrutinising their security measures and data flows. Weak spots identified in an audit can result in enforcement action.
Second, there is increased personal exposure for directors. In several recent cases, the ODPC has recommended prosecution of company directors for obstruction of investigations. Data protection failures may now result in personal liability for individuals, not solely corporate penalties.
Businesses that meet the statutory thresholds are required to appoint a Data Protection Officer (DPO). An effective DPO provides early identification and management of the risks described in this article.
Lesson 6: Prepare as though an audit is coming, because it may be
Organisations should maintain a comprehensive data inventory, document the lawful basis for each processing activity, keep data protection impact assessments (DPIAs) current for high-risk processing, and ensure that vendor contracts contain appropriate data protection clauses. Organisations with complete documentation are better positioned to navigate audits successfully.
Trend 6: Cross-Border Data Transfers Are Under the Microscope
Any Kenyan business using foreign cloud providers, regional shared-service centres, or international SaaS platforms is transferring personal data across borders. The Act permits cross-border data transfers from Kenya only on lawful grounds, the destination country's adequacy of protection, appropriate contractual safeguards, or the data subject's explicit consent, with stricter conditions for sensitive data.
Kenya is the first country to engage with the European Union in an adequacy dialogue, which, if successful, would permit the free flow of personal data from the EU to Kenya. Kenya's alignment with the GDPR framework is advantageous. However, until an adequacy decision is reached, each cross-border data transfer must have a documented legal basis.
Lesson 7: Map your data flows and document the basis for every transfer
Know where your data physically lives, which Organisations should identify the physical location of their data, the jurisdictions through which it is transferred, and the safeguards that justify each transfer. The growth of local data-centre capacity in Kenya now makes data residency a viable option for sensitive data processing.
All data controllers and data processors must register unless they have both an annual turnover below KES 5 million and fewer than ten employees. Entities in 18 designated sectors — including finance, health, telecoms, education, insurance, hospitality, and direct marketing — must register regardless of size.
Lesson 7: Map your data flows and document the basis for every transfer
Organisations should identify the physical location of their data, the jurisdictions through which it passes, and the safeguards that justify each transfer. The growth of local data-centre capacity in Kenya now makes data residency a viable option for sensitive data processing.
Frequently Asked Questions
Who must register with the ODPC in Kenya?
All data controllers and data processors must register unless they have both an annual turnover below KES 5 million and fewer than ten employees. Entities in 18 designated sectors including finance, health, telecoms, education, insurance, hospitality, and direct marketing must register regardless of size.
What are the penalties under the Data Protection Act in Kenya?
The ODPC can impose administrative fines of up to KES 5 million or 1% of annual turnover (whichever is lower), issue enforcement notices, order data subjects to pay compensation, and impose daily fines for continuing breaches. Criminal offences under the Act can attract fines of up to KES 3 million and imprisonment of up to ten years.
How quickly must a data breach be reported in Kenya?
A data controller must notify the ODPC within 72 hours of becoming aware of a breach. Affected individuals must be notified where there is a real risk of harm. Critical information infrastructure operators are subject to a 24-hour reporting requirement under the 2024 cybersecurity regulations.
Does my business need a Data Protection Officer in Kenya?
A DPO is required where processing meets the thresholds set out in the Act and Regulations — broadly, where core activities involve regular and systematic monitoring of data subjects or large-scale processing of sensitive personal data. Many businesses that fall below the threshold still appoint one (or outsource the role) as good practice.
Can the ODPC audit my company?
Yes. Under the 2024 Compliance Audit Regulations, the ODPC may audit data controllers and processors, including through site inspections, records reviews, and testing of security measures.
How Anyega Osiemo & Co. Advocates Can Help
Our data protection and privacy team advises businesses across Kenya on the full compliance lifecycle: ODPC registration, gap assessments and compliance audits, data protection impact assessments, breach response, cross-border transfer frameworks, outsourced Data Protection Officer services, and representation in ODPC complaints and enforcement proceedings.
The 2026 enforcement environment favours businesses that implement compliance measures proactively and imposes penalties on those that delay until a complaint is made.
EMAIL: info@anyegaosiemo.com
Phone: +254 741480122
Disclaimer: This article is general legal information, not legal advice. For guidance on your specific situation, book a consultation with our advocates.