
If your business collects customers' phone numbers, runs payroll, operates CCTV, markets via SMS, or processes any personal data, you've probably heard that you need to "register with the ODPC." But what does that actually mean, does it apply to you, and what happens if you ignore it?
Since the Data Protection Act, 2019 came into force and the registration regime was rolled out, the Office of the Data Protection Commissioner has moved steadily from awareness to enforcement. Fines are being upheld in court, audits are happening, and corporate clients now demand registration certificates from their vendors.
Here is a plain language guide to registration under Kenyan data protection law.
First: Controller or Processor?
The registration regime applies to two roles:
- A data controller determines why and how personal data is processed. Most businesses are controllers: you decide to collect customer data, employee records, and marketing lists, and decide what to do with them.
- A data processor processes data on behalf of a controller: payroll bureaus, cloud hosts, CRM providers, marketing agencies handling client databases.
Many businesses are both controllers of your customer data and processors of data you handle for clients. Each role requires its own registration where applicable.
Who Must Register With the ODPC?
Registration is required in two situations under the Data Protection (Registration of Data Controllers and Data Processors) Regulations:
1. Mandatory Categories
Registration is compulsory for entities whose core activities involve:
- Crime prevention and fraud detection
- Gambling and lotteries
- Financial services: banking, insurance, lending, payments
- Health administration and provision of health services
- Education and administration of educational institutions
- Property management
- Processing of location data
- Other categories as specified by the Data Commissioner from time to time
If your core business falls within one of these categories, registration is not optional, and "core activities" is interpreted with reference to your day-to-day operations rather than your articles of association.
2. Voluntary Registration Above Thresholds
Entities outside the mandatory categories whose processing exceeds prescribed thresholds, as measured by factors such as annual turnover and the number of employees, may register voluntarily. For growing businesses, voluntary registration is increasingly worthwhile: it signals maturity in compliance to corporate clients, lenders, and international partners.
What Does Registration Cost and How Long Does It Last?
- Registration runs annually; certificates must be renewed.
- Fees are tiered by entity size; micro, small, medium, and large enterprises pay different annual tiers, scaled so that compliance is affordable for SMEs
- The certificate of registration identifies your entity, its registration category, and validity period.
Check the current fee schedule on the ODPC portal; tiers and amounts are periodically reviewed.
How to Register: Step by Step
- Create an account on the ODPC registration portal
- Complete the registration form: entity details (including registration certificate number), category of registration, description of processing activities, categories of data subjects, and types of personal data processed
- Pay the applicable fee for your tier
- Receive your certificate of registration
The process is designed to be self-service and relatively fast. But accuracy matters: a registration that misdescribes your processing, understating data categories, or omitting processing activities is a compliance liability, not a shield.
What Happens If You Don't Register?
Operating in a mandatory category without registration is an offence under the Data Protection Act. The consequences include:
- Administrative fines of up to KSh 5 million or 1% of annual turnover, whichever is lower, per infringement
- Enforcement and penalty notices published by the ODPC; public reputational damage that clients and partners can see
- Heightened scrutiny in any subsequent audit or investigation
- Contractual consequences are increasingly severe; corporate procurement teams screen vendors for registration; unregistered vendors lose deals.
Registration Is Not the Finish Line — It's the Entry Ticket
This is the point most businesses miss. Registration is the floor of compliance, not the ceiling. A registered controller must still:
- Issue privacy notices that explain what is collected, why it is collected, and what their rights are.
- Establish a lawful basis for every processing activity (consent, contract, legal obligation, legitimate interest, and the other bases in the Act)
- Honour data subject rights: access, correction, deletion, objection, and the right not to be subject to solely automated decisions
- Report personal data breaches within 72 hours (see our companion guide)
- Implement technical and organisational safeguards, access controls, encryption, and staff training.
- Use compliant contracts with processors including mandatory breach notification clauses.
- Conduct data protection impact assessments for high-risk processing.
- Maintain records of processing activities.
Registration without these is like a driving licence: it proves you showed up, not that you're safe.
How Registration Fits Into a Compliance Programme
A sensible compliance journey for a Kenyan SME:
- Map your data: what personal data you hold, where, why, and who you share it with
- Register with the ODPC (if in a mandatory category or choosing voluntary registration)
- Publish privacy notices for customers, employees, and website visitors
- Fix consent and contracts; refresh marketing consents; paper your processor relationships
- Build breach response: a written plan, a responsible person, the 72-hour clock
- Train your team: most breaches are human before they are technical
- Review annually: data maps go stale; registrations expire
Frequently Asked Questions
Q1. Is ODPC registration mandatory for small businesses?
A. It depends on your core activities, not your size. If you're in a mandatory category, registration applies regardless of turnover. Outside those categories, thresholds determine whether voluntary registration applies.
Q2. Can I register as both controller and processor?
A. Yes, many businesses hold both roles and register accordingly.
Q3. What documents do I need to register?
A. Typically, your certificate of incorporation or registration, details of your processing activities, and the prescribed fee. The portal guides the specifics.
Q4. What if my registration lapses?
A. Renew promptly. Operating with an expired certificate in a mandatory category exposes you to the same penalties as if you had never registered.
Q5. Does registration protect me from liability?
A. No. Registration is a declaration of your processing, not a defence for bad processing. Liability depends on your actual compliance.
The Bottom Line
Registration is fast, affordable, and increasingly expected by regulators, corporate clients vetting vendors, and courts assessing whether a business took data protection seriously. If you're in a mandatory category and unregistered, every day adds risk. And once registered, build the compliance programme implied by the certificate.
Unsure whether your business must register or what a full compliance programme looks like? Contact Anyega Osiemo & Co., Advocates. We handle ODPC registrations and build practical, right-sized compliance frameworks for businesses of every size — including diaspora-owned companies operating in Kenya.
Disclaimer: This article is general legal information, not legal advice. For guidance on your specific situation, book a consultation with our advocates.
