Kenya Kenya data protection authority ODPC

Kenya's Data Commissioner Handover Will Test Whether ODPC Enforcement Rests on Institutions or on One Person

As Kassait's non-renewable term ends, the ODPC's record of 9,061 complaints and 20 penalty notices shows what the next commissioner inherits.

The ODPC record Kassait leaves behind People of Internet Research · Kenya 9,061 Complaints received Cumulative complaints since the Da… 20 Penalty notices issued Against 134 enforcement notices ov… 184 Compensation orders Orders issued to individuals affec… 13 of 152 Shortlisted from applicants PSC shortlist for the commissioner… peopleofinternet.com
The ODPC record Kassait leaves behind People of Internet Research · Kenya 9,061 Complaints received 20 Penalty notices issued 184 Compensation orders 13 of 152 Shortlisted from applicants peopleofinternet.com

Key Takeaways

A first handover for a young regulator

On 26 August 2026 Kenya's Public Service Commission (PSC) began recruiting a successor to Immaculate Kassait, the inaugural Data Protection Commissioner. Her six-year term is non-renewable and ends later this year, according to Capital FM's report on the search. Applicants need a master's degree and at least 10 years of relevant experience. The Office of the Data Protection Commissioner (ODPC) has never changed leaders before, and the office was built around its first one.

The case for worrying is strong. Young regulators often owe their authority to one credible, well-networked founder. If a successor is weaker, more politically exposed, or simply less known, enforcement can fade without any law changing. A statute establishes the office, but it does not guarantee that the office is used.

Our view is that the more useful question is not who replaces Kassait. It is whether the ODPC has built habits and a record that survive her departure. The evidence says it has built a good deal, though not enough to take continuity for granted.

What the next commissioner inherits

By January 2026 the ODPC reported 9,061 complaints since the Data Protection Act, 2019 took effect. According to Capital FM's account of those figures, these produced 357 determinations, 134 enforcement notices, 84 matters settled through alternative dispute resolution, 20 penalty notices and 184 compensation orders for affected individuals.

Two features of that pipeline matter for our argument.

First, it is overwhelmingly corrective rather than punitive. Twenty penalty notices against 9,061 complaints is roughly 0.2%. Most disputes end in an enforcement notice, a settlement or a compensation order. That is the proportionate shape we favour: fix the harm and reserve fines for firms that ignore instructions.

Second, fines follow non-compliance. In April 2023 the ODPC fined mobile lender Whitepath Limited and office-space provider Regus Kenya KES 5 million each, as ALN Africa reported. Whitepath had not complied with an earlier enforcement notice after more than 150 customers complained that it accessed their phone contacts without consent. Regus was fined after it failed to remedy spam sent despite opt-out requests. In both cases the penalty came after a chance to comply had been given.

This sequence is easier to hand over than a record built on headline fines. A successor who follows the same process inherits a defensible practice, and one that gives businesses predictable warning.

Where continuity is at risk

The steelman for pessimism has three parts.

We do not suggest any shortlisted candidate lacks independence; the reporting we reviewed describes no such concern. The point is structural. The recruitment is a public process with a public comment window, and that is the right design. Kenya's first recruitment was already tested in court: the Employment and Labour Relations Court suspended the 2020 process after a petitioner argued interviews exceeded the 21-day limit the Act sets for the PSC. Process shortcuts have had legal consequences before.

What proportionate continuity looks like

Pro-innovation policy needs a regulator that is predictable. Kenyan start-ups, fintechs and lenders do not need a lenient ODPC. They need one whose enforcement notices follow the same logic from one commissioner to the next. Three tests will show whether that is happening.

  1. Publish decisions. Determinations and penalty notices should stay public and reasoned, so the record belongs to the office rather than to a person.
  2. Keep the graduated sequence. Notice first, penalty only for non-compliance, compensation for the individual harmed. A successor who jumps straight to large fines would chill small firms; one who stops issuing penalties would invite abuse.
  3. Treat state bodies like private ones. Independence is proved when the regulator acts against a ministry or agency, not only a mobile lender.

The handover is not a crisis. Kenya now has a functioning complaints system with thousands of cases behind it, and that is more than many peers have after a similar period. The risk is that the system is mistaken for a person, and a quiet decline in decision speed or willingness to sanction is read as stability. Watch the first year of determinations, not the appointment announcement.

Sources & Citations

  1. Data Protection Act, 2019 (ODPC)
  2. Office of the Data Protection Commissioner
  3. Capital FM: PSC begins search for new Data Protection Commissioner
  4. Capital FM: ODPC issues 184 compensation orders
  5. ALN Africa: ODPC fines Whitepath and Regus Kenya
  6. TechTrends Kenya: 13 candidates shortlisted
  7. ENSafrica: Update on the Data Commissioner's appointment