Kenya Kenya data protection authority ODPC

Kenya's Data Commissioner Term Limit Forces a Clean Succession — And a Test of What the ODPC Built

A statutory six-year term, not political pressure, ends Immaculate Kassait's tenure, handing her successor an increasingly assertive regulator.

Kenya's Data Commissioner Succession, By the Numbers People of Internet Research · Kenya 6 years Non-renewable commissioner term Statutory limit under Section 7(2)… Sept 14, 2026 Application deadline PSC's cutoff for applications to t… 10 years Minimum experience required Statutory qualification threshold … KES 5M Max fine, unregistered controllers Ceiling the ODPC can levy against … peopleofinternet.com
Kenya's Data Commissioner Succession, … People of Internet Research · Kenya 6 years Non-renewable commissioner term Sept 14, 2026 Application deadline 10 years Minimum experience requi… KES 5M Max fine, unregistered con… peopleofinternet.com

Key Takeaways

Kenya's Public Service Commission (PSC) has opened recruitment for a new Data Protection Commissioner, with applications due September 14, 2026. The vacancy exists because Immaculate Kassait, the country's first-ever data commissioner, is reaching the end of a non-renewable six-year term — a hard statutory limit, not a political removal or a scandal-driven exit.

That distinction matters more than it might seem. Across the region, regulatory leadership changes are more often triggered by executive reshuffles, funding cuts, or quiet political pressure than by a law simply running its course. Kenya's case is the boring, functional version: Section 7(2) of the Data Protection Act, No. 24 of 2019, caps the Data Commissioner at a single six-year term with no re-appointment, and the clock is running out on schedule, five-plus years after Kassait was sworn in on November 16, 2020.

How the succession actually works

The appointment mechanics are worth stating plainly, because they are the real safeguard here. Under Section 6 of the Act, the PSC runs the recruitment and shortlisting process, then forwards names to the President, who nominates a candidate subject to approval by the National Assembly. Qualification is also statutory, not discretionary: a candidate needs a university degree in data science, law, information technology or a related field, plus at least ten years of relevant experience, and must meet Chapter Six integrity requirements under the Constitution.

The steelman: why a hard exit is defensible

There is a real case for forcing Kassait out regardless of performance. A single non-renewable term removes any incentive for a data protection chief to soften enforcement in the final years of office to curry favor with a re-appointing authority — a well-documented failure mode for regulators worldwide, from utility commissions to financial supervisors. It also guarantees institutional turnover, preventing any one office from calcifying around a founding personality. Given that the ODPC is Kenya's youngest major regulator, and one still building its enforcement muscle, a clean-break rule reduces the risk of regulatory capture setting in unnoticed.

What the successor inherits

Whoever the National Assembly confirms will not be starting from zero. Kassait's ODPC spent its term building the compliance architecture the Act only sketched: a mandatory registration regime for data controllers and processors, backed by fines of up to KES 5 million for entities operating unregistered, and a fast-expanding list of sectors the office has pulled under that net — most recently transport and logistics operators, including ride-hailing platforms, freight and courier firms, which the ODPC in April 2026 directed to keep a current, complete copy of Kenyan users' personal data on servers physically located inside the country.

That data-localization guidance is a useful marker of where the ODPC's posture has moved. It leans on Section 20(2)(c) of the Computer Misuse and Cybercrimes Act to designate public transport systems as "protected computer systems," which is a sovereignty-first justification more than a pure privacy one. The guidance closed its public comment window on May 15, 2026, without a published enforcement date — an unresolved compliance question the incoming commissioner will inherit on day one, alongside every foreign platform operator now wondering whether "one serving copy in Kenya" becomes a hard requirement or stays aspirational.

Why proportionality still matters here

Registration and a functioning complaints regime are legitimate, proportionate tools — they are what makes a data protection law more than a press release. Data localization mandates are a different animal. They raise compliance costs disproportionately for smaller platforms and foreign entrants relative to incumbents who can more easily absorb a Kenya-based server footprint, and the efficacy case for localization improving actual data security, versus simply making enforcement easier, is thin in the comparative literature on similar mandates in India, Nigeria, and Vietnam. A new commissioner inheriting this file has a real opportunity to recalibrate toward a risk-based standard — stronger breach-notification and audit requirements paired with cross-border transfer safeguards — rather than blanket localization that taxes market entry more than it protects Kenyan users.

The test of Kenya's data protection framework was never going to be the first six years. It's whether the institution survives its first leadership transition with its independence and its workload intact.

The National Assembly's vetting hearing, whenever it comes, will be the first real public signal of how seriously Parliament takes its check on this appointment — a check that, on paper, is stronger than in many peer jurisdictions but has yet to be tested by a contested nomination. Kenya built a genuinely independent-on-paper data authority in 2019 and staffed it credibly in 2020. The September 14 deadline starts the process of finding out whether that independence is durable enough to survive a change of leadership, or whether it was contingent on one commissioner's own initiative.

Sources & Citations

  1. Data Protection Act, No. 24 of 2019 (full text via ICNL)
  2. Public Service Commission — Vacant Positions
  3. AllAfrica: PSC Begins Search for New Data Protection Commissioner
  4. Pulse.co.ke: Kenya seeks new Data Commissioner as PSC opens vacancy
  5. Techweez: Kenya pushes mandatory local data storage for ride-hailing and booking apps