Kenya Kenya data protection authority ODPC

Kenya's Data Protection Handover Is Built Into the Statute, So the Next Commissioner Should Keep Enforcement Proportionate

Kassait's non-renewable term ends this year; the successor should keep the notice-and-cure enforcement style the ODPC used in its August renewal notice.

Kenya's ODPC Leadership Transition People of Internet Research · Kenya 6 years Commissioner's single term Non-renewable under section 7(2). 10+ years Minimum relevant experience Statutory requirement, section 7(1… 24 months Registration certificate validity Renewal advised 30 days before exp… 14 days Renewal cure window Notice dated 28 August 2026, deadl… peopleofinternet.com
Kenya's ODPC Leadership Transition People of Internet Research · Kenya 6 years Commissioner's single term 10+ years Minimum relevant experience 24 months Registration certificate vali… 14 days Renewal cure window peopleofinternet.com

Key Takeaways

Kenya's Public Service Commission (PSC) has begun recruiting a new Data Protection Commissioner. Capital FM reported on 26 August 2026 that Immaculate Kassait, the inaugural head of the Office of the Data Protection Commissioner (ODPC), is expected to leave office later this year at the end of a non-renewable six-year term. Applicants need a degree in a field such as data science, law or IT, a master's degree, and at least 10 years of relevant experience.

None of this is a surprise or a crisis. It is the statute working as written. How the successor uses the office's powers matters more than the handover itself.

The handover is designed, not improvised

The Data Protection Act, 2019 sets out the whole process. Section 6 tells the PSC to start recruitment whenever a vacancy arises. It must invite applications within seven days of being notified. Within 21 days of receiving applications it must shortlist, publish the names, interview in an open process, and send three nominees in order of merit to the President. The President nominates, and the National Assembly approves the appointment.

Section 7 adds the qualifications: a recognised degree, a master's degree, at least ten years of relevant experience, and compliance with Chapter Six of the Constitution. Section 7(2) says the Commissioner serves "a single term of six years" and is "not eligible for a re-appointment."

The strongest case for this design is independence. A commissioner who cannot be reappointed has no reason to please the executive in year five. Publishing the shortlist and interviewing in the open gives civil society and the private sector a chance to scrutinise candidates. Nothing in the advert departs from that. The master's degree and ten-year experience bars are the statutory minimums, not new hurdles.

What the next commissioner inherits

The office has not been idle. On 28 August 2026 the ODPC told controllers and processors with expired registration certificates to regularise their status within 14 days, which put the deadline at 11 September. CMS Kenya's summary notes that the notice applies to entities on a published list. It also says continued processing without valid registration is an offence under Regulation 18 of the Data Protection Regulations, 2021.

The registration regime is a serious case for enforcement, and it deserves a fair hearing. The register under the Act is the ODPC's map of who handles Kenyans' personal data. A register full of lapsed certificates cannot show regulators where risk sits. If lapsing carries no consequence, compliant firms that renewed on time are at a disadvantage, and the regime becomes voluntary in practice.

The ODPC's own guidance shows how the system is meant to work. Its registration FAQ says certificates are valid for 24 months and should be renewed at least 30 days before they expire. Organisations with turnover under KES 5 million and fewer than 10 employees are exempt, unless they work in listed sectors such as finance, telecoms, health, education, gaming or the public sector. Renewal fees run from KES 2,000 to KES 25,000, depending on the size of the entity.

Why proportion should stay the house style

The August notice is the model to keep. It named specific entities, gave a fixed window to cure, and pointed them to an online portal. That is enforcement a business can plan around. It treats a lapsed certificate as an administrative failure to fix, not as evidence of bad faith.

This matters because the people affected are not mostly large platforms. A Nairobi clinic, a school, a betting shop or a small fintech falls under the same rules as a multinational. For these firms the cost is not the KES 2,000 to 25,000 fee. It is the compliance staff time, and the risk of an offence for a missed date. A regulator that begins with a notice and a deadline, and saves penalties for those who ignore it, gets registers updated faster and sours the relationship less.

There is also a wider innovation case. Kenya's economy runs on mobile-first services, and the Act reaches any controller or processor handling data of people in Kenya. Predictable, published enforcement lets startups budget for compliance the way they budget for tax filings. Erratic enforcement pushes them towards jurisdictions where the rules are easier to read.

Three tests for the succession

The bottom line

A good regulator is measured by whether firms understand what will happen when they miss a deadline. Kassait's office set a workable pattern with a list, a window and a portal. The new commissioner should build on it rather than swap it for a heavier hand.

Sources & Citations

  1. Data Protection Act, 2019 (Act No. 24 of 2019)
  2. ODPC registration FAQ
  3. Capital FM: PSC begins search for new Data Protection Commissioner
  4. Capital FM: ODPC gives data handlers 14 days to renew expired certificates