Kenya's Public Service Commission (PSC) has begun recruiting a new Data Protection Commissioner. Capital FM reported on 26 August 2026 that Immaculate Kassait, the inaugural head of the Office of the Data Protection Commissioner (ODPC), is expected to leave office later this year at the end of a non-renewable six-year term. Applicants need a degree in a field such as data science, law or IT, a master's degree, and at least 10 years of relevant experience.
None of this is a surprise or a crisis. It is the statute working as written. How the successor uses the office's powers matters more than the handover itself.
The handover is designed, not improvised
The Data Protection Act, 2019 sets out the whole process. Section 6 tells the PSC to start recruitment whenever a vacancy arises. It must invite applications within seven days of being notified. Within 21 days of receiving applications it must shortlist, publish the names, interview in an open process, and send three nominees in order of merit to the President. The President nominates, and the National Assembly approves the appointment.
Section 7 adds the qualifications: a recognised degree, a master's degree, at least ten years of relevant experience, and compliance with Chapter Six of the Constitution. Section 7(2) says the Commissioner serves "a single term of six years" and is "not eligible for a re-appointment."
The strongest case for this design is independence. A commissioner who cannot be reappointed has no reason to please the executive in year five. Publishing the shortlist and interviewing in the open gives civil society and the private sector a chance to scrutinise candidates. Nothing in the advert departs from that. The master's degree and ten-year experience bars are the statutory minimums, not new hurdles.
What the next commissioner inherits
The office has not been idle. On 28 August 2026 the ODPC told controllers and processors with expired registration certificates to regularise their status within 14 days, which put the deadline at 11 September. CMS Kenya's summary notes that the notice applies to entities on a published list. It also says continued processing without valid registration is an offence under Regulation 18 of the Data Protection Regulations, 2021.
The registration regime is a serious case for enforcement, and it deserves a fair hearing. The register under the Act is the ODPC's map of who handles Kenyans' personal data. A register full of lapsed certificates cannot show regulators where risk sits. If lapsing carries no consequence, compliant firms that renewed on time are at a disadvantage, and the regime becomes voluntary in practice.
The ODPC's own guidance shows how the system is meant to work. Its registration FAQ says certificates are valid for 24 months and should be renewed at least 30 days before they expire. Organisations with turnover under KES 5 million and fewer than 10 employees are exempt, unless they work in listed sectors such as finance, telecoms, health, education, gaming or the public sector. Renewal fees run from KES 2,000 to KES 25,000, depending on the size of the entity.
Why proportion should stay the house style
The August notice is the model to keep. It named specific entities, gave a fixed window to cure, and pointed them to an online portal. That is enforcement a business can plan around. It treats a lapsed certificate as an administrative failure to fix, not as evidence of bad faith.
This matters because the people affected are not mostly large platforms. A Nairobi clinic, a school, a betting shop or a small fintech falls under the same rules as a multinational. For these firms the cost is not the KES 2,000 to 25,000 fee. It is the compliance staff time, and the risk of an offence for a missed date. A regulator that begins with a notice and a deadline, and saves penalties for those who ignore it, gets registers updated faster and sours the relationship less.
There is also a wider innovation case. Kenya's economy runs on mobile-first services, and the Act reaches any controller or processor handling data of people in Kenya. Predictable, published enforcement lets startups budget for compliance the way they budget for tax filings. Erratic enforcement pushes them towards jurisdictions where the rules are easier to read.
Three tests for the succession
- No gap in enforcement. The statutory timetable is compressed, seven days to advertise and 21 to shortlist. But nomination by the President and approval by the National Assembly can slow it. The PSC and Parliament should aim to seat a commissioner before Kassait leaves, so that complaint handling and registration follow-up do not stall.
- Keep the process open. Section 6 requires publication of applicants and open interviews. The ODPC will regulate government agencies as well as companies, so its credibility depends on a process that is visibly free of political favouritism.
- Publish the enforcement playbook. The next commissioner should state in writing how notices, cure periods and penalties escalate. The August notice gives a template. Putting it in guidance would let firms rely on it after the leadership changes.
The bottom line
A good regulator is measured by whether firms understand what will happen when they miss a deadline. Kassait's office set a workable pattern with a list, a window and a portal. The new commissioner should build on it rather than swap it for a heavier hand.