A Deadline With a Backstory
On August 29, 2026, Kenya's Office of the Data Protection Commissioner (ODPC) issued a public notice telling every data controller and processor whose registration certificate has expired that they have until September 11, close of business, to renew or face enforcement action. The regulator was explicit that continuing to process personal data on a lapsed certificate is itself an offence under Regulations 9 and 11 of the Data Protection (Registration of Data Controllers and Data Processors) Regulations, 2021, and that non-compliance can trigger penalty notices (Capital FM Kenya).
The timing matters. Commissioner Immaculate Kassait is finishing a single, non-renewable six-year term that began when she became Kenya's first Data Commissioner in November 2020 — and the Public Service Commission has already opened recruitment for her successor, with applications closing September 14, 2026, three days after the renewal deadline she just set (allAfrica; Pulse Kenya). A register-cleaning sweep landing in the final weeks of a founding commissioner's tenure is not automatically suspect, but it invites a fair question: is this durable enforcement policy, or a last legacy item before a handover?
The Case For the Sweep
The steelman is straightforward. Kenya's Data Protection Act, 2019 requires controllers and processors above thresholds set by the Commissioner to register, and Section 21 obliges the ODPC to maintain a public register open to inspection. A register full of expired entries is a register the regulator can no longer rely on — it can't confirm who is actually processing personal data, at what scale, or under what safeguards. Registration certificates are valid for 24 months and applicants are required to renew at least 30 days before expiry, according to the ODPC's own guidance (ODPC FAQs); a lapsed certificate means an entity that once disclosed its processing activities to the regulator has gone dark. For a young authority still building enforcement credibility — its Section 63 administrative-fine power tops out at Ksh5 million or 1% of annual turnover, whichever is lower (Data Protection Act, 2019, Kenya Law) — periodically forcing a refresh of who is actually on the rolls is basic regulatory hygiene, not overreach. Kenya has shown it will use that power: the ODPC fined Oppo Kenya the maximum Ksh5 million for ignoring an enforcement notice, a precedent that gives this week's warning some teeth.
Where the Execution Falls Short
The problem is not the requirement — it's the packaging. A 14-day compliance window, counted from a public notice rather than from individualised warnings to the specific entities whose certificates lapsed, is a tight ask in a market dominated by micro and small enterprises with limited in-house legal capacity. The renewal fees themselves are modest — Ksh2,000 for micro and small entities, Ksh9,000 for medium ones, Ksh25,000 for large controllers and processors (ODPC FAQs) — but the gap between a Ksh2,000 renewal fee and a Ksh5 million maximum penalty is enormous, and the ODPC's notice does not spell out whether first-time lapses will draw a graduated response (a further reminder, a short cure period) or go straight to a penalty notice. Proportionate enforcement means the size of the stick should track the seriousness of the lapse — an SME that missed a renewal date is not the same risk as an entity that never registered at all.
The leadership-transition timing compounds the ambiguity. If the ODPC intends to actually issue penalty notices for entities that miss the September 11 deadline, those decisions will land either in Kassait's final weeks or in the hands of an acting commissioner while the Public Service Commission finishes recruiting a successor. Regulatory continuity matters most exactly when discretion is being exercised — and a compliance sweep timed to close just before a leadership handover, without published guidance on how enforcement discretion will be applied, risks looking more like tidying the books for a successor than a considered enforcement decision.
The Broader Stakes
None of this undermines the case for registration itself. A functioning register is a precondition for the ODPC to do meaningful oversight, and Kenya has positioned itself as a data-protection leader in East Africa partly on the strength of visible enforcement. But the credibility of that leadership rests on predictable, proportionate process — not on compressed deadlines that coincide with an institutional changing of the guard. The ODPC would do more for long-term compliance culture by publishing a clear enforcement ladder now, before the current commissioner departs, than by leaving that judgment call to whoever answers the phone after September 11.