A Two-Week Ultimatum, Not a New Law
On August 29, 2026, Kenya's Office of the Data Protection Commissioner (ODPC) issued a public notice giving every data controller and processor whose registration certificate has expired 14 days to renew it. The deadline: close of business on September 11, 2026. Data Commissioner Immaculate Kassait's office said entities that keep processing personal data on an expired certificate are committing an offence under the Data Protection (Registration of Data Controllers and Data Processors) Regulations, 2021, and face enforcement action if they miss the window.
This is not a new statute. Registration has been mandatory since 2022 under Section 18 of the Data Protection Act, 2019, and certificates are valid for 24 months before they must be renewed. What is notable is the timing and the tone: a hard published deadline, tied to a named list of lapsed entities, arriving just as Kenya's penalty regime is quietly getting sharper.
The Case for the Deadline
The steelman is straightforward. Registration is the ODPC's basic visibility mechanism: without a current list of who is processing personal data, the regulator cannot target inspections, cannot verify that a breached company was ever accountable in the first place, and cannot distinguish a functioning business from one that quietly stopped filing years ago. Kenya's registration regime already spans sectors from telecoms and banks to CCTV operators and betting firms, because personal data flows through so much of the economy that case-by-case oversight would miss most of it. A lapsed certificate is not necessarily connected to a lapsed practice, but it removes the one instrument the regulator has for knowing whether that's true. Giving expired filers two weeks' notice, rather than proceeding straight to a penalty notice, is also a relatively light-touch way to run that check — a cure period, not a summary fine.
Enforcement With a Track Record
The threat behind the deadline is credible, which is exactly why the notice matters. The ODPC has already fined three organisations under the Act: Mulla Pride Ltd (KES 2.97 million, for using third-party contact data to pressure loan defaulters), Casa Vera Lounge (KES 1.85 million, for posting a customer's photo without consent), and Roma School (KES 4.55 million, the largest penalty yet against a school, for publishing images of minors without parental consent). When Mulla Pride challenged its fine as a constitutional violation rather than through the Act's statutory appeal route, the High Court dismissed the petition on July 31, 2025, holding that Section 64 already provides an adequate appeal mechanism and that the constitutional route was being used to bypass it. That ruling matters here: it confirms ODPC penalty notices carry real legal weight, and that the appeal path runs through ordinary administrative law, not around it.
Why the Timing Cuts Both Ways
Where the case for caution comes in is what's queued up behind this notice. Section 63 of the Data Protection Act currently caps administrative fines at KES 5 million or 1% of an undertaking's annual turnover — whichever is lower, a structure that shields large companies from fines scaled to their actual size. The pending Data Protection (Amendment) Bill, 2025 would flip that to "whichever is higher," a GDPR-style change that turns a capped, predictable exposure into one that scales directly with revenue. For a large bank, telecom, or multinational platform operating in Kenya, that is the difference between a fine that is a rounding error and one that shows up on an earnings call.
Neither change is objectionable in isolation. Registration compliance is a legitimate, low-cost ask, and scaling fines to turnover is standard practice in mature privacy regimes. The risk is sequencing: if Kenya moves from a registration sweep straight into a "whichever is higher" penalty regime without a comparable grace period for compliance uncertainty, small and medium enterprises — the same micro and small entities paying just KES 2,000 to renew — could face the same enforcement posture as a multinational, without the same capacity to track filing deadlines or de-risk quickly. Kenya's registration base already spans thousands of controllers across sectors most people wouldn't associate with "data processing": hospitality venues, schools, betting shops. A regulator that wants durable compliance, not just a clean published list, should keep pairing hard deadlines with genuine cure periods like this one, and calibrate the coming fine increase so it lands hardest on scale and recklessness — not on a small business that missed a renewal email.
"Failure to comply within the stipulated period may result in the ODPC initiating appropriate enforcement action in accordance with the law."
The Practical Takeaway
For now, the ask is narrow: check the ODPC's published list of expired certificates, and renew before September 11. But the notice is worth reading as a preview. Kenya's data protection regulator is demonstrating, ahead of a statutory amendment that will raise the stakes considerably, that it already treats registration lapses as an enforceable offence rather than paperwork. Businesses operating in Kenya should treat routine ODPC compliance the way they'd treat any GDPR-adjacent regime: with an actual renewal calendar, not the two weeks' notice currently on offer.