A Compliance Deadline With Teeth
On June 4, 2026, Kenya's Office of the Data Protection Commissioner (ODPC) issued a nationwide directive ordering every entity that handles personal data — businesses, government bodies, religious institutions, schools, hospitals — to register as a data controller or data processor under the Data Protection Act, 2019, or face administrative fines of up to KSh 5 million. The legal hook is Section 18 of the Act, which states plainly that "no person shall act as a data controller or data processor unless registered with the Data Commissioner," backed by Section 63's penalty ceiling of five million shillings or 1% of annual turnover, whichever is lower (Data Protection Act, No. 24 of 2019).
The registration regime itself is not new. It commenced on July 14, 2022 under the Data Protection (Registration of Data Controllers and Data Processors) Regulations, 2021 (K.O. Associates). Entities with annual turnover above KSh 5 million or more than 10 employees must register, and a list of designated sectors — health, finance, telecoms, education, insurance, gaming, direct marketing, hospitality, transport and CCTV operators among them — must register regardless of size (ODPC FAQs). Fees are tiered from KSh 4,000 for micro and small entities up to KSh 40,000 for large ones, with a certificate valid for 24 months. Four years on, over 15,000 controllers and processors have signed up (Tangara Advocates) — a real number, but one that undercounts the plausible universe of eligible entities in an economy where informal SMEs, congregations and county-level service providers routinely process customer, member, patient and student data without ever touching a compliance checklist.
The Steelman: Why a Registry Makes Sense
ODPC's frustration is defensible. A registry is the precondition for everything else a data protection authority does — it tells the regulator who is processing what, at what scale, and where to send an enforcement notice when something goes wrong. Kenya's own enforcement record shows why that matters: the ODPC has already issued penalty notices against Oppo Kenya, Whitepath Company and Regus Kenya, and a separate batch of three notices totaling KSh 9,375,000 (ODPC Press Releases) — action that depends on knowing which entities exist and hold data in the first place. Digital lenders, health providers and political actors have all handled Kenyans' personal data with real potential for harm — from credit-scoring abuse to unauthorized data-sharing by political campaigns. A functioning registry also gives ordinary Kenyans a single place to check whether an organization asking for their data is accountable to anyone. None of that is achievable if registration remains optional in practice, which is effectively what a four-year, slow-uptake compliance rate amounts to.
Where the Sweep Overreaches
The problem is not the registry — it's the blunt, undifferentiated way this directive applies it. Naming religious institutions and schools alongside fintechs and hospitals in the same enforcement threat conflates categorically different risk profiles. A rural parish keeping a paper membership list and a digital lender running automated credit scoring on thousands of borrowers are not equivalent data protection risks, yet both now face the same KSh 5 million exposure — a sum that is immaterial to a bank but existential to a small NGO or a single-branch school. The Act's own turnover-based exemption (below KSh 5 million revenue and under 10 employees) already recognizes that scale should matter; the June directive's blanket sectoral sweep for education, health and religious bodies overrides that calibration for exactly the entities least equipped to navigate a formal registration process, pay tiered fees, and renew a certificate every 24 months.
There is also a fairness problem in timing. A rule that has sat under-enforced since 2022 suddenly becoming fine-backed in mid-2026 reads less like proportionate regulation and more like enforcement-by-surprise. Businesses and institutions that assumed low uptake meant low priority are now being told the opposite, retroactively, with the same maximum penalty that applies to entities that ignored the law for years. Good regulatory practice pairs a compliance deadline with a grace period, a clear communication campaign, and a demonstrated on-ramp — not a single directive that pairs an old obligation with a new fine.
A Better Path: Risk-Tiered Enforcement
ODPC would serve its own enforcement goals better by triaging: prioritize registration and audit resources on the sectors it has already flagged as high-risk — digital lenders, data brokers, health-tech platforms, political data operations — where the Data Commissioner has shown it will act, and give low-risk, low-revenue entities (small schools, congregations, community organizations) a longer runway, simplified registration, or a nominal fee waiver rather than exposure to the same KSh 5 million ceiling. That approach would grow the registry's coverage without treating a rural clinic and a repeat corporate offender as the same compliance problem. Kenya's Data Protection Act is a genuinely modern framework; the test now is whether its enforcement matches its ambition without crushing the small entities regulators say they also want to protect.