Organisations whose data protection registration certificates have lapsed have two weeks to renew them, with the Office of the Data Protection Commissioner (ODPC) warning that failure to comply could trigger enforcement action.
The directive affects data controllers and data processors whose certificates had expired by Friday, August 28, 2026, when the regulator issued a public notice calling on them to regularise their registration.
The ODPC said affected organisations must apply for renewal within 14 days from the date of the notice to continue meeting the requirements for handling personal data in Kenya.
Under the Data Protection Act, 2019, registration certificates issued to data controllers and data processors remain valid for 24 months. Once the two-year period ends, organisations are required to renew their registration.
The regulator warned that organisations that continue processing personal data after their certificates have expired, without obtaining renewal, commit an offence under Regulations 9 and 11 of the Data Protection (Registration of Data Controllers and Data Processors) Regulations, 2021.
Those affected have been asked to check the list published by the ODPC to establish whether their certificates are among those that have expired.
The regulator said the 14-day window is intended to give the affected entities an opportunity to bring their registration status up to date before possible action is taken.
Registration requirements
Section 18 of the Data Protection Act requires data controllers and data processors operating in Kenya to be registered with the Data Commissioner.
Data controllers are responsible for deciding the purpose for which personal information is collected and the manner in which it is processed. Data processors, on the other hand, process personal information on behalf of a data controller.
The requirement covers organisations and individuals involved in collecting, keeping or processing personal information, including businesses and other entities falling within the scope of the Data Protection Act and related regulations.
The regulations allow some small organisations to be exempted from compulsory registration if they meet the set conditions.
However, the exemptions do not extend to some sectors regarded as carrying higher risks to personal data.
The ODPC also clarified that an organisation carrying out both data controller and data processor functions must obtain registration for each role.
The regulator has been keeping a list of organisations whose registration certificates have expired and has called on those listed to take action and restore their registration.
Organisations covered by the notice can make their renewal applications through the ODPC's online platform.
They can also contact the regulator for assistance with the renewal process, with [email protected] provided for enquiries related to expired certificates and applications.
The ODPC has reminded data handlers that registration must remain active throughout their operations involving personal information.
With the compliance period beginning on August 28, affected organisations have until the expiry of the 14-day period to renew their certificates and avoid possible enforcement measures under the data protection law.