ODPC Registration Checklist
A practical guide for Kenyan data controllers & processors — from prerequisites to certificate in hand.
A practical guide for Kenyan data controllers & processors — from prerequisites to certificate in hand.
If you handle any personal data of any person residing in Kenya, this checklist is for you.
Kenya's Data Protection Act, 2019 applies to every entity — company, NGO, SACCO, fintech, hospital, school, religious organisation — that processes the personal data of any person residing in Kenya. It does not matter if you are incorporated in Nairobi or Delaware. If you hold Kenyan data, the Act applies.
The Office of the Data Protection Commissioner (ODPC) is the regulator. They maintain the public register of data controllers and processors. They investigate complaints. They publish enforcement notices. They issue directives.
Registration with ODPC is mandatory under the Act. There is no revenue threshold, no employee-count exemption, no "we're too small" carve-out. If you process personal data, you register.
It does not replace legal advice for complex cross-border transfers, large-scale sensitive data processing, or sector-specific regulators (CBK, IRA, KMPDC). For those, talk to a qualified Kenyan lawyer. For everything else — register, document, defend.
ODPC's online portal will not save a half-completed form indefinitely. Get these four things on paper before you log in.
List every category of personal data you collect. Names, ID numbers, phone numbers, emails, addresses, payment data, health data, employment records, photos, location data. The portal will ask. "All of it" is not an answer.
Why do you collect each category? Customer onboarding? Payroll? Service delivery? Marketing? Each purpose must be specific and lawful under the Act. Vague purposes get rejected.
This is the person in your organisation who owns data protection. It can be your COO, head of legal, founder — anyone with authority to act. The portal requires their name, email, and phone. They will be ODPC's contact point.
The current fee schedule is published by the Office of the Data Protection Commissioner on their website. Check the schedule for your entity type and category before you start, not after.
Go to the Office of the Data Protection Commissioner's official portal. Use the entity's primary business email — not a personal Gmail — because this becomes your registered contact.
The form has six sections. Most rejections happen here, usually from vague language in section four.
Legal name as it appears on your CR12 or registration certificate. Trading name if different. Physical address (not a P.O. Box — ODPC wants a physical address). Country of incorporation.
Your designated accountable person from the pre-work. Full name, official title, direct phone, corporate email. ODPC will contact this person — make sure they know.
Only required if your core activities involve large-scale, regular, and systematic monitoring of data subjects, or large-scale processing of sensitive personal data. Most SMEs do not need a separately-named DPO.
Tick all that apply: customers, employees, job applicants, suppliers, website visitors, patients, students, members. Most companies tick three to five.
Names, contact details, identification numbers, financial data, health data, location data, biometric data, employment history. Tick only what you actually collect.
This is where most applications fall apart. Vague purposes like "service delivery" or "business operations" get challenged. Be specific:
Each purpose must be tied to a lawful basis under Section 30 of the Act: consent, contract, legal obligation, vital interest, public task, or legitimate interest.
ODPC publishes the current fee schedule by entity category. Categories typically include large organisations, medium organisations, small organisations, and specific sectors (telecoms, banks, insurers). Your category depends on turnover, employee count, or sector.
Fees are published on the ODPC website. Check the schedule before you submit the form — the portal will calculate the amount based on your category.
Keep your payment confirmation message or bank slip. You will upload it in step four.
The portal will ask for the following, depending on entity type:
Upload PDFs. Keep filenames clean: CR12_YourCompany_2026.pdf, not scan_final_v3.pdf. ODPC staff have to open these.
Review every section. Tick the declaration. Submit.
ODPC will email confirmation of receipt. They will then review the application. For straightforward applications, this takes two to four weeks. For complex applications (cross-border transfers, large-scale processing, sensitive data), it can take longer.
ODPC may write back asking for clarification on processing purposes, lawful basis, or cross-border transfers. Reply within the deadline they give — typically seven days. Vague or late replies reset the review clock.
"Service delivery" is not a purpose. "Verifying customer identity during onboarding to comply with AML regulations" is a purpose. Be specific or expect a clarification request.
If you process payroll for clients, host data for partners, or run analytics on someone else's customer data, you are a processor. Register as one. Most companies are both controller and processor — pick both.
Using AWS US-East, Google Cloud, Azure, a US payroll vendor, or any offshore service provider means your data leaves Kenya. Declare it.
Register with a corporate email. ODPC will not chase you if they email dpo@gmail.com and your cousin is using that address.
Your CR12 must be issued within the last 12 months. Older CR12s get rejected. Order a fresh one if yours is more than six months old.
Paying the small-entity fee when you are a medium or large entity is treated as underpayment. Your application is paused until the balance is cleared.
Registration is one obligation. It does not exempt you from maintaining a privacy notice, responding to data subject requests, documenting breach response, or annual renewal.
Registration is a snapshot. Compliance is continuous. Here is what you owe ODPC each year, after the certificate lands.
Pay the renewal fee before your certificate expires. Update any changed details (new address, new accountable person, new processing activities).
If you suffer a data breach that affects the rights and freedoms of data subjects, notify ODPC within the timeline prescribed by the Act and ODPC's breach notification guidance. Have a written breach response plan before you need one — not during a panic.
Any data subject can ask you what data you hold on them, correct it, delete it, or object to processing. You must respond within statutory timelines. Have a process. Have a form. Train your team to recognise a request.
Maintain an internal Register of Data Processing Activities. Each entry: purpose, lawful basis, data categories, recipients, retention period, security measures. ODPC can request this on inspection.
Publish a privacy notice on your website that names the data you collect, why, who you share it with, and how someone contacts you to exercise their rights. Keep it accurate. Update it when processing changes.
Registration is one requirement. The Data Protection Act, 2019 has seven others you are likely missing. Complya's free 5-minute assessment surfaces them — across registration, governance, data subject rights, breach response, cross-border transfers, retention, and training.
Run the free assessment →