Complya Resources · A Bitverse product ← Back to all resources
Complya · A Bitverse Product

What every ODPC portal field looks like — with a real filled-in answer.

A worked example of registering as a Data Controller in Kenya. The PDF version is the field-by-field reference. The page below shows Bitverse Limited as the registered entity.

Worked example — Bitverse Limited Bitverse Limited is a Nairobi-based SaaS and agro e-commerce operator that processes personal data for farmer-suppliers, retail customers, employees, and SaaS tenants. Below is how the ODPC portal would be filled for the company — Data Controller registration in the Private / Institution category. Every field shows the answer Bitverse would submit, with the field name and a short hint for why.
01

Verification — who's filling the form

Portal step 1 · Resume-code supported
FieldConstraint / Notes
Representative NameREQUIRED Stephen Muriithi
Phone NumberREQUIRED +254 7XX XXX XXXSafaricom-format placeholder; the portal accepts the 7XXX prefix common to Kenyan mobile numbers.
Email AddressREQUIRED stephen@bitverse.co.keCRITICAL — one email = one entity. Each subsidiary (Bitverse SaaS, plantain.co.ke, complya-app) needs its own separate email and separate registration. The portal will reject a duplicate email.
Institution Bitverse Limited
Relation to InstitutionREQUIRED Director & FounderThe portal placeholder reads: "indicate self if appropriate, or your role or relation to the institution."
02

Basic Details — the entity being registered

Portal step 2 · Most error-prone step
FieldConstraint / Notes
Data Handler TypeREQUIRED Data ControllerTwo radio options: Data Controller or Data Processor. Controllers decide why and how data is processed (Bitverse — the company decides what farmer and customer data to collect). Processors act on a controller's instructions (e.g. a cloud host). If you do BOTH, file two separate applications and pay the fee twice.
Handler CategoryREQUIRED PrivateThree radio options: Government Institution / Private / Not-for-Profit Entities & Religious Institutions. Determines the fee tier and which downstream fields appear (Government gets a State/County Department dropdown; Private gets the Private Type sub-radio).
Private TypeREQUIRED InstitutionAppears only if Handler Category = Private. Three sub-options: Institution / Individual / Others. Select Others only if you're a sole trader or unincorporated entity — most companies pick Institution.
Identification / BRS Registration NumberREQUIRED PVT-XXXXXXXXThe portal looks up your company on eCitizen (Business Registration Service) and auto-fills the institution name. Use the BRS number from your Certificate of Incorporation — typically in the format PVT-XXXXXXX or LLP-XXXXXXX depending on entity type.
Institution/Individual NameREQUIRED Bitverse LimitedThe exact legal name as incorporated. This is exactly how it will appear on your ODPC certificate — typos here mean a rejected certificate and a re-issue fee. Copy-paste from your Certificate of Incorporation.
Postal AddressREQUIRED P.O. Box 12345 – 00100, Nairobi
CountryREQUIRED KenyaDropdown of all 218 countries. Default is alphabetical; scroll to K. Foreign-domiciled controllers register here too but may need an additional local representative.
CountyREQUIRED NairobiDropdown of all 47 Kenyan counties — uppercase by convention. If you operate across counties, pick your registered/head-office county.
Telephone Number +254 20 XXX XXXX
State or County Department (field does not appear — Private/Institution path)This dropdown only appears if Handler Category = Government Institution. Options: County Department / County Corporation / State Department / State Corporation.
Legal EstablishmentREQUIRED Private Limited CompanyDropdown populated dynamically. Common options for Kenya: Sole Proprietorship, Partnership, Limited Liability Partnership, Private Limited Company, Public Limited Company, Society, Trust, Cooperative Society. Pick the one matching your Certificate of Incorporation.
SectorREQUIRED Information & CommunicationDropdown populated dynamically. Bitverse maps to Information & Communication (covers SaaS, e-commerce, fintech-adjacent). For dairy / agriculture pick Agriculture; for hospitals pick Health; for SACCOs pick Financial Services.
Sub SectorREQUIRED Software Development & IT ServicesDropdown populates based on Sector. Common sub-sectors under Information & Communication: Software Development, Telecommunications, Broadcasting, E-commerce, IT Services.
Establishment DocumentREQUIRED 📎 Certificate-of-Incorporation.pdf (1.2 MB)PDF only, max 8 MB. Must be the current establishment document — Certificate of Incorporation, Business Name Certificate, Partnership Deed, or founding instrument depending on entity type.
Street Westlands, Nairobi
Building Bitverse House, 3rd Floor
Office Number Office 3B
03

Data Protection Officer

Portal step 3 · Marked "Required" but conditionally so
FieldConstraint / Notes
Name of the OfficerREQUIRED [DPO's full name]Internal employee, or external DPO-as-a-service. The DPO must be reachable on the email and phone below — ODPC may contact them directly for verification.
Email Address of the OfficerREQUIRED dpo@bitverse.co.keShould be a role-based inbox (dpo@, privacy@), not a personal employee email — survives staff turnover without re-registration.
Phone Number of the OfficerREQUIRED +254 7XX XXX XXXWith country-code dropdown (defaulted to +254).
04

Personal Data — categories & purposes

Portal step 4 · Repeatable group ("Add Personal Data Group")
FieldConstraint / Notes
CategoryREQUIRED Farmer-suppliersPlaceholder reads: "E.g. employee, client, students, supplier, shareholder, etc." Free-text — use the label that matches your business language. Bitverse uses "Farmer-suppliers" because that's who they collect data from.
DescriptionREQUIRED Names, national ID/passport numbers, KRA PINs, bank/mobile-money details, GPS coordinates of farms, production records, photos of deliveries, biometric (fingerprint) for collection verification.List the specific data fields you hold in this category. The more specific, the better — ODPC wants to see you actually understand what you process.
PurposeREQUIRED Procurement contracts, payment processing, supply forecasting, traceability compliance, and farm-extension support services.State WHY you collect and process this data, tied to a real business purpose. Vague answers ("for business operations") get rejected.
05

Sensitive Personal Data

Portal step 5 · Conditional based on Yes/No
FieldConstraint / Notes
Do you handle any sensitive data?REQUIRED YesTwo radio options: Yes / No. "Yes" unlocks the Sensitive Personal Data section. Sensitive data under Section 2 of the DPA includes: racial/ethnic origin, political opinions, religious beliefs, health data, sex life, sexual orientation, genetic data, biometric data, and — Kenya-specific — property details (incl. financials) and GPS location.
Purpose — Racial or ethnic origin (not handled)
Purpose — Property Details (incl. financials) Used for credit assessment of farmer-suppliers and recovery of outstanding procurement balances.Kenya uniquely includes property/financial data under "sensitive" — this catches most fintechs, lenders, and SACCOs.
Purpose — Religious, philosophical conscience, beliefs (not handled)
Purpose — Marital status (incl. spouse & children's details) (not handled)
Purpose — Health status (physical or mental) Recorded for farmer wellness programmes and insurance underwriting.Only fill if you actually process this. If yes, expect ODPC to ask for explicit consent records.
Purpose — Sex / sexual orientation (not handled)
Purpose — Biometric data Fingerprint verification of farmer-suppliers at milk/tea collection points to prevent proxy collection.Biometrics are particularly sensitive — ODPC has flagged biometric collection programs multiple times. You need a clear lawful basis (typically consent + legitimate interest).
Purpose — GPS location data Captured at farm registration to verify farm location, model supply zones, and prevent duplicate registrations.
Purpose — Genetic data (not handled)
06

Transfer of Data — does data leave Kenya?

Portal step 6 · Drives cross-border obligations
FieldConstraint / Notes
Does your data reside outside Kenya?REQUIRED YesTwo radio options: Yes / No. Bitverse uses cloud infrastructure outside Kenya (e.g. AWS eu-central-1, Google Cloud us-central1) — the answer is Yes. If you self-host everything in Kenya and use no third-party processors abroad, answer No.
List of CountriesREQUIRED Germany · United States · Ireland · SingaporeMulti-select dropdown — add every jurisdiction you transfer to. Bitverse's hosting footprint drives this list. Be exhaustive: missing a country = non-compliance with Section 48 cross-border transfer rules.
07

Measures of Protection — risks & safeguards

Portal step 7 · Repeatable group ("Add Risk Measure")
RiskSafeguard measure (description)
Malware AttacksREQUIRED
Trojans, Spyware, Adware, Scareware, Ransomware, Botnets, Keyloggers, Worms, Rootkits, Viruses, Fileless malware.
Endpoint protection on all staff devices (CrowdStrike Falcon); email gateway filtering (Proofpoint); monthly vulnerability scans; weekly OS patching SLA.
Password Theft Mandatory SSO via Okta with MFA (TOTP + WebAuthn); password manager (1Password) for shared service accounts; 90-day rotation policy.
Phishing Attacks Quarterly phishing simulations (KnowBe4); DMARC enforcement on bitverse.co.ke domain; mandatory phishing-awareness training for all staff handling payments.
Social Engineering (Baiting, Shoulder surfing, Dumpster diving) Clean-desk policy; visitor escort at all times; secure shredding bins; physical access control (badge-only) at office and data centre.
Ransomware Immutable off-site backups (AWS S3 Object Lock); 3-2-1 backup strategy; tested ransomware-recovery runbook; cyber-insurance policy.
Fraud (SIM swap, Embezzlement, Insider trading) Separation of duties on all payment flows; dual-approval for transactions > KES 100,000; continuous audit log review; background checks on finance staff.
Cyberespionage Threat-intelligence feeds; EDR with behavioural analytics; principle of least privilege on production systems; no standing admin access.
Theft of Financial / Card Payment Data PCI-DSS-compliant payment processing (Stripe, no card data stored on Bitverse systems); tokenisation of all card references; P2PE at point of capture.
Cyber Extortion (Bribery) Whistleblower hotline; anti-bribery training; ethics policy signed by all staff; documented incident-response playbook.
Distributed Denial of Service Cloudflare DDoS protection in front of all public endpoints; rate-limiting on API; auto-scaling for traffic spikes.
Theft and Sale of Corporate Data DLP on email and endpoints (Microsoft Purview); encryption at rest (AES-256) on all data stores; access reviews quarterly.
Email and Internet Fraud SPF/DKIM/DMARC enforced; outbound payment verification via secondary channel (callback policy); clear desk for cheques and invoices.
Advanced Persistent Threats (incl. SQL injection, XSS, RFI) SAST/DAST in CI/CD (Snyk, OWASP ZAP); WAF (Cloudflare); annual third-party penetration test; secure SDLC policy.
Cloud Attacks AWS/GCP security posture management (Wiz); IaC scanning (Checkov); principle of least privilege on cloud IAM; cloud configuration audit monthly.
08

Employees & Turnover — fee determination

Portal step 8 · Wrong band = refused application (Reg 10 & 16)
FieldConstraint / Notes
Previous Year TurnoverREQUIRED Above KES 50,000,000Four dropdown bands: Below KES 5,000,000 / Between KES 5,000,001 and KES 50,000,000 / Above KES 50,000,000. Pick the band matching your most recent audited accounts (or KRA return for new entities). The portal uses this to compute your fee tier.
Number of EmployeesREQUIRED Over 99Four bands: 0–9 / 10–49 / 50–99 / Over 99. Counts both permanent and contract staff (not interns or pure consultants). Signed declaration required as upload.
Turnover EvidenceREQUIRED 📎 Audited-Accounts-2025.pdf (3.4 MB)PDF, max 8 MB. Audited accounts for the most recent year, OR — for new entities — a signed revenue statement or KRA tax return. The document must show the figure consistent with the band you selected above.
Signed Declaration of Employee NumbersREQUIRED 📎 Employee-Declaration.pdf (0.3 MB)PDF, max 8 MB. A letter signed by a Director or Company Secretary attesting to the number of employees in the band selected above. Template available from ODPC's website.
Non-Exempted CategoriesREQUIRED if turnover ≤ 5M (not applicable — turnover > KES 50M)14 listed categories — see warning box below. If your turnover is below KES 5M, you are exempted UNLESS you process data in any of these categories, in which case you must select all that apply. Above KES 5M, this section is not shown.
8 common mistakes that get applications refused
  1. Wrong turnover band — picking Below 5M when audited accounts show 12M triggers re-classification and a fresh fee
  2. Establishment document scanned at low resolution — ODPC wants a clear, machine-readable copy
  3. Audited accounts not the most recent year — if your FY ends December, the December 2025 accounts must be uploaded before February 2026
  4. Institution name typo on the form — must match the Certificate of Incorporation exactly
  5. Personal email reused across multiple entities — the portal rejects duplicate emails
  6. DPO details left blank when the entity is large-scale or public — Section 24 is mandatory
  7. Sensitive Personal Data marked "No" when GPS or biometrics are clearly collected
  8. Risk Measures submitted with empty safeguard fields — every selected risk needs a description
09

Application Overview & Confirmation

Portal step 9 · Review before submit
FieldConstraint / Notes
Confirmation CheckboxREQUIRED ☑ "I certify that the particulars provided are correct and complete and hereby apply to be registered as Data Controller or Data Processor."Single checkbox — must be ticked to submit. Ticking constitutes a statutory declaration under Section 30 of the DPA. False declarations expose the signatory to personal liability.
10

Login Credentials — portal account

Portal step 10 · Account created on submit
FieldConstraint / Notes
EmailREQUIRED stephen@bitverse.co.keSame email as Step 1 — used as the portal login after verification.
Confirm EmailREQUIRED stephen@bitverse.co.keMust match exactly — copy-paste to avoid typos.
PasswordREQUIRED •••••••••••••••Strong-password rules enforced: min 12 chars, mixed case, digit, special character. Use a generated password stored in the company password manager — do not use a personal password.
Confirm PasswordREQUIRED •••••••••••••••

Fee Schedule — what each band costs

Statutory fees · Per role · 2-year renewal
Employees & Turnover BandFee
Micro / Small (1–50 staff, ≤ KES 5M turnover) KES 4,000 registration · KES 2,000 renewal
Medium (51–99 staff, KES 5M–50M turnover) KES 16,000 registration · KES 9,000 renewal
Large (>99 staff, > KES 50M turnover) KES 40,000 registration · KES 25,000 renewal
Public entities (any size) KES 4,000 registration · KES 2,000 renewal
What happens after you click submit
"ODPC reviews within 14 working days, then issues a registration certificate. The certificate is renewable every 2 years — file annual returns or you lapse."
Section 33 of the DPA 2019: operating as a data controller without valid registration is a fine of up to KES 5 million or 1% of annual turnover (whichever is higher). Registration is the floor, not the ceiling — policies, DPIA, breach response, and a designated DPO are the other obligations.
Complya · A product by Bitverse Limited · Nairobi, Kenya · 2026 · Free to share with credit