Registration under the Kenya Data Protection Act 2019 is filed at dataportal.odpc.go.ke/Account/Register. The portal is a single long form broken into ten steps. This document lists every field, what it accepts, and what's required to upload before you start. The web version shows the same fields filled in using Bitverse Limited as a worked example.
Worked example — Bitverse Limited
Bitverse Limited is a Nairobi-based SaaS and agro e-commerce operator that processes personal data for farmer-suppliers, retail customers, employees, and SaaS tenants. Below is how the ODPC portal would be filled for the company — Data Controller registration in the Private / Institution category. Every field shows the answer Bitverse would submit, with the field name and a short hint for why.
01
Verification — who's filling the form
Portal step 1 · Resume-code supported
| Field | Constraint / Notes |
| Representative NameREQUIRED |
Stephen Muriithi |
| Phone NumberREQUIRED |
+254 7XX XXX XXXSafaricom-format placeholder; the portal accepts the 7XXX prefix common to Kenyan mobile numbers. |
| Email AddressREQUIRED |
stephen@bitverse.co.keCRITICAL — one email = one entity. Each subsidiary (Bitverse SaaS, plantain.co.ke, complya-app) needs its own separate email and separate registration. The portal will reject a duplicate email. |
| Institution |
Bitverse Limited |
| Relation to InstitutionREQUIRED |
Director & FounderThe portal placeholder reads: "indicate self if appropriate, or your role or relation to the institution." |
If you're resuming a half-done application
The first step doubles as a resume point — the radio switch toggles to "I have a Resume Code" instead, with a single Resume Code field. Don't start a new application if you've already begun one; you'll lose the in-progress data.
02
Basic Details — the entity being registered
Portal step 2 · Most error-prone step
| Field | Constraint / Notes |
| Data Handler TypeREQUIRED |
Data ControllerTwo radio options: Data Controller or Data Processor. Controllers decide why and how data is processed (Bitverse — the company decides what farmer and customer data to collect). Processors act on a controller's instructions (e.g. a cloud host). If you do BOTH, file two separate applications and pay the fee twice. |
| Handler CategoryREQUIRED |
PrivateThree radio options: Government Institution / Private / Not-for-Profit Entities & Religious Institutions. Determines the fee tier and which downstream fields appear (Government gets a State/County Department dropdown; Private gets the Private Type sub-radio). |
| Private TypeREQUIRED |
InstitutionAppears only if Handler Category = Private. Three sub-options: Institution / Individual / Others. Select Others only if you're a sole trader or unincorporated entity — most companies pick Institution. |
| Identification / BRS Registration NumberREQUIRED |
PVT-XXXXXXXXThe portal looks up your company on eCitizen (Business Registration Service) and auto-fills the institution name. Use the BRS number from your Certificate of Incorporation — typically in the format PVT-XXXXXXX or LLP-XXXXXXX depending on entity type. |
| Institution/Individual NameREQUIRED |
Bitverse LimitedThe exact legal name as incorporated. This is exactly how it will appear on your ODPC certificate — typos here mean a rejected certificate and a re-issue fee. Copy-paste from your Certificate of Incorporation. |
| Postal AddressREQUIRED |
P.O. Box 12345 – 00100, Nairobi |
| CountryREQUIRED |
KenyaDropdown of all 218 countries. Default is alphabetical; scroll to K. Foreign-domiciled controllers register here too but may need an additional local representative. |
| CountyREQUIRED |
NairobiDropdown of all 47 Kenyan counties — uppercase by convention. If you operate across counties, pick your registered/head-office county. |
| Telephone Number |
+254 20 XXX XXXX |
| State or County Department |
(field does not appear — Private/Institution path)This dropdown only appears if Handler Category = Government Institution. Options: County Department / County Corporation / State Department / State Corporation. |
| Legal EstablishmentREQUIRED |
Private Limited CompanyDropdown populated dynamically. Common options for Kenya: Sole Proprietorship, Partnership, Limited Liability Partnership, Private Limited Company, Public Limited Company, Society, Trust, Cooperative Society. Pick the one matching your Certificate of Incorporation. |
| SectorREQUIRED |
Information & CommunicationDropdown populated dynamically. Bitverse maps to Information & Communication (covers SaaS, e-commerce, fintech-adjacent). For dairy / agriculture pick Agriculture; for hospitals pick Health; for SACCOs pick Financial Services. |
| Sub SectorREQUIRED |
Software Development & IT ServicesDropdown populates based on Sector. Common sub-sectors under Information & Communication: Software Development, Telecommunications, Broadcasting, E-commerce, IT Services. |
| Establishment DocumentREQUIRED |
📎 Certificate-of-Incorporation.pdf (1.2 MB)PDF only, max 8 MB. Must be the current establishment document — Certificate of Incorporation, Business Name Certificate, Partnership Deed, or founding instrument depending on entity type. |
| Street |
Westlands, Nairobi |
| Building |
Bitverse House, 3rd Floor |
| Office Number |
Office 3B |
03
Data Protection Officer
Portal step 3 · Marked "Required" but conditionally so
Conditional requirement
The portal labels this section "Required" but you only need to fill it if your institution has a dedicated DPO. Under Section 24 of the DPA 2019, designation of a DPO is mandatory for: (a) public bodies, (b) entities that process large-scale data, (c) entities whose core activity is systematic monitoring of data subjects. Most medium and large companies should designate one — Bitverse designates because farmer PII is large-scale.
| Field | Constraint / Notes |
| Name of the OfficerREQUIRED |
[DPO's full name]Internal employee, or external DPO-as-a-service. The DPO must be reachable on the email and phone below — ODPC may contact them directly for verification. |
| Email Address of the OfficerREQUIRED |
dpo@bitverse.co.keShould be a role-based inbox (dpo@, privacy@), not a personal employee email — survives staff turnover without re-registration. |
| Phone Number of the OfficerREQUIRED |
+254 7XX XXX XXXWith country-code dropdown (defaulted to +254). |
04
Personal Data — categories & purposes
Portal step 4 · Repeatable group ("Add Personal Data Group")
Repeatable group
You can add as many Personal Data Groups as you have data-subject categories. Each group has three fields: Category, Description, Purpose. Add one group per category of people you hold data on (employees, customers, suppliers, etc.). Each group should be specific enough that ODPC can understand what you hold and why.
| Field | Constraint / Notes |
| CategoryREQUIRED |
Farmer-suppliersPlaceholder reads: "E.g. employee, client, students, supplier, shareholder, etc." Free-text — use the label that matches your business language. Bitverse uses "Farmer-suppliers" because that's who they collect data from. |
| DescriptionREQUIRED |
Names, national ID/passport numbers, KRA PINs, bank/mobile-money details, GPS coordinates of farms, production records, photos of deliveries, biometric (fingerprint) for collection verification.List the specific data fields you hold in this category. The more specific, the better — ODPC wants to see you actually understand what you process. |
| PurposeREQUIRED |
Procurement contracts, payment processing, supply forecasting, traceability compliance, and farm-extension support services.State WHY you collect and process this data, tied to a real business purpose. Vague answers ("for business operations") get rejected. |
Repeat for every data-subject category
Bitverse would add separate groups for: farmer-suppliers, retail customers, SaaS tenants, employees, contractors, and shareholders. Each group needs its own Category, Description, and Purpose.
05
Sensitive Personal Data
Portal step 5 · Conditional based on Yes/No
| Field | Constraint / Notes |
| Do you handle any sensitive data?REQUIRED |
YesTwo radio options: Yes / No. "Yes" unlocks the Sensitive Personal Data section. Sensitive data under Section 2 of the DPA includes: racial/ethnic origin, political opinions, religious beliefs, health data, sex life, sexual orientation, genetic data, biometric data, and — Kenya-specific — property details (incl. financials) and GPS location. |
| Purpose — Racial or ethnic origin |
(not handled) |
| Purpose — Property Details (incl. financials) |
Used for credit assessment of farmer-suppliers and recovery of outstanding procurement balances.Kenya uniquely includes property/financial data under "sensitive" — this catches most fintechs, lenders, and SACCOs. |
| Purpose — Religious, philosophical conscience, beliefs |
(not handled) |
| Purpose — Marital status (incl. spouse & children's details) |
(not handled) |
| Purpose — Health status (physical or mental) |
Recorded for farmer wellness programmes and insurance underwriting.Only fill if you actually process this. If yes, expect ODPC to ask for explicit consent records. |
| Purpose — Sex / sexual orientation |
(not handled) |
| Purpose — Biometric data |
Fingerprint verification of farmer-suppliers at milk/tea collection points to prevent proxy collection.Biometrics are particularly sensitive — ODPC has flagged biometric collection programs multiple times. You need a clear lawful basis (typically consent + legitimate interest). |
| Purpose — GPS location data |
Captured at farm registration to verify farm location, model supply zones, and prevent duplicate registrations. |
| Purpose — Genetic data |
(not handled) |
06
Transfer of Data — does data leave Kenya?
Portal step 6 · Drives cross-border obligations
| Field | Constraint / Notes |
| Does your data reside outside Kenya?REQUIRED |
YesTwo radio options: Yes / No. Bitverse uses cloud infrastructure outside Kenya (e.g. AWS eu-central-1, Google Cloud us-central1) — the answer is Yes. If you self-host everything in Kenya and use no third-party processors abroad, answer No. |
| List of CountriesREQUIRED |
Germany · United States · Ireland · SingaporeMulti-select dropdown — add every jurisdiction you transfer to. Bitverse's hosting footprint drives this list. Be exhaustive: missing a country = non-compliance with Section 48 cross-border transfer rules. |
Section 48 cross-border requirements
For each transfer destination, you should have: (a) a contract with adequate data-protection clauses, (b) a documented assessment of the destination country's protection level, and (c) one of the lawful bases (consent, contract performance, etc.). ODPC expects to see this in your policy pack, not in the registration form.
07
Measures of Protection — risks & safeguards
Portal step 7 · Repeatable group ("Add Risk Measure")
Repeatable group — for each risk, declare the safeguard
The portal pre-loads 14 standard risk types. You select the ones applicable to your entity, and for each one you describe the safeguard measure in place. The 14 standard risks are listed below.
| Risk | Safeguard measure (description) |
Malware AttacksREQUIRED Trojans, Spyware, Adware, Scareware, Ransomware, Botnets, Keyloggers, Worms, Rootkits, Viruses, Fileless malware. |
Endpoint protection on all staff devices (CrowdStrike Falcon); email gateway filtering (Proofpoint); monthly vulnerability scans; weekly OS patching SLA. |
| Password Theft |
Mandatory SSO via Okta with MFA (TOTP + WebAuthn); password manager (1Password) for shared service accounts; 90-day rotation policy. |
| Phishing Attacks |
Quarterly phishing simulations (KnowBe4); DMARC enforcement on bitverse.co.ke domain; mandatory phishing-awareness training for all staff handling payments. |
| Social Engineering (Baiting, Shoulder surfing, Dumpster diving) |
Clean-desk policy; visitor escort at all times; secure shredding bins; physical access control (badge-only) at office and data centre. |
| Ransomware |
Immutable off-site backups (AWS S3 Object Lock); 3-2-1 backup strategy; tested ransomware-recovery runbook; cyber-insurance policy. |
| Fraud (SIM swap, Embezzlement, Insider trading) |
Separation of duties on all payment flows; dual-approval for transactions > KES 100,000; continuous audit log review; background checks on finance staff. |
| Cyberespionage |
Threat-intelligence feeds; EDR with behavioural analytics; principle of least privilege on production systems; no standing admin access. |
| Theft of Financial / Card Payment Data |
PCI-DSS-compliant payment processing (Stripe, no card data stored on Bitverse systems); tokenisation of all card references; P2PE at point of capture. |
| Cyber Extortion (Bribery) |
Whistleblower hotline; anti-bribery training; ethics policy signed by all staff; documented incident-response playbook. |
| Distributed Denial of Service |
Cloudflare DDoS protection in front of all public endpoints; rate-limiting on API; auto-scaling for traffic spikes. |
| Theft and Sale of Corporate Data |
DLP on email and endpoints (Microsoft Purview); encryption at rest (AES-256) on all data stores; access reviews quarterly. |
| Email and Internet Fraud |
SPF/DKIM/DMARC enforced; outbound payment verification via secondary channel (callback policy); clear desk for cheques and invoices. |
| Advanced Persistent Threats (incl. SQL injection, XSS, RFI) |
SAST/DAST in CI/CD (Snyk, OWASP ZAP); WAF (Cloudflare); annual third-party penetration test; secure SDLC policy. |
| Cloud Attacks |
AWS/GCP security posture management (Wiz); IaC scanning (Checkov); principle of least privilege on cloud IAM; cloud configuration audit monthly. |
Add custom risks
The 14 pre-loaded risks are common categories. If you have entity-specific risks not in the list (e.g. GPS spoofing at milk collection points, agent fraud in last-mile delivery), add custom entries — the portal allows free-text risk + safeguard pairs.
08
Employees & Turnover — fee determination
Portal step 8 · Wrong band = refused application (Reg 10 & 16)
| Field | Constraint / Notes |
| Previous Year TurnoverREQUIRED |
Above KES 50,000,000Four dropdown bands: Below KES 5,000,000 / Between KES 5,000,001 and KES 50,000,000 / Above KES 50,000,000. Pick the band matching your most recent audited accounts (or KRA return for new entities). The portal uses this to compute your fee tier. |
| Number of EmployeesREQUIRED |
Over 99Four bands: 0–9 / 10–49 / 50–99 / Over 99. Counts both permanent and contract staff (not interns or pure consultants). Signed declaration required as upload. |
| Turnover EvidenceREQUIRED |
📎 Audited-Accounts-2025.pdf (3.4 MB)PDF, max 8 MB. Audited accounts for the most recent year, OR — for new entities — a signed revenue statement or KRA tax return. The document must show the figure consistent with the band you selected above. |
| Signed Declaration of Employee NumbersREQUIRED |
📎 Employee-Declaration.pdf (0.3 MB)PDF, max 8 MB. A letter signed by a Director or Company Secretary attesting to the number of employees in the band selected above. Template available from ODPC's website. |
| Non-Exempted CategoriesREQUIRED if turnover ≤ 5M |
(not applicable — turnover > KES 50M)14 listed categories — see warning box below. If your turnover is below KES 5M, you are exempted UNLESS you process data in any of these categories, in which case you must select all that apply. Above KES 5M, this section is not shown. |
8 common mistakes that get applications refused
- Wrong turnover band — picking Below 5M when audited accounts show 12M triggers re-classification and a fresh fee
- Establishment document scanned at low resolution — ODPC wants a clear, machine-readable copy
- Audited accounts not the most recent year — if your FY ends December, the December 2025 accounts must be uploaded before February 2026
- Institution name typo on the form — must match the Certificate of Incorporation exactly
- Personal email reused across multiple entities — the portal rejects duplicate emails
- DPO details left blank when the entity is large-scale or public — Section 24 is mandatory
- Sensitive Personal Data marked "No" when GPS or biometrics are clearly collected
- Risk Measures submitted with empty safeguard fields — every selected risk needs a description
09
Application Overview & Confirmation
Portal step 9 · Review before submit
| Field | Constraint / Notes |
| Confirmation CheckboxREQUIRED |
☑ "I certify that the particulars provided are correct and complete and hereby apply to be registered as Data Controller or Data Processor."Single checkbox — must be ticked to submit. Ticking constitutes a statutory declaration under Section 30 of the DPA. False declarations expose the signatory to personal liability. |
10
Login Credentials — portal account
Portal step 10 · Account created on submit
| Field | Constraint / Notes |
| EmailREQUIRED |
stephen@bitverse.co.keSame email as Step 1 — used as the portal login after verification. |
| Confirm EmailREQUIRED |
stephen@bitverse.co.keMust match exactly — copy-paste to avoid typos. |
| PasswordREQUIRED |
•••••••••••••••Strong-password rules enforced: min 12 chars, mixed case, digit, special character. Use a generated password stored in the company password manager — do not use a personal password. |
| Confirm PasswordREQUIRED |
••••••••••••••• |
★
Fee Schedule — what each band costs
Statutory fees · Per role · 2-year renewal
| Employees & Turnover Band | Fee |
| Micro / Small (1–50 staff, ≤ KES 5M turnover) |
KES 4,000 registration · KES 2,000 renewal |
| Medium (51–99 staff, KES 5M–50M turnover) |
KES 16,000 registration · KES 9,000 renewal |
| Large (>99 staff, > KES 50M turnover) |
KES 40,000 registration · KES 25,000 renewal |
| Public entities (any size) |
KES 4,000 registration · KES 2,000 renewal |
Controller + Processor?
If you act as both Data Controller and Data Processor (e.g. a SaaS that processes customer data on behalf of tenants AND controls data about its own employees), you pay the fee twice — file two separate applications from the same dashboard.
How to pay
After submitting the application, ODPC emails you an invoice. Payment methods on the portal: M-Pesa (most common), bank transfer, or cheque. Pick one, generate the invoice only once (re-clicking regenerates the same invoice — don't pay the old one then pay the new one).
What happens after you click submit
"ODPC reviews within 14 working days, then issues a registration certificate. The certificate is renewable every 2 years — file annual returns or you lapse."
Section 33 of the DPA 2019: operating as a data controller without valid registration is a fine of up to KES 5 million or 1% of annual turnover (whichever is higher). Registration is the floor, not the ceiling — policies, DPIA, breach response, and a designated DPO are the other obligations.