The Office of the Data Protection Commissioner (ODPC) has given data controllers and data processors with expired registration certificates 14 days to renew them, warning that those who continue handling personal information without valid registration could face enforcement action.

In a notice issued on August 28, 2026, the regulator urged all affected entities to urgently regularise their registration status by applying for renewal. The deadline for compliance has been set for September 11, 2026, close of business.

The ODPC said the directive applies to organisations whose registration certificates have expired and reminded them that entities required to register as data controllers or data processors cannot legally continue operating in that capacity without valid registration.

The regulator cited Section 18 of the Data Protection Act, 2019, which requires entities operating as data controllers or data processors to be registered with the Data Commissioner.

file_mlvsns
Photo of Data Protection Commissioner, Immaculate Kassait. /NATION MEDIA GROUP

It also referred to Regulations 9 and 11 of the Data Protection (Registration of Data Controllers and Data Processors) Regulations, 2021, which provide that registration certificates are valid for 24 months and are subject to renewal.

The regulations further state that continued processing of personal data after the expiry of a registration certificate without renewal constitutes an offence.

“Continued processing of personal data after expiry of a registration certificate without renewal constitutes an offence,” the ODPC stated.

The regulator warned that failure to comply with the latest directive could result in enforcement action in accordance with the law.

The renewal fees vary depending on the size and type of organisation. Micro and small entities will pay Ksh2,000 to renew their certificates, while medium-sized businesses will be charged Ksh9,000. Large entities will pay Ksh25,000, while public institutions, charities and religious organisations will be required to pay Ksh2,000.

Under the ODPC’s standing guidelines, registration certificates remain valid for two years, with organisations expected to submit renewal applications at least 30 days before their certificates expire.

The regulator has previously warned organisations handling personal information to comply with registration requirements, with failure to register attracting penalties of up to Ksh5 million.

The latest notice comes as the ODPC intensifies enforcement of data protection requirements covering organisations that collect, store, use or otherwise process personal information.

Businesses and other organisations have been reminded that registration is a legal requirement where their activities fall within the categories requiring registration under the Data Protection Act and its regulations.

The ODPC has also published the names of organisations whose registration certificates have expired on its website, allowing affected entities to confirm their status and take the necessary steps to regularise their operations.

The regulator has urged organisations appearing on the list to complete their renewal applications without delay to avoid possible enforcement measures.

Entities requiring assistance with the renewal process have been advised to contact the ODPC through registration@odpc.go.ke or visit the regulator’s website for further information and guidance.

The notice places organisations handling personal data on a tight timeline to ensure their certificates are valid before the September 11 deadline, with continued processing of personal information after expiry potentially exposing them to legal consequences.

file_jg9b06
A past photo of Nairobi CBD. /PULSE KENYA