ODPC gives data handlers 14 days to renew expired certificates
Data Commissioner Immaculate Kassait said all data controllers and data processors whose certificates have expired must regularise their status by September 11, 2026.
Kenyan organisations handling personal data now have 14 days to renew their expired registration certificates or face enforcement action from the Office of the Data Protection Commissioner (ODPC). Data Commissioner Immaculate Kassait emphasized that all data controllers and processors must regularise their status by September 11, 2026.
The directive aims to ensure compliance with Kenya’s data protection laws. Organisations must apply for renewal promptly, or risk enforcement measures. The deadline applies to entities listed on the regulator’s published list of those with expired certificates. Under the Data Protection Act 2019, organisations must register to act as data controllers or processors.
Registration certificates are valid for 24 months and must be renewed. Failure to renew could expose organisations to regulatory action. Renewal fees differ based on the size and category of the organisation. The ODPC advises submitting renewal applications 30 days before expiry. The registration covers various sectors, including education, healthcare, finance, and telecommunications.
Organisations must register separately if they perform both data controller and processor roles. The ODPC aims to protect privacy rights and oversee compliance with the Data Protection Act.
Written by urgent.news from Capital FM Kenya's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.