Two questions, in order
The first question is whether you are a data controller, a data processor, or both. A controller decides why and how personal data is processed. A processor handles it on someone else's instructions. Most organisations are controllers for their own staff and customer data and processors for anyone whose data they handle under contract, which means both registrations may be required.
The second question is whether the exemption applies. The Regulations exempt controllers and processors below a threshold set by annual turnover and number of employees, but the exemption is removed for a list of activities regardless of size. That list captures a great deal of ordinary commercial activity, including direct marketing, credit reference, health administration, telecommunications, financial services, property management and the sale of land, transport services, education, and the processing of personal data of children. If your organisation appears on that list, size does not help you.
What the application asks for
The application to the Office of the Data Protection Commissioner is short, but it asks for information that many organisations have never written down: the categories of personal data processed, the purposes, the recipients, whether data leaves Kenya, and the name and contact details of the person responsible. Completing it honestly is therefore a compliance exercise in itself. Organisations that struggle with the form usually do not have a record of processing activities, and that is the document to build first.
Before you apply
- A record of processing activities, by purpose
- The categories of data subject and of personal data
- Recipients, including processors and group companies
- Any transfer of data outside Kenya, and its basis
- A named contact, and a data protection officer where required
- Turnover and headcount, to test the exemption
The certificate is not the end of it
Registration is valid for a defined period and must be renewed. It must also be kept accurate: a new product line, a new processor, or a decision to start marketing changes what you told the Commissioner. Treat the registration as a live record rather than a certificate on the wall.
Processing without registration
Processing while unregistered, where registration is required, is an offence and is also an aggravating factor if a complaint or a breach brings the organisation to the Commissioner's attention for another reason. In practice, enforcement rarely begins with registration; it begins with a complaint, and the absence of a registration is what turns a narrow enquiry into a broad one.
Appointing a data protection officer
A data protection officer is required for public bodies, for organisations processing on a large scale, and where processing of sensitive data is a core activity. The role has to be genuinely independent of the decisions it oversees, which is why it sits badly with the head of marketing or the head of technology. Where the volume does not justify an internal appointment, the function can be outsourced, and the appointment notified in the registration.
This guide is general information about the law in Kenya and is not advice on your particular circumstances. Speak to an advocate about your own facts.
This guide is general information about the law in Kenya and is not advice on your particular circumstances.
Speak to an advocate