Policy brief

A new Data Commissioner for Kenya: what the next six years should fix

As Kenya appoints its second Data Commissioner, the Office handles thousands of complaints, but its fines are capped low, its decisions are fragile in court, and the state rarely comes before it.

Author
ACTPOL
Published
Topic
Data protection and privacy
Region
East Africa
Region: East Africa

Key points

  • Kenya’s Office of the Data Protection Commissioner has handled thousands of complaints, but its fines are capped at KSh 5 million or 1 per cent of turnover, whichever is lower.
  • The most consequential checks on the state and on large platforms have come from the courts: on Huduma Namba, on IMEI registration and on Worldcoin.
  • A civil society analysis found that only 2 of 51 determinations in 2024 involved public bodies.
  • Parliament should raise the fine cap, fund the Office’s strategic plan and make the state’s own data use a priority for the next Commissioner.

A moment of transition

Kenya’s Data Protection Act, 2019 came into force on 25 November 2019, and the Office of the Data Protection Commissioner was established a year later.1 The Data Commissioner serves a single, non-renewable term of six years.2 On 25 August 2026 the Public Service Commission advertised the “impending vacancy” in the post, so Kenya is about to choose its second Data Commissioner.3

The first six years have built a working institution. The Office has registered thousands of data controllers and processors, opened regional offices in seven locations, and issued decisions that are now published on Kenya Law.4 They have also shown where the law and the institution need strengthening. This brief sets out what the next Commissioner, the Cabinet Secretary and Parliament should fix.

A busy complaints office

The Act gives people real rights and a practical route to enforce them. A complaint to the Data Commissioner must be investigated and concluded within 90 days, and a person who suffers damage can be awarded compensation.5 Kenyans have used that route in large numbers. According to its strategic plan for 2025 to 2029, the Office received 6,817 complaints in its first plan period and resolved 6,516 of them, issuing 195 determinations, 100 enforcement notices and 12 penalty notices.6 In January 2026 the Data Commissioner was reported as citing 9,061 complaints and 184 compensation orders.7

Compensation has become the Office’s main remedy. It ordered a beverage company to pay KSh 1.5 million to three people whose images it used commercially without consent, Nairobi Hospital to pay KSh 500,000 for using covert footage of a patient in an advertisement, and an internet service provider to pay KSh 700,000.8 Early complaints were dominated by digital lenders: by September 2022, 299 of the 555 cases admitted concerned them.9

Fines capped too low

Penalties tell a different story. The Act caps administrative fines at KSh 5 million or, for an undertaking, 1 per cent of the previous year’s turnover, “whichever is lower”.10 For a large company, 1 per cent of turnover would often be the higher figure, so the cap works in reverse: the bigger the company, the more certain it is that KSh 5 million is the most it can be fined.

The Office has reached that ceiling three times: against Oppo Kenya in December 2022, its first penalty notice, and against Whitepath and Regus Kenya in April 2023.11 Its penalties have largely survived in court. Challenges by a school, a lounge and a digital lender to penalties imposed in September 2023 all failed.12 But when the High Court upheld the Regus notices in September 2025, it halved the fine to KSh 2.5 million.13

The largest case of all ended without a fine. The Office restricted Worldcoin’s processing in 2022 and cancelled its registration in 2023. But the decisive ruling came on a judicial review brought by the Katiba Institute and others: on 5 May 2025 the High Court found that consent had been obtained “through inducement of a cryptocurrency” and ordered the biometric data erased within seven days, under the Commissioner’s supervision.14 The Office supervised the deletion in Germany, where the data was held.15

When the largest penalty the law allows is smaller than a rounding error in a multinational’s accounts, compliance becomes a cost of doing business.

The state, and the courts

The most significant checks on the state’s own data systems have also come from the courts. In 2020 the High Court allowed the national digital identity system to proceed only once “an appropriate and comprehensive regulatory framework” had been enacted.16 In 2021 it quashed the rollout of Huduma cards for want of the data protection impact assessment the Act requires.17 In July 2025 it quashed notices requiring the registration of mobile phone IMEI numbers, holding that an IMEI number “became personal data as soon as it was associated with a person”.18

The Office’s own record against public bodies is thin. A civil society analysis of its 2024 decisions found that only 2 of 51 determinations concerned public sector data handlers, and that they “were not as harsh” as those against the private sector.19 In March 2025 the Office asked the Auditor-General to include data protection in public audits, noting that even basic checks, such as whether a public entity has registered, are needed for public agencies to “begin their journey toward lawful data processing”.20

The Office’s strategic plan is candid about the pressures. It lists “vested political interests on independent operations of ODPC” among its threats. It needs KSh 12.6 billion over the plan period against an expected KSh 9.0 billion, and it works with 91 staff.21

Decisions that fail in court

A heavy caseload has also made the Office’s decisions procedurally fragile. The High Court has held that a determination issued after the 90-day limit is “a nullity”, and has set aside compensation awards, one of them for lack of proof of service and of “meaningful investigations”.22 A statutory deadline that protects complainants from delay can also defeat them when an overstretched office misses it.

What the next six years should fix

Much of the agenda is already recognised. The Office has told the High Court that the Act “requires amendments to align with emerging challenges”, and its strategic plan identifies gaps in the Commissioner’s powers over foreign companies.23 Kenya has also begun to build rules through guidance, including standard clauses for cross-border transfers issued in 2026, and the Cabinet has approved accession to the African Union’s Malabo Convention.24

  1. Raise the fine cap. Parliament should amend section 63 so that the maximum fine is KSh 5 million or a percentage of turnover, whichever is higher, as Nigeria’s law and the European Union’s GDPR provide.
  2. Appoint for independence. The Public Service Commission and the National Assembly should run an open process with a published shortlist, and vetting should test each candidate’s readiness to enforce the law against the state.
  3. Make the state’s data use a priority. The next Commissioner should audit the registration and impact assessments of public bodies, starting with national identity and health data systems, and publish the results.
  4. Fund the plan. The Treasury should close the funding gap in the Office’s strategic plan and add investigators in proportion to complaints.
  5. Make decisions robust. The Act should allow the Commissioner to extend the 90-day period for complex complaints, with reasons, and the Office should adopt service and investigation standards that meet the courts’ expectations.
  6. Finish the international agenda. Parliament should complete accession to the Malabo Convention, and the government should keep data localisation confined to the narrow purposes set out in the 2021 regulations.

Notes

  1. Data Protection Act, 2019 (No. 24 of 2019); Office of the Data Protection Commissioner, press release on Oppo Kenya, 21 December 2022. ↩

  2. Data Protection Act, 2019, sections 6(4) and 7(2). ↩

  3. Public Service Commission, call for applications for the position of Data Commissioner, 25 August 2026. ↩

  4. Office of the Data Protection Commissioner, “Kenya marks 5 years since the implementation of the Data Protection Act”, November 2024, and report of the parliamentary committee’s visit, April 2026; for example Liquid Telecom determination on Kenya Law, 3 November 2025. ↩

  5. Data Protection Act, 2019, sections 56(5) and 65. ↩

  6. Office of the Data Protection Commissioner, Strategic Plan 2025–2029. The Office’s published figures vary between releases; we use the strategic plan where possible. ↩

  7. Capital FM, “ODPC issues 184 compensation orders to data protection complainants”, 26 January 2026. ↩

  8. Office of the Data Protection Commissioner, determination against Mast-Jägermeister SE, 16 April 2025, and determination against Nairobi Hospital, 16 December 2025; Liquid Telecom determination, 3 November 2025. ↩

  9. Office of the Data Protection Commissioner, press release on digital credit providers, 5 October 2022. ↩

  10. Data Protection Act, 2019, section 63. ↩

  11. Office of the Data Protection Commissioner, press release on Oppo Kenya, 21 December 2022, and press release on Whitepath and Regus Kenya, 11 April 2023. ↩

  12. Office of the Data Protection Commissioner, press release on three penalty notices, 26 September 2023; High Court decisions of 3 April 2024, 20 February 2025 and 31 July 2025. ↩

  13. High Court, decision on the Regus Kenya appeal, 30 September 2025. ↩

  14. High Court, judgment in the Worldcoin judicial review, 5 May 2025; see also the preservation order of 25 January 2024. ↩

  15. High Court, ruling of 14 November 2025. ↩

  16. Nubian Rights Forum and others v Attorney General and others, High Court, 30 January 2020. ↩

  17. Republic v Joe Mucheru, Cabinet Secretary for ICT and others, ex parte Katiba Institute, High Court, 14 October 2021. ↩

  18. Katiba Institute v Communications Authority of Kenya and others, High Court, 18 July 2025. ↩

  19. Data Privacy and Governance Society of Kenya, analysis of the ODPC’s 2024 determinations, January 2025. ↩

  20. Office of the Data Protection Commissioner, call to integrate data protection in audits, 20 March 2025. ↩

  21. Office of the Data Protection Commissioner, Strategic Plan 2025–2029, including table 7.2. ↩

  22. High Court decisions of 12 May 2023, 24 July 2025 and 7 May 2026. ↩

  23. High Court, Worldcoin judgment, 5 May 2025; Office of the Data Protection Commissioner, Strategic Plan 2025–2029. ↩

  24. Office of the Data Protection Commissioner, Guidance Notes for Cross-border Data Transfers, 2026, and consultations on accession to the Malabo Convention, 8 September 2025. ↩