Who Must Comply, What It Means, and Why It Matters
In Kenya’s thriving digital economy, personal data is the new gold: valuable, yet vulnerable. That’s why it is protected under the Data Protection Act, 2019 and enforced by the Office of the Data Protection Commissioner (ODPC). Yet, many businesses and professionals remain uncertain about whether the law applies to them and what compliance truly requires.
Take a friend of mine who runs a cosy 10-room hotel in Nanyuki. One evening, she messaged me, slightly panicked: “Wendy, all this data protection talk on WhatsApp, does it really apply to my small place? Guests give us their names, phone numbers, and ID copies at check-in!”
It’s a fair question and one I hear often.
What Qualifies as Personal Data?
Under the Data Protection Act, personal data refers to any information relating to an identified or identifiable individual. This includes:
• Names, ID numbers, passport details
• Phone numbers and email addresses
• Location data and online identifiers (IP addresses)
• Financial and employment information
• Biometric data (fingerprints, facial images)
• Health records and sensitive personal data
If the information can directly or indirectly identify a person, it is protected under the law.
Who Must Comply?
The short answer: almost every organization or individual handling personal data.
However, compliance is mandatory for:
• Businesses collecting customer information
• Employers handling employee records
• SMEs, startups, and online businesses
• NGOs, schools, hospitals, and financial institutions
• Digital platforms and e-commerce businesses
• Data controllers and processors within or outside Kenya handling Kenyan residents’ data
Under the Data Protection (General) Regulations, 2021, entities that process personal data, especially at scale or involving sensitive data, are required to register with the ODPC. Failure to register is itself an offence.
What Does Compliance Involve?
Compliance is not a one-time event. It is an ongoing legal obligation that includes:
• Registration as a Data Controller or Data Processor
• Development of data protection policies
• Ensuring lawful, fair, and transparent processing (Sections 25–30 of the Act)
• Obtaining valid consent before collecting or using personal data
• Implementing security safeguards against data breaches
• Establishing internal complaint mechanisms
• Respecting data subject rights (access, correction, deletion)
What Are the Penalties for Non-Compliance?
The Data Protection Act provides for serious consequences for non-compliance:
• Fines of up to KES 5 million or 1% of annual turnover
• Enforcement notices and administrative penalties issued by the ODPC
• Compensation claims by affected individuals
• Possible criminal liability for directors and officers
The ODPC has increasingly enforced these provisions, issuing penalty notices and compensation awards to affected individuals. (Kenya Times)
Enforcement in Kenya
Kenyan courts and regulators have already begun shaping data protection jurisprudence.
In Regus Kenya Limited v Data Protection Commissioner & Another (2025) (Kenya Law Reports), the High Court upheld a penalty notice of KES 5,000,000 imposed for failure to demonstrate compliance with the Data Protection Act. (Kenya Law)
Similarly, the ODPC fined Oppo Kenya KES 5,000,000 for using a customer’s image without consent and failing to comply with enforcement directives, demonstrating that non-compliance has real financial consequences. (odpc.go.ke) These cases confirm that regulators and courts are actively enforcing compliance and that organisations must take their obligations seriously.
Why Compliance Matters
Beyond legal requirements, data protection compliance is a business advantage. It builds credibility, strengthens client confidence, and positions your organisation as trustworthy in an increasingly regulated global environment. For organisations engaging in cross-border transactions, compliance is even more critical, aligning operations with international data protection standards like the EU’s GDPR,
Final Thoughts
Data protection is no longer optional. It is a legal and strategic necessity in Kenya’s evolving regulatory landscape. Whether you are a small business, a growing startup, or an established organisation, taking proactive steps toward compliance protects both your operations and the rights of individuals whose data you handle.
So my answer to my friend was straightforward:
Yes, it does apply. Hospitality businesses like hotels fall into a mandatory registration sector with the ODPC. No exemptions for small size, low turnover, or few staff (unlike some private sectors, which can skip it if under 10 employees and KES 5 million turnover). Registration is straightforward, with affordable fees and validity for two years.
Beyond that, compliance stays simple and guest-focused. Also, add a quick privacy note at booking or check-in, collect only what’s essential, store it securely, and honour guests’ rights to access or delete their information.
It’s really just thoughtful hospitality. You protect the privacy of your clients the same way you protect their stay and comfort.
If this sounds like your business, let’s get the basics sorted. Reach out for the next easy steps!
I offer professional services in data protection registration and compliance, including ODPC registration, policy development, audits, and advisory support. Reach out to ensure your organisation is fully compliant.