Data Handler Registration Kenya

Data Handler Registration Kenya

Data Handler Registration in Kenya: What You Actually Need to Register As


If you searched for data handler registration in Kenya, you are looking for the right thing, but not quite the right term. Kenya's Data Protection Act, 2019 does not use "data handler" as a defined legal category. The Act instead recognizes two distinct roles, data controller and data processor, and the registration requirement, the deadlines, the fees, the obligations, all attach to one or both of these specific terms, not to a general "data handler" label. Understanding which one actually applies to your organization is the real first step, and it changes how you register, what you disclose, and what ongoing obligations follow.


Why "Data Handler" Is Not the Correct Legal Term

"Data handler" is a term used informally, and in some other countries' data protection frameworks, to describe any organization that touches personal data in some way. Kenya's Data Protection Act, 2019 does not use it. Instead, Section 2 of the Act defines two specific roles. A data controller is a natural or legal person, public authority, agency, or other body that determines the purpose and means of processing personal data, in plain terms, the organization that decides why data is collected and how it will be used. A data processor is a natural or legal person, public authority, agency, or other body that processes personal data on behalf of a data controller, acting under instruction rather than independent decision making authority.

If your business collects customer information and decides how to use it, you are a data controller. If you process personal data on behalf of another organization, for example as a payroll provider, a cloud hosting company, or an outsourced call center, you are a data processor. Many organizations are genuinely both at once, controller for some activities, processor for others, and where that applies, both roles must be registered separately with the Office of the Data Protection Commissioner.


Who Actually Needs to Register

Regardless of which of these two roles applies to you, the registration requirement itself works the same way. Under the Data Protection (Registration of Data Controllers and Data Processors) Regulations, 2021, registration is generally mandatory if your organization has an annual turnover above five million Kenyan Shillings and more than ten employees, meeting either threshold alone is enough to trigger the requirement. Certain categories must register regardless of size, including organizations processing sensitive personal data at scale, financial services providers, telecommunications companies, healthcare providers, and betting and gaming companies.


How to Determine Whether You Are a Controller, a Processor, or Both

Ask a simple question about each data processing activity your organization carries out: who decided why this data is being collected and how it will be used? If your organization made that decision independently, you are the data controller for that activity. If you are carrying out processing strictly on someone else's instructions, under a contract, you are the data processor for that activity. A marketing agency running a campaign using its own client acquisition data is a controller for that activity, but a processor when it executes a campaign using a client's own customer list under that client's instructions. Getting this distinction right at the outset determines which registration category, or categories, your organization actually needs.


The Registration Process

Once you have correctly identified your role, or roles, registration follows the same process either way, completed through the Office of the Data Protection Commissioner's online portal. This involves creating an account, completing the prescribed application detailing your organizational information, a description of your processing activities, categories of data subjects and personal data involved, and your security safeguards, paying the applicable fee, tiered by organization size, and awaiting review. Where a complete, properly prepared application is submitted, the ODPC generally issues a certificate of registration within about fourteen days, valid for twenty four months before renewal is required.


Why Getting the Terminology Right Matters

This is not just a semantic point. Using the wrong terminology when preparing your registration application, describing your organization generically as a "data handler" rather than correctly identifying whether you are acting as a controller, a processor, or both for specific activities, can lead to an incomplete or inaccurate application, which risks delay, rejection, or a registration that does not actually reflect what your organization does. The ODPC's application process is built around the Act's actual defined roles, and a precise, accurate application from the outset moves through review far more smoothly than one built on informal terminology.


Getting Registered Correctly the First Time

Whether your organization is acting as a data controller, a data processor, or both, the underlying registration obligation, and the risk of getting it wrong, is the same. At Kathurima N Advocates, we help businesses correctly identify which role applies to each of their data processing activities, prepare complete and accurate ODPC applications reflecting that correctly, and manage the registration process end to end, so you register as what you actually are under Kenyan law, not under an informal label that does not map cleanly to the Act's actual requirements.


Book a Free Consultation with Kathurima N Advocates

0 Comments

No comments yet — be the first to share your thoughts.

Leave a Comment

Your email address will not be published. Comments are reviewed before appearing.

WhatsApp