Data Processor Kenya: What the Data Protection Act Requires and How Processor Obligations Differ From Controllers

Data Processor Kenya: What the Data Protection Act Requires and How Processor Obligations Differ From Controllers

Data Processor vs Controller in Kenya: DPA Obligations


A payroll company running salary calculations for a client. A cloud hosting provider storing customer records on behalf of an ecommerce platform. A call center handling customer support on behalf of a bank. A marketing agency sending email campaigns using a client's subscriber list. None of these businesses decide why the personal data is collected or how it will ultimately be used, yet all of them touch personal data directly, often at significant scale. Under Kenya's Data Protection Act, 2019, each of them is a data processor, and each carries its own distinct set of legal obligations to the Office of the Data Protection Commissioner.

Many businesses in Kenya understand that data controllers must register and comply with the Act, but assume processors are somehow covered indirectly through their contracts with controllers. That assumption is incorrect, and it exposes processors to real regulatory risk. This article explains what a data processor is, how the role differs from a data controller, and what obligations, including registration, contractual requirements, and liability, apply specifically to processors.


What Is a Data Processor Under Kenyan Law

The Data Protection Act, 2019 defines a data processor as any natural or legal person, public authority, agency, or other body that processes personal data on behalf of a data controller. The defining feature of a processor is that it does not determine the purpose or means of processing. It acts on instructions from the controller, within the scope defined by a contract, without independent decision making power over how the data is ultimately used.

Common examples of data processors operating in Kenya include cloud storage and IT service providers, payroll and HR outsourcing firms, call centers and business process outsourcing companies, marketing and advertising agencies executing campaigns on a client's data, payment gateway and transaction processing providers, and software as a service platforms that host customer data for their business clients.

An organization can be both a controller and a processor at the same time, depending on the activity in question. A digital marketing agency, for example, is a controller of the data it collects for its own internal analytics, but a processor of the client data it uses to run campaigns on that client's behalf. Where an organization sits in both roles, it carries the obligations of both.


Data Processor vs Data Controller: The Key Difference

The distinction comes down to decision making authority. A data controller decides why personal data is collected and how it will be used. A data processor carries out processing activities strictly according to the controller's instructions and does not make independent decisions about the purpose of that processing.

This distinction matters because the Data Protection Act assigns different, though overlapping, obligations to each role. Controllers bear primary responsibility for establishing a lawful basis for processing, informing data subjects, and honoring data subject rights requests such as access or erasure. Processors, by contrast, are responsible for processing data securely, strictly within the scope authorized by the controller, and for supporting the controller in meeting its own obligations, including breach notification and responding to data subject rights requests that flow through the processor.

An employee is not considered a data processor merely by handling data as part of their job for their employer. The processor relationship specifically requires a separate legal or organizational entity acting on behalf of a controller under a defined contractual relationship.


Registration Obligations for Data Processors

Data processors are not exempt from ODPC registration simply because they act on a controller's instructions. Under the Data Protection (Registration of Data Controllers and Data Processors) Regulations, 2021, the same thresholds that apply to controllers generally apply to processors: an organization must register if it has an annual turnover above five million Kenyan Shillings and more than ten employees, or meets one of those thresholds individually. Certain sectors must register regardless of size, including processors handling sensitive personal data at scale, financial services, telecommunications, and healthcare related processing.

Where an organization acts as both a controller and a processor, it is required to register in both capacities separately, since each registration reflects a different processing role and set of obligations. Registration is completed through the ODPC's online portal, requiring organizational details, a description of the processing activities carried out on behalf of controllers, categories of data processed, and details of the security safeguards applied. Fees follow the same tiered structure used for controllers, ranging from roughly four thousand shillings for micro and small entities to around forty thousand shillings for large organizations, with certificates valid for twenty four months and renewable thirty days before expiry.

Operating as an unregistered data processor where registration is required carries the same criminal exposure as unregistered controller activity, including fines of up to three million shillings, imprisonment of up to ten years, or both.


Contractual Requirements Between Controllers and Processors

The Data Protection Act requires that the relationship between a controller and a processor be governed by a written contract or other legal instrument, not an informal or verbal arrangement. This is one of the most commonly overlooked obligations, particularly among smaller businesses that engage freelancers or small vendors to handle customer data without a formal data processing agreement in place.

A compliant processing agreement should clearly set out the subject matter, nature, and duration of the processing, the specific purpose for which the processor is authorized to process data, the categories of personal data and data subjects involved, the controller's instructions that the processor is bound to follow, the security measures the processor must implement to protect the data, confidentiality obligations for anyone within the processor's organization who handles the data, terms governing the use of any sub processors, procedures for assisting the controller with data subject rights requests and breach notifications, and obligations to delete or return personal data once the processing engagement ends.

Without this kind of agreement in place, both parties are exposed. The controller cannot demonstrate it exercised proper oversight of how its customers' data was handled, and the processor has no documented boundary defining what it was authorized to do with the data it received.


Security and Operational Obligations

Processors carry a direct obligation under the Act to implement appropriate technical and organizational security measures to protect the personal data they handle, proportionate to the risk involved. This includes safeguards against unauthorized access, accidental loss, alteration, or destruction of data. A processor cannot rely solely on the controller's own security posture and treat itself as exempt from independent responsibility.

Processors must also notify the relevant data controller promptly upon becoming aware of a personal data breach, specifically within forty eight hours, so the controller can meet its own seventy two hour notification obligation to the ODPC. This shorter internal timeline exists precisely because the controller needs time to assess the breach, prepare notifications, and meet its own regulatory deadline. A processor that delays reporting a breach internally puts the controller at risk of missing the ODPC's statutory window, which becomes a compliance failure attributable to both parties.


Liability and Enforcement

A common misconception is that liability under the Data Protection Act rests entirely with the controller, since the controller is the party that determines how and why data is processed. In practice, the ODPC can and does hold processors directly accountable for their own conduct, particularly where a processor exceeds its authorized instructions, fails to implement adequate security measures, engages an unauthorized sub processor, or fails to notify a controller of a breach within the required timeframe.

Where a processor is found to have contributed to a violation, it can face the same categories of consequence as a controller, including administrative fines, enforcement notices, and in serious cases criminal liability. Compensation claims from affected data subjects can also extend to processors where their conduct directly caused or contributed to the harm suffered.


Why This Distinction Matters for Compliance Strategy

Businesses that engage third party vendors, cloud providers, outsourced HR firms, marketing agencies, or IT support companies need to know precisely which entity in the relationship is the controller and which is the processor, since this determines who must register in which capacity, whose obligations apply where, and how liability is likely to be apportioned if something goes wrong. Getting this wrong, either by assuming a processor role does not require registration, or by operating without a proper data processing agreement, is one of the more common and preventable compliance gaps the ODPC encounters.

Firms such as Kathurima N Advocates work with both controllers and processors to clarify exactly where each party sits in a given data relationship, draft and review data processing agreements that meet the Act's requirements, guide processors through ODPC registration in the correct capacity, and help both sides build the internal safeguards and breach response procedures the law expects, so that compliance obligations are met on both sides of every vendor and outsourcing relationship rather than assumed away.


Final Thoughts

Being a data processor in Kenya is not a lighter version of being a data controller, it is a distinct legal role with its own registration duties, contractual requirements, security obligations, and exposure to enforcement. Any business that processes personal data on behalf of another organization, whether through hosting, outsourcing, marketing, or payment services, should treat its processor obligations under the Data Protection Act as a compliance priority in its own right, not as something covered automatically by the controller's paperwork.

0 Comments

No comments yet — be the first to share your thoughts.

Leave a Comment

Your email address will not be published. Comments are reviewed before appearing.

WhatsApp