ODPC Data Breach: A Practical Guide to Reporting and What the Regulator Does Next

ODPC Data Breach: A Practical Guide to Reporting and What the Regulator Does Next

ODPC Data Breach Reporting: A Practical Guide


When a data breach happens in Kenya, the Office of the Data Protection Commissioner is not a passive recipient of a formality, it is an active regulator that reviews what you report, can request more information, and can open a full investigation based on what your notification does or does not say. Understanding exactly what the ODPC expects, in what format, and what happens after you submit, is different from understanding breach response in general terms. This guide focuses specifically on the ODPC side of a data breach: what makes a breach reportable, what a compliant notification must contain, how to actually submit it, and what the regulator does once it lands on their desk.


What Makes a Breach Reportable to the ODPC

Under Section 43 of the Data Protection Act, 2019, any personal data breach must be assessed for reportability the moment it is discovered. A breach is any incident involving unauthorized or unlawful destruction, loss, alteration, disclosure of, or access to personal data. The ODPC's own guidance makes clear that reporting is required in essentially all cases, not just severe ones, with the seventy two hour clock running regardless of how the breach occurred, whether through a cyberattack, an internal error, a lost device, or a vendor's mistake.

Where the breach also poses a high risk to the rights and freedoms of the individuals affected, a second, parallel obligation applies to notify those individuals directly. The ODPC treats these as two distinct duties, both time sensitive, both capable of being assessed independently during any later review.


What a Compliant ODPC Notification Must Include

The ODPC expects a breach notification to contain specific elements, and a vague or incomplete submission is one of the most common triggers for a follow up inquiry. A proper notification should set out a description of the nature of the breach, including how and when it occurred and when the organization became aware of it, the categories and approximate number of data subjects affected, the categories and approximate volume of personal data records involved, the likely consequences of the breach for the individuals concerned, and the measures already taken or proposed to address the breach and mitigate its effects, including any containment steps completed.

If the seventy two hour deadline cannot be met, the notification must explain the reason for the delay. The ODPC does not treat an unexplained late notification the same as a timely one, even where the underlying breach itself was handled reasonably well.

Organizations should also be prepared to name a contact person within the notification, typically the Data Protection Officer where one has been designated, since the ODPC frequently follows up with clarifying questions before reaching a determination.


How to Submit a Breach Notification to the ODPC

Notifications are directed to the Office of the Data Protection Commissioner through its official channels, and organizations that are already registered as data controllers or processors should reference their registration details in the notification. Where an organization is not yet registered, submitting a breach notification does not resolve that separate compliance gap, and the ODPC can treat unregistered status as an additional issue during its review.

Because the notification becomes a formal record, it is worth preparing it with the same care as any other regulatory submission, factually precise, free of speculation about matters still under investigation, and clear about what remains unknown versus what has been confirmed. Organizations frequently make the mistake of either over promising a level of certainty they do not yet have, or under disclosing out of caution, both of which can complicate the ODPC's assessment and any later determination.


The Forty Eight Hour Processor Rule

Where a data processor, rather than the controller itself, discovers the breach, the processor must notify its controller within forty eight hours of becoming aware of it. This shorter internal window exists specifically so the controller retains enough time within the overall seventy two hour period to assess the incident properly and prepare a complete notification to the ODPC. Processors that delay this internal notification put their controller's compliance at risk, and the ODPC can hold both parties accountable where a processor's delay caused the controller to miss its own deadline.

Any organization that relies on outsourced IT, hosting, payroll, or customer service providers should have this forty eight hour obligation written directly into its data processing agreements, rather than assuming it applies automatically without being documented.


What the ODPC Does After Receiving a Notification

Once a notification is received, the ODPC can take several paths depending on the severity and clarity of what has been reported. For lower risk, well documented incidents, the office may simply record the notification and close the matter, particularly where the organization demonstrates it acted promptly and appropriately. For more serious or ambiguous cases, the ODPC can request additional information, review the organization's broader data processing and security practices, and open a formal investigation under the Data Protection (Complaints Handling Procedure and Enforcement) Regulations, 2021.

Where an investigation proceeds, it typically examines whether the organization met its notification timelines, whether the security measures in place before the breach were adequate given the risk involved, and whether the organization's response and remediation were reasonable. The outcome is a formal determination, which can range from a finding of no further action, to an enforcement notice requiring specific corrective steps, to a penalty notice imposing an administrative fine, to an order of compensation for affected individuals, or referral for criminal prosecution in serious cases.


Documentation the ODPC May Request

Organizations should be prepared to produce, on request, their internal breach log and timeline of discovery and response, the data processing agreement with any processor involved if the breach originated with a vendor, evidence of the security measures in place at the time of the breach, the risk assessment used to determine whether individuals needed to be notified directly, and copies of any communications sent to affected data subjects. Having these ready in advance, rather than assembling them for the first time when the ODPC asks, significantly shortens and simplifies the review process.


Penalties Tied Specifically to ODPC Breach Reporting Failures

Failing to notify the ODPC within the required window is treated as its own compliance failure, separate from any penalty tied to the breach itself. Administrative fines can reach up to five million Kenyan Shillings or one percent of annual turnover for the preceding financial year, whichever is lower, while criminal penalties for certain offences under the Act can include fines up to three million shillings and imprisonment of up to ten years. Where the ODPC finds that an organization also failed to notify affected individuals despite a high risk breach, this typically compounds the outcome of any determination, since it represents a second, distinct failure on top of the reporting gap to the regulator.


Why Legal Support Matters at the ODPC Reporting Stage

The content and framing of a breach notification to the ODPC has a direct bearing on how the regulator treats the matter afterward. A precise, complete, well evidenced notification submitted on time signals a well governed organization and often results in a lighter touch review. A vague, late, or inconsistent notification tends to invite exactly the kind of follow up scrutiny that turns a single incident into a prolonged investigation.

Firms such as Kathurima N Advocates provide urgent support the moment a breach is discovered, helping organizations assess reportability quickly, prepare a notification that meets the ODPC's expectations within the statutory deadline, and represent the organization directly before the Commissioner if the matter proceeds to a formal investigation, with the aim of resolving the matter efficiently and limiting regulatory exposure.


Final Thoughts

Reporting a breach to the ODPC is not just a formality to tick off within seventy two hours, it is the document the regulator will use to decide how closely to look at everything else your organization has done. Treating the notification itself as a serious, carefully prepared piece of regulatory communication, backed by proper documentation and, where needed, experienced legal support, is what separates organizations that close out a breach quickly from those that end up managing a drawn out ODPC investigation on top of the original incident.

0 Comments

No comments yet — be the first to share your thoughts.

Leave a Comment

Your email address will not be published. Comments are reviewed before appearing.

WhatsApp