Ask a Kenyan online shop owner about the Data Protection Act and you will usually get a blank look. Ask whether they have registered with the Office of the Data Protection Commissioner and you will get the same look, slightly more worried. This is the least-discussed legal obligation in Kenyan ecommerce, and a meaningful share of shops are on the wrong side of it without knowing.
This is a practical summary written for merchants, not a legal opinion. Every figure comes from the ODPC's own published guidance as of August 2026. If your situation is unusual — health data, children's data, anything sensitive — pay a lawyer. For an ordinary shop selling ordinary things, what follows is most of what you need.
Skip to: Do you need to register? · What it costs · What your website needs · The 72-hour rule · Penalties · What to actually do this week
Do you need to register?
The exemption test is the part most people get wrong, because it is an AND, not an OR. You are exempt only if your annual turnover is below KES 5 million and you have fewer than 10 employees. Both conditions. Fail either one and you are in scope.
This catches a specific and very common Kenyan business shape: the shop doing KES 6–8 million a year with two or three people. Owners assume the small headcount exempts them. It does not.
Three further conditions remove the exemption regardless of how small you are:
- You operate in a mandatory sector. A defined list of sectors must register whatever their size. Check the current list on the ODPC site rather than assuming — it is broader than most people expect.
- You process sensitive personal data. Health information, biometrics, and similar categories carry the obligation regardless of turnover.
- You process the data of 10,000 or more people in a year. Note that this counts data subjects, not orders or revenue. A shop with a large newsletter list and modest sales can cross this line.
And one that surprises foreign sellers: the Act reaches organisations based outside Kenya if they offer goods or services to people in Kenya or monitor their behaviour. Incorporating abroad does not put you out of scope.
What registration costs
Less than most people fear. The fee is one-time, banded by size.
| Band | Definition | Registration | Renewal |
|---|---|---|---|
| Micro and small | 1–50 employees, up to KES 5M turnover | KES 4,000 | KES 2,000 |
| Medium | 51–99 employees, KES 5M–50M turnover | KES 16,000 | KES 9,000 |
| Large | Over 99 employees, over KES 50M turnover | KES 40,000 | KES 25,000 |
| Public entities | — | KES 4,000 | KES 2,000 |
| Charities and religious entities | — | KES 4,000 | KES 2,000 |
Mobile money and card payments add a KES 50 transaction cost. The certificate is issued within 14 days of a satisfactory application and is valid for 24 months. Renewal must be applied for at least 30 days before expiry.
For most Kenyan online shops that is KES 4,000, once, every two years. Set against the penalties below, it is one of the cheapest pieces of compliance you will ever buy — and unlike most, it takes an afternoon.
What your website actually needs
Registration is the paperwork. These are the things that have to be true of your shop day to day, and they are where most merchants are quietly non-compliant.
1 — A real privacy policy, linked from every page
Not a template with another company's name still in it, which is depressingly common on Kenyan ecommerce sites. It needs to say what you collect (name, phone, delivery address, M-Pesa reference, browsing data), why you collect each thing, how long you keep it, and who else sees it. That last one matters more than people realise: your courier sees the delivery address, your payment gateway sees the transaction, your analytics provider sees the browsing. Those are disclosures.
2 — A lawful basis for each thing you collect
You need a reason for every field. A delivery address is necessary to perform the contract — easy. A date of birth collected because the form template had the field is not defensible. The practical rule: if you cannot say in one sentence why you need a field, delete the field. This makes your checkout convert better anyway.
3 — Opt-in consent for marketing, not pre-ticked boxes
A pre-ticked "send me offers" box is not consent. Neither is burying it in terms the customer accepts to complete a purchase. The customer must actively choose it, and must be able to withdraw it as easily as they gave it — an unsubscribe link that works, every time, without a reply-to-request dance.
4 — A working way to request data or deletion
Customers have the right to ask what you hold and to have it deleted. You need a route for that — an email address that a human actually reads is sufficient for a small shop — and you need to be able to honour it. That means knowing where customer data actually lives, which for many merchants is the uncomfortable part: the site database, an exported spreadsheet, WhatsApp, and an old laptop.
5 — Reasonable security
HTTPS on every page, no exceptions. Access to the admin panel limited to people who need it, with their own logins rather than a shared password. Customer data not living in a WhatsApp group or an unprotected spreadsheet. None of this is exotic; all of it is the sort of thing that gets noticed after an incident rather than before.
Every site we build ships the technical half of this — HTTPS, sane access control, and a privacy policy page wired into the footer. The words in the policy are yours, and are worth a lawyer's hour. See the launch checklist for where this sits in the wider pre-launch sequence.
The 72-hour rule
If personal data you hold is breached, you must notify the ODPC within 72 hours of becoming aware of it.
Three things about that sentence are worth sitting with. The clock starts when you become aware, not when the breach occurred — so "we did not realise for a month" does not buy you time, but it does mean you should not delay investigating. Seventy-two hours includes weekends. And "breach" is broader than hacking: a customer list emailed to the wrong person, a laptop stolen from a car, or an employee taking the database on their way out all count.
The practical preparation is one paragraph in your operating notes: who decides this is a breach, who contacts the ODPC, and where the customer data actually lives. Written now, that paragraph takes ten minutes. Written during an incident, it does not get written.
What non-compliance costs
Administrative fines run to up to KES 5 million or 1% of annual turnover, whichever is lower. Note "lower" — the current ceiling is comparatively merciful for a large business. The Data Protection (Amendment) Bill 2025 proposes flipping that to whichever is higher, which would change the arithmetic substantially for anyone turning over more than KES 500 million. Worth watching if that describes you.
Separately, the Act carries criminal penalties of up to KES 3 million in fines and imprisonment of up to 10 years. Those attach to serious offences rather than to a shop that forgot to register, and the realistic exposure for a small merchant is the administrative fine. But the gap between "KES 4,000 to register" and "up to KES 5 million if it goes badly" is wide enough that the calculation is not close.
What to actually do this week
- Work out if you are exempt. Turnover under KES 5M and fewer than 10 employees. If either fails, you are registering.
- Check the mandatory-sector list on the ODPC site even if you think you are exempt on size.
- Read your own privacy policy. If it names another company, or you cannot remember where it came from, it needs rewriting.
- Audit your form fields. Delete anything you cannot justify in one sentence. Your conversion rate will thank you.
- Find every place customer data lives. Site database, exports, spreadsheets, WhatsApp, personal laptops. You cannot honour a deletion request against data you have forgotten about.
- Write the breach paragraph. Who decides, who calls, where the data is. Ten minutes.
- Register if you need to, and diarise the 24-month expiry the day the certificate arrives.
None of this is glamorous and none of it will sell a single extra order. It is also the cheapest legal risk you will ever retire — KES 4,000 and an afternoon for most shops. Do it before you need to have done it.
For the rest of the pre-launch sequence, work through the 30-item Kenyan ecommerce launch checklist. If you are still choosing how to take payment, the gateway fee comparison covers what each provider actually charges — and note that your gateway is a third party who sees customer data, so it belongs in your privacy policy.
Figures verified against ODPC published guidance, August 2026. This is general information for merchants, not legal advice — for anything sensitive or unusual, talk to a Kenyan data protection lawyer.