Insights / Regulatory & Compliance

Registering as a Data Handler in Kenya: What Life Sciences Companies Need to Know

By Clay & Associates Advocates · 6 min read ·

An African businesswoman typing on a laptop at an office desk, representing data protection and registration compliance

Registering as a data handler, more precisely as a data controller or data processor with the Office of the Data Protection Commissioner, is a step a life sciences or healthcare company operating in Kenya is almost never exempt from, regardless of size. Registration is also only the first of two separate obligations the Data Protection Act 2019 imposes on a company handling health or genetic data, and a company that stops at registration has not finished the job.

Who Must Register, and Why the Small-Business Exemption Rarely Helps Here

Section 18 of the Data Protection Act 2019 requires every data controller and data processor to register with the Data Commissioner before acting as one. The Data Protection (Registration of Data Controllers and Data Processors) Regulations 2021, Legal Notice No. 265 of 2021, set out the operative detail: regulation 13 exempts an entity from registration only where its annual turnover is below KES 5 million and it has fewer than 10 employees, and only where both conditions hold. Critically, that exemption does not apply, regardless of size, to an entity processing personal data for a purpose listed in the Third Schedule, which expressly includes health administration and the provision of patient care, alongside financial services, telecommunications, and businesses that process genetic data. This means a clinic, a pharmaceutical company handling patient data, a diagnostics provider, or a health-tech company almost always falls into the mandatory-registration category no matter how small it is. An exempted entity still has to comply with the Act’s substantive obligations under Parts IV and VI; exemption from registration is not exemption from the Act.

Registration Fees and Process

The Second Schedule to the 2021 Regulations sets registration and renewal fees by size band: a micro or small entity with 1 to 50 employees and turnover up to KES 5 million pays KES 4,000 to register and KES 2,000 to renew; a medium entity with 51 to 99 employees and turnover between KES 5 million and KES 50 million pays KES 16,000 to register and KES 9,000 to renew; a large entity with 99 or more employees or turnover above KES 50 million pays KES 40,000 to register and KES 25,000 to renew. Public entities and charities pay the lowest tier regardless of size. Applications are submitted electronically using Form DPR1, and require entity registration documents, contact details, a description of the purposes for which data is processed, and the categories of data involved. The Data Commissioner must issue a certificate or a decision within 14 days of a complete application, and any refusal comes with written reasons within 21 days. A certificate is valid for 24 months, and renewal, using Form DPR2, should be filed before or at expiry. A registered entity must notify the Commissioner of any change to its registered particulars within 14 days of that change.

Penalties for Getting This Wrong

Regulation 18 sets out three specific registration offences: processing personal data without registering, supplying false or misleading information in a registration application, and continuing to process after a certificate has expired without renewing. Each is referred back to section 73 of the Act, the general penalty provision, which sets a fine not exceeding KES 3 million, imprisonment for a term not exceeding 10 years, or both. The Data Commissioner’s office has demonstrated it will use its enforcement powers: it has issued penalty determinations in the millions of shillings against organisations for data protection breaches, though the exact figures and case details should be confirmed against the Commissioner’s own published determinations before being cited in any specific compliance advice, since press-reported figures on individual cases are not always straightforward to verify against the underlying determination.

Registration Is Not the Whole Job: The Data Protection Officer Requirement

Section 24 of the Act requires a data controller or processor to designate a data protection officer in three circumstances: where it is a public body, where its core activities require regular and systematic monitoring of data subjects on a large scale, or where its core activities consist of processing special categories of personal data. Section 2 of the Act defines sensitive personal data to expressly include health status and genetic data, among other categories. For a life sciences or healthcare company, this means the data protection officer requirement will almost always apply alongside the registration requirement, because health and genetic data processing is exactly the kind of core activity section 24 is aimed at. These are two separate obligations under two separate sections of the Act, and a company that registers with the Data Commissioner but never designates a data protection officer has completed only one of two mandatory steps, not the whole of its compliance obligation.

What This Means for a Life Sciences Company

The practical sequence is to register under section 18 using the correct fee tier and Form DPR1, treat that certificate as valid for 24 months with a renewal reminder well before expiry, and separately confirm whether a data protection officer needs to be designated under section 24, which for most health and genetic data processing will be yes. Because health data processing sits squarely inside the Third Schedule’s no-exemption list, a life sciences company should not spend time evaluating whether the small-business exemption applies to it; in almost every case it will not.

How We Can Help

Clay & Associates Advocates advises life sciences and healthcare companies on Data Protection Act compliance, including registration with the Office of the Data Protection Commissioner and data protection officer designation for entities handling health and genetic data. Our guide to the legal checklist for diaspora-backed health-tech startups in Kenya is a useful companion covering related compliance obligations for health-tech ventures. Contact our Life Sciences & Healthcare practice to register as a data controller or processor and confirm your data protection officer obligations.

Sources: Data Protection Act 2019, sections 2, 18, 24, and 73; Data Protection (Registration of Data Controllers and Data Processors) Regulations 2021, Legal Notice No. 265 of 2021, regulations 4, 5, 8 to 11, 13, 15, and 18, and the First and Second Schedules; Office of the Data Protection Commissioner (odpc.go.ke), registration guidance.

Frequently asked questions

Is my small clinic or health-tech startup exempt from registering with the ODPC?
Almost certainly not. The small-business exemption requires both turnover under KES 5 million and fewer than 10 employees, and it does not apply at all to entities processing data for health administration and patient care, which the Third Schedule names as a no-exemption category regardless of size.

How much does registration cost?
It depends on your size band: KES 4,000 for a micro or small entity, KES 16,000 for a medium entity, and KES 40,000 for a large entity, with lower renewal fees at each tier.

Do I still need a data protection officer if I’ve already registered?
Yes, if your core activity involves processing health or genetic data. Registration under section 18 and data protection officer designation under section 24 are separate legal requirements, and most health and genetic data processing triggers both.

What happens if I process data without registering?
Processing without registration is a specific offence under the 2021 Regulations, carrying the Act’s general penalty of a fine up to KES 3 million, imprisonment up to 10 years, or both.

&

Clay & Associates Advocates
This article is general information, not legal advice. For advice on your matter, speak to counsel.

Related Insights

Discover more