
The Office of the Data Protection Commissioner (ODPC) has given businesses 14 days to renew their expired data protection certificates or face penalties.
The directive targets organisations whose certificates have lapsed and forms part of the regulator’s efforts to ensure continued compliance with Kenya’s data protection laws.
The ODPC urged affected businesses to complete the renewal process within the stipulated period to avoid enforcement action.
The regulator warned that organisations that fail to renew their certificates could face penalties for non-compliance.
Businesses are required to maintain valid registration certificates where their operations involve the processing of personal data under the Data Protection Act.
The ODPC has continued to strengthen oversight of organisations that collect, store or use personal information.
The regulator said the renewal requirement was necessary to ensure that businesses remained compliant with their obligations under the law.
Affected organisations were advised to review the status of their certificates and take the necessary steps to renew them before the deadline expires.
The directive comes amid increased scrutiny of how businesses handle personal data and protect it from misuse or unauthorised access.
The ODPC has previously urged organisations to put in place appropriate safeguards and comply with registration and reporting requirements.
Businesses that fail to comply may be subjected to enforcement measures in accordance with the Data Protection Act and related regulations.
The regulator encouraged organisations to seek clarification through its official channels if they experienced difficulties during the renewal process.
The 14-day notice has renewed attention on the need for businesses to keep their regulatory certificates up to date and comply with Kenya’s data protection requirements.