Yes — most Kenyan NGOs, charities and faith-based organisations must register with the Office of the Data Protection Commissioner (ODPC), and the requirement applies regardless of the organisation’s revenue or headcount. Charities pay a flat KES 4,000 registration fee, wait up to 14 days for a certificate, and must renew every 24 months. The rule that trips up most nonprofits: the usual small-organisation exemption under the Data Protection Act does not apply to charities and religious entities the way it does to small businesses.
That single fact surprises a lot of NGO managers, because the exemption gets repeated so often in general compliance guides written for small businesses. It doesn’t hold for the nonprofit sector, and as of September 2026, ODPC enforcement in Kenya has moved well past its early “awareness-building” phase into audits and financial penalties.
Do NGOs actually have to register with the ODPC?
Under Section 18 of the Data Protection Act, 2019, and the Data Protection (Registration of Data Controllers and Data Processors) Regulations, 2021, any entity processing personal data — beneficiary records, donor details, staff payroll, volunteer applications — must register as a data controller, a data processor, or both if it does both.
Most private businesses with under 10 employees and turnover below KES 5 million are exempt. Charities and religious entities are carved out of that exemption entirely: the ODPC’s own FAQ lists “charities and religious entities offering charity or religious functions” as required to register “regardless of revenue/turnover.” An NGO running a single field office with three staff still has to register.
What does registration actually cost, and how long does it take?
The fee schedule is tiered by organisation type, and the charity tier is flat rather than scaled to size:
| Category | Registration fee | Renewal fee (every 24 months) |
|---|---|---|
| Charities and religious entities | KES 4,000 | KES 2,000 |
| Micro and small controllers/processors | KES 4,000 | KES 2,000 |
| Medium controllers/processors | KES 16,000 | KES 9,000 |
| Large controllers/processors | KES 40,000 | KES 25,000 |
| Public entities | KES 4,000 | KES 2,000 |
If an organisation acts as both a data controller and a data processor — common for NGOs that both hold their own beneficiary data and process data on behalf of a donor or partner — it must register, and pay, twice. Mobile-money and card payments carry an extra KES 50 transaction fee; bank transfers and RTGS don’t. Once a complete application and payment are confirmed, ODPC has 14 days to issue the certificate, which is valid for 24 months.
What counts as “personal data” for an NGO?
It’s broader than most program staff assume. Personal data includes anything that identifies a person — name, national ID number, phone number, physical address, photos, location data, biometric data collected for aid distribution. Certain categories count as “sensitive data” needing extra protection under the Act: health status, ethnic origin, genetic or biometric data, and family details. An NGO running a health clinic, a WASH beneficiary registry, or a cash-transfer programme is very likely handling sensitive data as defined by law, not just routine contact lists.
Why is this more urgent for NGOs specifically right now?
Two things have converged in 2026. First, ODPC enforcement has sharpened — the office determined dozens of complaints in the past year, with penalties running up to KES 5 million or 1% of annual turnover for serious breaches, and its Compliance Directorate now runs scheduled inspections rather than only responding to complaints. Second, the sector itself has become a bigger target: nonprofits worldwide are reported to face breach rates roughly three times higher than private companies, and industry researchers note that NGOs are increasingly compromised through third parties — fundraising platforms, cloud hosts, CRM tools and marketing agencies — rather than their own core systems. Surveys cited by cybersecurity researchers this year found only about one in ten NGOs trains staff regularly on data-security basics and only around one in five has a written security plan at all.
For a Kenyan NGO, that combination means two separate but related risks: ODPC penalties for failing to register or for mishandling personal data, and the reputational and donor-relationship damage of an actual breach involving beneficiary or donor information.
What should an NGO have ready before applying?
- Establishment documents (certificate of registration/incorporation)
- Contact details for the organisation and its designated data-protection contact person
- A description of what personal data is processed and why (e.g. beneficiary registration, payroll, donor management)
- Categories of data subjects — beneficiaries, staff, donors, volunteers, suppliers
- Recipients the data is shared with (a donor, a government agency, a partner NGO)
- Basic safeguards already in place — access controls, a privacy policy, a visitor log, an information-security policy
- The organisation’s most recent annual turnover/revenue figure, for tier classification
Applications go through the ODPC’s online portal at odpc.go.ke. Payment can be made by M-Pesa, card, RTGS or cheque, and the review clock starts once payment is confirmed.
What happens if an NGO skips registration?
Operating as an unregistered data controller or processor is itself a compliance breach the ODPC can act on directly, separate from any complaint about how data was actually handled. Beyond the direct legal exposure, unregistered status is increasingly something institutional donors check for during due diligence, alongside PBO registration status — Kenya’s civil-society sector has already been through one major compliance reckoning this year with the rollout of the 2026 PBO Regulations, and data-protection registration is shaping up as the next box donors expect ticked.
Frequently asked questions
Does a small, volunteer-run NGO still need to register with the ODPC?
Yes. The small-organisation exemption (under 10 employees, under KES 5 million turnover) does not apply to charities and religious entities — they must register regardless of size or revenue.
How much does ODPC registration cost for a charity?
KES 4,000 for initial registration, and KES 2,000 to renew every 24 months, plus a KES 50 transaction fee if paying by M-Pesa or card.
How long does ODPC registration take?
Up to 14 days from a complete, paid application, assuming the Data Commissioner is satisfied the requirements are met. If an application is rejected, the ODPC must notify the applicant with reasons within 21 days.
Do we need to register as both a controller and a processor?
If your NGO both determines how its own beneficiary or donor data is used (controller) and processes data on behalf of another organisation, such as a donor or partner (processor), you register — and pay — separately for each role.
Where do we actually apply?
Through the ODPC’s online registration portal, linked from odpc.go.ke. The office can also be reached at registration@odpc.go.ke for questions before applying.
For NGOs still working through wider PBO Act compliance, it’s worth handling data-protection registration alongside it rather than as an afterthought — see our guide to Kenya’s PBO Act 2026: What NGOs Must Do Now, and if your organisation is winding down or restructuring, PBO Deregistration in Kenya: What NGOs Should Do Now covers the related process. Organisations collecting donor payment details through mobile channels should also check our guide to digital fundraising tools, since donation platforms are exactly the kind of third-party system that widens an NGO’s data-protection exposure.
By the NGOs.ke Editorial Team.
Leave your comment