DATA PROTECTION LEGAL UPDATE

Key Highlights from the ODPC’s Guidance Notes for Data Protection Officers, 2026

Every organisation that has appointed a Data Protection Officer under section 24 of the Data Protection Act, 2019 (the “Act”) has, at some point, faced the same set of unanswered questions: who, exactly, should hold this office? To whom should they report? What should they be paid, and how far does their independence really extend?

The Office of the Data Protection Commissioner’s Guidance Notes for Data Protection Officers, 2026, seeks to address some of these issues and offers detailed direction on designating a DPO, positioning the office within the organisation, safeguarding its independence, defining its responsibilities, setting the competencies expected of the holder, guiding remuneration, and publishing the office’s contact details. This write up seeks to highlight how the 2026 Guidance Notes support organisations in implementing their obligations under the Act.

1.  When Must a DPO Be Appointed — and by Whom?

Section 24(1) requires a DPO wherever an organisation processes personal data as a public or private body, engages in regular and systematic monitoring of data subjects, or handles sensitive personal data as a core activity. Determining whether an organisation falls within this threshold is not always straightforward, and the Guidance Notes respond with concrete illustrations drawn from everyday operations: a national hospital processing thousands of patient records daily, a telecommunications company tracking call and location data, a digital lender handling credit histories and identity documents, a county government collecting residents’ biometric data. Each, on the Office’s reasoning, triggers the obligation to appoint.

Having established when an appointment is required, the Guidance Notes turn to how it may be structured, recognising three distinct models.

Internal, External and Shared DPOs

An internal DPO may be drawn from existing staff or hired specifically for the role, provided the individual does not also hold a position that determines the purposes or means of processing, and is given sufficient authority and direct access to senior management.

An external DPO, by contrast, is engaged where an organisation lacks in-house expertise or requires independent oversight, though the Guidance Notes are careful to note that such arrangements must be structured so the external DPO does not also design or operate the systems and controls they are required to oversee, and that it is the named individual, not the consultancy engaging them, who is the DPO of record.

A shared DPO arrangement, meanwhile, is available to groups of related entities — subsidiaries, associations, or organisations under common ownership — and, for public bodies, to several institutions with interrelated functions. Before adopting this model, the Guidance Notes direct organisations to weigh the scale and complexity of processing across the participating entities, the need for sector-specific expertise, clear reporting lines to each body served, and freedom from undue influence by any one participant. The Office illustrates the boundary with real precision: a corporate group operating under one umbrella may share a single Group DPO, but a diversified group with genuinely unrelated business lines may not; a county government may designate one DPO across its executive departments given their interrelated functions, while a ministry whose state departments operate as separate, independent data controllers generally may not.

A New Governance Layer: The Data Protection Committee

Perhaps the most notable structural addition in the Guidance Notes is the Data Protection Committee, an optional body of senior representatives who provide strategic oversight and coordination of data protection matters at the organisational level, supported by data protection champions embedded within individual departments to drive day-to-day implementation. The Committee may be constituted as a stand-alone body or folded into an existing governance structure, and its function is deliberately distinct from that of the DPO: where the Committee sets policy direction and provides collective oversight, the DPO and the departmental champions carry that direction into daily practice.

2.  Positioning the DPO: Independence as a Discipline, Not a Description

It is one thing to appoint a DPO; it is another to ensure the appointment means anything. Section 24(2) prohibits assigning the DPO duties that create a conflict of interest, but says little else about how independence should be secured in practice. The Guidance Notes close that gap with five specific safeguards that organisations are now expected to build into the role.

  • Independence: the DPO must be free to conduct audits, issue compliance advice and liaise with the ODPC without instruction on how those functions are performed.
  • Reporting line: the DPO should report directly to the highest level of management so that compliance risks reach decision-makers without being filtered through intermediate layers.
  • Resources and support: a dedicated budget, adequate staffing, continuous training, and access to legal, IT and risk management specialists where required.
  • Freedom from conflict of interest: the DPO should not simultaneously hold a role that determines the purposes or means of processing such as the Head of IT, HR Director, Legal Counsel or Compliance Manager are given as examples, since doing so would place the officer in the position of overseeing decisions they themselves are making.
  • Protection from retaliation: a DPO may not be dismissed, penalised or otherwise disadvantaged for the proper discharge of statutory duties.

3.  From Statutory Function to Daily Practice

The Act sets out the DPO’s core functions in broad terms: advising the organisation and its staff on data processing requirements, ensuring compliance with the Act, facilitating capacity building, advising on Data Protection Impact Assessments, and cooperating with the Data Commissioner.

The Guidance Notes take each of the elements above and give it operational shape, alongside the further expectation that the DPO ensures compliance audits are carried out.

In practical terms, this now means the DPO is expected to:

  1. advise continuously on lawful processing and embed privacy-by-design thinking into new initiatives from the outset;
  2. to monitor compliance through regular audits that extend to third-party processors and their data processing agreements;
  3. to guide departments through DPIAs for high-risk projects, including cross-border transfers, and see mitigation measures through to completion;
  4. to lead the organisation’s response when a breach occurs — investigating, coordinating communication, and ensuring timely notification to the ODPC and affected data subjects;
  5. to build and maintain clear procedures for data subject rights requests, met within statutory timelines; to serve as the organisation’s principal point of contact with the ODPC during audits and investigations;
  6. to design and deliver ongoing training across the organisation; to keep the Record of Processing Activities current; and to compile periodic compliance reports that escalate significant risks to senior management or the Board.

4.  What Academic and Professional Qualifications Make a DPO Competent?

Section 24(5) of the Act requires a DPO to hold relevant academic or professional qualifications and expertise in data protection law and practice. The Guidance Notes seeks to give life to implementation of the above Section 24(5) in two parts.

The first, privacy governance, expects a DPO to understand the organisation’s own processing activities, their scale, complexity, sensitivity and sector together with Kenyan data protection law and practice, an appreciation of international and regional frameworks, the ability to draft and review privacy documentation such as policies, notices and consent mechanisms.

The second, privacy risk management and compliance, is more technical: the ability to translate legal requirements into operational practice, familiarity with sector-specific compliance frameworks across finance, healthcare, telecommunications and other regulated industries, working knowledge of cybersecurity and privacy-enhancing technologies, hands-on experience conducting audits, DPIAs and ROPA development, an understanding of cross-border transfer mechanisms such as Standard Contractual Clauses, and the ability to manage third-party and vendor relationships, including reviewing data processing agreements.

Local and international professional certification is strongly encouraged, though not made mandatory, as is continuous professional development which ensures that a DPO is keeping pace with a field that continues to evolve.

5.  Remuneration of DPOs

The Guidance Notes provide that when it comes to remuneration, organisations should consider the size and complexity of their operations, the scope of the DPO’s responsibility and risk exposure, including any oversight of subsidiaries or third-party processors, the DPO’s professional experience and qualifications, and relevant market benchmarks for comparable governance or compliance roles.

The underlying concern is independence: however remuneration is structured, it must not create incentives capable of compromising the DPO’s professional judgement. In the public sector, this determination sits within existing institutional machinery, the Public Service Commission provides DPO career guidelines, while the Salaries and Remuneration Commission sets the applicable remuneration.

6.  Publishing of DPO’s contact details

Section 24(6) requires organisations to publish their DPO’s official contact details on their website and to communicate those details to the Data Commissioner. The Guidance Notes now seek to operationalise this requirement through a prescribed DPO Contact Submission Form (Annexure 1), to be submitted to the Office of the Data Protection Commissioner at Britam Towers, 12th Floor, Nairobi, or by email to registration@odpc.go.ke. The form captures the organisation’s particulars, the DPO’s full name, job title and appointment type together with the date of appointment, official email address and telephone number.

On what should actually appear on the website, the Guidance Notes strike a sensible balance. Published contact details may include the DPO’s full name, mailing address, dedicated telephone number and official email, but need not disclose the officer’s personal information — a role-based address such as dpo@organisation.co.ke will do, provided data subjects can reach the DPO without difficulty.

Conclusion: An Office Worth Investing In

For organisations that seeks to onboard a DPO or that already have a DPO in place, the Guidance Notes are a good audit tool in regards to appointment and remuneration of DPOs as well as independence and qualifications amongst other factors.

As the regulatory landscape continues to evolve, organisations that get ahead of it, rather than react to it will be the ones best placed to demonstrate accountability and earn stakeholder trust.

At Karanu Kanai & Company Advocates, we see data protection compliance as more than a statutory checkbox. Our Data Protection and Privacy Practice works with public and private sector clients to build practical, risk-based compliance frameworks suited to their operations and aligned with Kenya’s evolving regulatory landscape, from DPO designation and governance, to compliance audits, DPIAs, ROPAs, cross-border transfer compliance, data processing agreements and regulatory engagement with the ODPC.

Facebook
Twitter
LinkedIn
WhatsApp
Email

Related News & Updates