On 26 January 2026, ahead of Kenya's 2026 Data Privacy Day Conference in Mombasa, the Office of the Data Protection Commissioner announced that it had issued 184 compensation orders to data subjects whose personal data was mishandled. The cumulative figures behind that announcement: 9,061 complaints received, 357 determinations issued, 134 enforcement notices, 20 penalty notices, and more than 15,000 registered data controllers and processors (Capital FM).

No other African data protection authority publishes a docket at this volume. Our enforcement tracker holds every published ODPC determination as a structured record, and the dataset shows what the headline numbers hide.

Where enforcement concentrates. The 2026 determinations page (odpc.go.ke) listed 17 published decisions for January and February when we checked at our July 2026 coverage date; the page shows upload dates and keeps growing. The respondents map three sectors: health (Penda Health, Shree Swaminarayan Hospital, Megahealth Insurance), financial services and lending (Momentum Credit, Tinycost Credit), and education (Nairobi Academy), plus a water utility and a suo moto investigation into Capital SACCO. The 2025 docket reads the same way: lending apps (RocketPesa, Platinum Credit, Fingrow Capital, LendPlus), an insurer, a betting operator, and major employers. Digital lenders are the most frequent respondents in the dataset. If your organisation holds financial, health or school records on Kenyans, you are in the ODPC's demonstrated enforcement zone, not a hypothetical one.

The ratio that matters. 9,061 complaints have produced 357 determinations. That filter means the complaints that survive to determination are the ones with documentary evidence and a responsive complainant, which is also why the compensation orders stick: the High Court has said it will not interfere with ODPC's discretion on compensation unless the decision is irrational, and data subjects can now register determinations as court orders for execution.

The number that is smaller than you expect. Twenty penalty notices, against 357 determinations. The ODPC's primary instrument is compensation to the data subject, not fines to the state. For budgeting purposes that changes the exposure model: the long tail of Kenyan enforcement is many mid-size awards plus remediation orders, with penalty notices reserved for aggravated cases. Averages mislead here; the typical exposure is a five-to-six-figure KSh award, and the outliers get the headlines.

Who is affected. The 15,000-plus registered controllers and processors first, because registration puts you on the map. But the docket shows unregistered and informal processors being pursued too, and the LOLC determination added personal exposure for directors who ignore investigations.

What to do now:

  1. Benchmark your sector against the docket. If you operate in lending, health or education, assume complaint-driven scrutiny and pre-build your evidence file: consent records, DSAR logs, deletion trails.
  2. Track determinations as they publish, not annually. The ODPC publishes continuously, and each determination is guidance on how the next complaint against you would be decided. Our tracker structures every record by violation type, sector and outcome.
  3. Treat the complaints channel as your early-warning system. 9,061 complaints started as customer disputes; most determinations follow a complaint your customer service team saw first.