For years, a quiet question has lingered around Kenya’s data protection framework: does the Office of the Data Protection Commissioner (ODPC) actually have the authority the law says it does, or is it stepping on the High Court’s toes?
The High Court recently answered that question directly, in a ruling that Kenyan businesses, HR departments, and anyone handling personal data should understand.
The Case
In Arunda v Office of the Data Protection Commissioner & another, a petitioner went straight to the High Court, arguing that the ODPC had overstepped its mandate. The petition challenged the constitutionality of Section 56 of the Data Protection Act, 2019 (DPA) and Regulation 14(5) of the Complaints and Enforcement Regulations, the provisions that allow the ODPC to investigate complaints and issue binding decisions, including orders for compensation.
The argument was twofold. First, that by making binding findings and awarding compensation, the ODPC was exercising judicial power that belongs exclusively to the High Court under Articles 23(1) and 165(3)(b) of the Constitution. Second, that the ODPC’s mandate duplicated the role of the Kenya National Human Rights and Equality Commission (KNHREC), which also has a role in protecting rights under the Bill of Rights, including the right to privacy under Article 31.
What the Court Decided
The High Court dismissed the petition, and its reasoning gives useful clarity on how Kenya’s data protection enforcement system is meant to work.
On the first issue, the Court held that the ODPC’s power to investigate complaints and make administrative findings is not a judicial function at all; it is a regulatory and administrative one. The ODPC’s role, the Court found, complements rather than replaces the courts, and remains subject to the High Court’s supervisory jurisdiction under Section 64 of the DPA (which provides for appeals against ODPC decisions).
On the constitutionality question, the Court found that Section 56 and Regulation 14(5) simply give a specialised regulator the practical enforcement tools it needs to protect the right to privacy, while preserving judicial oversight through the appeal mechanism.
Perhaps most practically significant was the Court’s finding on exhaustion of remedies. The petitioner had bypassed the ODPC’s complaints process entirely and gone straight to the High Court. The Court reaffirmed the doctrine of exhaustion: complainants must first use the statutory remedy available to them, namely lodging a complaint with the ODPC, before approaching the courts, unless there are exceptional circumstances. None were shown here.
Finally, on the claimed overlap with the KNHREC, the Court found no real conflict. The two institutions were designed to work alongside each other within Kenya’s human rights enforcement architecture, not against each other.
Why This Matters for Businesses
This ruling isn’t just an academic win for the regulator; it has practical consequences for any organisation that collects or processes personal data in Kenya:
- The ODPC’s authority is confirmed, not diminished. Its investigations, determinations, and compensation orders are legally sound and enforceable, not merely advisory.
- The complaints process matters. If a data subject raises a complaint with your organisation or with the ODPC, that process cannot simply be sidestepped by either party rushing to court. The ODPC route generally has to be exhausted first.
- Compliance obligations are real, not theoretical. With the ODPC’s mandate judicially affirmed, and enforcement activity in Kenya generally increasing, organisations should treat data protection compliance (registration, breach notification, lawful processing bases, data subject rights) as an active legal risk area, not a box ticking exercise.
The Takeaway
Kenya’s data protection framework is often treated as still “settling in.” This ruling suggests the opposite: the courts are actively reinforcing the ODPC’s role as the primary, functional enforcement body for data protection in Kenya. For businesses, that means the regulator’s determinations carry real legal weight, and getting compliance right matters more than ever.
This article is for general educational purposes and does not constitute legal advice. For guidance specific to your organisation’s data protection obligations, consult a qualified advocate.


