Data Controller or Data Processor in Kenya? Who Must Do What

Vendors, clients and regulators all ask whether your organisation is a data controller or a data processor. The answer shapes who must register, who answers complaints and how your contracts should be drafted , and the two roles are often confused.

Kenyatta International Convention Centre in Nairobi
Photo: Francis Akuka for the Wikimedia Foundation (CC0), via Wikimedia Commons

What is the difference between a controller and a processor?

A data controller decides why and how personal data is processed. A data processor acts on the controller’s documented instructions , a payroll bureau, a cloud hosting provider or a marketing agency, for example. Many organisations hold both roles at once: a hospital controls its patient records while also processing payroll on behalf of another business. The Data Protection Act 2019 attaches different duties to each role, so getting the labels right is the starting point for compliance.

Mislabelling the relationship does not change the underlying facts. If a supplier exercises real control over purposes , for instance deciding which of your customers to contact about its own products , it may be treated as a controller for that processing, with all the duties that follow.

Which duties sit with each role?


  • Controllers carry the primary duties: identifying a lawful basis, giving privacy notices, responding to data subject requests and registering with the ODPC where required.
  • Processors must process only on the controller’s instructions, maintain appropriate security, and assist with requests and breach notifications.
  • Both roles must keep personal data accurate, secure and retained no longer than necessary.

How should the relationship be recorded?

The Act expects the controller-processor relationship to be governed by a written contract, so every engagement that touches personal data should include one. The agreement should record the subject matter, duration, nature and purpose of the processing, the security measures to be applied, and what happens when the engagement ends. Our commercial contracts team drafts such agreements regularly. Where processing cuts across a group or a supply chain, a governance review confirms that each entity’s role has been correctly identified before documents are signed , see our governance advisory services.

Guidance on the distinction is published by the Office of the Data Protection Commissioner, and the Act itself is available on Kenya Law.

For guidance on your specific situation, contact CS Advocates LLP , call, WhatsApp, or book a confidential consultation at our Westlands, Nairobi office.

Leave a Comment

Your email address and phone number are for verification only and will never be published. Comments appear after approval by the firm. Ask a question anonymously if you prefer.

+254 728 293 000 Email us +254 20 80 93 000 Confidential consultation