Registration gets you a certificate. A retainer keeps you compliant — quarterly reviews, direct access to a practising advocate, and someone who actually answers when the ODPC (or your board) asks a question. Transparent monthly fees, no 12-month lock-in.
184 compensation orders and 96 determinations in 2025 — the ODPC's enforcement activity nearly doubled year-on-year. Registration alone doesn't cover ongoing conduct. See what triggered them → · Browse 30+ ODPC & High Court case briefs →
Running a SACCO? You're dual-regulated — SASRA and the ODPC both expect governance over the same member data. See where SASRA and ODPC compliance overlap →
Priced for organisations that need real ongoing support without enterprise-firm overhead. Every tier includes a three-month onboarding term, then runs month-to-month — cancel or change tiers with 30 days' notice. Prefer to pay once? Every tier can be pre-paid annually at 10% off — most SACCO boards find it easier to approve one compliance line item at AGM than re-justify a monthly cost every cycle.
Rates shown are our current professional fees for outsourced DPO / compliance retainer services and are reviewed periodically. Not sure which tier fits? Tell us your headcount and sector on the contact form and we'll recommend one.
Everything outside your included quota, priced up front so there's never a surprise invoice.
| Item | Fee |
|---|---|
| Additional DPIA (beyond your tier's included screening) | KES 15,000 each |
| Extra on-site training / staff refresher session | KES 12,000 per session |
| Additional data-subject request review (beyond quota) | KES 3,500 each |
| On-site visit outside Nairobi | KES 8,000 + travel at cost |
| Ad-hoc advisory hour beyond your monthly allocation | KES 6,000 / hour |
| ODPC registration itself (one-off, if not yet registered) | See ODPC Registration |
No vague "ongoing support" — here's what happens on a real timeline.
15–20 minutes to understand what data you process, your sector's specific obligations (SACCOs and financial services carry extra scrutiny), and which tier actually fits — we won't sell you more than you need.
In month one, we review what compliance documentation already exists, flag the urgent gaps, and set the cadence for your check-ins.
Quarterly or monthly, depending on tier — policy updates, training refreshers, and a standing line to ask questions as they come up, not just at renewal time.
A regulator query, a data subject request, a suspected breach — you have a named advocate already familiar with your organisation, not a cold call to a new firm under time pressure.
Most SACCOs and SMEs need both, at different points. Here's the honest split.
| ODPC Registration | Compliance Retainer | |
|---|---|---|
| What it is | A one-time regulatory filing — your data controller/processor certificate. | Ongoing outsourced DPO support, month to month. |
| Frequency | Filed once, renewed every 2 years. | Continuous — quarterly or monthly check-ins depending on tier. |
| What it covers | Getting you legally on record with the ODPC. | Staying compliant after that — policies, DPIAs, breach response, DSRs, ODPC liaison. |
| Best for | Businesses that need to be registered but have simple, low-risk processing. | Any organisation handling member, customer or employee data at real scale — especially SACCOs. |
| Typical path | Register first (or alongside), then move to a retainer once you're handling live member/customer data day to day. | |
ODPC registration is a one-time filing. A retainer is ongoing — it reflects the ODPC's expectation that organisations in regulated sectors, SACCOs and financial services among them, maintain continuous oversight of how personal data is handled, not just a certificate on file. If your processing is simple and low-risk, registration alone may be enough; if you handle member or customer data at any real scale, ongoing support meaningfully reduces your exposure.
No. After an initial three-month onboarding period, every retainer runs month-to-month. You can pause or cancel with 30 days' written notice.
Direct access to a named, practising advocate who personally handles your file — the same person who has argued these matters before the ODPC and the High Court, not a call centre and not a junior associate rotated onto your account. By the time something urgent comes up (a regulator query, a data subject request, a suspected breach), that advocate already knows your organisation, your data flows and your sector's specific exposure. That continuity is the product, and it's reflected in the response times set out for each tier.
Yes, with 30 days' notice, once the initial three-month term is complete — plenty of SACCOs start on Essential and move to Standard once membership or loan-book data grows.
You get immediate advisory support on containment, the 72-hour ODPC notification requirement, and — where there's a real risk of harm to data subjects — the notification obligations that follow. Deeper investigation work beyond the included hours is quoted separately and always agreed with you first.
Start with our free ODPC Compliance Checklist self-assessment, or handle registration on its own via ODPC Registration — you can add a retainer later.
Tell us a little about your organisation and we'll recommend a tier within one working day — no obligation.
A short monthly briefing from the Kenya Privacy Law Review — new ODPC determinations, guidance notes, and compliance deadlines. No spam, unsubscribe anytime.