Kenya is preparing to find Immaculate Kassait’s successor as Data Protection Commissioner, but the significance of the appointment goes well beyond replacing the first person to hold the job.
Kassait leaves the Office of the Data Protection Commissioner (ODPC) after a six-year, non-renewable term during which Kenya moved from having a data-protection law on paper to having a regulator with enforcement powers, complaint mechanisms and a growing body of decisions.
The next commissioner will inherit a country where personal information has become central to how government collects taxes, businesses sell services, lenders assess borrowers and digital platforms operate. At the same time, proposals around internet usage metering, courier information, government datasets and digital services are raising fresh questions about how much information the State should be able to collect and what safeguards should apply once it has it.
That makes the succession an important test of Kenya’s data-governance model. The first commissioner had to build the institution; the person who follows her will have to decide how effectively that institution can constrain misuse of data while dealing with a much larger and more complicated digital economy.
Kassait’s first achievement was building the regulator
When Kassait took office in 2020, the ODPC was a new institution created to give practical effect to the Data Protection Act, 2019. There was no established enforcement culture, no long record of determinations and no public expectation that a Kenyan regulator could intervene when companies mishandled personal information.
Her tenure changed that.
The ODPC developed registration and compliance systems, established channels for complaints, conducted investigations and audits, issued enforcement notices and penalties, and began building a body of decisions that gives the Data Protection Act meaning in specific cases. The regulator also expanded its public education work and established regional offices, taking data protection beyond Nairobi and beyond the confines of corporate legal departments.
That institutional work is easy to overlook because it is less visible than a fine or a headline-making investigation, but it is probably the strongest part of Kassait’s legacy. Kenya now has a recognisable privacy regulator that businesses, public agencies and individuals can engage with.
Digital lenders gave ODPC its clearest enforcement test
The fight with digital lenders became one of the most visible demonstrations of what the new regulator could do.
ODPC investigated lenders over complaints involving access to borrowers’ phone contacts, unsolicited communications and the use of personal information in debt collection. Some companies were fined, while the regulator later sought stronger action against repeat offenders, including asking the Central Bank of Kenya to revoke licences in cases where lenders continued to breach data-protection requirements.
The significance goes beyond the individual penalties. Digital lending exposed a basic problem with Kenya’s data economy: people often surrender access to personal information because they need a service, without understanding how broadly that information can subsequently be used.
ODPC gave those consumers somewhere to complain and established that consent to a digital service does not give a company unlimited freedom to exploit a customer’s information. Complaints against digital lenders subsequently fell, although the existence of repeat offenders showed that enforcement had not completely solved the problem.
That combination of progress and limitation runs through Kassait’s tenure.
Worldcoin showed both the regulator’s strength and its limits
The confrontation with Worldcoin was an even more difficult test because it involved biometric data, a global technology company and a product built around a form of identity verification that was unfamiliar to most consumers.
ODPC raised concerns about the collection and processing of biometric information, while the government suspended Worldcoin-related activities in Kenya in 2023. The controversy eventually produced a prolonged legal and regulatory process, with the ODPC later confirming the deletion of biometric data collected by the company.
Kassait can reasonably count the episode as an important regulatory achievement. Kenya demonstrated that a domestic privacy regulator could scrutinise a powerful international technology company and insist that sensitive personal information remained subject to Kenyan law.
But Worldcoin also exposed a difficult weakness in the system. A large amount of sensitive biometric information had already been collected before the regulatory process reached its conclusion. Deleting the data later provides a remedy, but it does not erase the underlying question of whether privacy regulation should have been capable of preventing the risk at the point of collection.
That distinction will matter even more as AI and other data-intensive technologies become embedded in everyday services.
The fine is only as useful as the behaviour it changes
The ODPC’s growing enforcement record is another measure of Kassait’s impact, but it also raises an uncomfortable question about deterrence.
TechTrendsKE’s analysis of ODPC determinations found that the regulator had issued dozens of decisions involving organisations that mishandled personal information, yet the financial penalties were often modest relative to the size of some of the companies involved. The same analysis found that enforcement cases were overwhelmingly concentrated on private organisations, with relatively few involving public institutions.
That matters because data protection is ultimately about behaviour rather than the number of enforcement notices an institution can publish.
A KSh500,000 penalty can be painful for a small company, but its deterrent value may be very different for a large financial institution or technology company. The regulator therefore faces a difficult balancing act: enforcement must be strong enough to change corporate incentives while remaining proportionate to the violation.
Kassait’s record suggests the ODPC has established the machinery of enforcement. Whether that machinery has enough capacity, resources and authority to consistently deter large organisations is a harder question.
Government data will be the harder test for her successor
The public-sector side of the equation is where the next commissioner will face some of the most politically sensitive questions.
Kenya is digitising government services and building systems that generate enormous amounts of information about citizens. KRA wants greater visibility into economic activity and transactions; government platforms such as eCitizen sit at the centre of an expanding digital public-service ecosystem; and policymakers are considering new ways of collecting and using information generated by digital networks.
There is nothing inherently improper about the State collecting information it needs to administer taxes, deliver public services or enforce the law. The difficult questions concern proportionality, purpose limitation, retention, access and oversight.
That is why the relatively small share of public-sector enforcement in the ODPC’s published record deserves attention. The regulator has jurisdiction over public and private data processors, but holding government institutions to the same privacy standards as private companies is institutionally more difficult.
The issue becomes particularly relevant when proposals involve information that can reveal aspects of an individual’s behaviour rather than simply confirming their identity.
Internet metering brings the question closer to ordinary users
The proposed internet-metering framework is a good example of why the next Data Commissioner will have a different job from the first.
A system that requires internet service providers to measure subscriber usage, generate consumption records and submit information to the State could have a legitimate administrative or billing purpose. But the privacy implications depend heavily on what is actually recorded, how granular the information becomes, who can access it, how long it is retained and whether it can later be combined with other datasets.
The same principle applies to the debate around courier and parcel information. Government agencies have legitimate reasons to know what goods cross the country’s borders and who is responsible for them, particularly for customs, taxation and security. Yet the existence of a legitimate purpose does not automatically answer the privacy questions that follow.
Those details matter because data can become far more revealing when different datasets are connected. Information about an internet connection, a financial transaction, a shipment or a government service may appear innocuous in isolation; linked together, such records can create a much more detailed picture of an individual’s activities.
That is precisely the kind of issue a mature data-protection regulator should be equipped to examine.
The State is also beginning to treat data as an economic asset
Another development during the latter part of Kassait’s tenure points to an even bigger challenge.
Kenya has been considering frameworks for making government-generated datasets available for economic use, including a proposed marketplace for non-personal data generated through eCitizen and other public systems. The government has emphasised that personal identifiers would be excluded, which is an important distinction.
But anonymisation is not the end of the privacy discussion.
The next questions involve whether datasets can be re-identified when combined with other information, who verifies that anonymisation has worked, what governance applies to organisations purchasing or accessing the data, and what happens if a supposedly anonymous dataset can later be connected to identifiable individuals.
This is where data protection begins to overlap with data governance and digital sovereignty. The government wants data to help drive economic activity; citizens need assurance that the pursuit of that value does not quietly weaken their privacy rights.
AI is expanding the regulator’s workload
Artificial intelligence adds another layer to the problem.
During Kassait’s term, the conversation moved from relatively familiar questions about customer databases and direct marketing to issues involving automated systems, offshore AI platforms, biometric technologies and cross-border data transfers.
A Kenyan company can now send information to an AI service whose infrastructure and processing may sit outside the country. That creates questions about where the data is processed, which laws apply, what happens to prompts and uploaded documents, whether the information is retained for model improvement and whether individuals can exercise their rights once their information has entered an international AI ecosystem.
Kassait has already spoken about the regulatory challenges presented by disruptive technologies and cross-border transfers. Her successor will have to turn that recognition into practical supervision.
That may require a regulator that understands both privacy law and the technical architecture through which modern data moves.
Kassait leaves behind a regulator that is stronger, but not finished
There is a temptation to assess a first commissioner simply by asking how many fines were issued or complaints resolved. That would undersell what happened during Kassait’s term.
She helped create an institution from scratch, established enforcement as a normal part of Kenya’s privacy regime, challenged digital lenders, dealt with a major biometric-data controversy involving Worldcoin, expanded public awareness and helped give citizens practical avenues for seeking redress.
The unfinished work is equally important. ODPC still has to demonstrate that it can supervise a data economy much larger than the one it inherited, make penalties sufficiently meaningful to deter repeat violations, move further toward proactive enforcement and apply the same seriousness to public institutions that it applies to private companies.
Cybersecurity adds another complication. A company can have a privacy policy, register with the regulator and still suffer a serious breach. The exposure of sensitive information in incidents involving large digital platforms demonstrates why data protection increasingly has to be understood alongside security engineering, incident response and technical governance.
Kassait’s tenure therefore looks strongest when viewed as the construction of Kenya’s privacy regime, rather than the completion of it.
The next commissioner inherits a much bigger question
This is why the search for an Immaculate Kassait successor matters more than a routine change of office might suggest.
Kassait was Kenya’s first Data Protection Commissioner. Her central task was to make the Data Protection Act real: establish the institution, build enforcement capacity and convince organisations that personal information comes with legal obligations.
Her successor inherits a different environment. Government agencies want more data to improve taxation and public administration; companies want more data to personalise services and train or operate digital systems; AI companies can process information across borders; and consumers generate vast quantities of information every time they use a phone, financial service or online platform.
The central question for the next commissioner will therefore be how to balance those competing interests without allowing the expansion of data collection to outrun the protections attached to it.
That is also why the timing of the appointment deserves scrutiny. Kenya is debating new systems for internet usage, courier information and government datasets at roughly the same point that it is choosing the person who will be responsible for protecting the rights of the people whose information those systems may capture.
There is no evidence from these developments alone that they form a coordinated surveillance programme, and it would be irresponsible to claim otherwise. But there is a clear and observable expansion in the amount of information available to the State and private organisations.
Kassait’s biggest legacy may therefore be that she made Kenya take data protection seriously. Her successor’s legacy will depend on whether the ODPC can make data power answerable to the same law, whether that power sits inside a bank, a technology company, a telecom operator or a government agency.
The succession will test whether ODPC can mature beyond its first chapter
The next commissioner does not need to recreate the institution Kassait built. That foundation already exists.
The harder task is to make it strong enough to operate when data itself has become infrastructure.
That means scrutinising government databases as closely as commercial ones, demanding meaningful safeguards around emerging technologies, making repeat violations genuinely costly, strengthening proactive audits and ensuring that citizens can understand and exercise their rights without needing to become privacy lawyers first.
If Kassait’s first term was about establishing Kenya’s answer to “Who protects personal data?”, the next term will have to answer a more difficult question:
Who protects Kenyans when the organisations collecting their data have more information, more computing power and more reasons to use it than ever before?
That is the test waiting for whoever takes over the ODPC.
Real ESG impact doesn’t happen in panels alone, it happens in the rooms where financiers, operators, and policymakers actually align. Our GreenShift Forum 2026 cuts the noise, bringing together the people rewiring Africa’s sustainability and energy frameworks for one focused day in Nairobi. Secure your seat.
Go to TECHTRENDSKE.co.ke for more tech and business news from the African continent and across the world.
Follow us on WhatsApp, Telegram, Twitter, and Facebook, or subscribe to our weekly newsletter to ensure you don’t miss out on any future updates. Send tips to editorial@techtrendsmedia.co.ke



