- ODPC gives businesses 14 days to renew expired certificates.
- Non-compliant firms risk enforcement action and disruption.
- Renewal deadline is September 11, 2026.
Businesses and other organisations handling personal data now have 14 days to renew expired registration certificates or risk enforcement action that could disrupt their operations, the Office of the Data Protection Commissioner (ODPC) has said.
Compliance deadline puts pressure on data-handling businesses
In a notice posted on August 28, 2026, the ODPC said any business registered as a data controller or data processor whose certificate has expired must regularise its status by applying for renewal before September 11, 2026, close of business.
For companies, the requirement means checking their registration status is no longer optional administrative housekeeping — it is now tied directly to their legal right to keep operating. The ODPC said entities that continue processing personal data on an expired certificate, without renewal, commit an offence.
“Failure to comply within the stipulated period may result in the ODPC initiating appropriate enforcement action in accordance with the law,” the regulator said.
What the law requires of businesses
The requirement is anchored in Section 18 of the Data Protection Act, 2019, which bars any business required to register as a data controller or data processor from operating in that capacity unless it is registered with the Data Commissioner.
READ ALSO:
Under the Data Protection (Registration of Data Controllers and Data Processors) Regulations, 2021, registration certificates are valid for 24 months. Businesses are required to renew on expiry, meaning renewal is a recurring compliance cost every two years rather than a one-off registration step.
Businesses urged to check their status before the deadline
The ODPC has published a list of entities with expired registration certificates on its website, giving businesses a way to confirm whether they are affected before the September 11 deadline.
Businesses whose certificates have lapsed have been advised to renew “without delay” rather than wait for the deadline to approach, as the 14-day window applies uniformly to all affected data controllers and processors, regardless of size or sector.
By Benedict Aoya
Get more stories from our website: Sacco Review.
For comments and clarifications, write to: Saccoreview@
Kindly follow us via our social media pages on Facebook: Sacco Review Newspaper for timely updates
Stay ahead of the pack! Grab the latest Sacco Review newspaper!



