Data protection compliance when screening: what the ODPC expects

Screening a counterparty means collecting personal data — ID numbers, court records, adverse media. Kenya's Data Protection Act does not carve out an exception for KYC.

Every counterparty screening check produces a small dossier of personal data: identity numbers, dates of birth, director names, sometimes court case details or news mentions tied to a named individual. Under the Data Protection Act, 2019, collecting and storing that information makes a compliance team a data controller — the entity that decides why and how personal data is processed — and any vendor that processes it on their behalf a data processor. Screening is not exempt just because the purpose is compliance rather than marketing.

Registration applies to more teams than banks and telcos assume

Section 18 of the Act, together with the Data Protection (Registration of Data Controllers and Data Processors) Regulations, 2021, requires every data controller and processor to register with the Office of the Data Protection Commissioner (ODPC) unless they fall under a specific exemption. Registration opened on 14 July 2022 through the ODPC's online portal.

The commonly cited threshold is an annual turnover of at least KSh 5 million or 10 or more employees — but the ODPC's own guidance is explicit that size alone does not decide the outcome. Entities that process personal data for certain listed purposes must register regardless of turnover or headcount, and Know Your Customer (KYC) processing is named directly in the ODPC's FAQ as one of those purposes, alongside direct marketing, political canvassing, and health administration.

In practice, that means a lean compliance or credit team running onboarding checks can have a registration obligation even if it would otherwise sit below the turnover and employee thresholds.

What the registration application actually asks for

The application (Form DPR1) is not a formality. It requires:

  • Establishment documents for the entity.
  • A description of the purpose for which personal data is processed — the ODPC's own examples include payroll, invoicing, and KYC.
  • The categories of personal data processed (e.g. name, national ID number, address).
  • The categories of data subjects (employee, client, supplier, shareholder).
  • The recipients to whom personal data is disclosed — the ODPC's guidance lists examples such as KRA and CBK.
  • Whether the entity has a designated Data Protection Officer.

Filling this in forces a useful exercise on its own: most teams have never written down, in one place, exactly which personal data categories their screening process touches and who else sees them.

Consent, purpose limitation, and screening files

Registration is the entry point, not the whole obligation. The Act's core principles — lawful basis, purpose limitation, and data minimisation — apply directly to a screening file:

  • Data collected to assess onboarding risk should not be quietly repurposed for an unrelated use without a fresh lawful basis.
  • Retention should have a defined period tied to the purpose, not "indefinitely, just in case".
  • The ODPC's Compliance Directorate runs data protection impact assessments, inspections, and audits, and takes breach reports directly — so a screening provider's own security posture is part of what an inspection can look at.

Practical checklist for a screening workflow

  1. Confirm whether your entity — or the screening vendor you use — is registered as a data controller or processor with the ODPC.
  2. Document the lawful basis and retention period for each category of data a screening report contains (identity, litigation, adverse media, licence status).
  3. Name a Data Protection Officer if your processing profile requires one, and route breach reports through them.
  4. Keep an access log — who pulled which report, on which counterparty, and when — so a DPIA or audit has something concrete to review.

None of this replaces legal advice on a specific registration question. It does mean data protection compliance belongs in the same conversation as AML and litigation screening, not a separate track that gets addressed later.

See how a screening report is structured. The live demo shows exactly which data categories and sources feed a report. For how BRIA handles data as a processor, see Security.

← All insights