Data Commissioner Immaculate Kassait during a past event/COURTESY
The Office of the Data Protection Commissioner (ODPC) has given data controllers and data processors with expired registration certificates 14 days to renew them or face enforcement action.
In a notice posted on August 28, 2026, the ODPC said affected entities must regularise their registration status by applying for renewal.
The deadline for compliance is September 11, 2026, close of business.
The ODPC said the requirement is anchored in Section 18 of the Data Protection Act, 2019, which bars entities required to register as data controllers or data processors from acting in those capacities unless they are registered with the Data Commissioner.
The Data Protection (Registration of Data Controllers and Data Processors) Regulations, 2021 also provide that registration certificates are valid for 24 months and are subject to renewal.
The regulations further state that continued processing of personal data after a registration certificate has expired, without renewal, constitutes an offence.
“Failure to comply within the stipulated period may result in the ODPC initiating appropriate enforcement action in accordance with the law,” the regulator said.
The ODPC has urged affected entities to check whether their names appear on its list of data handlers with expired registration certificates.
Entities whose certificates have expired have been advised to renew their registration “without delay”.
The notice comes as the data protection regulator moves to ensure entities handling personal data remain compliant with registration requirements.
The ODPC said the 14-day period applies to all affected data controllers and data processors.
The ODPC has published the list of entities with expired registration certificates on its website, allowing data handlers to confirm their registration status.
The Data Protection Act established the ODPC as an independent oversight institution responsible for regulating the processing of personal data, protecting individuals' privacy and ensuring organisations comply with data protection obligations.
The regulator has previously undertaken registration and compliance initiatives targeting entities that process personal data, with registration serving as one of the key mechanisms for bringing data handlers within the regulatory framework.
The latest notice means organisations with expired certificates now face a short window to avoid possible enforcement measures.
The ODPC urged affected data controllers and processors to take immediate action rather than wait until the deadline approaches.