Wednesday, 30 September 2026NairobiLatest edition
From CIO Africa

Immaculate Kassait’s Tenure At ODPC: Milestones, Lessons And The Road Ahead

When Immaculate Kassait walked into the Office of the Data Protection Commissioner (ODPC) in November 2020, she was not taking over an established regulator. She was helping build one.The Office had a mandate under Kenya’s data protection framework, but lacked many of the institutional structures, systems, processes and public awareness mechanisms needed to turn that mandate into a functioning regulatory institution.Kassait’s tenure has coincided with a fundamental shift in how Kenya approaches personal data. Data protection has moved from a relatively new regulatory concept to a growing part of corporate governance, public-sector administration, technology policy and individual awareness.As she reflects on her tenure, Kassait discusses the challenges of establishing the ODPC, the evolution of enforcement, the rise of AI and digital public infrastructure, and the unfinished work facing her successor.A: I was essentially walking into an institution that had a mandate but no institutional structures, systems, processes or public understanding and awareness.It was a big opportunity, but also an enormous responsibility. We had to establish an institution that Kenyans could trust while helping organisations understand what data protection meant in practical terms.We were not simply implementing a law. We were building a new regulatory culture around privacy and the responsible use of personal data.That included institutional structures, regulatory processes and policies, systems for handling complaints and registrations, investigative and enforcement capabilities, public awareness programmes and relationships with stakeholders.The priorities were quite foundational: establishing the institution, putting the right people and systems in place, creating awareness about the new law and beginning to build public and stakeholder confidence in the Office.Q: What was the biggest challenge in establishing a new regulator, and how did you navigate it?A: The biggest challenge was building credibility while building the institution itself.As a new regulator, we had to establish our authority, but we also had to demonstrate that our authority was being exercised fairly, independently and in the public interest.We were also introducing a relatively new concept to organisations across very different sectors. That meant engaging government, private companies, civil society, technology companies, professionals and ordinary citizens, all of whom had different levels of understanding of data protection.We navigated this through a combination of education, engagement, guidance and, where necessary, enforcement.Regulation is most effective when people understand both what is expected of them and why it matters.Q: When you accepted the appointment in 2020, what did you expect the ODPC to look like by the end of your tenure? How different is the reality?A: I expected the ODPC to become a credible, independent and respected regulator capable of protecting the rights of data subjects while supporting responsible innovation.The Office has grown institutionally, our enforcement work has become more visible, public awareness has increased, and data protection has become part of conversations around business, government and technology.Today, organisations and citizens are much more likely to ask questions about how personal data is collected, used, shared and protected. That shift in consciousness is significant.Q: Five to six years later, how would you describe the transformation of Kenya’s data protection landscape?A: Years ago, data protection was largely a new regulatory concept for many organisations. Today, it has become part of corporate governance, public-sector administration, technology conversations and individual awareness.We have moved from introducing the framework to operationalising it. Organisations are increasingly appointing data protection officers, conducting assessments, reviewing their data practices and engaging with the regulator.Citizens are also becoming more conscious of their rights. They are asking questions, raising complaints and expecting organisations to account for how their personal information is handled.Q: What is the single biggest change you have seen in how Kenyan organisations handle personal data?A: Organisations are increasingly recognising that personal data is not simply an asset that they collect and store. It is information entrusted to them, and that comes with responsibility.Organisations now think more carefully about why they need particular information, how long they should retain it, who should have access to it and what safeguards should be in place.The conversation has definitely moved from, “Do I have to comply?” to, “How do I build responsible data practices into the way my organisation operates?”Q: Has Kenya moved from treating data protection primarily as a compliance requirement to recognising it as a fundamental business and governance issue?

Continue with the publisherThe full report is available at CIO Africa.
Read original article

This page contains an attributed headline and the preview text supplied through the publisher’s RSS feed. Copyright in the original reporting belongs to CIO Africa.

WhatsApp