Here is a sentence that surprises most Kenyan business owners:

If you have installed CCTV cameras at your premises, you are almost certainly a data controller under the Data Protection Act 2019, and you are almost certainly required to register with the Office of the Data Protection Commissioner.

Not a large corporation. Not a tech company. A shop with four cameras over the till. An office with a camera at reception. A residential estate with cameras at the gate. A clinic, a school, a petrol station, a warehouse.

Video footage of identifiable people is personal data. Capturing it systematically is processing. That places you inside the Act, with a defined set of duties, and penalties for a data controller reaching up to KES 5 million or 1% of annual turnover, whichever is lower, with separate criminal offences carrying fines up to KES 3 million or imprisonment up to ten years.

Almost nobody has done anything about it. This guide sets out what is actually required.

Why CCTV falls under the Act

The Data Protection Act 2019 gives effect to Article 31(c) and (d) of the Constitution, the right to privacy. It applies to the processing of personal data, meaning any information relating to an identified or identifiable natural person.

CCTV footage identifies people. Recording it, storing it, reviewing it, and handing it to police or an insurer are all processing operations. You determine why the cameras are there and how the footage is handled, which makes you the data controller, the party carrying the legal responsibility. If a third-party security firm monitors or stores the footage on your behalf, they are typically a data processor, and you need a written contract governing what they may do with it.

Being the controller does not mean CCTV is prohibited. Security and crime prevention are legitimate purposes. It means the surveillance has to be justified, proportionate, transparent, and properly governed.

Do you have to register with the ODPC?

Registration is mandatory for data controllers and processors meeting defined criteria. Broadly, you must register if any of the following applies:

  • Your annual turnover exceeds KES 5 million, or
  • You have more than 10 employees, or
  • You operate in one of the mandatory categories set out in the registration regulations, regardless of your size or revenue.

That last point is the one that catches people. Those mandatory categories include crime prevention and prosecution of offenders, which expressly covers the operation of security CCTV systems.

The practical effect: a small business that would otherwise fall below both the turnover and headcount thresholds can be pulled into mandatory registration purely because it operates CCTV. A twelve-person business with cameras at the entrance is in scope on two grounds at once.

Registration is done through the ODPC's online portal, and certificates are issued for a defined period and must be renewed. Verify your specific position against the current regulations, or with counsel, rather than assuming you are too small to matter.

The seven duties that actually apply to your cameras

Registration is the administrative step. These are the substantive obligations, and they are where most installations fail.

1. Have a lawful basis and a defined purpose

Write down why the cameras exist: theft prevention, staff and visitor safety, access control at a specific entrance. "General security" is not a purpose; it is a shrug. The purpose then constrains everything else: what you may look at, how long you keep it, and who sees it.

And it constrains where cameras may point. Cameras in toilets, changing rooms, or prayer rooms are effectively impossible to justify. Cameras trained on individual staff workstations for productivity monitoring are a different purpose entirely from crime prevention, and require their own justification, transparency and almost certainly consultation with staff.

2. Tell people they are being recorded

Transparency is not optional. Clear, visible signage at every entrance and in every monitored area, stating that CCTV is in operation, who operates it, why, and how to contact them. A faded sticker behind a plant does not discharge this.

You also need a written CCTV or surveillance policy that a data subject can actually request and read.

3. Collect only what you need

Data minimisation applies to camera placement and to capability. Ask honestly:

  • Does this camera need to cover the neighbouring property or the public pavement? Overspill onto adjoining land or public space is one of the most common complaints, and one of the hardest to defend.
  • Do you need audio recording? Audio is significantly more intrusive than video and is rarely justifiable for general security. Most systems ship with it enabled by default; turn it off unless you have a specific, documented reason.
  • Do you need facial recognition or analytics? That is a materially different processing activity with a higher bar.

4. Set a retention period and enforce it automatically

You may not keep footage indefinitely because the recorder happens to have the capacity.

Set a defined retention period justified by your purpose; most general security footage is retained for a period of days to a few weeks, long enough that an incident would realistically be discovered and investigated, and configure the system to overwrite automatically at the end of it. Where specific footage is retained beyond that for an active investigation, insurance claim, or legal matter, export it, log it, and delete it when the matter closes.

Design point: this is a storage-sizing decision made at installation. A system specified without a retention policy will simply keep whatever fits on the disks, which is the definition of unlawful retention.

5. Secure the footage properly

The security obligation applies to the surveillance system itself, and this is where a very large number of Kenyan installations are indefensible:

  • Default passwords still in place on recorders and cameras. Extremely common. It means anyone can watch your premises.
  • NVRs exposed directly to the internet for remote viewing, with no VPN and unpatched firmware.
  • Unrestricted access — everyone from the receptionist upward able to scroll back through weeks of footage.
  • No audit trail of who viewed or exported what.
  • The recorder sitting in an unlocked room anyone can reach.

A recorder that is compromised or stolen is a personal data breach, and serious breaches carry notification obligations to the ODPC and, in some cases, to affected individuals. The way to avoid that conversation is to segment the surveillance network, enforce credentials and role-based access, keep firmware current, log access, and physically secure the equipment. This is one of the strongest arguments for integrating security with properly designed network infrastructure rather than bolting cameras onto the office LAN, a point we cover in why integrated security systems beat standalone surveillance.

6. Be able to respond to a data subject request

An individual has the right to ask whether you hold footage of them and to receive access to it. You need a route to search footage by time and location, to redact or obscure other identifiable people before disclosure, and to respond within the statutory period.

Two things follow. First, a system with no usable search function makes compliance practically impossible. Second, you cannot hand over raw footage showing other people that discloses their personal data. Consider redaction capability at the specification stage, not when the request arrives.

7. Carry out a Data Protection Impact Assessment where the risk is high

A DPIA is required where processing is likely to result in high risk to individuals. Systematic monitoring of publicly accessible areas, large-scale surveillance, facial recognition and biometric processing all point firmly in that direction.

The assessment documents what you are doing, why, what the risk to individuals is, and what you have done to reduce it. Done before installation, it also produces a better system; it forces the camera-by-camera justification that most designs skip.

Where installations most commonly fall down

From what we see on site:

ProblemWhy it matters
No ODPC registrationDirect breach; operating CCTV is a mandatory registration category
No signage, or token signageFails the transparency requirement outright
Cameras overspilling onto neighbouring property or the streetDisproportionate; a frequent source of complaints
Audio recording enabled by defaultRarely justifiable, rarely a deliberate decision
Footage kept until the disk fillsNo defined retention period; unlawful retention
Default credentials on NVR and camerasBreach waiting to happen
NVR port-forwarded to the internetSame, with a public front door
No access control or viewing logCannot demonstrate accountability
No written contract with the monitoring firmProcessor relationship ungoverned
No DPIA for a large or public-facing deploymentRequired where risk is high

Every one of these is fixable, and most are cheaper to fix at design stage than after installation.

A compliance checklist

  • Registered with the ODPC as a data controller (and renewal current)
  • Written purpose for surveillance, documented and specific
  • Signage at every entrance and monitored area, naming the operator and contact
  • Written CCTV policy, available on request
  • Camera placement reviewed for overspill and prohibited areas
  • Audio disabled unless separately justified
  • Defined retention period, enforced by automatic overwrite
  • Default passwords changed; firmware current; remote access via VPN, not port forwarding
  • Role-based access to live and recorded footage, with an audit log
  • Recorder physically secured
  • Written data processing agreement with any third-party monitoring or storage provider
  • Documented process for data subject access requests, including redaction
  • DPIA completed where processing is high risk
  • Breach response plan covering the surveillance system