Engage Benson

Personal Information

1 / 4
The Data Controller-Processor Relationship Explained: Lessons from a KES 450,000 ODPC Decision

The Data Controller-Processor Relationship Explained: Lessons from a KES 450,000 ODPC Decision

2 August 2026

Do you believe in the saying, “It is better to ask for forgiveness than permission.” If you work with personal data, forget that saying. It will cost you.

This is the story of Christine, a retiree and content creator who was invited by the National Social Security Fund (NSSF) to share her retirement experience. What began as an exciting opportunity to showcase her journey ended with a video being broadcast on national television without her consent, and a Ksh. 450,000 lesson in data protection law that every organization must understand.

The Office of the Data Protection Commissioner (ODPC) recently delivered a determination that has become a cornerstone for understanding the controller-processor relationship under Kenya’s Data Protection Act, 2019. This article exhaustively examines the case, the legal principles at play, and the practical lessons for all organisations that process personal data.

The Facts of the Case

On 19th April 2024, Christine received a call from a representative of NSSF’s Corporate Communications Department. The representative, impressed by Christine’s YouTube content, invited her to participate in a video interview about her retirement experience. The arrangement was simple: Christine would share her story, NSSF would pay an appreciation fee of Ksh. 20,000, and an Indemnity Agreement Form would be signed before the video was published.

Christine was hesitant at first but agreed. NSSF had engaged an independent contractor, Off Grid Concepts Limited, to handle the filming and production.

On 25th April 2024, a director at Off Grid Concepts contacted Christine to arrange the interview. He proposed filming at her home to depict the picture of a retiree. Christine agreed, and the interview proceeded on 26th April. She was shown the edited version on 7th May and was impressed by the final product.

Crucially, Christine had been assured repeatedly that the video would only be used after she had signed the Indemnity Agreement Form. The form was not ready on 7th May, and when it arrived on 8th May, Christine was surprised to find it contained no provision for payment beyond the initial token. She sought advice and proposed a counter-offer. NSSF responded that they could not afford her request and would not proceed with the video.

Christine believed the matter was closed. It was not.

On 16th May 2024, a friend who worked at NSSF called to congratulate Christine after seeing her video during the NSSF National Strategic Launch, which had been broadcast live on NTV, KTN, KBC, and TV47. The video had been played on 7th May, the same day Christine had been shown the edit, and a full day before the Indemnity Agreement Form was even sent to her.

Christine was shocked. She had never given consent. She had never signed any agreement. The video had been broadcast without her knowledge or permission.

The Legal Framework

i. The Controller-Processor Distinction

The Data Protection Act defines these roles with precision: Data Controller is defined under Section 2 as a natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purpose and means of processing of personal data. Data Processor is defined under Section 2 as a natural or legal person, public authority, agency or other body which processes personal data on behalf of the data controller.

In this case, NSSF was the Data Controller, it determined the purpose (producing a testimonial video for its Strategic Plan launch) and the means (engaging a contractor to film and edit). Off Grid Concepts was the Data Processor, it processed Christine’s personal data on behalf of NSSF. This distinction determines who bears liability when things go wrong. And as this case demonstrates, the line can shift dramatically.

ii. The “Deemed Controller” Principle

Section 42(3) of the Data Protection Act provides: “Where a data processor processes personal data other than as instructed by the data controller, the data processor shall be deemed to be a data controller in respect of that processing.”

This is the game-changing provision. A processor who steps outside the controller’s instructions is no longer a mere processor. They become a controller for that specific processing, with all the attendant obligations and liabilities.

iii. The Processor’s Liability

Section 65(2)(b)(ii) of the Data Protection Act reinforces this by providing that a data processor involved in processing of personal data is liable for damage caused by the processing only if the processor has acted outside, or contrary to, the data controller’s lawful instructions.

iv. The Consent Requirement

Section 30(1)(a) provides that “a data controller or data processor shall not process personal data unless the data subject consents to the processing for one or more specified purposes.”

Section 25 establishes the principles of data protection, including: Lawfulness, fairness, and transparency. Processing must be lawful, fair, and transparent in relation to the data subject. The fairness principle requires the handler to process personal data in ways the data subject would reasonably expect.

v. Commercial Use of Personal Data

Section 37(1) prohibits the use of personal data for commercial purposes unless: Express consent has been sought and obtained; or The use is authorised by written law and the data subject has been informed. Regulation 14(1) of the General Regulations defines commercial purposes as using personal data to “advance commercial or economic interests, including inducing another person to buy, rent, lease, join, subscribe to, provide or exchange products, property, information or services.”

The ODPC’s Analysis

Who Was Liable?

The ODPC examined the evidence carefully. NSSF had instructed Off Grid Concepts not to publish the video until it was properly edited and the Indemnity Agreement signed. The contractor, through its director, admitted that the video was aired erroneously when his technical team included it in the materials for the Strategic Plan launch.

The ODPC applied Section 42(3) of the Data Protcetion Act. Off Grid Concepts had processed Christine’s personal data (the video) contrary to NSSF’s instructions. By doing so, Off Grid Concepts was deemed a data controller for that processing. The liability shifted entirely to the contractor.

The complaint against NSSF was dismissed. Off Grid Concepts was found liable.

Was There Commercial Use?

Christine alleged that her video was used for commercial purposes without consent. The ODPC examined this under Section 37(1) and Regulation 14. The airing of the video did not confer any direct benefit to Off Grid Concepts, as the content did not advertise or promote the contractor’s services. Therefore, the ODPC found that the video was not used for commercial purposes as alleged.

This finding is significant. It confirms that the mere fact of broadcast or publication does not automatically constitute commercial use. The determining factor is whether the processing advances the commercial or economic interests of the processor.

The Core Violation: Lack of Consent

The ODPC found that Off Grid Concepts violated Section 30(1)(a) by processing Christine’s personal data without obtaining her consent. She had agreed to be interviewed. She had agreed to be filmed. She had not agreed to have the video broadcast nationally. Consent must be specific, informed, and purpose-limited.

The ODPC also found a violation of Section 25, specifically the fairness principle. Christine reasonably expected her video to be used only after she had signed the Indemnity Agreement. Using it before then was unfair and contrary to her reasonable expectations.

The Compensation Award

Christine had prayed for Ksh. 5 million in compensation. The ODPC declined this amount, finding it “so inordinately high and an erroneous estimate of the damage.” Instead, the ODPC awarded Ksh. 450,000, taking into account the scope of publication—the video had been aired on national television stations and circulated widely.

LESSONS FROM CHRISTINE OCHOLA V. NSSF & OFF GRID CONCEPTS LIMITED

i. The Controller’s Responsibility to Document Instructions

NSSF was not held liable because they had documented their instructions clearly. They had told Off Grid Concepts not to publish the video without completion of editing and execution of the indemnity. They had WhatsApp communications and other records to prove this.

Takeaway: Controllers must document all instructions to processors. Emails, contracts, and written communications are essential. They are not just formalities; they are your defence when a processor steps out of line.

ii. The Processor’s Sole Liability When Acting Outside Instructions

Off Grid Concepts was held solely liable because its director admitted the error. The company had aired the video without consent, contrary to NSSF’s instructions. Once a processor acts outside the controller’s lawful instructions, it steps out of the protective umbrella of the controller and becomes a controller itself, with all attendant liabilities .

Takeaway: Processors must verify consent before processing. They cannot assume that the controller has obtained consent. They cannot rely on instructions that are unclear. The moment they act outside the controller’s instructions, they become solely liable.

iii. Consent Must Be Purpose-Specific

Christine consented to the interview. She consented to being filmed. She did not consent to the video being broadcast nationally. Consent under Section 2 must be express, unequivocal, free, specific, and informed. A general consent to “make a video” does not constitute consent to “broadcast the video nationally.”

Takeaway: Consent forms must be purpose-specific. They must state exactly how the personal data will be used. A broad, vague consent is not consent at all.

iv. The Fairness Principle

The ODPC found that Off Grid Concepts violated the fairness principle by airing the video in a way Christine would not have expected. She had been assured the video would only be used after she signed the form. Using it before then was unfair.

Takeaway: Process personal data in ways the data subject would reasonably expect. If you intend to use data in a way that might surprise the data subject, inform them and obtain their consent.

v. Commercial Use: A Fact-Specific Inquiry

The ODPC found no commercial use because the video did not promote Off Grid Concepts’ services. This does not mean that using personal data in videos is never commercial. The analysis is fact-specific.

Takeaway: If personal data is used to advance commercial or economic interests, including attracting customers, promoting services, or generating revenue, consent is required. Analyse each use case carefully.

PRACTICAL INSTRUMENTS AND BEST PRACTICES

i. Controller-Processor Contracts

The ODPC’s Guidance Note for the Public Sector sets out the requirements for controller-processor contracts. These contracts should specify:

(a) The subject matter of processing; (b) The types of personal data; (c) The nature and duration of processing; (d) The required security measures; (e) Obligations for staff confidentiality; (f) Assistance in meeting legal requirements; (g) Handling of data at the contract’s end; (h) Provisions for auditing, inspection, and liability.

Takeaway: A written contract is mandatory. Do not engage a processor without one. The contract must specify that the processor acts only on the controller’s instructions.

ii. Due Diligence in Processor Selection

Public institutions must exercise due diligence in selecting registered vendors that provide sufficient guarantees of compliance with the Act and protection of data subjects’ rights.

Takeaway: Verify that your processors are registered with the ODPC. Conduct due diligence on their data protection practices.

iii. Technical and Organisational Measures

Section 41 of the Data Protection Act requires controllers and processors to implement appropriate technical and organisational measures to ensure data protection principles are implemented effectively.

The General Regulations require, among other things: (a) Hashing and cryptography to limit repurposing of personal data; (b) Access controls ensuring only authorised personnel have access; (c) Audit trails and event monitoring; (d) Routines to detect, handle, report, and learn from data breaches; (e) Regular review and testing of software for vulnerabilities .

Takeaway: Implement robust technical and organisational measures. Document them. Regularly review and update them.

iv. Compliance Checklist

The ODPC’s Guidance Note provides a compliance checklist that includes:

(a) Have we identified an appropriate legal basis for our processing under Section 30?

(b) If we are processing sensitive data, have we identified permitted grounds under Section 44?

(c) Do we handle data about individuals in ways they would reasonably expect?

(d) Have we clearly identified our purposes for processing?

(e) Do we regularly review whether processing is necessary for the purposes for which data was collected?

(f) Do we have appropriate contracts with our processors?

Takeaway: Use the ODPC’s compliance checklist as a starting point. Review it regularly.

v. Training and Awareness

The Off Grid Concepts case illustrates the consequences of poor training. The technical team aired Christine’s video because they assumed all clips in the NSSF folder were to be played. There was no briefing. There was no verification. There was no consent check.

Takeaway: Train all staff and contractors on data protection obligations. Ensure they understand the distinction between controller and processor. Ensure they know that processing personal data without consent is unlawful.

vi. The Bigger Picture: ODPC’s Emerging Jurisprudence

This determination is part of a growing body of ODPC decisions that are shaping Kenya’s data protection landscape. Key cases include:

  1. Mhasibu Housing Company (Complaint No. 371 of 2024): Ordered to pay Ksh. 650,000 for using personal data for marketing without consent.

  2. Brainstorm Insurance Brokers (Complaint No. 1500 of 2025): Ordered to pay Ksh. 1,012,500 for using professional names and titles on its website without consent.

  3. St. Luke Orthopaedic & Trauma Hospital (Complaint No. 2125 of 2025): Ordered to pay Ksh. 525,000 for sharing patient data with a third-party laboratory without consent and handing one patient another patient’s medical results.

These cases demonstrate that the ODPC is taking its enforcement role seriously. Organisations that fail to comply with the Data Protection Act face significant financial penalties.

Conclusion

The Christine Ochola determination is a masterclass on the controller-processor relationship in data protection. It teaches us that:

  1. Instructions must be documented. Controllers must have written records of their instructions to processors.

  2. Processors who step outside instructions become controllers. Section 42(3) is a game-changer. Processors cannot hide behind the controller’s instructions when they act contrary to them.

  3. Consent is mandatory. Processing personal data without consent is unlawful. Consent must be specific, informed, and capable of proof.

  4. The fairness principle is real. Process personal data in ways the data subject would reasonably expect.

  5. Contracts are essential. Controller-processor contracts must be in writing and must specify the scope of processing, security measures, and liability provisions.


These liabilities are real. Your contracts and data protection practices must anticipate them or they may devour your business. Review your controller-processor agreements, consent mechanisms, and data protection practices with me to scan for compliance, indemnity and risk allocation.

By: Benson Odiwuor

Advocate of The High Court of Kenya

Should you have any questions regarding the subject, reach out at insights@bensonodiwuor.com

Found this useful? Share it with a colleague.

Share
All posts

Legal counsel, research collaboration, or speaking inquiries.

Engage Benson

Personal Information

1 / 4