Kenya's data protection regulator has put content recommendation engines in the same compliance bracket as facial recognition and loan scoring. A draft guidance note dated July 2026 sets out seven lifecycle stages, a 72-hour breach clock and a flat statement that public availability of data does not make it lawful training material.
The Office of the Data Protection Commissioner has circulated a draft Guidance Note on Artificial Intelligence, dated July 2026, that maps the Kenyan Data Protection Act onto every stage of an AI system's existence, from problem definition through to the deletion of model weights. The document runs to 36 pages, two annexes and a definitions section that formalises five distinct actor roles. It is the first Kenyan instrument to state, in operational terms, what a data controller running an algorithmic system is expected to have documented before that system touches a single record.
For anyone buying or selling audience data in the market, one line in Annex 2 carries more weight than the rest of the text combined. An AI content recommendation engine operating on a consumer platform is listed as requiring a Data Protection Impact Assessment, with no discretion and no low-risk carve-out. The stated risk factors are large-scale profiling of consumer preferences and potential sensitive data inference. That places personalisation infrastructure alongside AI credit scoring, clinical diagnostics and biometric authentication in the same mandatory tier.
What triggers a mandatory assessment
Annex 2 of the guidance note sets out twelve illustrative AI use cases and sorts each into one of three categories. Eight are marked as requiring a DPIA outright. Three fall into a review category, where an assessment is expected unless a documented analysis establishes the risk as low. One, predictive maintenance in an industrial setting with no personal data, is marked as requiring nothing.
The eight mandatory cases are credit scoring for loan decisions, health diagnostics using patient records, facial recognition for customer authentication, content recommendation on consumer platforms, student assessment and adaptive learning, recruitment screening and candidate ranking, fraud detection in payment systems, and employee productivity monitoring. According to the guidance note, the trigger in each case is some combination of scale, automated decisions affecting rights, and the possibility of discriminatory outcomes.
The review tier is narrower than it first appears. A generative chatbot with no personal data input still lands there, because the risk depends on whether personal data ends up in user prompts incidentally. An AI translation tool with anonymised inputs is treated the same way, with the note flagging re-identification from surrounding context as the reason the question stays open.
The high-risk table
Section 9 of the document lists seven categories of high-risk AI application, each attracting four minimum obligations: a mandatory DPIA, involvement of a Data Protection Officer subject to Section 24 of the Act, meaningful human review of automated decisions, and regular algorithmic audit. The categories are credit scoring and financial decisioning, health diagnostics and clinical decision support, biometric recognition, employment screening and monitoring, education technology, generative AI platforms, and law enforcement applications.
Generative AI platforms carry their own obligation set within that table. The note requires a privacy notice disclosing generative processing, a training data audit for personal data compliance, and output monitoring for personal data reproduction. The stated risks are training data privacy, reproduction of personal data in outputs, and generation of misleading content about real persons.
Biometric recognition attracts the strictest language in the document. Alongside a mandatory DPIA and a mandatory DPO, the note sets out a prohibition on real-time biometric surveillance absent specific legal authority.
Training data and the public availability question
The guidance note takes a position on scraped and aggregated data that leaves little room for interpretation. Entities are directed not to use personal data scraped from the internet or aggregated from public sources as AI training data without first assessing whether that collection and use is lawful under the Act. The note then states directly that the fact personal data is publicly accessible does not, of itself, provide a lawful basis for processing it as AI training data.
That formulation converges with the direction European regulators have taken. The European Data Protection Board adopted guidelines on web scraping for generative AI on 7 July 2026, concluding that consent is unlikely to work as a legal basis for training-scale collection and that publishing data on an open web page does not amount to agreeing to its use for model training. Kenya's draft reaches a similar destination through a different statutory route.
Purpose limitation is handled with equal bluntness. Repurposing production or operational data for AI training without a fresh legal basis or a compatibility assessment is not permitted, according to the note. The worked example concerns a public hospital that collected patient records under a public interest basis and cannot supply those records to a commercial vendor building a diagnostic tool for licensing. The original purpose and the new one are described as incompatible.
Storage limitation extends past the dataset itself. The note directs that model weights and parameters encoding personal information be addressed in retention and deletion policies, not just the training corpus. At decommissioning, entities are told to assess whether trained weights encode personal data recoverable through model inversion or membership inference, and to implement erasure measures where that risk is present.
Seven stages, and what attaches to each
The lifecycle framework is the structural centre of the document. Stage 1 covers problem definition and system design, where DPIA scoping, lawful basis identification and DPO engagement sit. Stage 2 is data collection and preparation. Stage 3 is model training and development. Stage 4 is testing, validation and pre-deployment review. Stage 5 is deployment and integration. Stage 6 is operation, monitoring and maintenance. Stage 7 is decommissioning and disposal.
Stage 4 is where the compliance burden concentrates for anyone shipping a system. Before an AI system processes live personal data, the note requires finalisation and sign-off of the DPIA, technical testing of the human review mechanism, testing of access, rectification and erasure interfaces, accuracy and fairness validation against test datasets representative of the affected population with attention to differential performance across demographic groups, an explainability review, and DPO sign-off where one has been designated.
Stage 6 introduces continuing duties that do not expire. Ongoing monitoring for drift and discriminatory output patterns, periodic DPIA revision triggered by material change, periodic algorithmic auditing by a qualified internal or independent auditor, a documented change management procedure covering retraining and provider changes, and a documented incident register recording discriminatory outcomes, systemic inaccuracies and privacy harms alongside the remedial action taken.
Where a system is replaced rather than retired, the successor is treated as a new deployment and the full lifecycle process restarts at Stage 1, including a fresh DPIA addressing architectural and contextual differences.
Breach clocks and the processor chain
Two separate deadlines govern incident reporting, and they interlock. The Office must be notified within 72 hours of an entity becoming aware of a breach likely to result in risk to data subjects. Where the breach occurs inside a data processor's systems, including those of a third-party AI service provider, that processor has 48 hours from becoming aware to notify the controller. Responsibility for notifying the Office, and for communicating with affected individuals where the risk is high, remains with the controller throughout.
The note is explicit that AI-specific incident types fall inside the breach definition. Unauthorised access to training datasets counts. So does a model extraction attack. So does adversarial manipulation of AI outputs.
Automated decisions and the human in the loop
Section 35 of the Kenyan Act supplies the right not to be subject to a decision based solely on automated processing where that decision significantly affects the individual. The guidance note lists the sectors it considers in scope: credit, employment, insurance, housing, healthcare, education and access to public services.
Five obligations attach. Decisions must not be made solely by automated means without meaningful human involvement. Individuals must be told a decision was automated. They must be able to request human review. They must receive, on request, a meaningful explanation of the logic and its consequences. And a contest mechanism must route to a human with authority to reverse or modify the outcome.
Regulation 22 of the Data Protection (General) Regulations, 2021 layers four further requirements: prevention of errors, use of appropriate mathematical or statistical procedures, technical and organisational measures to correct inaccuracies, and processing conducted in a manner that eliminates discriminatory effects and bias.
The note also addresses a category that sits uncomfortably with most current disclosure practice. AI systems generate inferred data, including behavioural profiles, risk scores and predictions. Because those inferences relate to identifiable people, the note treats them as personal data under Section 2 of the Act, subject to the transparency and fairness duties in Sections 25 and 29. Outputs including classifications and recommendations are handled the same way. Compliance is required across the full processing chain, not only at collection.
Children, sensitive data and inference
Section 33 protections for children's data are restated with an addition that reaches directly into advertising practice. AI systems are not to be used to profile children for commercial purposes, or to make automated decisions significantly affecting children without appropriate human oversight and the involvement of a parent or guardian. Age verification mechanisms and verifiable parental consent are listed as design requirements for systems likely to be accessed by children.
The sensitive data provisions contain a technical point that will complicate audit work. AI systems that generate inferences about sensitive categories, for example a model that infers health status or ethnicity from non-sensitive inputs, may themselves produce sensitive personal data. Entities are directed to assess whether their outputs constitute sensitive personal data and apply the corresponding legal standards. A recommendation engine that never ingests a sensitive field can still, on this reading, manufacture one.
Cross-border transfers and vendor contracts
Part VI of the Act restricts transfers outside Kenya to jurisdictions providing adequate protection or where appropriate safeguards exist. The note applies this to training data sent to offshore developers, cloud-based inference services and the sharing of AI outputs with offshore recipients. Transfers to offshore AI processors without a lawful transfer basis are not permitted.
Where a third party processes personal data as part of an AI service, the note requires a written data processing agreement containing five mandatory elements: processing only on controller instructions, appropriate security measures, no sub-processors without prior authorisation, assistance with data subject rights and DPIA obligations, and deletion or return of all personal data on termination.
Entities are also directed to assess and document whether each third party is acting as processor, controller or joint controller, based on whether it determines the purposes and means of processing. For advertising technology stacks built from layered vendors, that classification exercise is neither trivial nor optional.
Why this lands on marketing desks
The compliance mechanics here will look familiar to anyone who has worked through European rules, and that is the point. Kenya is not inventing a separate vocabulary. DPIAs, lawful basis documentation, legitimate interests assessments, privacy by design and processor agreements all carry the same names and broadly the same content as their GDPR counterparts. A team that has built compliance artefacts for the European market is not starting from zero.
What differs is the classification. European supervisory authorities have circled recommender systems for years without fully resolving whether algorithmic curation constitutes an Article 22 decision. The EDPB noted in its DSA guidance that content presentation through algorithmic curation could produce significant effects on users. Kenya's draft skips that argument and simply lists consumer recommendation engines as DPIA-mandatory.
Legitimate interests, the workhorse basis for much of the programmatic ecosystem, receives a cautious treatment. The note permits it but requires a documented assessment identifying the interest, demonstrating necessity and balancing against data subject rights, with the intrusiveness of AI profiling weighed in. It then flags that legitimate interests may not be appropriate for high-risk applications involving large-scale profiling, sensitive data or significant automated decisions. That mirrors the pattern European authorities have applied in cross-border enforcement, where behavioural targeting and data broker purchasing have repeatedly failed the balancing test.
Market context matters for scale. Google extended advertising inside AI Overviews to Kenya alongside ten other markets on 19 December 2025, and Kenya sits in the highest quintile for relative AI search interest in Google Trends data covering January through April 2026. The systems the guidance note describes are already running in the market it governs.
The draft also arrives alongside a separate national process. Kenya's Ministry of Information, Communications and the Digital Economy opened public consultation on a draft Artificial Intelligence and Other Emerging Technologies Policy in late July 2026, with submissions due 4 August 2026. Regulatory activity across Kenyan data institutions has been sustained through the year, including a Statistics Bill published in 2026 that would seat the Data Protection Commissioner on the board of a new national statistics authority.
Timing puts the Kenyan draft roughly in step with the European Union's Article 50 transparency obligations, which became applicable on 2 August 2026 after Digital Omnibus negotiations collapsed without producing a delay. Two jurisdictions, different instruments, converging demands on the same documentation.
What the note does not settle
Several questions stay open. The document is marked as a draft and carries no stated commencement date. It describes itself as a minimum standard capable of supplementary measures, and directs entities in regulated sectors to comply additionally with sector-specific guidance from the Office and from sector regulators.
The DPO position is also softer than the high-risk table implies. Section 24 of the Act provides that a controller or processor may designate a DPO, and the note describes designation as strongly advisable for entities conducting large-scale systematic monitoring or large-scale processing of sensitive data. The high-risk table nonetheless marks DPO involvement as a minimum obligation, and lists a mandatory DPO for health diagnostics and biometric recognition specifically. The tension between the permissive statutory language and the mandatory framing in the table is not resolved in the text.
Enforcement remains governed by the Data Protection (Complaints Handling Procedure and Enforcement) Regulations, 2021. The note lists seven complaint categories tied specifically to AI, including failure to disclose AI processing in a privacy notice, absence of a human review mechanism, refusal to explain an automated decision, discriminatory profiling producing adverse outcomes, processing sensitive data without lawful basis, failure to conduct a required DPIA, and unlawful cross-border transfer to an AI processor. Cooperation and proactive engagement with the Office may be considered among relevant factors during enforcement, according to the document.
Timeline
- 2010: Constitution of Kenya adopted, establishing Article 31 privacy rights, Article 27 equality guarantees, Article 35 access rights and Article 46 consumer protections cited throughout the guidance note
- 2019: Kenyan Data Protection Act enacted, later codified as Cap 411C
- 2021: Data Protection (General) Regulations, Registration Regulations and Complaints Handling Procedure and Enforcement Regulations come into force
- 6 August 2025: Leaked internal documents show Meta scraped roughly 6 million domains for AI training data
- 14 September 2025: EDPB guidance addresses whether algorithmic curation triggers automated decision-making provisions
- 19 December 2025: Google extends AI Overviews advertising to Kenya and ten other markets
- 28 March 2026: EDPB digest documents repeated failures of legitimate interest in cross-border advertising cases
- Late April 2026: Digital Omnibus negotiations in Brussels collapse, leaving the 2 August 2026 AI Act date intact
- 6 May 2026: Kenya's Statistics Bill, 2026 proposes a new data authority with the Data Protection Commissioner on its board
- 7 July 2026: EDPB adopts Guidelines 03/2026 on web scraping for generative AI
- July 2026: Office of the Data Protection Commissioner issues the draft Guidance Note on Artificial Intelligence
- 21 July 2026: Kenya's ICT ministry opens public participation on a separate draft national AI and emerging technologies policy
- 2 August 2026: EU AI Act Article 50 transparency obligations become applicable
- 4 August 2026: Deadline for submissions on Kenya's draft national AI policy
Related PPC Land coverage
- EDPB blocks AI firms from using consent as an excuse to scrape sets out the European position on scraped training data and the three-condition legitimate interest test that parallels Kenya's treatment of publicly accessible sources.
- EDPB's damning digest: how legitimate interest fails in practice documents how behavioural targeting and data broker purchasing have fared under the balancing test Kenya now imports into AI profiling assessments.
- European data protection board clarifies DSA compliance for marketers covers the unresolved European question of whether recommender systems constitute automated decisions, which the Kenyan draft answers by classification.
- Kenya's Statistics Bill, 2026 replaces KNBS with sweeping new data authority tracks the parallel legislative activity reshaping Kenyan data institutions.
- Brussels AI Act talks collapse - but the August 2026 deadline holds explains why the European transparency deadline landed in the same window as the Kenyan draft.
- Google shifts AI ad labeling liability entirely to advertisers shows how platform-level design choices distribute regulatory exposure down to individual advertisers.
Summary
Who: The Office of the Data Protection Commissioner, the Kenyan regulator established under Section 5 of the Data Protection Act, Cap 411C. The guidance note addresses data controllers, data processors, AI developers, AI providers, AI deployers and AI users, a five-role taxonomy the document defines formally.
What: A draft Guidance Note on Artificial Intelligence mapping the Data Protection Act and its 2021 Regulations onto AI systems. It sets seven lifecycle stages with obligations attached to each, seven high-risk application categories, a twelve-case DPIA trigger table with eight mandatory entries, a 72-hour regulator notification window and a 48-hour processor-to-controller notification window, and explicit treatment of generative AI, inferred data and cross-border transfers.
When: The document carries a July 2026 date and is marked as a draft. It sits alongside a separate Ministry of ICT consultation on a national AI policy that closed for submissions on 4 August 2026, and lands in the same period as the European Union's 2 August 2026 Article 50 transparency deadline.
Where: Kenya. The note applies to entities, public or private, that develop AI systems trained on personal data, deploy AI systems processing personal data of persons located in Kenya, procure AI-as-a-service products involving personal data, or use AI in automated decision-making affecting data subject rights.
Why: AI adoption across Kenyan finance, health, employment, retail and government has outpaced sector-specific guidance, according to the document, which cites algorithmic opacity, training dataset aggregation, inference generation, discriminatory outcomes from biased data and reduced human involvement in consequential decisions as the gaps requiring AI-calibrated rules.
Discussion