A Data Protection Impact Assessment (“DPIA”) is a structured assessment used to identify and mitigate privacy risks before an organisation undertakes personal-data processing that is likely to result in a high risk to the rights and freedoms of individuals.
Under section 31 of the Data Protection Act, 2019, a data controller or data processor in Kenya must undertake a DPIA where the nature, scope, context or purposes of the proposed processing are likely to create a high risk to data subjects.
DPIAs are particularly relevant to businesses using artificial intelligence, automated decision-making, biometric systems, large-scale surveillance, sensitive personal data, employee monitoring, health information, financial information or other technology-driven processing.
For Kenyan businesses, the DPIA should not be treated as a regulatory formality. It is a practical risk-management tool that can identify privacy, cybersecurity, contractual, vendor and governance risks before a project is launched.
Sunday Memba Mayama advises businesses and organisations on DPIAs, data-protection compliance, regulatory engagement and privacy-risk management under Kenyan law.
What is a Data Protection Impact Assessment in Kenya?
A DPIA is a documented assessment of a proposed personal-data processing activity.
It examines:
- what personal data will be collected;
- why the organisation needs the data;
- how the data will be used;
- who will access it;
- whether the processing is necessary and proportionate;
- what risks the processing creates for individuals; and
- what safeguards should be implemented before processing begins.
The purpose is preventive.
A DPIA enables a business to identify privacy risks before it launches a product, system or service rather than responding only after a complaint, security incident or regulatory investigation.
When is a DPIA required under Kenyan law?
Section 31 of the Data Protection Act, 2019 requires a DPIA where processing is likely to result in a high risk to the rights and freedoms of a data subject because of its nature, scope, context or purpose.
Not every processing activity requires a DPIA.
The critical question is:
Could the proposed processing materially affect the privacy, autonomy, security or other rights of individuals?
Where the answer is yes, the organisation should determine whether a formal DPIA is required before processing begins.
What types of processing may require a DPIA in Kenya?
High-risk processing may include activities involving:
- automated decision-making;
- profiling;
- large-scale processing;
- sensitive personal data;
- biometric information;
- genetic information;
- children’s data;
- vulnerable persons;
- systematic monitoring;
- CCTV and surveillance systems;
- combining data from different sources; and
- innovative technologies.
The requirement is particularly important where the processing may have legal, financial, employment, health or other significant consequences for the individual.
Which Kenyan businesses should be particularly concerned about DPIAs?
DPIAs are relevant across sectors.
Financial institutions and fintech companies
A bank or fintech platform may use personal information for:
- credit scoring;
- fraud detection;
- customer profiling;
- automated lending decisions;
- identity verification; and
- behavioural analysis.
These activities can significantly affect an individual’s access to financial services.
Employers
Employers increasingly deploy:
- biometric attendance systems;
- employee-monitoring software;
- productivity tracking;
- automated recruitment systems;
- background screening; and
- workplace surveillance.
These technologies may create significant privacy risks.
Hospitals and healthcare providers
Health information is sensitive personal data.
Hospitals, clinics, laboratories and digital-health platforms should carefully assess systems involving:
- electronic patient records;
- telemedicine;
- health applications;
- diagnostic technology;
- biometric identification; and
- sharing of patient information.
Schools and educational institutions
Educational institutions may process information relating to children, students and parents.
A DPIA may become relevant where schools deploy:
- biometric access systems;
- online learning platforms;
- student-monitoring software;
- CCTV;
- educational analytics; or
- cloud-based student databases.
E-commerce and technology businesses
Digital platforms frequently rely on:
- behavioural advertising;
- cookies and tracking technologies;
- recommendation systems;
- customer profiling;
- personalised marketing; and
- cross-platform data sharing.
The more extensive the profiling and automated processing, the stronger the case for conducting a DPIA.
Why are DPIAs increasingly important for artificial intelligence?
Artificial intelligence has significantly increased the importance of privacy-risk assessment.
AI systems may use large datasets to:
- make predictions;
- classify individuals;
- assess risk;
- determine eligibility;
- recommend decisions; or
- automate decisions altogether.
The legal concern is not simply that an organisation uses AI.
The concern is what data the AI uses, how the system reaches decisions and what consequences those decisions have for individuals.
Before deploying an AI-driven system, a business should ask:
- What personal data will the system use?
- Was that data lawfully obtained?
- Is all of the data necessary?
- Could the system produce discriminatory or unfair outcomes?
- Can individuals understand how significant decisions are made?
- Is human intervention available?
- Can decisions be challenged?
- What happens if the system produces inaccurate results?
- Where is the underlying data stored?
A DPIA creates a structured process for answering these questions before deployment.
What should a DPIA contain?
A properly prepared DPIA should ordinarily address four core areas.
- Description of the processing
The organisation should identify:
- the categories of personal data;
- the data subjects affected;
- how information will be collected;
- the purpose of processing;
- who will receive the data;
- where the data will be stored; and
- how long it will be retained.
A DPIA cannot properly assess risk unless the organisation understands the processing activity itself.
- Necessity and proportionality
The organisation should determine whether the processing is genuinely necessary for the intended purpose.
The fact that information can be collected does not mean that it should be collected.
The organisation should ask:
Can the same legitimate business objective be achieved using less personal data or a less intrusive method?
This is particularly important where sensitive information is involved.
- Assessment of risks to data subjects
The DPIA should identify potential adverse consequences for individuals.
These may include:
- identity theft;
- financial loss;
- discrimination;
- reputational harm;
- unlawful surveillance;
- loss of confidentiality;
- inaccurate profiling;
- exclusion from services;
- unauthorised disclosure; and
- loss of control over personal information.
Risk should be considered from the perspective of the data subject, not only the business.
- Measures to reduce the identified risks
The organisation should then determine what safeguards can reduce those risks.
Possible measures include:
- encryption;
- pseudonymisation;
- anonymisation;
- access controls;
- multifactor authentication;
- retention limits;
- employee training;
- contractual safeguards;
- security testing;
- human review of automated decisions;
- audit trails; and
- incident-response procedures.
The DPIA should explain why the proposed safeguards are adequate.
When should a DPIA be conducted?
A DPIA should be conducted before high-risk processing begins.
This is fundamental.
The purpose is to influence the design of the project.
If an organisation conducts the DPIA after:
- purchasing the software;
- signing the vendor contract;
- collecting the data; or
- launching the system,
many of the important privacy decisions may already have been made.
The better sequence is:
Assess → Design safeguards → Implement → Monitor.
Not:
Launch → Discover risk → Correct later.
Do DPIAs need to be filed with the ODPC?
Kenyan law requires regulatory engagement in specified circumstances, particularly where high-risk processing remains after appropriate mitigation measures have been considered.
The Office of the Data Protection Commissioner (“ODPC”) is the principal regulator responsible for oversight and enforcement of the Data Protection Act.
Businesses should therefore determine whether the particular processing activity requires notification, submission, prior consultation or another form of regulatory engagement before implementation.
This analysis should be undertaken early.
What happens if significant risk remains after the DPIA?
A DPIA does not automatically authorise processing.
If the assessment shows that substantial privacy risks remain despite proposed safeguards, the organisation should reconsider the proposed processing.
Options may include:
- reducing the amount of data collected;
- removing sensitive data fields;
- redesigning the system;
- increasing human oversight;
- strengthening security controls;
- changing the vendor;
- limiting retention;
- restricting access; or
- abandoning the proposed processing altogether.
Where required, prior consultation with the ODPC should occur before processing begins.
DPIAs and third-party vendors
A significant portion of modern data processing is outsourced.
Businesses rely on:
- cloud-storage providers;
- payroll platforms;
- payment processors;
- customer-relationship management systems;
- marketing platforms;
- recruitment software;
- cybersecurity providers; and
- AI vendors.
Outsourcing processing does not necessarily outsource accountability.
Before appointing a vendor, the business should understand:
- what information the vendor receives;
- where the data will be stored;
- whether subcontractors are involved;
- what security controls exist;
- whether data will leave Kenya;
- how incidents are reported;
- what happens when the contract ends; and
- whether the vendor can demonstrate compliance.
A DPIA can expose these risks before a contract is signed.
DPIAs and cross-border data transfers
Many digital services store data outside Kenya.
A Kenyan business may therefore collect information locally while relying on servers or service providers located in another jurisdiction.
This creates additional questions concerning:
- the destination country;
- safeguards governing the transfer;
- access by foreign service providers;
- contractual protections;
- retention;
- onward transfers; and
- regulatory compliance.
Cross-border transfer analysis should therefore form part of a DPIA where relevant.
DPIAs as a board and corporate governance issue
Data protection should not be confined to the IT department or legal department.
High-risk data processing can create:
- regulatory risk;
- litigation exposure;
- reputational damage;
- cybersecurity risk;
- contractual liability; and
- operational disruption.
Where a processing activity has material enterprise-wide consequences, management and appropriate board or risk functions should understand the findings of the DPIA.
A significant project involving personal data should therefore be approached in much the same way as other material corporate risks.
The organisation should know:
- the risk;
- its likelihood;
- its potential impact;
- who is responsible for mitigation; and
- whether residual risk is acceptable.
Example: a Kenyan lender introducing automated credit scoring
Consider a Kenyan financial-services company introducing an automated system that assesses loan applications.
The platform analyses:
- identification data;
- transaction history;
- mobile-phone information;
- previous borrowing behaviour; and
- other behavioural indicators.
The system then determines whether an applicant qualifies for credit.
Before deployment, the lender should consider:
- whether every category of data is necessary;
- the lawful basis for processing;
- whether the algorithm may disadvantage particular groups;
- whether applicants understand how their information is used;
- whether incorrect data can be corrected;
- whether human review is available;
- how long information is retained; and
- what security measures protect the data.
A DPIA provides the framework for carrying out this analysis.
Example: an employer introducing biometric attendance
Consider an employer replacing ordinary attendance registers with fingerprint or facial-recognition technology.
The convenience of the system does not end the legal inquiry.
The employer should determine:
- whether biometric processing is necessary;
- whether a less intrusive alternative exists;
- where biometric templates will be stored;
- who has access;
- how long the information will be retained;
- what happens when an employee leaves; and
- what would happen if the database were compromised.
Conducting this assessment after the system has been installed would significantly reduce its usefulness.
Common DPIA mistakes Kenyan businesses should avoid
Conducting the DPIA too late
The assessment should influence system design, not simply document decisions already made.
Copying a generic template
A DPIA should reflect the actual project.
Generic descriptions provide little value where the risks are specific to a particular system or business model.
Treating legal compliance as the only risk
Privacy failures may also create:
- cybersecurity incidents;
- customer complaints;
- loss of trust;
- contractual disputes; and
- reputational harm.
Ignoring vendors
An organisation should understand what third-party processors are doing with its data.
Failing to review the DPIA
A DPIA is not necessarily permanent.
It should be revisited where:
- processing changes;
- new data is introduced;
- technology changes;
- a new vendor is engaged;
- the purpose changes; or
- new risks emerge.
Frequently Asked Questions About DPIAs in Kenya
Is a DPIA mandatory in Kenya?
Yes, where processing is likely to result in a high risk to the rights and freedoms of data subjects under section 31 of the Data Protection Act, 2019.
Does every company need a DPIA?
No. The requirement depends on the nature and risk of the proposed processing rather than the mere fact that a business handles personal data.
Should a DPIA be conducted before or after processing begins?
Before processing begins. A DPIA is intended to identify and reduce privacy risk during the design and planning stage.
Is a DPIA necessary for CCTV?
Potentially. Systematic monitoring, particularly where surveillance is extensive or affects publicly accessible areas, may amount to high-risk processing requiring assessment.
Does biometric attendance require a DPIA?
It may. Biometric information is particularly sensitive, and businesses should assess whether the processing creates a high risk to employees or other data subjects.
Does using artificial intelligence automatically require a DPIA?
Not automatically. However, AI involving profiling, automated decisions, sensitive data or significant effects on individuals is more likely to require one.
Who should prepare a DPIA?
The data controller or processor remains responsible for ensuring that an appropriate DPIA is undertaken. Effective assessments commonly require input from legal, compliance, technology, cybersecurity, procurement and relevant operational personnel.
Can a business continue processing if the DPIA identifies serious risk?
The business should first determine whether the risk can be adequately mitigated. Where high residual risk remains, further regulatory engagement may be required before processing begins.
How Sunday Memba Mayama Can Assist
Data-protection compliance requires more than preparing privacy notices.
Sunday Memba Mayama advises businesses, technology companies, financial institutions, employers, healthcare providers and other organisations on privacy compliance and data-risk management under Kenyan law.
He assists clients with:
- conducting and reviewing Data Protection Impact Assessments;
- determining whether a proposed activity requires a DPIA;
- assessing high-risk processing;
- advising on artificial intelligence and automated decision-making;
- reviewing biometric and surveillance systems;
- reviewing vendor and data-processing arrangements;
- drafting data-processing agreements;
- advising on cross-border data transfers;
- developing privacy and data-governance frameworks;
- advising on data breaches;
- assisting with regulatory engagement with the ODPC; and
- advising management and boards on material data-protection risks.
Early advice is particularly valuable where an organisation is developing a new product, procuring technology, implementing artificial intelligence or introducing a system involving sensitive personal information.
The objective is to identify legal and privacy risk before the organisation becomes operationally committed to the proposed processing.
Conclusion
A Data Protection Impact Assessment is one of the most important preventive tools available to Kenyan businesses processing high-risk personal data.
It requires an organisation to identify:
- what data it intends to process;
- why the processing is necessary;
- what risks individuals may face; and
- what safeguards should be implemented before processing begins.
For organisations deploying artificial intelligence, biometrics, surveillance, automated decision-making, health technologies or other data-intensive systems, this assessment is increasingly central to responsible business governance.
The practical principle is straightforward:
privacy risk should be assessed before technology is deployed, not after harm occurs.
For Kenyan businesses, a properly conducted DPIA is therefore more than a statutory compliance exercise.
It is a mechanism for making better decisions, reducing regulatory exposure and building trust in data-driven products and services.
This article is intended for general information only and does not constitute legal advice. Specific advice should be obtained based on the nature of the organisation and its proposed personal-data processing activities.
Get In Touch
(+254) 713741741
info@kmlawchambers.comRelated Insights
Data Protection Impact Assessments in Kenya: When Businesses Need a DPIA and How to Conduct One
A Data Protection Impact Assessment (“DPIA”) is a structured...
Read More
Living Abroad with Property in Kenya? Protecting Your Matrimonial Property Interest Before Divorce
You may be living outside Kenya while substantial property...
Read More
Commercial Debt Recovery and Disputes in Kenya: What Businesses Should Consider Before Acting
Commercial Debt Recovery and Disputes in Kenya: What Businesses...
Read More
