Skip to Content

ACAIGO's Comments on the ODPC's Draft Guidance Notes on AI and Emerging Technologies

August 22, 2026 by
Charles Ombiro

The African Centre for AI Governance and Oversight (ACAIGO) has submitted comments on two draft guidance notes published for consultation by Kenya’s Office of the Data Protection Commissioner (ODPC):

• the Draft Guidance Note on Artificial Intelligence; and
• the Draft Guidance Note on Emerging Technologies.

The consultation also covered a third document, the Draft Guidance Note on Privacy-Enhancing Technologies.

The publication of these drafts is a welcome step. As artificial intelligence and other emerging technologies become more widely adopted in Kenya, organizations need guidance that explains how the country’s data protection framework applies to the development, procurement and use of these technologies.

ACAIGO submitted its comments on 17 August 2026, following a detailed review of the two drafts. Our review considered whether the proposed guidance is legally grounded, technically coherent and sufficiently clear to support its practical application.

Our comments on the Draft Guidance Note on Artificial Intelligence

The Draft Guidance Note on Artificial Intelligence addresses several important questions arising from the use of personal data in AI systems. Our comments focused on areas where greater precision would make the guidance clearer and more useful to the organizations expected to apply it.

1. Defining artificial intelligence more clearly

The definition of AI in the Draft Guidance Note closely resembles the OECD’s 2019 definition of an AI system. However, its broad, capability-focused formulation does not establish a sufficiently clear distinction between AI systems and conventional automated software. Conventional software may also operate according to predefined objectives, produce predictions, recommendations or decisions, and influence physical or virtual environments. Consequently, the definition may encompass systems that would not ordinarily be regarded as AI, creating uncertainty regarding the intended scope of the Guidance.

ACAIGO did not propose a replacement definition. We recognize that there is no single, universally accepted definition of AI and that legal, scientific and technical definitions serve different purposes. We did, however, invite the ODPC to adopt a more conceptually and technically sound definition that distinguishes AI systems more clearly from conventional automated software.

2. Addressing personal data throughout the AI lifecycle

The draft states that it applies to the development, deployment and procurement of AI systems. Much of its substantive guidance, however, concentrates on the use of personal data to train AI models.

Training is only one stage at which personal data may be processed.  We therefore proposed that the substantive provisions and compliance checklists reflect the full scope set out in the Guidance Note. Organizations should be guided on their responsibilities wherever personal data is processed during the development, procurement or deployment of an AI system, rather than being left with the impression that training is the principal concern.

3. Recognizing that AI-related bias has several sources

The draft discusses discriminatory profiling and bias mainly in relation to historical training data. Historical data can certainly reproduce or amplify existing patterns of discrimination, but it is not the only source of bias in an AI system.

Bias may be introduced through the collection, selection, representation or labelling of data. It may also arise from decisions made during model design and testing, the use of variables that act as proxies for protected characteristics, the context in which a system is deployed or the way its outputs are interpreted by human decision-makers.

The final Guidance Note should reflect these different sources of bias. Doing so would encourage organizations to examine the entire AI lifecycle instead of concentrating only on the composition of historical datasets.

4. Determining legal roles across the AI supply chain

Some provisions and examples in the draft appear to assume that an external or offshore AI provider will necessarily act as a data processor.

Whether a provider is a controller, joint controller or processor cannot be determined solely from its position as a service provider. Its legal role depends on what it actually does and, in particular, the extent to which it determines the purposes and means of processing personal data.

We proposed the use of role-neutral language where the parties’ legal status has not yet been established. Each arrangement should be assessed on its facts so that responsibility is allocated according to the parties’ actual involvement in the processing.

5. Making Legitimate Interests Assessments more useful in practice

The draft requires organizations relying on legitimate interests to conduct and document a Legitimate Interests Assessment. However, it largely restates the conventional stages of an assessment without explaining how those stages should be applied to AI-related processing. 

Organizations would benefit from more practical guidance. Additionally, given the growing reliance on legitimate interests for activities such as AI-model training, we also invited the ODPC to consider publishing separate and more comprehensive guidance on conducting Legitimate Interests Assessments.


6. Clarifying the rules on cross-border data transfers

The draft contains provisions that could be read as requiring individual organizations to determine whether another country provides an adequate level of data protection.

Under regulation 44 of the Data Protection (General) Regulations 2021, adequacy determinations are made by the Data Commissioner. An adequacy decision must be distinguished from an organization’s assessment of whether appropriate safeguards or another legally recognized transfer basis is available.

At the time of our submission, the ODPC had not published a list of countries, territories, sectors or international organizations recognized as providing an adequate level of protection under Kenyan law. Unless an applicable adequacy decision exists, an organization must identify another transfer basis recognized under the Data Protection Act and Regulations and put in place the safeguards required by that mechanism.

The final Guidance Note should draw these distinctions clearly. It should also recognize that cross-border processing may involve more than training data. User inputs, prompts, system outputs, logs and other operational data may also be transferred or accessed outside Kenya.

7. Separating legal obligations from recommended governance measures

The draft states that organizations shall establish particular institutional structures, including AI governance committees and documented AI governance frameworks.

These can be valuable accountability measures. However, a guidance note should not present a measure as a mandatory requirement unless that obligation is grounded in the Data Protection Act or its Regulations.

We proposed that these structures be presented as recommended governance measures. This would allow organizations to integrate AI oversight into their existing data protection, compliance and risk-management arrangements in a way that reflects their size, resources, activities and risk profile.

8. Reflecting the law on registration

The draft refers to confirming registration with the ODPC or updating an existing registration when undertaking a new AI processing activity.

Registration is not an unqualified requirement for every organization using personal data. Whether an organization is required to register must be determined under section 18 (2) of the Data Protection Act and the Data Protection (Registration of Data Controllers and Data Processors) Regulations 2021, taking account of the applicable categories, thresholds and exemptions.

The final Guidance Note should therefore make clear that its registration-related requirements apply only where an organization is required to register under the Act and the applicable Regulations.

Our comments on the Draft Guidance Note on Emerging Technologies

Our review of the Draft Guidance Note on Emerging Technologies focused particularly on the scope of retention obligations, cross-border transfers, the monitoring of children, the appointment of data protection officers and registration with the ODPC.

1. Applying retention requirements to all personal data processed

The draft refers to retention policies for personal data “generated by” emerging technologies. That expression is too narrow and may be understood as excluding data that was not created by the technology itself.

An emerging technology may collect, receive, store or use personal data obtained from individuals or third parties. It may also infer, derive or generate new information from the data it receives.
We proposed wording that would apply the retention requirement to all personal data processed through an emerging technology.

2. Revising the cross-border transfer example

The draft includes an example of a Kenyan hospital transferring patient information to a cloud service provider whose servers are located in the European Union and the United States. The hospital is instructed to assess the adequacy of protection in the receiving jurisdictions, with the European Union described as “likely adequate.”

This approach does not reflect how adequacy is determined under Kenyan law. Regulation 44 of the Data Protection (General) Regulations 2021 reserves adequacy determinations for the Data Commissioner. A hospital or another transferring organization cannot independently declare a foreign jurisdiction adequate.

At the time of our submission, the ODPC had not issued an adequacy decision recognizing the European Union as providing an adequate level of protection under Kenyan law. The fact that the European Union has an established data protection framework does not, by itself, amount to a Kenyan adequacy decision.

We proposed revising the example so that the organization must first establish whether an applicable adequacy decision exists. If there is none, it should identify another legally recognized transfer basis and implement the necessary contractual, technical and organizational safeguards.

3. Reconsidering the continuous monitoring of children

One of the examples in the draft concerns a virtual-reality education platform that monitors students’ gaze patterns, movements and engagement levels during virtual lessons.

The example raises questions that go beyond obtaining parental consent and adopting procedural safeguards. Parental consent does not, on its own, make continuous monitoring of children necessary, proportionate or consistent with their best interests.

Section 33 of the Data Protection Act requires the processing of children’s personal data not only to be supported by the consent of a parent or guardian but also to protect and advance the child’s rights and best interests.

Before using this form of monitoring, a school should be able to demonstrate that it is strictly necessary for a clearly defined educational purpose and that the same purpose cannot reasonably be achieved through less intrusive means. It should also consider whether consent can genuinely be withheld without excluding or disadvantaging a student.

The example should further address whether the information could be used for behavioral, disciplinary or other consequential profiling. Restricting only its use for commercial profiling does not deal with the full range of possible harms.

The respective roles of the school and the technology company also require clarification. The example does not clearly explain which party is responsible for the different data protection obligations arising from the processing.

Rather than proposing revised wording, ACAIGO invited the ODPC to reconsider the example in light of these concerns.

4. Preserving the statutory position on DPO appointments

The draft states that organizations whose core activities involve large-scale systematic monitoring or the large-scale processing of sensitive personal data through emerging technologies shall designate a data protection officer.

Section 24 of the Data Protection Act provides that a data controller or data processor may designate or appoint a DPO in the circumstances set out in that provision. By stating that relevant organizations “shall” appoint a DPO, the draft turns the Act’s discretionary wording into a mandatory requirement.

The appointment of a DPO may be strongly advisable where an organization undertakes large-scale systematic monitoring or processes sensitive personal data on a large scale. Nevertheless, the Guidance Note should preserve the statutory position.

5. Avoiding an unqualified registration requirement

The draft suggests that an organization must register with the ODPC before deploying any emerging technology that processes the personal data of individuals in Kenya.

This may create the impression that the use of an emerging technology automatically triggers registration. It does not. Registration must be determined under section 18 (2) of the Data Protection Act and the Data Protection (Registration of Data Controllers and Data Processors) Regulations 2021, which establish relevant categories, thresholds and exemptions.

Organizations should first determine whether they are subject to mandatory registration. Where registration is required, it should be completed before the organization begins processing personal data through the emerging technology.

Towards clear, practical and legally grounded guidance

ACAIGO’s comments are intended to support the development of guidance that is clear, useful in practice and firmly grounded in Kenya’s Data Protection Act and Regulations.

The consultation provided an important opportunity for stakeholders to contribute to the development of Kenya’s approach to technology governance. ACAIGO appreciates the opportunity to take part in that process and looks forward to the publication of the final guidance notes.

Download the documents

Our complete comments and recommendations are available below:
The consultation documents are also available on the ODPC Draft Guidance Notes page.