Kenya's data protection regulator has issued a guidance note treating every emerging-technology deployment that touches personal data as high-risk and therefore DPIA-mandatory

Kenya ODPC Guidance Note on Emerging Technologies. The Leveraged Years regulation briefing card.

Guidance does not bind. This one restates statutory duties in mandatory language and then adds a sentence that goes further than the Act plainly requires: new technologies are high-risk processing, so every deployment gets a DPIA.

The short version

Bottom line: A guidance note, not legislation. It does not create obligations by itself; the obligations it describes come from the Data Protection Act, Cap. 411C and the 2021 Regulations. The note says it should be regarded as a minimum standard.

Who this affects: Data protection officers and general counsel at Kenyan banks, insurers, hospitals, telecoms and county governments, plus vendors selling IoT, cloud, biometric or connected-vehicle systems into Kenya from abroad.

Issue date: The document's cover reads July 2026. It carries no draft marking and states no consultation deadline anywhere in its 31 pages.

What changed: The note declares that processing personal data using new technologies is high-risk processing, and concludes that all emerging technology deployments involving personal data are therefore subject to a DPIA.

Analysis: AI is conspicuously absent from the scope list. The note covers IoT, cloud, blockchain, biometrics, extended reality, connected vehicles and drones, and where an IoT system incorporates AI it defers to a separate Artificial Intelligence Guidance Note. Kenya is building its data protection guidance as a set of parallel notes, and knowing which one governs is now a threshold question.

Primary sources: ODPC Guidance Note on Emerging Technologies, July 2026 (PDF)

Instrument (EN)
Guidance Note on Emerging Technologies
Authority
Office of the Data Protection Commissioner (ODPC), Kenya
Jurisdiction
Kenya, including processing of personal data of persons located in Kenya by entities established elsewhere
Status
Issued. 31 pages, with a compliance checklist at Annex 1. No draft label and no comment period appear in the document.
Bindingness
Not binding as guidance. It interprets and applies the Data Protection Act, Cap. 411C and the 2021 Regulations, which are binding.
Issue date / next deadline
July 2026. No deadline is stated in the document.
Scope
IoT, cloud computing, blockchain and DLT, biometric recognition, immersive and extended reality, connected and autonomous vehicles, and unmanned aircraft systems. The list is stated to be illustrative and not exhaustive.
Primary source
https://www.odpc.go.ke/wp-content/uploads/2026/07/Emerging-Tech-Guidance-Note.-July-2026.pdf

The DPIA line is the operative one

Section 13.3 begins conventionally: a DPIA is required before deploying any emerging technology system likely to result in high risk to the rights and freedoms of data subjects. Then it takes a step. Processing of personal data using new technologies is considered high-risk processing. Accordingly, all emerging technology deployments that involve the processing of personal data are subject to a DPIA.

That collapses a risk assessment into a categorical rule. The note goes on to enumerate examples anyway, including any blockchain system recording personal data, all biometric recognition system deployments, and smart city or public space surveillance deployments.

For a DPO in Kenya the practical consequence is a backlog question, not a legal one. If your organisation has deployed cloud, IoT or biometric systems without DPIAs, this note tells you what the regulator expects to find on inspection.

Where AI actually lives

The scope list is worth reading for what it omits. Seven categories are named; artificial intelligence is not among them, except that autonomous vehicles are defined as relying on artificial intelligence-based processing systems, and the IoT obligations say that where IoT systems incorporate AI, entities shall comply with the applicable requirements under the Artificial Intelligence Guidance Note.

So this note is one of a family. It cross-refers to a Guidance Note on Data Protection Impact Assessments and a Guidance Note on Biometric Data, both said to be available on the ODPC website, and to the AI note. Compliance work in Kenya now starts with deciding which note applies to the system in front of you.

Blockchain gets the most demanding treatment

The erasure problem is handled without hedging. Entities are told to assess at design stage whether personal data needs to be on-chain at all, or whether the chain can hold only cryptographic references to off-chain data that can actually be deleted. Where on-chain personal data is unavoidable, the note asks for a documented lawful basis that takes account of the immutability constraint, encryption before recording, and permissioned rather than public architectures where feasible.

Where erasure is technically impossible, the note accepts a compensating measure: rendering the data functionally inaccessible, for example by destroying the encryption key, together with documentation of the impossibility and the measure adopted. That is a workable position, and it is stated as guidance, not as a safe harbour.

Extraterritorial reach, stated plainly

One sentence in the IoT section deserves attention from vendors outside Kenya. Entities that manufacture IoT devices for the Kenyan market, or that supply IoT device management platforms used by Kenyan deployers, are told that the Act applies to the processing of personal data of persons located in Kenya regardless of where the manufacturer or platform operator is established.

The note also sets a 72-hour breach notification expectation to the Office for any breach likely to result in risk to data subjects, with notification to affected data subjects without undue delay where the risk is high. Annex 1 reduces the whole document to a fifteen-row compliance checklist, which is the page most readers will actually use.

What we did not verify

We opened and read the full 31-page ODPC Guidance Note on Emerging Technologies dated July 2026, including the definitions, the legislative framework, all seven technology sections, the obligations, the enforcement section and Annex 1.

We did not open the Data Protection Act, Cap. 411C, any of the 2021 Regulations, or the companion ODPC guidance notes on DPIAs, biometric data and artificial intelligence that this note cross-refers to. We did not check the ODPC website for a consultation page.

The brief we worked from described this as a draft with comments due 17 August 2026. The document itself carries no draft marking, and the words comment, consultation deadline and August appear nowhere in its text. We report the document as it stands and make no claim that a comment period exists or has closed. We also make no claim that the mandatory-DPIA reading has been tested by the Office in an enforcement action.

Key compliance takeaway

Treat the DPIA sentence as the note's real content: on the regulator's stated view, any deployment of these technologies that touches personal data needs an assessment, without a preliminary risk screen. Then check which guidance note governs your system, because AI sits in a different document and IoT with AI in it sits in both.

Source File

https://www.odpc.go.ke/wp-content/uploads/2026/07/Emerging-Tech-Guidance-Note.-July-2026.pdf

Open the PDF and confirm three things: section 13.3 states that processing of personal data using new technologies is considered high-risk processing and concludes that all such deployments require a DPIA; the scope list in section 2.3 names seven technologies and does not name AI; and the IoT obligations defer AI-enabled processing to the Artificial Intelligence Guidance Note.

This Guidance Note should be regarded as a minimum standard. ยท ODPC Guidance Note on Emerging Technologies, July 2026

FAQ

Does this guidance note create new legal obligations?

No. It is guidance. The obligations it describes come from the Data Protection Act, Cap. 411C and the 2021 Regulations. The note positions itself as a minimum standard for applying those obligations.

Do I need a DPIA for every cloud migration?

The note says all emerging technology deployments involving personal data are subject to a DPIA, and lists cloud migrations involving sensitive personal data or large volumes of personal data as an example. That is the Office's stated expectation, not a statutory test it has restated word for word.

Does it cover artificial intelligence?

Not directly. AI is not in the scope list. The note refers AI-enabled IoT processing to a separate Artificial Intelligence Guidance Note issued by the same office.

Does it apply to a foreign vendor?

On the note's account, yes for IoT: it states that the Act applies to processing of personal data of persons located in Kenya regardless of where the manufacturer or platform operator is established.

Sponsored Training

Practical AI training for regulated professionals, built around verification, documentation and a defensible process. See the courses.

."}}]}