Kenya's data protection regulator has published a Guidance Note telling controllers to select, document and periodically review privacy-enhancing technologies as part of the privacy by design duty

Kenya ODPC Guidance Note on Privacy Tech. The Leveraged Years regulation briefing card.

Guidance notes do not create obligations. This one tells you how the Office intends to read an obligation that already exists, and that is the part worth reading closely.

The short version

Bottom line: A guidance note, not a statutory instrument. It binds nobody by itself. The obligations it interprets, in particular Section 41 of the Data Protection Act, Cap. 411C, already bind data controllers and data processors.

Who this affects: Data protection officers, in-house counsel, chief information security officers and system architects at Kenyan banks, mobile money operators, hospitals, telecommunications providers and government agencies, plus the technology developers who supply them.

Issue date: The document is dated July 2026 on its cover page. It sets no compliance deadline and names no transition period.

What changed: The Office set out, in one place, which privacy-enhancing technologies it maps to which statutory principle, and stated that it will treat a failure to deploy an available and appropriate PET in high-risk sensitive processing as evidence of non-compliance with Section 41.

Analysis: The cost sentence is the operative one. The Office writes that technical complexity, commercial cost or operational inconvenience does not relieve a controller of the obligation where a PET is appropriate and reasonably available. That is a budget argument being answered in advance.

Primary sources: Guidance Note on Privacy-Enhancing Technologies, July 2026 (PDF) · Office of the Data Protection Commissioner

Instrument (EN)
Guidance Note on Privacy-Enhancing Technologies
Authority
Office of the Data Protection Commissioner (ODPC)
Jurisdiction
Kenya
Status
Published guidance note, 38 pages, two annexes
Bindingness
Not binding of itself. Interprets the Data Protection Act, Cap. 411C and the 2021 Regulations, which are binding.
Issue date / next deadline
July 2026. No deadline stated in the document.
Legal hooks cited
Section 25 (principles), Section 31 (DPIA), Section 41 (privacy by design and by default), Section 24 (DPO)
Primary source
https://www.odpc.go.ke/wp-content/uploads/2026/07/PET-Guidance-Note.-July-2026.pdf

What the Office actually published

The Guidance Note runs to 38 pages and covers anonymisation and pseudonymisation, encryption, differential privacy, federated learning, secure multi-party computation, zero-knowledge proofs, homomorphic encryption, synthetic data and data clean rooms. Two annexes follow: a selection guide keyed to processing objectives, and a compliance checklist.

Its stated scope is broad. It applies, on its own terms, to all entities, whether public or private, that process personal data of persons located in Kenya and that are considering, deploying or governing the use of PETs.

The Office positions PETs as the technical measures through which controllers give effect to Section 41, which requires appropriate technical and organisational measures designed to implement the data protection principles and to integrate safeguards into processing activities.

The AI-specific passages

Several parts of the document address machine learning directly. Among the concerns the Office says PETs address is AI model memorisation and training data exposure, on the basis that models trained on personal data can memorise individual records and reproduce them in outputs.

The federated learning chapter is the most detailed. It states that federated learning is not inherently privacy-preserving, and names three risks to be addressed: gradient inversion attacks, model inversion and membership inference, and poisoning attacks. Entities deploying federated learning for processing involving personal data are told to conduct a DPIA addressing those risks and the mitigations adopted.

The erasure passage is the one most likely to reach a machine learning team. Where a data subject requests erasure of data used to train an AI model, the Office says entities should assess whether the model memorises that individual's data, through membership inference testing, and implement machine unlearning or model retraining where memorisation is identified.

A worked example describes three Kenyan commercial banks training a fraud detection model through federated learning with secure aggregation and differential privacy applied to the aggregated gradients, with a joint DPIA.

Where the Office draws a hard line

Anonymisation gets the strictest treatment. The standard, in the Office's words, is objective and absolute: data is anonymised only if re-identification is not reasonably possible given all means likely to be available to any potential adversary, including the data controller itself and third parties.

That matters because truly anonymised data falls outside the Act. The Office warns that achieving genuine anonymisation is significantly more technically demanding than is commonly assumed, and lists linkage and inference attacks as the principal risks.

Location data is singled out. The Office says it is among the most re-identifiable categories of personal data, that even coarse or sampled traces can single out an individual, and that heightened measures apply before location data is analysed or shared.

The annex separates differential privacy from k-anonymity in blunt terms, describing the latter and its extensions as weaker, heuristic protections vulnerable to composition and attribute disclosure attacks, suitable only for lower-sensitivity datasets under controlled access.

What it does not do

Nothing in the document creates a new obligation, a registration step or a filing. The Office lists the enforcement powers it already holds under the Act, including complaints, inspections and audits, enforcement and penalty notices, administrative fines and criminal referrals.

It is also explicit that a PET is not a compliance substitute. An entity that deploys encryption but has no lawful basis for processing is not compliant, and the Office says PETs must be deployed in support of the principles rather than in place of them.

Registration is restated rather than changed: entities processing personal data of persons in Kenya, including those deploying PETs, are to be registered under the 2021 Registration Regulations.

What a DPO should do with it this quarter

The document tells controllers what the Office expects to see on the page. Four things recur: an assessment of available PETs at system design stage, documented; selection of the appropriate PET or combination; implementation as a core system feature rather than a retrofit; and periodic review as technology and risk change, recorded in the records of processing activities.

Two contract families are named. Data processing agreements for high-risk or sensitive processing should specify the required PETs, and the Office gives examples, including requiring an AI developer to use federated learning or synthetic data instead of raw personal data. Data sharing agreements should record an assessment of whether the sharing objective could have been met without disclosing identifiable data.

Staff competency is treated as a governance item. The Office says DPOs, data protection leads, IT architects and procurement officers need a working understanding of PET properties and limitations, while stating that this does not require them to be cryptography experts.

What we did not verify

We opened and read the primary source: the 38-page PDF at odpc.go.ke dated July 2026, including the definitions, the legislative framework chapter, the principle mapping table, the sectoral chapters, the obligations and enforcement chapters and both annexes.

We did not open the Data Protection Act, Cap. 411C, the Data Protection (General) Regulations 2021, the Registration Regulations 2021, or the separate ODPC Guidance Note on Registration referred to in the text. Our description of Sections 25, 31 and 41 reflects how the Guidance Note characterises them, not our own reading of the statute.

Two things we will not claim. First, the brief that reached us called this a draft; the PDF we read carries no draft marking, and its cover reads Guidance Note on Privacy-Enhancing Technologies, July 2026. We note that the contents page contains an unresolved field reference where a foreword should sit, which is consistent with a document that was not fully finalised in production, but we cannot say whether a consultation preceded publication or whether a later version exists. Second, we cannot say whether the Office has yet taken any enforcement step in reliance on this Guidance Note.

Key compliance takeaway

The transferable point is documentary. This Guidance Note converts a general privacy by design duty into a record the regulator can ask for: which PETs you assessed, which you chose, why, and when you last reviewed the choice. If your DPIAs for high-risk processing do not name a specific technology, the risk it addresses and the residual risk it leaves, you have the gap the Office says it will look for. Budget objections have been pre-empted in the text.

Source File

https://www.odpc.go.ke/wp-content/uploads/2026/07/PET-Guidance-Note.-July-2026.pdf

Open the PDF at odpc.go.ke and confirm the cover date of July 2026, the Section 41 discussion in chapter 3, the enforcement statement in chapter 17 that failure to implement appropriate PETs will be treated as evidence of non-compliance, and the machine unlearning sentence in section 15.2.

The fact that a PET is technically complex, commercially costly, or operationally inconvenient does not relieve a data controller of the obligation to implement it where it is appropriate and reasonably available. ยท Office of the Data Protection Commissioner, Guidance Note on Privacy-Enhancing Technologies, July 2026

FAQ

Does this Guidance Note create a new legal obligation?

No. It is guidance. The obligation it interprets is Section 41 of the Data Protection Act, Cap. 411C, which already requires appropriate technical and organisational measures. The Office describes how it intends to assess compliance with that existing duty.

Does deploying a PET make processing lawful?

No, and the document says so directly. It gives the example of an entity that deploys encryption but has no lawful basis for processing, and states that such an entity is not compliant with the Act.

What does it say about deleting someone's data from a trained model?

Where erasure is requested and the data was used to train an AI model, the Office says entities should assess memorisation through membership inference testing and implement machine unlearning or model retraining where memorisation is found.

Can we treat synthetic or anonymised data as outside the Act?

Only if re-identification is not reasonably possible using all means likely to be available to any adversary, including the controller. The Office calls that standard objective and absolute, and warns that many datasets treated as anonymous remain re-identifiable through linkage.

Sponsored Training

Practical AI training for regulated professionals, built around verification, documentation and a defensible process. See the courses.

."}}]}