5 MCP servers live now What’s live ›
Real Biz Digital logo Real Biz Digital

Kenya

Automated decisions under Kenya's Data Protection Act: what section 35 actually requires

Section 35 of the Data Protection Act, 2019 gives every data subject a right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or significantly affects them. That is a prohibition on the decision itself, not merely a duty to disclose that a machine was involved. Kenya's rule takes the European shape and is stricter than many organisations running scoring, screening or eligibility models here assume. Three exceptions exist — and even inside them, the data subject may request reconsideration or a new decision that is not based solely on automated processing.

How Barzel applies here Start free with BarzelVault

What does section 35 actually say?

The operative words are not to be subject to. The right attaches to the outcome, not to the notice. An organisation that discloses its use of automated decisioning in a privacy notice and stops there has left section 35 untouched.

Two conditions define the scope. The decision must be based solely on automated processing — profiling is expressly included — and it must produce legal effects concerning the data subject or significantly affect them. Credit and digital-lending decisions, insurance pricing, automated fraud blocks, tenant or employment screening and eligibility scoring sit comfortably inside that description. A recommendation ranking usually does not.

"Solely" is where most compliance arguments are made and where most of them are weak. A human who receives a model output, has no practical capacity to disagree with it and approves it as a matter of throughput is not making the decision. Nominal review does not convert automated processing into human processing.

How narrow are the three exceptions?

ExceptionWhat it requiresWhere it usually fails
Performance of a contract The decision is necessary for entering into or performing the contract. Convenience and volume are not necessity. If a human could decide on the same facts, necessity is hard to argue.
Authorised by law An authorising law, plus suitable safeguards. The safeguards half is skipped. An authorising provision alone does not carry the exception.
Express consent Consent specific to the automated decision, not bundled. Acceptance of general terms is not express consent, and consent is withdrawable.

Does relying on an exception remove the right to reconsideration?

No. This is the point most often missed. Data subjects may request reconsideration or a new decision that is not based solely on automated processing. An organisation that has established contract necessity has bought the right to run the decision automatically — not the right to refuse to look at it again. A lawful exception still requires a working human reconsideration route: a channel the data subject can find, a person with authority to reach a different outcome, and a timescale.

How does Kenya compare with Switzerland, the UK and California?

JurisdictionInstrumentWhat triggers the ruleRemedy
Kenya DPA 2019, s.35 Decision based solely on automated processing, including profiling, with legal effects or significant effect Right not to be subject to it; may request reconsideration or a new decision not based solely on automated processing
Switzerland DSG Art. 21 Automated individual decision with legal effect or significant effect Information duty, plus a right to have the decision reviewed by a natural person
United Kingdom UK GDPR Arts 22A–22D, in force 5 Feb 2026 (DUAA 2025 s.80 replaced Art. 22) General prohibition relaxed for non-special-category data Safeguards regime rather than a general prohibition
California CPPA ADMT rules, duties from 1 Jan 2027 Technology that "replaces or substantially replaces human decision-making" Notice, opt-out and access duties rather than a right against the decision

Kenya and Switzerland are the closest pair: a threshold defined by the effect on the person, and a remedy routed through a human being. The practical warning is the United Kingdom. A group that rebuilt its policy around the post-DUAA position and rolled it out to a Nairobi entity has under-protected in Kenya, because Kenya retains the shape the UK left behind.

Why is ODPC registration where organisations are quietly non-compliant?

Registration with the ODPC is mandatory unless the entity is both under KES 5 million turnover and has fewer than 10 employees. Both conditions, not either. And the exemption does not apply at all, regardless of size, to entities processing for financial services, telecommunications, health administration, education, direct marketing, transport, hospitality, digital credit and several other listed purposes — which covers most organisations running automated decisioning in the first place.

Registration binds controllers and processors handling data about people in Kenya regardless of where the entity is established, so a foreign scoring vendor serving Kenyan customers is in scope where it sits. Administrative fines run to KES 5 million or 1% of annual turnover, whichever is lower.

What does reconsideration require operationally?

To reconsider a decision rather than re-run it, someone must be able to establish what the system acted on and under which model or rule version. Re-running an agent produces a new decision, not an explanation of the old one — inputs have moved, the model may have been updated, and the second output tells you nothing reliable about the first.

Section 35 therefore depends on capture most deployments do not have: the inputs as they stood at decision time and the model or configuration version that produced the outcome, both recorded before the decision executes rather than reconstructed afterwards. It is the same audit-trail problem that arises wherever agents act on people's behalf.

Under section 31, a data protection impact assessment is required where processing is likely to result in high risk, with reports submitted 60 days prior to the processing — a lead time that belongs in the project plan, not the launch checklist.

Which incident clock applies: 72 hours or 24 hours?

Keep these separate; conflating them produces either over-reporting or a missed statutory deadline. Under section 43, controllers notify the ODPC of a personal data breach without delay and within 72 hours; processors notify controllers within 48 hours. That applies to everyone.

The 24-hour duty under the Computer Misuse and Cybercrime (Critical Information Infrastructure and Cybercrime Management) Regulations, 2024 applies only to designated critical information infrastructure owners, who must also appoint a CISO, keep the infrastructure physically located in Kenya and conduct annual risk assessments. An ordinary business not so designated has no general 24-hour cyber reporting duty.

Does an AI law change any of this?

Not yet. Kenya has no AI law. The Kenya National AI Strategy 2025–2030, launched March 2025, creates no obligations. The draft Kenya AI and Other Emerging Technologies Policy (July 2026) closed for public comment on 4 August 2026 and remains draft. The Artificial Intelligence Bill, 2026 (Senate Bills No. 4 of 2025) was published 19 February 2026, had its first reading on 2 April 2026 and was referred to committee — it has not passed. Its proposals, including EU-style risk tiers, an Office of the Artificial Intelligence Commissioner, a public register of high-risk systems and retention of input, output and performance records for at least five years, are not law. What binds AI use in Kenya today is the Data Protection Act 2019, the Computer Misuse and Cybercrimes Act 2018, the Consumer Protection Act 2012, and sector regulation such as CBK requirements for financial services.

Frequently asked questions

Does section 35 ban automated decisions?

Not outright, but it is a prohibition rather than a disclosure duty. It is permitted only under contract necessity, legal authorisation with safeguards, or express consent.

If an exception applies, does the right to reconsideration disappear?

No. The data subject may still request reconsideration or a new decision not based solely on automated processing.

Is Kenya's rule closer to the European or the American model?

The European shape — closest to Switzerland's DSG Art. 21 and to the pre-2026 UK position, not the US patchwork.

Does my organisation have to register with the ODPC?

Almost certainly, if you run automated decisioning. The small-entity exemption needs both conditions and does not apply to the listed sectors at any size.

Do I report an incident within 24 hours or 72 hours?

72 hours to the ODPC for a personal data breach. The 24-hour rule is for designated critical information infrastructure owners only.

Where this leads

With eTIMS validation live from the 2026 tax year — KRA matching declared income and expenses against eTIMS and TIMS invoices, withholding tax data and customs import records, the transitional relief having ended at the 30 June 2026 filing deadline — Kenyan organisations are now running automated decisions in two regulated domains at once. Tax and personal data. The evidence requirement is identical in both: what did the system act on, under which version, and can you show it afterwards.

Related

BarzelVault enforces policy and approval thresholds and records each operation before it executes. FinOps Atlas measures the cost of automated workflows and API operations.

In practice

Permission before the action. Evidence after it.

The duties on this page attach to the moment an automated system acts: who permitted it, on which data, under which policy version, and what a person saw before approving. Barzel enforces that decision before execution and writes the record an auditor, a regulator or a data subject can be shown.

Section 35 of the Data Protection Act 2019: in force

BarzelVault

The AI action firewall: decide what an agent may do before it does it.

  • Approval thresholds and policy checks enforced before execution; human approvals that expire and escalate.
  • Cryptographically signed audit receipts: trigger, inputs, policy version, approver, outcome.
  • Credential isolation, spend and action limits, and an emergency kill switch.

Free tier: 10,000 calls a monthPaid plans from $199 a monthLive on MCPize

Start free Ask by emailProduct pageDocumentation

Barzel FinOps Atlas

Intelligent financial operations for AI agents and automation.

  • Cost per action, workflow and business outcome, allocated as it happens.
  • Spend limits and anomaly detection before the bill, not after.
  • Financial evidence tracing and close-readiness for SOX, SOC 2 and external audit.

Free tier: 500 calls a monthPaid plans from $29 a monthLive on MCPize

Start free Ask by emailProduct pageDocumentation

Enterprise: written quote by email within two business days. No sales call.


Sources

  1. Data Protection Act, 2019 (Kenya), sections 31, 35 and 43.
  2. Office of the Data Protection Commissioner, registration guidance and exempt-threshold criteria.
  3. Computer Misuse and Cybercrimes Act, 2018; Computer Misuse and Cybercrime (Critical Information Infrastructure and Cybercrime Management) Regulations, 2024.
  4. Swiss Federal Act on Data Protection (DSG), Article 21.
  5. Data (Use and Access) Act 2025 (UK), section 80, inserting UK GDPR Articles 22A–22D, in force 5 February 2026.
  6. California Privacy Protection Agency, automated decision-making technology regulations; duties from 1 January 2027.
  7. Kenya National AI Strategy 2025–2030; draft Kenya AI and Other Emerging Technologies Policy (July 2026); Artificial Intelligence Bill, 2026 (Senate Bills No. 4 of 2025).
  8. KRA public notice, Validation of income and expenses in the income tax returns.

This article is for information and does not constitute legal advice.