<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Kenya Data Protection Act Archives - Insider Bits News</title>
	<atom:link href="https://insiderbits.co.ke/tag/kenya-data-protection-act/feed/" rel="self" type="application/rss+xml" />
	<link>https://insiderbits.co.ke/tag/kenya-data-protection-act/</link>
	<description>Stay Informed, Stay Ahead</description>
	<lastBuildDate>Wed, 04 Feb 2026 20:27:45 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.1</generator>

<image>
	<url>https://insiderbits.co.ke/wp-content/uploads/2024/08/cropped-favicon-32x32.png</url>
	<title>Kenya Data Protection Act Archives - Insider Bits News</title>
	<link>https://insiderbits.co.ke/tag/kenya-data-protection-act/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>How Recording a “Simple” HR Call Could Land You in KSh700,000 Trouble</title>
		<link>https://insiderbits.co.ke/news/how-recording-a-simple-hr-call-could-land-you-in-ksh700000-trouble/</link>
		
		<dc:creator><![CDATA[IB Reporter]]></dc:creator>
		<pubDate>Wed, 04 Feb 2026 20:27:45 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[biometric data voice]]></category>
		<category><![CDATA[call recording law]]></category>
		<category><![CDATA[consent and data law]]></category>
		<category><![CDATA[data privacy fines kenya]]></category>
		<category><![CDATA[data protection kenya]]></category>
		<category><![CDATA[digital privacy kenya]]></category>
		<category><![CDATA[employee privacy rights]]></category>
		<category><![CDATA[HR compliance]]></category>
		<category><![CDATA[Kenya Data Protection Act]]></category>
		<category><![CDATA[liquid telecommunications case]]></category>
		<category><![CDATA[ODPC ruling]]></category>
		<category><![CDATA[workplace recordings]]></category>
		<guid isPermaLink="false">https://insiderbits.co.ke/?p=4557</guid>

					<description><![CDATA[<p>What many companies treat as a routine workplace practice, pressing the record button during virtual meetings,has just proven to be a costly mistake in Kenya’s fast-tightening data protection landscape. A recent ruling by the Office of the Data Protection Commissioner (ODPC) has shown that even an internal human resource consultation call can spiral into legal [&#8230;]</p>
<p>The post <a href="https://insiderbits.co.ke/news/how-recording-a-simple-hr-call-could-land-you-in-ksh700000-trouble/">How Recording a “Simple” HR Call Could Land You in KSh700,000 Trouble</a> appeared first on <a href="https://insiderbits.co.ke">Insider Bits News</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>What many companies treat as a routine workplace practice, pressing the record button during virtual meetings,has just proven to be a costly mistake in Kenya’s fast-tightening data protection landscape.</p>
<p>A recent ruling by the Office of the Data Protection Commissioner (ODPC) has shown that even an internal human resource consultation call can spiral into legal liability if consent, transparency and clear purpose are ignored.</p>
<p>In the case of Andrew Alston against his employer Liquid Telecommunications Kenya Ltd, a single recorded call ultimately resulted in a KSh700,000 compensation order and an enforcement notice against the company.</p>
<p>The dispute arose from a virtual HR consultation call linked to an employee’s exit discussions.</p>
<p>According to the complainant, he expressly declined consent to the recording and was assured it would be deleted.</p>
<p>Instead, the audio was retained and later surfaced in separate arbitration proceedings involving a related company.</p>
<p>For regulators, that sequence of events triggered multiple red flags — not just about consent, but about how long data was kept, who accessed it, and why it was used beyond its original context.</p>
<p>One of the most striking findings from the ODPC was the classification of a voice recording as biometric personal data.</p>
<p>In simple terms, your voice is considered an identifying feature, just like a fingerprint or facial image.</p>
<p>That means recording a conversation is not a harmless administrative act; it is the collection of protected personal data.</p>
<p>The determination highlights three common pitfalls that can quickly turn an ordinary recording into a compliance nightmare:</p>
<p>1. Assuming a Beep Equals Consent<br />
Automated “this call may be recorded” notices are not enough. The regulator found that organisations must clearly explain why data is being recorded, who might receive it, and how it will be protected.</p>
<p>2. Stretching the Purpose Later<br />
Recording a meeting for “internal reference” and later using it for litigation or sharing it with affiliates breaches the principle of purpose limitation, a core rule that data should only be used for the reason it was first collected.</p>
<p>3. Ignoring Deletion Requests<br />
When a person asks for their data to be erased, the law requires prompt action or formal notification if deletion is refused for legal reasons. Silence or delay can amount to a violation on its own.</p>
<p>The company argued that keeping the recording served a “legitimate interest” in case of future disputes.</p>
<p>The ODPC disagreed, finding that less intrusive alternatives, such as written minutes, could have achieved the same goal without retaining sensitive biometric data.</p>
<p>The lesson is stark: “just in case” is not a lawful basis on its own.<br />
Without necessity and proportionality, that precaution can morph into unlawful processing.</p>
<p>Beyond the financial penalty, the enforcement notice signals that regulators are increasingly willing to scrutinize everyday corporate practices, especially in multinational structures where data may move across borders between affiliated companies.</p>
<p>For employers, HR teams, and managers, the message is clear: recording workplace conversations is no longer a casual administrative decision.</p>
<p>It is a regulated activity with legal consequences if mishandled.</p>
<p>In an era of virtual meetings and remote work, the record button can feel harmless.</p>
<p>But as this ruling demonstrates, a few seconds of audio can carry months of legal exposure.and a six-figure price tag.</p>
<p>The post <a href="https://insiderbits.co.ke/news/how-recording-a-simple-hr-call-could-land-you-in-ksh700000-trouble/">How Recording a “Simple” HR Call Could Land You in KSh700,000 Trouble</a> appeared first on <a href="https://insiderbits.co.ke">Insider Bits News</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Court Declares KBC Workers’ Biometric Clock-In Illegal, Orders Data deletion</title>
		<link>https://insiderbits.co.ke/court/court-declares-kbc-workers-biometric-clock-in-illegal-orders-data-deletion/</link>
		
		<dc:creator><![CDATA[IB Reporter]]></dc:creator>
		<pubDate>Thu, 04 Dec 2025 09:10:35 +0000</pubDate>
				<category><![CDATA[Court]]></category>
		<category><![CDATA[biometric clock-in Kenya]]></category>
		<category><![CDATA[court orders data deletion]]></category>
		<category><![CDATA[data protection ruling]]></category>
		<category><![CDATA[KBC]]></category>
		<category><![CDATA[KBC biometric data]]></category>
		<category><![CDATA[KBC facial recognition]]></category>
		<category><![CDATA[KBC privacy case]]></category>
		<category><![CDATA[Kenya Data Protection Act]]></category>
		<guid isPermaLink="false">https://insiderbits.co.ke/?p=4114</guid>

					<description><![CDATA[<p>The Employment and Labour Relations Court has barred the Kenya Broadcasting Corporation (KBC) from continuing the use of facial recognition technology on its employees after finding that the system violated constitutional privacy protections and the Data Protection Act, 2019. Justice Maureen Odero ordered the state broadcaster to immediately erase all facial images and biometric data [&#8230;]</p>
<p>The post <a href="https://insiderbits.co.ke/court/court-declares-kbc-workers-biometric-clock-in-illegal-orders-data-deletion/">Court Declares KBC Workers’ Biometric Clock-In Illegal, Orders Data deletion</a> appeared first on <a href="https://insiderbits.co.ke">Insider Bits News</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>The Employment and Labour Relations Court has barred the Kenya Broadcasting Corporation (KBC) from continuing the use of facial recognition technology on its employees after finding that the system violated constitutional privacy protections and the Data Protection Act, 2019.</p>
<p>Justice Maureen Odero ordered the state broadcaster to immediately erase all facial images and biometric data it had collected from staff through its digital time and attendance monitoring system.</p>
<p>In the judgment, the court held that facial recognition data qualifies as sensitive personal data under Kenyan law and therefore requires strict legal safeguards before it can be collected or processed.</p>
<p>Justice Odero found that KBC introduced the invasive technology without first carrying out a mandatory Data Protection Impact Assessment, a failure she ruled rendered the entire process unlawful and unconstitutional.</p>
<p>The court further established that KBC failed to obtain clear, informed and voluntary consent from its workers before subjecting them to biometric registration. Instead, employees were compelled to surrender their facial data as a requirement for clocking in and out of work, effectively stripping them of their freedom of choice in the matter.</p>
<p>Evidence placed before the court showed that the biometric system was rolled out between September 15 and 20, 2017, and involved a third-party technology vendor that collected facial images for purposes of staff attendance tracking and movement monitoring within KBC premises.</p>
<p>However, the broadcaster did not adequately disclose how the data would be stored, how long it would be retained, or who would have access to it, creating serious risks of misuse, exposure and abuse.</p>
<p>Justice Odero held that the lack of transparency surrounding the data handling process amounted to a direct violation of employees’ right to privacy as guaranteed under Article 31 of the Constitution.</p>
<p>She ruled that KBC’s actions failed the legal tests of necessity, proportionality and legality required where sensitive biometric surveillance is involved.</p>
<p>The court directed KBC to permanently destroy all facial recognition and biometric data collected through the impugned system.</p>
<p>&#8220;I do order KBC to develop and implement a comprehensive data privacy policy within 60 days to guide any future adoption of technology involving personal information,&#8221; the judged directed.</p>
<p>In addition, the court instructed that the judgment be served upon the Office of the Data Protection Commissioner to facilitate regulatory oversight.</p>
<p>KBC was further ordered to file a formal compliance report with the Data Protection Commissioner within 30 days confirming that all the biometric data has been fully and irreversibly deleted.</p>
<p>The matter is scheduled for a status review on January 21, 2026, when the court will assess whether the broadcaster has fully complied with its directives.</p>
<p>The post <a href="https://insiderbits.co.ke/court/court-declares-kbc-workers-biometric-clock-in-illegal-orders-data-deletion/">Court Declares KBC Workers’ Biometric Clock-In Illegal, Orders Data deletion</a> appeared first on <a href="https://insiderbits.co.ke">Insider Bits News</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
