Skip to content

Using AI on customer data under Kenya's Data Protection Act: an SME guide

What Kenya's Data Protection Act and the ODPC's July 2026 draft AI guidance mean for SMEs using AI on customer data, with a practical checklist.

Published
Last reviewed
Author
Deefrent team

Kenyan SMEs are putting AI to work on customer data: agents that answer on WhatsApp, tools that summarise calls, models that score leads or flag late payers. All of it is processing personal data, and the Data Protection Act, 2019 applies to it just as it does to a spreadsheet or a CRM.

In July 2026 the Office of the Data Protection Commissioner (ODPC) published a Guidance Note on Artificial Intelligence for public consultation, which ran from 1 to 17 August 2026. It sets out how the regulator reads the Act for AI systems. It is a draft and the final text may differ, but it shows clearly where the regulator is heading.

Here is what it means for a business with tens or hundreds of staff and no compliance department.

Enforcement is real

The ODPC is an active regulator. By January 2026 the Data Commissioner was reporting running totals, not monthly figures: 9,061 complaints received; 357 determinations, 134 enforcement notices and 20 penalty notices issued; and 184 compensation orders since the Act was enacted.

Under section 63 of the Act, a penalty notice can reach KES 5 million or, for an undertaking, 1% of the previous financial year’s annual turnover, whichever is lower. People who suffer damage can also claim compensation under section 65.

1. Check whether you must register

Section 18 of the Act requires data controllers and data processors to register with the Data Commissioner, subject to thresholds. Under the 2021 Registration Regulations, you are exempt if your annual turnover or revenue is below KES 5 million and you have fewer than ten employees.

Some purposes require registration whatever your size. They include operating an educational institution, health administration and patient care, financial services, hospitality, property management, transport services, and businesses wholly or mainly in direct marketing. A small clinic, school or SACCO should assume it must register.

Exempt or not, the Act’s principles and people’s rights still apply to you.

2. Know what the AI is for, and say so

The Act requires personal data to be collected for explicit, specified and legitimate purposes, and not processed further in ways incompatible with them. Before you switch on an AI tool, write one paragraph: what it does, which data it uses, and your lawful basis.

Be careful with reuse. Using last year’s WhatsApp chats to train or tune a model is a new purpose that needs its own justification. The draft guidance also states that personal data being publicly accessible does not, by itself, make it lawful training data.

Then tell people. Update your privacy notice to say that you use AI and what for. The draft guidance asks businesses to disclose generative AI where its output could reasonably be mistaken for a human’s. On WhatsApp, that means telling customers when they are talking to an agent and how to reach a person.

3. Send the model only what it needs

Data minimisation is a principle of the Act, and with AI it is also your cheapest risk control.

  • Strip ID numbers, full phone numbers and M-Pesa transaction codes from prompts unless the task needs them.
  • Never paste customer lists into consumer chat tools.
  • Prefer AI services that let you switch off training on your data, and set a retention period for chat logs and AI outputs.

Take extra care with sensitive personal data, which under the Act includes health status, biometric data and family details. The draft guidance expects explicit consent or another specific legal basis before AI touches it, and warns that AI inferences about health or ethnicity can themselves be sensitive data. Clinics, pharmacies and insurers should plan on a full impact assessment.

4. Keep a person on decisions that matter

Section 35 gives everyone the right not to be subject to a decision based solely on automated processing that produces legal effects or significantly affects them. There are exceptions for contracts, decisions authorised by law and consent. But where you do take such a decision, you must notify the person in writing, and they can ask you to reconsider it or take a new decision that is not solely automated.

In practice: let AI recommend, and let a person decide on credit limits, loan approvals, claim rejections, hiring and admissions. Record who made the decision.

5. Assess the risk before you start

Section 31 requires a data protection impact assessment (DPIA) where processing is likely to result in high risk to people’s rights and freedoms.

The draft guidance includes a trigger table. It marks credit scoring, recruitment screening, employee productivity monitoring, payment fraud detection and health diagnostics as needing a DPIA. A generative AI chatbot with no personal data input is marked for review rather than an automatic DPIA.

A customer-service agent that reads order history and payment status sits between those two. Write down your reasoning either way, and keep it with the project.

6. Get your AI vendors in writing

Many AI models run on servers outside Kenya. Section 48 allows personal data to leave Kenya only under set conditions, such as giving the Data Commissioner proof of appropriate safeguards, or where the transfer is necessary, for example to perform your contract with the customer. The draft guidance says you may not send personal data to an offshore AI processor without a lawful transfer basis.

For every AI vendor that processes your customers’ data, the draft guidance asks for a written agreement that:

  • limits processing to your instructions;
  • requires appropriate security measures;
  • bars sub-processors without your authorisation;
  • obliges the vendor to help with data subject requests and DPIAs; and
  • requires the data to be deleted or returned when the contract ends.

7. Plan for a breach

If personal data is accessed or acquired by an unauthorised person and there is a real risk of harm, section 43 requires you to notify the Data Commissioner within 72 hours of becoming aware, and to tell the affected people in writing. A processor, including an AI vendor, must tell you without delay and, where reasonably practicable, within 48 hours. Agree who calls whom before you need to.

Checklist

  • Registration checked against the thresholds and the mandatory-registration purposes.
  • Purpose, data used and lawful basis written down for each AI tool.
  • Privacy notice updated to mention AI; customers told when they are talking to an agent.
  • Prompts stripped of data the task does not need.
  • Sensitive data excluded, or handled with explicit consent and a DPIA.
  • A person makes any decision with legal or similarly significant effects.
  • DPIA done, or a written note explaining why one is not needed.
  • A processing agreement and a transfer basis in place for every AI vendor.
  • Retention periods set for chat logs and AI outputs.
  • A breach plan with the 72-hour clock and named owners.

This is general information, not legal advice. For a specific system, take advice from a data protection practitioner.

Building AI you can defend

None of this rules AI out. It means designing it properly: minimal data in prompts, clear disclosure, a human handover, and logs you own and can produce when the regulator asks.

That is how we build AI agents and automations for Kenyan businesses. See our AI automation practice.

Sources

Find out what your systems could run on their own

Start with a free 30-minute automation audit. We look at how your team works across WhatsApp, M-Pesa and other mobile money, your bank, Odoo and eTIMS, and you leave with a one-page map of what to automate first.