The ODPC’s Proposed Guidance Note on AI
The Office of the Data Protection Commissioner (ODPC) has issued a draft Guidance Note on Artificial Intelligence (AI), setting out the obligations of data controllers, data processors, AI developers, deployers, providers and foundation model providers under the Data Protection Act. The guidance covers the development, deployment, procurement and use of AI systems that process the personal data of individuals in Kenya. The guidance adopts a lifecycle-based approach, organising compliance obligations across the development, deployment, and post-deployment stages of AI systems.
The Guidance Note responds to the rapid adoption of AI technologies, which increasingly process not only data provided directly by individuals but also data inferred from it, such as behavioural profiles, risk scores, and predictive insights. Because these inferences relate to identifiable individuals, they are treated as personal data under the Act.
Key Privacy and Data Protection Concerns in AI
The ODPC further recognises that the growing use of AI presents unique data protection challenges that are not fully addressed by existing regulatory guidance. These include the large-scale collection and use of personal data for training, the opacity of algorithmic decision-making, the creation of automated inferences and predictions, the risk of bias and discriminatory outcomes, and the reduced role of human oversight in decision-making. The Guidance Note therefore seeks to provide a data protection framework tailored to the specific risks and characteristics of AI systems.
Application of Data Protection Principles to AI Systems
The draft Guidelines require all AI-related processing of personal data to comply with the core data protection principles under Section 25 of the Act. In practice, this means that AI systems must process data lawfully, fairly, and transparently; use personal data only for specified and compatible purposes; collect and process only the minimum data necessary; ensure the accuracy of data and AI-generated outputs; retain personal data only for as long as necessary; implement appropriate security measures throughout the AI lifecycle; and maintain accountability through governance, record-keeping, DPIAs, and ongoing monitoring to ensure continuous compliance with data protection obligations.
Proposed Data Protection Obligations
The draft Guidelines recognise that AI systems evolve through a lifecycle rather than being created at a single point in time. Accordingly, the Office of the Data Protection Commissioner (ODPC) requires AI developers, deployers, providers, and foundation model providers to maintain continuous compliance with the Data Protection Act throughout the lifecycle of an AI system.
During the pre-deployment stage, entities must embed privacy-by-design principles in AI system design and procurement, ensure that any training data is collected and used lawfully, and avoid relying on publicly available personal data as a lawful basis for AI training without further assessment. Where third-party developers are engaged, appropriate data processing agreements must be in place before personal data is shared. Entities must also ensure that testing and validation activities have a lawful basis, comply with data minimisation and security requirements, and, where possible, rely on synthetic or anonymised data for testing purposes.
At the deployment stage, entities must ensure that all compliance measures and governance controls are operational before the AI system goes live. AI systems should be integrated into the organisation’s broader data protection framework, including updating privacy notices to inform data subjects about the use of AI, the categories of personal data processed, and any automated decision-making or profiling. Entities must also ensure that their registration with the ODPC accurately reflects any new AI-related processing activities and that all applicable transparency and accountability requirements are met before deployment.
During the post-deployment stage, entities are required to maintain ongoing oversight of AI systems through continuous monitoring, governance, and risk management. Recognising that AI systems may evolve through retraining, fine-tuning, or exposure to new data, the Guidelines require organisations to establish governance structures, such as AI governance committees, with the involvement of the Data Protection Officer, where applicable. When an AI system is retired or replaced, entities must ensure the secure disposal or management of all personal data associated with the system. Any successor AI system must be treated as a new deployment and subjected to the full lifecycle compliance process, including a fresh Data Protection Impact Assessment to evaluate any changes in data processing, system architecture, or deployment context.
Recommendations
Organisations developing or deploying generative AI in Kenya should review their AI deployments against regulatory expectations for use-case risk assessments, limitations on system autonomy and action space, technical safeguards, monitoring mechanisms, and meaningful human oversight. They should ensure that contracts and operational arrangements across the AI value chain clearly allocate responsibilities for third-party AI behaviour, data protection compliance, security, logging, disclosures, audit rights, and the management of unforeseen actions. Additionally, entities should strengthen their Data Protection Act compliance frameworks by implementing AI-specific measures, including transparency and notification requirements, clearly defining the responsibilities of AI providers and deployers, and establishing appropriate safeguards for prompts, outputs, and data generated through third-party AI activities.
Conclusion
The Guidance Note is a timely intervention as entities that develop, provide, procure, deploy, or otherwise use generative AI systems that process personal data face increasing regulatory and compliance obligations. It clarifies that compliance with the Data Protection Act must be embedded throughout the AI lifecycle, from design and development to deployment and decommissioning. By emphasizing transparency, lawful processing, data minimization, accountability, and ongoing oversight, the ODPC seeks to promote responsible AI innovation while safeguarding the rights and freedoms of data subjects in Kenya.
