Your organisation is about to deploy an AI recruitment system. Procurement has approved the vendor. IT has completed integration. HR is ready to go live. Then the Data Protection Officer asks one question: “Has anyone assessed the privacy risks?”
The problem isn’t that someone forgot to complete a form. The problem is that privacy risk was considered after the technology decision had already been made. This scenario plays out in boardrooms with increasing frequency. As organisations race to adopt AI, cloud platforms, biometric systems and advanced analytics, the question of when to conduct a Data Protection Impact Assessment (DPIA) is often asked far too late — or not at all.
Why the DPIA Question Matters More Than Ever in 2026
Three developments make this conversation urgent for Kenyan organisations.
First, Kenya’s regulatory environment is maturing. The Office of the Data Protection Commissioner (ODPC) has issued guidance notes on DPIAs and on biometric data, and has published draft guidance addressing emerging technologies and artificial intelligence. Enforcement now has real consequences — the Data Protection Act provides for administrative fines, and whether or not a DPIA was carried out is a factor the ODPC weighs when a breach or complaint arises.
Second, the technology landscape has shifted. Generative AI, automated decision-making and biometric systems are no longer futuristic concepts. They are operational realities across Kenyan financial services, healthcare, retail and government.
Third, the courts have spoken. In the Worldcoin litigation, the High Court found that biometric personal data had been processed without a prior DPIA, in contravention of the Act, and prohibited any further processing of that data collected in Kenya until a DPIA is undertaken. The lesson is unambiguous: failure to conduct a DPIA can bring a project to a complete halt. The question is no longer whether organisations should take DPIAs seriously — it is whether they know when one is required.
What a DPIA Actually Is (and Isn’t)
The ODPC is explicit on this point: a DPIA is not a compliance form to be filed and forgotten. Its Guidance Note describes a DPIA as a process designed to describe the processing, assess its necessity and proportionality, and identify and manage the risks that the processing poses to the rights and freedoms of data subjects. In short, a DPIA helps you answer four questions:
Done properly, a DPIA is an early-warning system. It shapes project design, procurement, contracts, security controls and governance — moving the organisation from reactive compliance to proactive risk management, and giving practical effect to the “data protection by design and by default” duty in Sections 41 and 42 of the Act.
When the Law Requires a DPIA
Section 31 of the Data Protection Act, 2019 requires a data controller or data processor to carry out a DPIA, prior to processing, wherever a processing operation is “likely to result in a high risk to the rights and freedoms of a data subject” by virtue of its nature, scope, context or purpose. At a minimum, the assessment must contain a systematic description of the intended processing and its purpose, an assessment of the necessity and proportionality of the processing, and an assessment of the risks to data subjects — together with the measures put in place to address those risks.
Regulation 49 of the Data Protection (General) Regulations, 2021 lists specific high-risk operations that call for a DPIA, including automated decision-making with legal or similar significant effect, large-scale use of personal data, processing of biometric or genetic data, changes to processing that raise the risk to data subjects, and processing of sensitive personal data or children’s data. The ODPC’s DPIA Guidance Note builds on this with a set of criteria that controllers and processors should weigh — among them systematic monitoring, matching or combining datasets, processing involving vulnerable data subjects, innovative use of new technologies, and processing that itself prevents people from exercising a right.
Two points from the Guidance Note are easy to miss but important:
The 10 Situations Organizations Often Miss
Understanding when a DPIA is triggered means looking beyond the obvious. Many organisations assume they would recognise a high-risk project on sight, but the reality is more nuanced. The most dangerous risks often emerge from projects that seem routine, or from changes that feel incremental. Here are ten situations that frequently catch organisations off guard.
1. Introducing AI or Automated Decision-Making
When an organisation deploys AI for recruitment screening, credit scoring, fraud detection, customer profiling or predictive analytics, it places significant power in the hands of an algorithm. A rejected loan application, a failed job screening or an incorrect fraud flag can alter a person’s life. Both Regulation 49 and the ODPC’s DPIA Guidance Note treat automated decision-making that produces legal or similarly significant effects — including profiling — as a clear DPIA trigger, and Section 35 of the Act gives data subjects specific protections against such decisions. The question to ask is whether you truly understand what your algorithms are doing, and what happens when they get it wrong.
2. Introducing Biometric or Genetic Processing
Fingerprint scanners, facial recognition, iris scanning and voice recognition are increasingly used for everything from employee access control to customer authentication. Biometric data is classified as sensitive personal data under the Act, and for good reason: unlike a password, you cannot change your fingerprint or your face. Once compromised, a biometric identifier is compromised for life. Regulation 49 lists the processing of biometric or genetic data as a high-risk operation, and the ODPC’s Guidance Note on Biometric Data stresses the significant impact such processing has on the rights and freedoms of data subjects. This is not a risk that standard security controls alone can manage.
3. Starting Large-Scale Processing
When a bank processes millions of transactions, a hospital manages patient records at scale, or a telecommunications company handles subscriber data for an entire nation, volume alone elevates the risk. The Guidance Note asks organisations to weigh four factors: the number of data subjects concerned, the volume and range of data being processed, the duration or permanence of the activity, and its geographical extent. A breach affecting millions is a different order of harm from one affecting a handful of people, and organisations operating at this scale cannot treat privacy as an afterthought.
4. Combining or Matching Datasets Collected Separately
Merging customer data with transaction history, location data, behavioural information and marketing profiles creates a new and far more detailed picture of an individual — one that may enable profiling, inference or re-identification that was impossible when each dataset stood alone. The privacy risk is not simply additive; it is multiplicative. The Guidance Note flags matching or combining datasets — particularly where data collected for one purpose is combined in ways that exceed a data subject’s reasonable expectations — as a situation calling for a DPIA.
5. Changing an Existing System or Processing Activity
A completed DPIA does not provide permanent cover. Adding a new data source, introducing AI, switching vendors, expanding the purpose, collecting more data, adjusting retention periods, or expanding into a new country can all change the risk profile. Organisations often make these changes incrementally, without pausing to ask whether the original DPIA still reflects reality. Regulation 49 expressly treats any change in processing that may result in higher risk to data subjects as a trigger, and the Guidance Note is clear that a DPIA is a living document — it must be revisited whenever the processing, or the environment around it, changes.
6. Introducing New or Innovative Technology
IoT devices, drones, blockchain, immersive technologies and advanced analytics all bring uncertainty. When you cannot fully predict how a technology will behave or what data it will collect, privacy risk rises. The Guidance Note identifies innovative use or the application of new technological or organisational solutions as a situation requiring DPIA consideration, noting that the personal and social consequences of a new technology may simply be unknown at the outset. Resist deploying new technology just because it is available — first understand what it will do with personal data.
7. Processing Sensitive, Children’s or Vulnerable People’s Data
Data revealing race, health status, ethnic or social origin, genetic or biometric information, property details, family details or sexual orientation carries inherent high risk — its disclosure can lead to discrimination, stigma or serious harm. The same applies to data about children and other vulnerable groups, who may be unable to protect their own interests or to meaningfully consent. Regulation 49 lists sensitive personal data and children’s data, and the Guidance Note separately flags vulnerable data subjects — including children, employees, persons with disabilities, refugees, the elderly and patients — wherever a power imbalance exists between the individual and the organisation.
8. Systematically Monitoring People
CCTV, workplace monitoring, location tracking, online behaviour analysis and employee-productivity software are all areas where organisations routinely underestimate privacy risk. Continuous monitoring is intrusive by nature: it can create a chilling effect, erode trust, and collect far more information than individuals expect. The Guidance Note singles out systematic monitoring — especially in public or publicly accessible spaces, where people may be unaware of who is collecting their data or unable to avoid it — as a DPIA criterion.
9. Introducing a Third-Party Processor, Cloud Platform or Data-Sharing Arrangement
When data leaves your direct control, you must be able to say who processes it, what is shared, where it is stored, who can access it, whether sub-processors are involved, and what security measures apply. Third-party and cloud arrangements are not, on their own, a standalone statutory trigger — but they rarely travel alone. They frequently combine with large-scale processing or cross-border transfers, and the DPIA is precisely where these questions get answered: the ODPC template requires you to describe the parties involved in the processing and their roles, how you safeguard the processing of personal data, and how you safeguard any international transfers. If you cannot answer these questions, you cannot honestly say you understand the processing risk.
10. When Processing Could Interfere with People’s Rights or Cause Significant Harm
Finally, and most fundamentally, consider whether the processing could interfere with people’s rights or cause significant harm. The Guidance Note lists processing that in itself prevents data subjects from exercising a right — for example, operations that allow, modify or refuse a person’s access to a service or entry into a contract — as a criterion in its own right. More broadly, processing that could affect access to services, influence employment decisions, limit financial opportunity, create discrimination, cause reputational harm or expose sensitive information deserves scrutiny. DPIAs exist to protect people from exactly these harms. The central question is not merely whether the law requires a DPIA, but whether the processing could create significant risk to the people affected — and that question belongs at the heart of every processing decision.
Timing: Why Earlier Is Always Better
Under the Act, a DPIA must be submitted to the ODPC 60 days before processing begins. But treat that as a floor, not a target. Where a DPIA reveals a high residual risk that you cannot reduce, you must consult the ODPC before going ahead. Early DPIA involvement supports privacy by design, better procurement, better architecture, lower remediation costs, clearer accountability and stronger governance. A privacy risk caught on a whiteboard is cheap to fix; the same risk caught after go-live rarely is.
How South-End Tech Can Help
We do not simply help organisations complete DPIA templates. We help them understand the processing, identify the risks, design appropriate safeguards, and make better decisions about data. Our approach is practical. We work with Kenyan and East African organisations across financial services, healthcare, technology, government and professional services, and we understand the local regulatory context, the technology landscape and the business realities you operate in.
The most important question about a DPIA is not whether you have a template. It is whether your organisation understands the privacy risks before processing begins. A DPIA is an opportunity to discover privacy, operational, security, technology and business risks before they become expensive problems.
Ready to assess your organisation’s data protection compliance? Let’s talk.
+254 728 223 333
?? cybersecurity@southendtech.co.ke | info@southendtech.co.ke | dataprotection@southendtech.co.ke
South-End Tech Limited — Helping East African businesses build secure, AI-ready foundations.