Fingerprints, facial images and voice recordings identify a person as nothing else can , and Kenyan law treats them accordingly. Biometric data falls within the sensitive category under the Data Protection Act 2019, and organisations that collect it, from schools running attendance systems to fintechs verifying customers, must meet a higher standard than for ordinary records.

What counts as biometric data in Kenya?
The Act’s definition of sensitive personal data expressly includes biometric data, meaning data relating to the unique physical characteristics used to identify a person: fingerprints, facial images, iris patterns, voice patterns and similar identifiers. The label matters: sensitive data attracts stricter conditions , a lawful basis that is harder to establish, heightened security expectations, and closer regulatory scrutiny when things go wrong.
What must an organisation do before collecting biometrics?
- Register with the Office of the Data Protection Commissioner as a controller or processor, if not already registered
- Establish a lawful basis , where consent is relied upon, it must generally be explicit for sensitive data
- Conduct a data protection impact assessment before deployment , biometric identification is the paradigm of high-risk processing
- Put security safeguards proportionate to the harm a breach would cause , biometrics cannot be reissued like a password
- Inform data subjects in clear terms what is collected, why, for how long, and who has access
Where has enforcement focused so far?
The Office of the Data Protection Commissioner has issued determinations in which biometric collection featured prominently , systems rolled out without impact assessments, consent obtained as a blanket term, or data retained long after the purpose ended. The question asked is rarely whether the technology works, but whether the process around it was lawful and proportionate.
What practical steps should organisations take now?
Audit any system that captures biometric identifiers , time and attendance, access control, customer onboarding , and test it against the list above. Where consent is the basis, check that it is genuinely explicit and freely given , consent under pressure is not consent. Vendor contracts should address security, retention and deletion. Our governance and advisory practice assists organisations with compliance programmes, and our practice areas page describes the wider work. The Act itself is accessible on Kenya Law.
For guidance on your specific situation, contact CS Advocates LLP , call, WhatsApp, or book a confidential consultation at our Westlands, Nairobi office.