Employee Data Privacy in Kenya: Rights & Employer Rules
Fingerprint clock in systems at the office door. CCTV cameras covering the sales floor. A recruitment agency running background checks before an offer letter goes out. A WhatsApp group for the operations team that management can read. Every one of these is personal data processing under Kenya's Data Protection Act, 2019, and every one of them creates legal obligations for the employer, whether the HR team has thought of it that way or not.
Employee data privacy is one of the most overlooked areas of compliance in Kenya, partly because employers assume that having authority over staff extends to having unrestricted authority over their data. It does not. This guide covers what employers can legally collect from employees, how long that data can be kept, what monitoring is and is not permitted, and what rights employees hold over their own information throughout and after employment.
Employee Data Is Personal Data, Full Stop
Under the Act, an employee is a data subject in exactly the same sense as a customer or a member of the public. Names, ID numbers, phone numbers, bank details, next of kin information, performance reviews, disciplinary records, and email correspondence all qualify as personal data. Health records, biometric data such as fingerprints, ethnic or religious information sometimes collected during onboarding, and details about family members qualify as sensitive personal data, which the Act protects more strictly and generally requires explicit consent or another specific legal basis to process.
This applies regardless of company size. A three person startup collecting fingerprint data for office access, or medical information for a health cover application, is subject to the same sensitive data obligations as a large corporate, and may need to register with the ODPC purely because of that sensitive data processing even if it falls below the general revenue and employee count thresholds.
What Data Employers Can Actually Collect
Employers are not free to collect whatever data seems useful. The Act's data minimization principle requires that only data genuinely necessary for a specific, disclosed purpose be collected. In practice, this covers a fairly predictable set of categories through the employment lifecycle: identity and contact details for onboarding and payroll, banking information for salary payments, academic and professional qualifications relevant to the role, tax and statutory deduction details, performance and disciplinary records tied to management of the employment relationship, and, where relevant to the role, background check results from a properly engaged screening provider.
Sensitive categories, health information, biometric data, criminal history, or details about an employee's family, require a clear justification tied to a specific need, not a general assumption that HR should have it on file. A common example from the ODPC's own guidance involves a company collecting fingerprint data for office access control. That data can lawfully be used for that stated purpose, but reusing the same biometric database to monitor employee timekeeping without separately disclosing and justifying that additional purpose would breach the Act's purpose limitation principle, even though the data itself was lawfully collected.
Recruitment data deserves particular care. Candidate information gathered during hiring, including from third party screening firms, should not be retained indefinitely once a hiring decision has been made, and any external recruitment or background check provider should be engaged as a registered data processor under a proper written agreement rather than an informal arrangement.
Lawful Basis for Processing Employee Data
Employers frequently assume consent is the only basis for processing employee data, then worry about whether consent given by someone in an employment relationship, where there is an inherent power imbalance, can really be considered freely given. In practice, consent is only one of several lawful bases available under Section 30 of the Act. Much routine employee data processing, payroll, statutory reporting, contract administration, is more appropriately justified as necessary for the performance of the employment contract, or necessary to comply with a legal obligation such as tax or social security law, rather than relying on consent at all.
Consent remains the appropriate basis for certain sensitive or discretionary processing, such as enrolling in an optional wellness program or agreeing to have a professional photo used in external marketing. Where consent is used, it must be specific, informed, freely given, and capable of being withdrawn, which means an employer cannot bundle consent to biometric data collection into a blanket employment contract clause an employee has no real ability to negotiate or decline.
Monitoring Employees: What Is Permitted
Employee monitoring, email review, device tracking, CCTV, attendance systems, is one of the most common sources of complaints and enforcement action under the Act, precisely because employers often treat it as an unrestricted management prerogative rather than a form of data processing subject to the same legal tests as anything else.
For monitoring to be lawful, it generally needs to be disclosed clearly in HR policy before it begins, proportionate to the stated purpose rather than sweeping in scope, and genuinely justified by a legitimate interest such as security, fraud prevention, or system integrity. Continuous surveillance that goes beyond what the stated purpose requires, monitoring private communications unrelated to work, or covert monitoring without any disclosure, are all likely to fall outside what the Act permits. For employees working remotely, the same standards apply, and the fact that monitoring software is installed on a home device does not reduce an employee's underlying privacy rights, even under bring your own device arrangements.
CCTV coverage of common work areas is generally more defensible than coverage of spaces like restrooms or break areas, and footage should be retained only as long as necessary for the stated security purpose rather than indefinitely.
How Long Employers Can Retain Employee Data
The Act's storage limitation principle requires that personal data not be kept longer than necessary for the purpose it was collected for, but Kenyan employers also operate under separate statutory retention requirements from tax, employment, and social security law that specify minimum retention periods for certain records. This creates a genuine tension that many HR teams have not resolved with a documented policy: data protection law pushes toward deletion once data is no longer needed, while other statutes require certain records be kept for a set number of years regardless.
The practical solution is a documented retention schedule that sets specific, justified timeframes for each category of employee data, statutory records kept for the legally required minimum period, general HR files retained for a defined period after employment ends, and biometric data deleted promptly once its specific purpose, such as office access, no longer applies, for example immediately upon an employee's departure. Retention without a documented schedule and rationale is itself a compliance gap, since the Act expects organizations to be able to demonstrate why data is still being held, not simply that it has not yet been deleted.
Employee Rights Under the Act
Employees hold the same core rights as any other data subject, and employers are obligated to provide practical ways for staff to exercise them, not just acknowledge them in policy documents. These include the right to access, allowing an employee to request to see what personal data the employer holds about them, how it is used, and who it has been shared with, the right to rectification, allowing correction of inaccurate or outdated information, such as updated biometric data following a change in physical appearance, the right to object to certain processing, including some forms of monitoring where the employee believes it is disproportionate, and the right to lodge a complaint with the ODPC if they believe their data has been mishandled.
These rights do not disappear when someone leaves a job. Obligations relating to an employee's personal data continue after employment ends, including securely archiving remaining records with restricted access, promptly revoking system and building access tied to personal data, and applying the same retention and deletion discipline to former employee data as to current staff.
Common Compliance Gaps Kenyan Employers Should Fix
The most frequent issues seen in employee data practices are informal or nonexistent HR privacy policies, biometric systems installed for one purpose and quietly repurposed for another without fresh disclosure, recruitment and background check data retained indefinitely with no deletion schedule, monitoring tools deployed without proportionality assessment or employee disclosure, and third party HR, payroll, or recruitment vendors engaged without a proper data processing agreement in place.
Each of these is straightforward to correct with a documented policy and a bit of process discipline, but each is also a real source of ODPC complaints and enforcement action when employees feel their data has been mishandled, particularly around monitoring and image use.
Building a Compliant HR Data Framework
Getting employee data privacy right requires more than a generic privacy notice pasted into an employee handbook. It requires mapping exactly what data is collected at each stage of the employment lifecycle, documenting the lawful basis for each category, setting a retention schedule that reconciles data protection law with other statutory requirements, and building a monitoring policy that survives scrutiny for proportionality.
Firms such as Kathurima N Advocates help Kenyan employers build these frameworks properly, from reviewing recruitment and onboarding data practices to drafting monitoring and retention policies that meet the Act's requirements, while also advising individual employees on how to assert their rights, including access and rectification requests, where they believe their workplace data has been mishandled.
Final Thoughts
Employee data privacy in Kenya is not a lesser version of customer data privacy, it carries the same legal weight under the Data Protection Act, with the added complexity of sensitive data like biometrics and health information appearing routinely in ordinary HR processes. Employers who treat staff data with the same discipline they apply to customer data, clear purpose, proper lawful basis, documented retention, and genuine respect for access and correction rights, are far better positioned than those relying on the assumption that being an employer comes with unrestricted authority over an employee's personal information.

0 Comments
No comments yet — be the first to share your thoughts.
Leave a Comment
Your email address will not be published. Comments are reviewed before appearing.