What new electoral privacy rules mean for you

Citizens must be told what is happening to their data. Transparency is central to these rules.

Photo credit: Shutterstock

The next General Election is only one year away. That is why we must have this conversation now. Every election cycle, millions of Kenyans hand over their personal information along with their vote, including their names, addresses, national ID card numbers, and fingerprints.

This data flows through the electoral agency IEBC, political parties, observers, and countless campaign volunteers. Until recently, most Kenyans had little idea where that information went, who used it, or how to stop it being misused.

That is changing. The Office of the Data Protection Commissioner (ODPC) has issued guidance notes for several sectors, including for electoral processes, bringing Kenya’s election machinery firmly under the Data Protection Act of 2019. The rules apply to every organisation touching voter data, from the IEBC to small civil society groups helping with voter registration.

Here is what these rules mean for you in plain terms. The starting point is that no organisation can collect or process your personal data just because it wants to. The law requires what it calls a “lawful basis”, a legitimate, identifiable reason.

For the IEBC, that basis is largely built into existing electoral law. Maintaining the voter register, for instance, is a statutory public duty, so the agency doesn’t need your individual consent to keep your name and address on that list once you have registered.

Political parties, however, operate differently. Because joining a party is voluntary (nobody is legally required to become a card-carrying member) parties must obtain genuine consent before collecting member data. That consent must be freely given, specific, and informed. A buried checkbox in fine print doesn’t qualify.

High-risk data requires extra caution. Biometric data (such as fingerprints) is classified as sensitive personal data under the Act, and the IEBC collects it routinely. Processing this category of data carries a higher inherent risk to people’s rights and freedoms, and therefore demands stronger protections. Organisations handling biometrics cannot simply apply standard procedures and move on.

Organisations should think before they collect data. One of the most practical requirements in the guidance is the Data Protection Impact Assessment, or DPIA.

Before any large-scale or high-risk processing of voter data begins, organisations are expected to formally assess what could go wrong.

That includes who might gain unauthorised access, what harm could result, and what safeguards are in place. For the IEBC and similar bodies, this is mandatory. For smaller governance organisations, it is strongly recommended even when not strictly required.

A DPIA should be seen as a safety checklist. It forces organisations to ask the uncomfortable questions before data collection starts, not after a breach has already occurred.

Privacy must be built into an organisation’s systems. The guidance introduces a concept called privacy by design and default.

This is the idea that data protection should be embedded into systems and processes from the very beginning, not treated as an afterthought. In practice, this means collecting only the minimum data necessary, storing it securely, restricting access to those who truly need it, and deleting it once its purpose is served.

For electoral organisations, this matters greatly. Campaign data is routinely shared with volunteers, contractors, and third-party service providers. Every one of those handoffs is a potential weakness. The guidance requires that confidentiality agreements, access controls, and staff training on privacy be standard practice, not optional extras.

Citizens must be told what is happening to their data. Transparency is central to these rules.

Organisations collecting voter or member data are legally required to notify individuals (at the point of collection) of what data is being taken, why, who else will receive it, and what rights the individual holds. This notification should be in plain language and provided free of charge.

This duty to notify has real teeth. A privacy notice buried in a 40-page document written in legal jargon does not meet the standard. The information must be truly accessible and understandable.

You have the right to say no. Voters and party members retain meaningful control over their personal information, even after it has been collected. You can request access to what an organisation holds about you. You can demand corrections if it is wrong. You can object to certain kinds of processing.

Kenya’s electoral system generates and processes massive data. The ODPC guidance exists to ensure that the machinery of democracy does not become an apparatus for surveillance or manipulation.

Immaculate  Kassait is Kenya’s Data Commissioner.

PAYE Tax Calculator

Note: The results are not exact but very close to the actual.