ODPC warns security firms over excessive data collection

The Office of the Data Protection Commissioner (ODPC) has warned private security firms in Kenya against unlawfully harvesting excessive personal data from visitors. In a draft guidance note, the ODPC states that only names, identification numbers, and entry times should be collected for building access. This alert comes amid rising cyber threats and major data breaches in the country.

The Office of the Data Protection Commissioner (ODPC) has expressed deep concern over routine data collection practices at security desks, describing them as posing significant privacy risks. In a draft Guidance Note released on December 19, 2025, the ODPC highlights that private security firms must stop requiring visitors to provide phone numbers, home addresses, marital status, and other personal details, as these violate the Data Protection Act of 2019.

According to the regulator, the only permissible information for basic access is a visitor's name, identification number, and time of entry. Firms are urged to limit collection to what is strictly necessary and delete any data without a lawful basis.

This warning arises against a backdrop of escalating data breaches in Kenya. In October 2025, a popular health app was breached, exposing medical records of 4.8 million users. A February 2025 incident at the Business Registration Service leaked details of over two million firms. Government websites faced defacement in coordinated cyber attacks in November 2025.

The Communications Authority reported detecting more than 4.5 billion cyber threat events between April and June 2025. The ODPC emphasizes strengthened individual rights, including the ability to request access to CCTV footage or visitor logs featuring oneself. This provision applies to all firms under the Private Security Regulation Act of 2016.

Concerns also extend to data misuse, such as using visitor details for unsolicited marketing or public sharing, which breaches purpose limitation principles. The draft is open for public input before finalization, indicating a push for stricter oversight of everyday data practices.

As Kenya contends with data sovereignty, cross-border transfers, and intensifying cyber threats, the ODPC views curbing unnecessary collection at security points as a vital first defense.

関連記事

Police in cybercrime unit tracking IP of Chinese suspect in massive Coupang data breach exposing 33.7 million customers' info.
AIによって生成された画像

Police tracking Coupang data breach suspect via IP

AIによるレポート AIによって生成された画像

A massive data breach at South Korea's leading e-commerce firm Coupang has exposed personal information of 33.7 million customers. Police are tracking a Chinese former employee suspect using an IP address, while the government considers fines up to 1 trillion won. The breach, starting in June, went undetected for five months.

The Kenya Revenue Authority (KRA) has reaffirmed that data collected will be protected by existing laws, while dispelling fears over data privacy following the bodycam rollout to customs officers nationwide on Tuesday. The response on Wednesday, March 11, came after several netizens, especially on X, raised concerns fearing that the footage captured by the bodycams would not be used for the intended purpose. KRA stressed that the recordings will be processed in accordance with the law governing data handling in Kenya.

AIによるレポート

Hong Kong's privacy watchdog plans to consult lawmakers this year on introducing mandatory data breach reporting and related penalties, after the legislative reform was put on hold in 2024 due to concerns over the local business environment. Privacy Commissioner for Personal Data Ada Chung Lai-ling revealed details of the proposed amendments to the city's privacy ordinance on Saturday, suggesting the measures could be implemented in phases.

South Africa's Information Regulator has ruled against the Johannesburg Stock Exchange's refusal to release trading records, deeming it a public body under the Promotion of Access to Information Act. The decision stems from a 2023 complaint by Inhlanhla Ventures seeking details of potentially manipulative trades in enX Group shares from May 2020. The regulator mandates notification to involved parties before disclosure.

AIによるレポート

The Kenyan government has implemented a new digital system to oversee healthcare delivery in real time, as explained by Public Health Principal Secretary Mary Muthoni. This system, enabled by the 2023 Digital Health Act, tracks activities across all 47 counties to ensure accountability and prevent fraud.

Hong Kong's privacy watchdog is investigating risks to early users of HSBC's popular PayMe mobile app after the South China Morning Post found some remain unaware their personal details may have been exposed. The compliance review will examine vulnerabilities of legacy users and the need for in-app prompts. The watchdog stressed that the bank must ensure the highest level of privacy protection by default.

AIによるレポート

メイン州の米国地方裁判所に提出された集団訴訟は、国土安全保障長官クリスティ・ノーム氏とトランプ政権が、顔認識ソフトウェアや他の監視ツールを使用して憲法修正第1条の権利を侵害したと非難している。訴状は、連邦捜査官が移民法執行作戦中に公の場で活動を記録する市民を標的にしたと主張。原告らはこれらの慣行を停止するための差し止め命令と関連記録の抹消を求めている。

 

 

 

このウェブサイトはCookieを使用します

サイトを改善するための分析にCookieを使用します。詳細については、プライバシーポリシーをお読みください。
拒否