ODPC warns security firms over excessive data collection

The Office of the Data Protection Commissioner (ODPC) has warned private security firms in Kenya against unlawfully harvesting excessive personal data from visitors. In a draft guidance note, the ODPC states that only names, identification numbers, and entry times should be collected for building access. This alert comes amid rising cyber threats and major data breaches in the country.

The Office of the Data Protection Commissioner (ODPC) has expressed deep concern over routine data collection practices at security desks, describing them as posing significant privacy risks. In a draft Guidance Note released on December 19, 2025, the ODPC highlights that private security firms must stop requiring visitors to provide phone numbers, home addresses, marital status, and other personal details, as these violate the Data Protection Act of 2019.

According to the regulator, the only permissible information for basic access is a visitor's name, identification number, and time of entry. Firms are urged to limit collection to what is strictly necessary and delete any data without a lawful basis.

This warning arises against a backdrop of escalating data breaches in Kenya. In October 2025, a popular health app was breached, exposing medical records of 4.8 million users. A February 2025 incident at the Business Registration Service leaked details of over two million firms. Government websites faced defacement in coordinated cyber attacks in November 2025.

The Communications Authority reported detecting more than 4.5 billion cyber threat events between April and June 2025. The ODPC emphasizes strengthened individual rights, including the ability to request access to CCTV footage or visitor logs featuring oneself. This provision applies to all firms under the Private Security Regulation Act of 2016.

Concerns also extend to data misuse, such as using visitor details for unsolicited marketing or public sharing, which breaches purpose limitation principles. The draft is open for public input before finalization, indicating a push for stricter oversight of everyday data practices.

As Kenya contends with data sovereignty, cross-border transfers, and intensifying cyber threats, the ODPC views curbing unnecessary collection at security points as a vital first defense.

関連記事

Police in cybercrime unit tracking IP of Chinese suspect in massive Coupang data breach exposing 33.7 million customers' info.
AIによって生成された画像

Police tracking Coupang data breach suspect via IP

AIによるレポート AIによって生成された画像

A massive data breach at South Korea's leading e-commerce firm Coupang has exposed personal information of 33.7 million customers. Police are tracking a Chinese former employee suspect using an IP address, while the government considers fines up to 1 trillion won. The breach, starting in June, went undetected for five months.

The notification of the Digital Personal Data Protection Rules 2025 has activated provisions of the DPDP Act 2023, significantly impacting the healthcare sector. The law designates medical institutions as data fiduciaries and grants patients rights over their data. Yet, ambiguities in the details pose challenges for healthcare providers.

AIによるレポート

Electronic Privacy Information Center (EPIC)の新しい報告書は、監視と移民執行によって引き起こされる米国での健康プライバシー危機の増大を強調している。データブローカー、ad-tech追跡、Immigration and Customs Enforcement (ICE)の行動などの要因が患者の信頼を損ない、人々が医療を求めるのを阻害している。これにより治療の遅れと健康結果の悪化が生じている。

米国移民税関執行局(ICE)は、企業に対し、商用ビッグデータおよび広告技術ツールに関する情報を共有するよう要請を発行した。これらの製品は、最近の連邦提出書類に記載されているように、捜査活動を支援する可能性がある。この動きは、政府の民間セクターの監視能力への関心の高まりを強調している。

AIによるレポート

プライバシーが絶え間ない脅威にさらされる時代に、普通の人々がシナリオを逆転させ、法執行機関を自分たちが見張られるのと同じ厳しさで監視しています。この変化は、当局が支配する伝統的な監視の概念に挑戦します。最近の記事がこの進化するダイナミクスを強調しています。

The Directorate of Criminal Investigations (DCI) has dismantled a cross-border mobile phone theft and black-market network in Nairobi, arresting seven suspects and recovering 150 phones. The intelligence-led operation took place on January 24, 2026, spanning multiple city locations. The network linked Kenyan receivers with buyers in Uganda.

AIによるレポート

The National Transport and Safety Authority (NTSA), alongside the National Police Service (NPS), has begun piloting unique identification numbers for boda boda riders nationwide, starting in Nairobi. The move seeks to regulate a sector criticized for flouting traffic laws. Boniface Otieno, NPS traffic liaison in Nairobi, explained that the program will assign riders numbers distinct from their vehicle plates.

 

 

 

このウェブサイトはCookieを使用します

サイトを改善するための分析にCookieを使用します。詳細については、プライバシーポリシーをお読みください。
拒否