ODPC warns security firms over excessive data collection

The Office of the Data Protection Commissioner (ODPC) has warned private security firms in Kenya against unlawfully harvesting excessive personal data from visitors. In a draft guidance note, the ODPC states that only names, identification numbers, and entry times should be collected for building access. This alert comes amid rising cyber threats and major data breaches in the country.

The Office of the Data Protection Commissioner (ODPC) has expressed deep concern over routine data collection practices at security desks, describing them as posing significant privacy risks. In a draft Guidance Note released on December 19, 2025, the ODPC highlights that private security firms must stop requiring visitors to provide phone numbers, home addresses, marital status, and other personal details, as these violate the Data Protection Act of 2019.

According to the regulator, the only permissible information for basic access is a visitor's name, identification number, and time of entry. Firms are urged to limit collection to what is strictly necessary and delete any data without a lawful basis.

This warning arises against a backdrop of escalating data breaches in Kenya. In October 2025, a popular health app was breached, exposing medical records of 4.8 million users. A February 2025 incident at the Business Registration Service leaked details of over two million firms. Government websites faced defacement in coordinated cyber attacks in November 2025.

The Communications Authority reported detecting more than 4.5 billion cyber threat events between April and June 2025. The ODPC emphasizes strengthened individual rights, including the ability to request access to CCTV footage or visitor logs featuring oneself. This provision applies to all firms under the Private Security Regulation Act of 2016.

Concerns also extend to data misuse, such as using visitor details for unsolicited marketing or public sharing, which breaches purpose limitation principles. The draft is open for public input before finalization, indicating a push for stricter oversight of everyday data practices.

As Kenya contends with data sovereignty, cross-border transfers, and intensifying cyber threats, the ODPC views curbing unnecessary collection at security points as a vital first defense.

관련 기사

Police in cybercrime unit tracking IP of Chinese suspect in massive Coupang data breach exposing 33.7 million customers' info.
AI에 의해 생성된 이미지

경찰, 쿠팡 데이터 유출 용의자 IP 추적 중

AI에 의해 보고됨 AI에 의해 생성된 이미지

한국 최대 전자상거래 기업 쿠팡의 대규모 데이터 유출 사건으로 3370만 명의 고객 정보가 노출된 것으로 확인됐다. 경찰은 중국 국적의 전 직원을 용의자로 지목하고 IP 주소를 통해 추적 중이며, 정부는 최대 1조 원의 벌금을 검토하고 있다. 이 사건은 6월부터 시작된 것으로, 5개월간 탐지되지 않았다.

The notification of the Digital Personal Data Protection Rules 2025 has activated provisions of the DPDP Act 2023, significantly impacting the healthcare sector. The law designates medical institutions as data fiduciaries and grants patients rights over their data. Yet, ambiguities in the details pose challenges for healthcare providers.

AI에 의해 보고됨

A new report from the Electronic Privacy Information Center (EPIC) highlights a growing health privacy crisis in the United States, driven by surveillance and immigration enforcement. Factors such as data brokers, ad-tech tracking, and actions by Immigration and Customs Enforcement (ICE) are eroding patient trust and discouraging people from seeking medical care. This leads to delayed treatments and poorer health outcomes.

US Immigration and Customs Enforcement has issued a request for companies to share information on commercial big data and advertising technology tools. These products could assist in investigative activities, as outlined in a recent federal filing. The move highlights growing government interest in private-sector surveillance capabilities.

AI에 의해 보고됨

In an era where privacy faces constant threats, ordinary people are flipping the script by monitoring law enforcement as rigorously as they are watched. This shift challenges traditional notions of surveillance dominated by authorities. A recent article highlights this evolving dynamic.

The Directorate of Criminal Investigations (DCI) has dismantled a cross-border mobile phone theft and black-market network in Nairobi, arresting seven suspects and recovering 150 phones. The intelligence-led operation took place on January 24, 2026, spanning multiple city locations. The network linked Kenyan receivers with buyers in Uganda.

AI에 의해 보고됨

The National Transport and Safety Authority (NTSA), alongside the National Police Service (NPS), has begun piloting unique identification numbers for boda boda riders nationwide, starting in Nairobi. The move seeks to regulate a sector criticized for flouting traffic laws. Boniface Otieno, NPS traffic liaison in Nairobi, explained that the program will assign riders numbers distinct from their vehicle plates.

 

 

 

이 웹사이트는 쿠키를 사용합니다

사이트를 개선하기 위해 분석을 위한 쿠키를 사용합니다. 자세한 내용은 개인정보 보호 정책을 읽으세요.
거부