ODPC warns security firms over excessive data collection

The Office of the Data Protection Commissioner (ODPC) has warned private security firms in Kenya against unlawfully harvesting excessive personal data from visitors. In a draft guidance note, the ODPC states that only names, identification numbers, and entry times should be collected for building access. This alert comes amid rising cyber threats and major data breaches in the country.

The Office of the Data Protection Commissioner (ODPC) has expressed deep concern over routine data collection practices at security desks, describing them as posing significant privacy risks. In a draft Guidance Note released on December 19, 2025, the ODPC highlights that private security firms must stop requiring visitors to provide phone numbers, home addresses, marital status, and other personal details, as these violate the Data Protection Act of 2019.

According to the regulator, the only permissible information for basic access is a visitor's name, identification number, and time of entry. Firms are urged to limit collection to what is strictly necessary and delete any data without a lawful basis.

This warning arises against a backdrop of escalating data breaches in Kenya. In October 2025, a popular health app was breached, exposing medical records of 4.8 million users. A February 2025 incident at the Business Registration Service leaked details of over two million firms. Government websites faced defacement in coordinated cyber attacks in November 2025.

The Communications Authority reported detecting more than 4.5 billion cyber threat events between April and June 2025. The ODPC emphasizes strengthened individual rights, including the ability to request access to CCTV footage or visitor logs featuring oneself. This provision applies to all firms under the Private Security Regulation Act of 2016.

Concerns also extend to data misuse, such as using visitor details for unsolicited marketing or public sharing, which breaches purpose limitation principles. The draft is open for public input before finalization, indicating a push for stricter oversight of everyday data practices.

As Kenya contends with data sovereignty, cross-border transfers, and intensifying cyber threats, the ODPC views curbing unnecessary collection at security points as a vital first defense.

관련 기사

Police in cybercrime unit tracking IP of Chinese suspect in massive Coupang data breach exposing 33.7 million customers' info.
AI에 의해 생성된 이미지

경찰, 쿠팡 데이터 유출 용의자 IP 추적 중

AI에 의해 보고됨 AI에 의해 생성된 이미지

한국 최대 전자상거래 기업 쿠팡의 대규모 데이터 유출 사건으로 3370만 명의 고객 정보가 노출된 것으로 확인됐다. 경찰은 중국 국적의 전 직원을 용의자로 지목하고 IP 주소를 통해 추적 중이며, 정부는 최대 1조 원의 벌금을 검토하고 있다. 이 사건은 6월부터 시작된 것으로, 5개월간 탐지되지 않았다.

The Kenya Revenue Authority (KRA) has reaffirmed that data collected will be protected by existing laws, while dispelling fears over data privacy following the bodycam rollout to customs officers nationwide on Tuesday. The response on Wednesday, March 11, came after several netizens, especially on X, raised concerns fearing that the footage captured by the bodycams would not be used for the intended purpose. KRA stressed that the recordings will be processed in accordance with the law governing data handling in Kenya.

AI에 의해 보고됨

홍콩 개인정보 보호 당국은 올해 의원들과 의무 데이터 유출 보고 및 관련 처벌 도입에 대해 상담할 계획이며, 이는 2024년 지역 비즈니스 환경 우려로 입법 개혁이 보류된 후의 일이다. 개인정보 보호 담당 위원 아다 청 라이링은 토요일 시의 개인정보 보호 조례 개정안 세부 사항을 공개하며, 이러한 조치를 단계적으로 시행할 수 있다고 제안했다.

South Africa's Information Regulator has ruled against the Johannesburg Stock Exchange's refusal to release trading records, deeming it a public body under the Promotion of Access to Information Act. The decision stems from a 2023 complaint by Inhlanhla Ventures seeking details of potentially manipulative trades in enX Group shares from May 2020. The regulator mandates notification to involved parties before disclosure.

AI에 의해 보고됨

The Kenyan government has implemented a new digital system to oversee healthcare delivery in real time, as explained by Public Health Principal Secretary Mary Muthoni. This system, enabled by the 2023 Digital Health Act, tracks activities across all 47 counties to ensure accountability and prevent fraud.

홍콩 개인정보보호처가 HSBC의 인기 모바일 앱 PayMe 초기 사용자 위험을 조사 중이며, 사우스 차이나 모닝 포스트가 일부 사용자가 개인 정보가 노출됐을 수 있다는 사실을 모르고 있다고 보도한 데 따른 것이다. 준법 검토는 레거시 사용자 취약점과 앱 내 알림 필요성을 검토할 예정이다. 보호처는 은행이 기본적으로 최고 수준의 프라이버시 보호를 보장해야 한다고 강조했다.

AI에 의해 보고됨

A class-action lawsuit filed in U.S. District Court in Maine accuses Homeland Security Secretary Kristi Noem and the Trump administration of violating First Amendment rights through the use of facial recognition software and other surveillance tools. The complaint alleges that federal agents targeted citizens recording their activities in public spaces during immigration enforcement operations. Plaintiffs seek an injunction to halt these practices and expunge related records.

 

 

 

이 웹사이트는 쿠키를 사용합니다

사이트를 개선하기 위해 분석을 위한 쿠키를 사용합니다. 자세한 내용은 개인정보 보호 정책을 읽으세요.
거부