ODPC warns security firms over excessive data collection

The Office of the Data Protection Commissioner (ODPC) has warned private security firms in Kenya against unlawfully harvesting excessive personal data from visitors. In a draft guidance note, the ODPC states that only names, identification numbers, and entry times should be collected for building access. This alert comes amid rising cyber threats and major data breaches in the country.

The Office of the Data Protection Commissioner (ODPC) has expressed deep concern over routine data collection practices at security desks, describing them as posing significant privacy risks. In a draft Guidance Note released on December 19, 2025, the ODPC highlights that private security firms must stop requiring visitors to provide phone numbers, home addresses, marital status, and other personal details, as these violate the Data Protection Act of 2019.

According to the regulator, the only permissible information for basic access is a visitor's name, identification number, and time of entry. Firms are urged to limit collection to what is strictly necessary and delete any data without a lawful basis.

This warning arises against a backdrop of escalating data breaches in Kenya. In October 2025, a popular health app was breached, exposing medical records of 4.8 million users. A February 2025 incident at the Business Registration Service leaked details of over two million firms. Government websites faced defacement in coordinated cyber attacks in November 2025.

The Communications Authority reported detecting more than 4.5 billion cyber threat events between April and June 2025. The ODPC emphasizes strengthened individual rights, including the ability to request access to CCTV footage or visitor logs featuring oneself. This provision applies to all firms under the Private Security Regulation Act of 2016.

Concerns also extend to data misuse, such as using visitor details for unsolicited marketing or public sharing, which breaches purpose limitation principles. The draft is open for public input before finalization, indicating a push for stricter oversight of everyday data practices.

As Kenya contends with data sovereignty, cross-border transfers, and intensifying cyber threats, the ODPC views curbing unnecessary collection at security points as a vital first defense.

相关文章

Police in cybercrime unit tracking IP of Chinese suspect in massive Coupang data breach exposing 33.7 million customers' info.
AI 生成的图像

警方通过IP追踪Coupang数据泄露嫌疑人

由 AI 报道 AI 生成的图像

韩国领先电商公司Coupang发生大规模数据泄露,暴露3370万客户个人信息。警方正通过IP地址追踪一名中国前雇员嫌疑人,政府考虑最高1万亿韩元罚款。该泄露从6月开始,持续五个月未被发现。

The Kenya Revenue Authority (KRA) has reaffirmed that data collected will be protected by existing laws, while dispelling fears over data privacy following the bodycam rollout to customs officers nationwide on Tuesday. The response on Wednesday, March 11, came after several netizens, especially on X, raised concerns fearing that the footage captured by the bodycams would not be used for the intended purpose. KRA stressed that the recordings will be processed in accordance with the law governing data handling in Kenya.

由 AI 报道

香港私隐监察专员计划今年就引入强制数据泄露报告及相关处罚措施咨询立法会议员,此前该立法改革因担忧本地营商环境而于2024年搁置。个人资料私隐专员钟丽玲周六透露了该市私隐条例拟议修订细节,建议可分阶段实施这些措施。

The Kenyan government has implemented a new digital system to oversee healthcare delivery in real time, as explained by Public Health Principal Secretary Mary Muthoni. This system, enabled by the 2023 Digital Health Act, tracks activities across all 47 counties to ensure accountability and prevent fraud.

由 AI 报道

Kenya's High Court has suspended implementation of parts of the Kenya-US Health Cooperation Framework involving sensitive health data transfer. Signed on December 4, 2025, the deal faces a petition from Busia Senator Okiya Omtatah and the Consumers Federation of Kenya (COFEK), who argue it violates privacy rights and national sovereignty. Government officials have criticized the petitioners for obstructing health programs.

A class-action lawsuit filed in U.S. District Court in Maine accuses Homeland Security Secretary Kristi Noem and the Trump administration of violating First Amendment rights through the use of facial recognition software and other surveillance tools. The complaint alleges that federal agents targeted citizens recording their activities in public spaces during immigration enforcement operations. Plaintiffs seek an injunction to halt these practices and expunge related records.

由 AI 报道

电商巨头 Coupang 发生大规模数据泄露,从6月24日至11月8日,3370万客户的个人信息暴露。官员透露,攻击者利用公司电子签名密钥,引发政府全面调查。此事件加剧了公众对韩国数据保护能力的担忧。

 

 

 

此网站使用 cookie

我们使用 cookie 进行分析以改进我们的网站。阅读我们的 隐私政策 以获取更多信息。
拒绝