Privacy by Design in Government Digital Services | Data Governance Africa

The Data Privacy and Governance Society of Kenya (DPGSK) recently convened a webinar examining how government institutions can move privacy by design and privacy by default from legal requirements on paper to practical principles embedded throughout the lifecycle of digital public services.

The discussion brought together an external data protection consultant, a Data Protection Officer (DPO) working within a public sector institution, and a DPO with experience across the financial and technology sectors. Together, the speakers explored the legal framework, lessons from litigation, institutional challenges, procurement, data sharing, system architecture, and the role of DPOs in government digital transformation.

1. Privacy Must Begin at the Design Stage

The webinar opened with a discussion of Section 41 of Kenya’s Data Protection Act, 2019, which requires data controllers and processors to implement appropriate technical and organisational measures and integrate data protection principles and data subject rights into the design of processing activities.

This obligation is reinforced by Article 31 of the Constitution of Kenya, which guarantees the right to privacy.

The key message was that privacy by design is not simply about conducting a Data Protection Impact Assessment (DPIA) immediately before a system goes live. A DPIA is an important tool, particularly for high-risk processing, but privacy by design requires a much broader and continuous approach.

Privacy considerations should be incorporated from the earliest stages of a project, including policy development, budgeting, procurement, system architecture, data sharing arrangements, access controls, retention, security, and ultimately the decommissioning of a system.

In other words, privacy should be treated as part of the architecture of a public service, rather than a compliance exercise undertaken immediately before launch.

2. A Lawful Basis Does Not Mean Unlimited Processing

The webinar also addressed what was described as a common misunderstanding of Section 30 of the Data Protection Act, particularly in relation to processing undertaken in the exercise of a statutory function or duty.

A statutory mandate may provide a lawful basis for processing personal data, but it does not give a public institution unrestricted authority to collect whatever information it considers useful.

The principles of data minimisation, purpose limitation, proportionality, security and accountability continue to apply.

For government institutions, this distinction is particularly important. The fact that an agency has a statutory mandate to provide a service does not automatically justify collecting excessive personal information or retaining it indefinitely.

3. When Privacy Is Ignored, Projects Can Become More Expensive

The panel used several Kenyan cases and ongoing disputes to illustrate the practical consequences of failing to address data protection considerations early.

Huduma Namba

The litigation surrounding the National Integrated Identity Management System (Huduma Namba) demonstrated the risks associated with deploying a major digital identity programme without adequately addressing privacy safeguards and DPIA requirements.

Among the concerns raised were the proposed collection and processing of highly sensitive information, including DNA and GPS-related data. The litigation ultimately disrupted the rollout and resulted in significant project and public expenditure implications.

IMEI Registration

The litigation concerning mandatory registration of mobile device identifiers similarly demonstrated the importance of establishing a clear lawful framework before implementing large-scale data collection initiatives.

The High Court found the framework for collecting IMEI information unlawful, preventing the proposed collection from proceeding in the manner contemplated.

SHA and Digital Health Systems

The panel also discussed litigation surrounding the Social Health Authority (SHA) and the implementation of digital health systems.

The matter remains subject to further proceedings before the Court of Appeal, following the High Court’s intervention and issuance of a structural interdict requiring evidence of compliance with the Data Protection Act.

Kenya–US Health Cooperation Framework

Another ongoing matter concerns a challenge to aspects of a Kenya–US health cooperation framework, including questions around transparency, public participation and the absence of an adequate DPIA in relation to health data sharing.

Together, these matters demonstrate that privacy failures can have consequences far beyond regulatory criticism. They can result in project delays, suspended programmes, invalidated decisions, additional procurement costs, regulatory complaints, increased breach exposure and reputational damage.

Government institutions are not insulated from these consequences simply because they are public bodies.

4. The Reality of Privacy Work Inside Government

The perspective of the serving public sector DPO highlighted a different challenge: even when the legal framework is clear, implementing it within a large public institution can be difficult.

DPO Capacity Remains a Challenge

One concern raised was the absence of formally recognised DPO positions within many public sector organisational structures.

In practice, data protection responsibilities may be added to the existing responsibilities of officers, particularly legal officers, without a corresponding reduction in their workload.

This creates a structural challenge. Effective privacy governance requires sufficient authority, expertise, independence and resources, yet DPOs may have to perform their responsibilities alongside their primary institutional roles.

DPGSK is working to address this institutional gap and strengthen the recognition of DPO functions within the public sector.

Legacy Systems Create Legacy Privacy Problems

Many government systems were designed and deployed before the current focus on data protection and digital governance.

As a result, issues such as excessive data collection, inappropriate retention periods, inadequate access controls or weak data-sharing arrangements may only become visible once a system is already operational.

At that stage, correcting the problem can be technically complicated and financially expensive.

This reinforces the importance of involving DPOs and privacy professionals before procurement and development decisions are finalised.

5. Procurement: A Practical Entry Point for Privacy

One of the more encouraging developments discussed was the integration of data protection requirements into government procurement.

Rather than waiting until after a vendor has been selected, institutions can require prospective suppliers to demonstrate compliance as part of the procurement process.

This can include evidence of:

  • ODPC registration where applicable;
  • current privacy policies and procedures;
  • appropriate technical and organisational measures;
  • information security controls;
  • data handling arrangements; and
  • mechanisms for managing data subject rights and breaches.

Embedding these requirements into procurement makes privacy part of vendor selection rather than an issue to be negotiated after a contract has already been awarded.

6. Government-to-Government Data Sharing Is More Complicated

Data sharing between public institutions was identified as one of the more difficult areas to operationalise.

The panel noted that standard Memoranda of Understanding (MOUs) between government institutions are not, by themselves, sufficient to establish the detailed data protection obligations required for data sharing. Consequently, institutions may use separate data sharing agreements alongside confidentiality undertakings for individual officers handling the information.

Effective agreements should address issues such as:

  • purpose limitation;
  • data minimisation;
  • retention and deletion;
  • deletion certificates;
  • technical and organisational security measures;
  • staff training;
  • access controls;
  • remote-working arrangements;
  • breach management; and
  • accountability responsibilities.

Rather than relying on a single generic template, agreements may need to be negotiated according to the nature of the information being shared, the purpose of the processing and the risks involved.

7. A Privacy Notice Is Not the End of Compliance

Another important point from the discussion was that publishing a privacy notice or internal privacy policy does not, by itself, establish effective compliance.

The real question is whether employees know the policy exists, understand their responsibilities and consistently follow the procedures it establishes.

This requires ongoing awareness, training, monitoring and accountability.

Policies must also remain aligned with applicable legislation and guidance, including the ODPC’s guidance for the public sector.

The panel also cautioned against treating consent as a default lawful basis for government processing.

Where a service is mandatory, individuals may not have a genuine choice. Filing a tax return, for example, is not something a citizen can meaningfully refuse simply because they do not wish their personal data to be processed.

In such circumstances, reliance on consent may be inappropriate. Institutions should instead identify the lawful basis that actually supports the processing, including statutory functions or obligations where applicable.

The discussion also highlighted the importance of maintaining compliance with ODPC registration and certification requirements.

9. The Biggest Challenge: Getting DPOs Involved Early

Perhaps the most consistent challenge identified during the webinar was the timing of DPO involvement.

DPOs are frequently brought into projects at the end of the process, when a contract is ready for signature, a data sharing agreement needs to be approved, or a system is approaching deployment.

By then, fundamental decisions about the technology, data flows and processing activities may already have been made.

The more effective approach is to involve the DPO from project inception.

The panel suggested that this can be achieved by building strong working relationships with ICT, registry, procurement and other relevant teams. DPOs also need to remain aware of projects being developed informally across the institution so that privacy considerations can be introduced before decisions become difficult to change.

Importantly, early involvement should not always be framed as an enforcement exercise. Collaboration and relationship-building can be more effective in securing buy-in across an institution.

A formal directive from senior leadership or the board requiring DPO involvement from the beginning of relevant projects was identified as a particularly sustainable solution.

10. Designing APIs to Minimise Data Exposure

Digital integration between government platforms can significantly improve public services. Connecting revenue systems, company registries and other platforms can reduce duplication and make services faster and easier for citizens.

However, every integration can also increase the number of systems through which personal data flows and consequently expand the potential attack surface.

One mitigation discussed was the use of validation-only APIs where possible.

Instead of transferring an entire record between systems, an API can simply confirm a particular fact. For example, rather than transferring a complete personal record, one system could ask another system to confirm whether a specific piece of information is valid.

This approach reflects a fundamental privacy-by-design principle:

If you do not need to transfer the data, do not transfer it.

11. The Policy Landscape Is Evolving

The discussion also took place against a rapidly developing policy environment.

Several policy and legislative initiatives are likely to influence how government processes and governs personal data, including the national data policy being developed through the Ministry of Information, Communications and the Digital Economy, Kenya’s existing National AI Strategy, the Digital Health Act, and emerging work around the Digital Agriculture Act and related policy initiatives.

As government digitisation accelerates, these frameworks will increasingly intersect with data protection, cybersecurity, artificial intelligence and digital governance.

12. From Compliance Exercise to Institutional Culture

The central lesson from the DPGSK webinar was that privacy by design cannot be reduced to a DPIA, a privacy notice, a procurement clause or a data sharing agreement.

It is an institutional approach to decision-making.

For government, this means asking privacy questions when a project is conceived, before a budget is approved, when technology is procured, when systems are designed, when APIs are connected, when data is shared and when information is eventually deleted.

The cost of asking these questions early is generally far lower than the cost of redesigning a system, suspending a project or defending litigation after deployment.

As Kenya continues to digitise public services, privacy by design should therefore be viewed not as an obstacle to innovation, but as part of building lawful, secure, proportionate and trustworthy digital government.

The most effective digital public services will not simply be those that work. They will be those that work while respecting the rights of the people they are designed to serve.

Leave a Reply

Your email address will not be published. Required fields are marked *