Kenya’s Iris Dilemma: The Ballot Meets the Biometric Age

When the Independent Electoral and Boundaries Commission (IEBC) introduced iris recognition as part of its Continuous Voter Registration (CVR) exercise, the move was presented as a technological upgrade aimed at strengthening the integrity of Kenya’s electoral system.

The objective is straightforward: use another biometric identifier to improve voter identification, reduce duplicate registrations and make impersonation more difficult.

But the rollout has also triggered an important national debate. The Elections Observation Group (ELOG) and members of the public have raised concerns about the privacy and data protection implications of collecting iris biometrics at scale. Those concerns deserve serious attention, particularly given Kenya’s recent experience with Worldcoin and the regulatory questions that followed its collection of biometric data.

The issue is not whether technology belongs in elections. It does.

The question is whether the governance framework surrounding that technology is strong enough to protect citizens’ rights.

Why Iris Data Raises a Different Kind of Risk

Iris biometrics are among the most sensitive forms of personal data because they are highly distinctive and, unlike passwords or identity documents, cannot simply be changed if compromised.

That permanence changes the risk calculus.

A compromised password can be reset. A compromised identity document can be replaced. Biometric characteristics are fundamentally different. Once biometric information is exposed, the individual cannot obtain a new iris in the same way they can obtain a new password or identification number.

The concern also extends beyond a single database. Biometric systems can create powerful capabilities for identification and verification. If datasets are improperly linked, shared or repurposed, information originally collected for electoral purposes could potentially contribute to profiling or other forms of surveillance.

This is why the question of biometric security cannot be reduced to whether a system is technically accurate.

It must also address who controls the data, why it is collected, how long it is retained, where it is stored, who can access it, and whether it can be used for purposes beyond those originally communicated to citizens.

The Worldcoin Lesson

Kenya’s experience with Worldcoin provides an important point of comparison.

In 2023, the government suspended Worldcoin’s activities amid concerns surrounding the collection and processing of personal and biometric data. The controversy subsequently drew significant regulatory and public scrutiny, including investigations by the Office of the Data Protection Commissioner (ODPC).

The Worldcoin experience demonstrated something important: public concern about biometric technology is not necessarily resistance to innovation. It can be a demand for greater transparency and accountability around technologies that create unusually persistent risks.

The parallels with large-scale electoral biometric collection are therefore worth examining.

Both involve:

  • The collection of highly sensitive biometric information at scale.
  • Questions about transparency and meaningful information to data subjects.
  • Concerns about data minimisation and proportionality.
  • Significant questions about security, retention and access.
  • The need for strong institutional oversight.

There is, however, a fundamental difference.

IEBC is a constitutional commission performing a public electoral function. Its authority to process personal data therefore arises in a very different context from that of a private commercial entity.

But a public mandate does not eliminate data protection obligations.

If anything, the use of biometrics by a constitutional institution makes accountability even more important.

The Legal and Governance Questions

Under Kenya’s Data Protection Act, 2019, biometric data falls within the category of sensitive personal data. Its processing therefore demands particular attention to lawful processing, purpose limitation, data minimisation, security safeguards and accountability.

That raises several questions about the deployment of iris recognition in voter registration.

Has IEBC undertaken a Data Protection Impact Assessment (DPIA)?

Where processing is likely to result in a high risk to the rights and freedoms of individuals, the Data Protection Act provides for a DPIA. Given the scale, sensitivity and permanence of electoral biometric data, the question of whether such an assessment has been conducted should be publicly addressed.

How long will the biometric data be retained?

The public should understand the retention period, the criteria determining when data may be deleted or archived, and what happens to biometric information when a voter dies, transfers registration or is otherwise removed from the register.

Who can access the biometric information?

Access controls should be clearly defined. Citizens should know which institutions, officials, contractors and technology providers can access the data and under what circumstances.

Can the data be used for another purpose?

This is perhaps the most important governance question.

Data collected to establish electoral identity should not quietly become a resource for unrelated government functions or third parties. Strong purpose limitation and institutional separation are essential to prevent function creep.

Where is the data stored and processed?

Data sovereignty matters, but so does the legal basis for any transfer or access outside Kenya. If vendors or infrastructure providers located outside the country are involved, the public should understand what safeguards govern those arrangements and whether applicable requirements for cross-border transfers are being met.

Governance Must Come Before Deployment

The answer is not to reject biometric technology.

Kenya can legitimately use technology to improve the accuracy, efficiency and integrity of elections. But technological capability should not be allowed to move faster than the governance mechanisms designed to control it.

Several measures could strengthen public confidence.

1. Explain the System Before Asking for Trust

IEBC should clearly communicate what iris data is being collected, why it is necessary, how it will be used, how long it will be retained and who will have access to it.

Transparency should be part of the system’s design, not a response to public criticism.

2. Conduct and Communicate the DPIA

If a DPIA is required, it should be completed before high-risk processing proceeds. At minimum, IEBC should consider publishing a meaningful summary of the assessment, including the principal risks identified and the safeguards adopted to mitigate them.

Independent oversight by the ODPC can provide an additional layer of assurance.

3. Prevent Function Creep

Electoral biometric data should remain tied to clearly defined electoral purposes.

Any attempt to repurpose the data for unrelated government, commercial or surveillance functions should face a clear legal and governance barrier.

4. Audit the Technology and Vendors

Biometric security cannot depend solely on assurances from technology suppliers.

Independent experts should be able to assess the system’s architecture, encryption, access controls, authentication mechanisms, logging, incident-response procedures and vendor arrangements.

Civil society organisations and election observers can also play an important role in scrutinising the governance framework.

5. Establish Clear Redress Mechanisms

Citizens need to know what happens if their biometric information is compromised, processed unlawfully or used for an unauthorized purpose.

There should be clear channels for complaints, investigations and redress, supported by effective coordination between IEBC’s internal accountability mechanisms and the ODPC’s regulatory mandate.

Democracy Should Not Require a Privacy Trade-Off

Kenya’s adoption of iris recognition in voter registration presents an opportunity to demonstrate that technological modernization and rights protection can advance together.

But biometric technology changes the stakes.

The more permanent the identifier, the more consequential the governance failures.

The lesson from the Worldcoin controversy is not that Kenya should avoid biometric innovation. It is that innovation without transparency, accountability and enforceable safeguards can quickly undermine public confidence.

IEBC therefore has an opportunity to set a higher standard for biometric governance in the public sector.

The goal should not simply be a more technologically sophisticated voter register.

It should be a voter registration system that is secure, proportionate, transparent and accountable.

Because the integrity of an election is not only about ensuring that every eligible voter can vote.

It is also about ensuring that citizens do not have to surrender control over some of their most sensitive personal information simply to participate in democracy.

Leave a Reply

Your email address will not be published. Required fields are marked *