Data Privacy
Kenya’s Draft National Data Governance Policy: From Data Protection to Data Governance
By Frederick Ofwono
Why Data Governance Matters Now
Data has become one of the most valuable assets in the modern economy. It drives innovation, powers AI, impacts how governments deliver services and how businesses compete. As data grows, so do questions around its value, who controls it, who benefits from it, and how it should be governed. Furthermore, as AI becomes more widespread and digital financial services continue to expand, Kenya is generating unprecedented volumes of data. Although the Data Protection Act, 2019 established an essential framework for safeguarding personal information, it was never intended to address the wider governance challenges that arise when data is viewed not only as something to be protected, but also as a strategic national resource and economic asset. The Draft National Data Governance Policy, published by the Ministry of Information, Communications and Digital Economy in May 2026, seeks to address this gap. It represents Kenya’s most comprehensive effort to establish a coordinated framework for managing, sharing, protecting and deriving value from data across both the public and private sectors.
More importantly, the policy signals a shift in thinking. Rather than viewing data solely through the lens of privacy and compliance, it treats data as a strategic national asset capable of supporting economic growth, innovation, public service delivery, and regional digital integration.
What the Policy Seeks to Achieve
At its core, the policy seeks to move Kenya beyond data protection and towards comprehensive data governance.
While data protection focuses primarily on safeguarding personal information, data governance addresses a broader set of questions: How should data be collected, managed, shared, and reused? How can institutions improve data quality and interoperability? How should emerging technologies such as AI be governed? How can citizens' rights be protected while still enabling innovation and economic development?
To answer these questions, the policy proposes reforms across six key areas:
Institutional coordination and governance;
Data quality, standards, and interoperability;
Legal and regulatory harmonisation;
Data sharing and value creation;
Capacity building and data literacy; and
Governance of AI and emerging technologies.
The policy explicitly recognises data as a factor of production alongside traditional economic inputs such as labour and capital. This is a significant development. It reflects a growing international consensus that data should not only be protected but should also be responsibly leveraged to create economic and social value.
Beyond institutional reforms, the policy places significant emphasis on improving data quality, standardization, and stewardship. It proposes national data standards based on internationally recognized FAIR (Findable, Accessible, Interoperable, and Reusable) principles, the establishment of national data inventories, and clearer accountability through designated data officers and custodians across government. These measures address a practical challenge: ensuring that data is reliable, discoverable, and capable of being shared securely across institutions.
Five Strengths of the Policy
1. Recognising Data as an Economic Asset
One of the policy's most important contributions is its recognition that data has economic value. Data regulation is typically focused on privacy, cybersecurity, and compliance. While these issues remain important, the draft policy expands the conversation by recognising that data can also drive innovation, productivity, investment, and economic growth. The policy proposes mechanisms for data sharing, data valuation, and regulated data marketplaces that could enable greater value creation across sectors such as agriculture, healthcare, education, and financial services. This approach is broadly aligned with the African Union Data Policy Framework, which encourages African states to leverage data as a strategic asset for development and regional integration.
2. Addressing Fragmentation Through a National Framework
Kenya's current data governance landscape is characterised by multiple laws, sector-specific frameworks, and institutional mandates that do not always align. The policy attempts to address this fragmentation through a coordinated national framework supported by a proposed National Data Governance and Emerging Technologies Council and a dedicated Data Governance Office. The success of these institutions will depend on their eventual legal mandate and operational effectiveness. Nevertheless, the policy correctly identifies institutional fragmentation as one of the major barriers to effective governance and seeks to address it directly.
3. Building Foundations for Interoperability
For many years, public institutions have operated in silos, often collecting the same information repeatedly. The policy proposes a more integrated national data architecture, including interoperability standards, data catalogues, master data management systems, and secure data-sharing mechanisms. Drawing lessons from Estonia's X-Road digital infrastructure and India's digital public infrastructure initiative, India Stack, the policy envisions a future where data can move securely and efficiently between authorised institutions. If realised, this could improve service delivery, reduce duplication, and support evidence-based policymaking.
4. Preparing Kenya for AI
Many governments are still debating whether artificial intelligence should be regulated through standalone legislation or integrated into existing governance frameworks. Kenya's policy adopts the latter approach by embedding AI governance within broader data governance structures. The policy proposes measures such as algorithmic impact assessments, risk-based oversight, human accountability, and governance requirements for AI training data. This approach recognises a simple but important reality: effective AI governance begins with effective data governance.
5. Balancing Sovereignty and Openness
The policy also addresses one of the most difficult questions facing policymakers globally: how to balance national data sovereignty with the need for cross-border data flows. On the one hand, Kenya must ensure that sensitive data is protected and that the country derives value from its digital resources. On the other hand, participation in regional and global digital markets requires trusted mechanisms for international data transfers. The policy attempts to strike this balance by aligning with continental initiatives such as the African Continental Free Trade Area (AfCFTA) Digital Trade Protocol while maintaining safeguards for security, privacy, and accountability.
Key Risks and Considerations
While the policy is ambitious and largely well-conceived, several issues deserve further consideration.
Institutional Overlap
The proposed governance architecture introduces new institutions and responsibilities into an already crowded regulatory environment. The relationship between the Office of the Data Protection Commissioner, the ICT Authority, the Kenya National Bureau of Statistics, sector regulators, and the proposed Data Governance Office will require careful clarification. Without clearly defined roles and dispute-resolution mechanisms, institutional overlap could undermine implementation.
Implementation Capacity
Many public institutions continue to face resource constraints, limited technical capacity, and competing priorities. Similar challenges are likely to affect implementation of the proposed policy unless adequate funding and capacity-building programmes are prioritised from the outset.
County-Level Readiness
The policy rightly recognises the role of county governments in data governance. However, implementation capacity varies significantly across counties. Without dedicated financial support, technical assistance, and skills development programmes, there is a risk that implementation becomes uneven across the country.
The Human Dimension: Rights, Trust and Inclusion
One of the more important aspects of the policy is its recognition that data governance is ultimately about people rather than technology. The policy emphasises public trust, transparency, participation, and protection for vulnerable groups, including children, persons with disabilities, and marginalised communities. It also acknowledges the importance of community data rights and the governance of traditional knowledge. This people-centred approach reflects emerging international best practice. Effective data governance requires public confidence that data will be used fairly, securely, and in ways that deliver tangible benefits to society. Without trust, even the most sophisticated technical frameworks are unlikely to succeed.
How Kenya Compares Internationally
The policy draws extensively from international experience while attempting to respond to Kenya's unique circumstances. The European Union's General Data Protection Regulation (GDPR) and Data Governance Act remain the global benchmark for rights-based data governance. Kenya's policy adopts similar principles around accountability, transparency, and risk-based regulation while avoiding some of the complexity associated with the European model.
India offers perhaps the most relevant comparison. Through initiatives such as India Stack and the Data Empowerment and Protection Architecture (DEPA), India has demonstrated how digital public infrastructure can support innovation while preserving individual control over data. Several aspects of Kenya's proposed framework appear influenced by this experience.
Closer to home, South Africa's Protection of Personal Information Act (POPIA) highlights the importance of adequately resourcing regulators and ensuring practical implementation. Rwanda's National Data Governance Framework similarly demonstrates how strong political commitment and institutional coordination can accelerate digital transformation. Rather than copying any single model, Kenya's policy attempts to combine lessons from multiple jurisdictions into a framework tailored to local realities.
Conclusion
The Draft National Data Governance Policy represents a comprehensive attempt to address data governance in Kenya. Perhaps the most important aspect of the policy is the shift in thinking. Kenya is moving beyond a narrow focus on data protection towards a broader understanding of data as a strategic national resource that must be protected, shared, governed, and leveraged responsibly. The policy gets several important things right. Its recognition of data as an economic asset, its focus on interoperability, its integration of AI governance, and its commitment to regional alignment provide a strong foundation for future growth. Kenya has developed an ambitious framework for governing data in the digital age. The next challenge will be transforming that framework into institutions, systems, and outcomes that deliver measurable benefits for citizens, businesses, and government alike.