Data Privacy

Kenya’s Draft National Data Governance Policy: From Data Protection to Data Governance

By Frederick Ofwono

Why Data Governance Matters Now 

Data has become one of the most valuable assets in the modern economy. It drives innovation,  powers AI, impacts how governments deliver services and how businesses  compete. As data grows, so do questions around its value, who controls it, who benefits from it, and how it should be governed. Furthermore, as AI becomes more widespread and digital financial services  continue to expand, Kenya is generating unprecedented volumes of data. Although the Data  Protection Act, 2019 established an essential framework for safeguarding personal information,  it was never intended to address the wider governance challenges that arise when data is viewed  not only as something to be protected, but also as a strategic national resource and economic  asset.  The Draft National Data Governance Policy, published by the Ministry of Information,  Communications and Digital Economy in May 2026, seeks to address this gap. It represents Kenya’s most comprehensive effort to establish a coordinated framework for managing, sharing,  protecting and deriving value from data across both the public and private sectors. 

More importantly, the policy signals a shift in thinking. Rather than viewing data solely through  the lens of privacy and compliance, it treats data as a strategic national asset capable of  supporting economic growth, innovation, public service delivery, and regional digital integration. 

What the Policy Seeks to Achieve 

At its core, the policy seeks to move Kenya beyond data protection and towards comprehensive  data governance. 

While data protection focuses primarily on safeguarding personal information, data governance  addresses a broader set of questions: How should data be collected, managed, shared, and  reused? How can institutions improve data quality and interoperability? How should emerging  technologies such as AI be governed? How can citizens' rights be protected  while still enabling innovation and economic development? 

To answer these questions, the policy proposes reforms across six key areas: 

  • Institutional coordination and governance; 

  • Data quality, standards, and interoperability; 

  • Legal and regulatory harmonisation; 

  • Data sharing and value creation; 

  • Capacity building and data literacy; and

  • Governance of AI and emerging technologies. 

The policy explicitly recognises data as a factor of production alongside traditional economic  inputs such as labour and capital. This is a significant development. It reflects a growing  international consensus that data should not only be protected but should also be responsibly  leveraged to create economic and social value. 

Beyond institutional reforms, the policy places significant emphasis on improving data quality,  standardization, and stewardship. It proposes national data standards based on internationally  recognized FAIR (Findable, Accessible, Interoperable, and Reusable) principles, the establishment  of national data inventories, and clearer accountability through designated data officers and  custodians across government. These measures address a practical challenge: ensuring that data  is reliable, discoverable, and capable of being shared securely across institutions. 

Five Strengths of the Policy 

1. Recognising Data as an Economic Asset 

One of the policy's most important contributions is its recognition that data has economic value. Data regulation is typically focused on privacy, cybersecurity, and compliance. While these issues  remain important, the draft policy expands the conversation by recognising that data can also  drive innovation, productivity, investment, and economic growth. The policy proposes mechanisms for data sharing, data valuation, and regulated data  marketplaces that could enable greater value creation across sectors such as agriculture,  healthcare, education, and financial services. This approach is broadly aligned with the African Union Data Policy Framework,  which encourages African states to leverage data as a strategic asset for development and  regional integration. 

2. Addressing Fragmentation Through a National Framework 

Kenya's current data governance landscape is characterised by multiple laws, sector-specific  frameworks, and institutional mandates that do not always align. The policy attempts to address this fragmentation through a coordinated national framework  supported by a proposed National Data Governance and Emerging Technologies Council and a  dedicated Data Governance Office. The success of these institutions will depend on their eventual legal mandate and operational  effectiveness. Nevertheless, the policy correctly identifies institutional fragmentation as one of  the major barriers to effective governance and seeks to address it directly. 

3. Building Foundations for Interoperability 

For many years, public institutions have operated in silos, often collecting the same information  repeatedly. The policy proposes a more integrated national data architecture, including interoperability  standards, data catalogues, master data management systems, and secure data-sharing  mechanisms. Drawing lessons from Estonia's X-Road digital infrastructure and India's digital public infrastructure initiative, India Stack, the  policy envisions a future where data can move securely and efficiently between authorised  institutions. If realised, this could improve service delivery, reduce duplication, and support  evidence-based policymaking. 

4. Preparing Kenya for AI

Many governments are still debating whether artificial intelligence should be regulated through  standalone legislation or integrated into existing governance frameworks. Kenya's policy adopts the latter approach by embedding AI governance within broader data  governance structures. The policy proposes measures such as algorithmic impact assessments,  risk-based oversight, human accountability, and governance requirements for AI training data. This approach recognises a simple but important reality: effective AI governance begins with  effective data governance. 

5. Balancing Sovereignty and Openness 

The policy also addresses one of the most difficult questions facing policymakers globally: how to  balance national data sovereignty with the need for cross-border data flows. On the one hand, Kenya must ensure that sensitive data is protected and that the country derives  value from its digital resources. On the other hand, participation in regional and global digital  markets requires trusted mechanisms for international data transfers. The policy attempts to strike this balance by aligning with continental initiatives such as the African Continental Free Trade Area (AfCFTA) Digital Trade Protocol while  maintaining safeguards for security, privacy, and accountability. 

Key Risks and Considerations 

While the policy is ambitious and largely well-conceived, several issues deserve further  consideration. 

  • Institutional Overlap 

The proposed governance architecture introduces new institutions and responsibilities into an  already crowded regulatory environment. The relationship between the Office of the Data Protection Commissioner, the ICT Authority, the Kenya National Bureau  of Statistics, sector regulators, and the proposed Data Governance Office will require careful  clarification. Without clearly defined roles and dispute-resolution mechanisms, institutional  overlap could undermine implementation.

  • Implementation Capacity

Many public institutions continue to face resource constraints, limited technical capacity, and  competing priorities. Similar challenges are likely to affect implementation of the proposed policy  unless adequate funding and capacity-building programmes are prioritised from the outset. 

  • County-Level Readiness 

The policy rightly recognises the role of county governments in data governance. However,  implementation capacity varies significantly across counties. Without dedicated financial support, technical assistance, and skills development programmes,  there is a risk that implementation becomes uneven across the country. 

  • The Human Dimension: Rights, Trust and Inclusion 

One of the more important aspects of the policy is its recognition that data governance is  ultimately about people rather than technology. The policy emphasises public trust, transparency, participation, and protection for vulnerable  groups, including children, persons with disabilities, and marginalised communities. It also  acknowledges the importance of community data rights and the governance of traditional  knowledge. This people-centred approach reflects emerging international best practice. Effective data  governance requires public confidence that data will be used fairly, securely, and in ways that  deliver tangible benefits to society. Without trust, even the most sophisticated technical frameworks are unlikely to succeed. 

How Kenya Compares Internationally 

The policy draws extensively from international experience while attempting to respond to  Kenya's unique circumstances. The European Union's General Data Protection Regulation (GDPR) and Data  Governance Act remain  the global benchmark for rights-based data governance. Kenya's policy adopts similar principles  around accountability, transparency, and risk-based regulation while avoiding some of the  complexity associated with the European model. 

India offers perhaps the most relevant comparison. Through initiatives such as India Stack and  the Data Empowerment and Protection Architecture (DEPA), India has demonstrated how digital  public infrastructure can support innovation while preserving individual control over data. Several  aspects of Kenya's proposed framework appear influenced by this experience. 

Closer to home, South Africa's Protection of Personal Information Act (POPIA) highlights the importance of adequately resourcing regulators and  ensuring practical implementation. Rwanda's National Data Governance Framework similarly demonstrates how strong political commitment and  institutional coordination can accelerate digital transformation. Rather than copying any single model, Kenya's policy attempts to combine lessons from multiple  jurisdictions into a framework tailored to local realities. 

Conclusion

The Draft National Data Governance Policy represents a comprehensive attempt to address data  governance in Kenya. Perhaps the most important aspect of the policy is the shift in thinking. Kenya is moving beyond  a narrow focus on data protection towards a broader understanding of data as a strategic national  resource that must be protected, shared, governed, and leveraged responsibly. The policy gets several important things right. Its recognition of data as an economic asset, its  focus on interoperability, its integration of AI governance, and its commitment to regional  alignment provide a strong foundation for future growth. Kenya has developed an ambitious framework for governing data in the digital age. The next  challenge will be transforming that framework into institutions, systems, and outcomes that  deliver measurable benefits for citizens, businesses, and government alike.