TwinEthos homeRequest access

Law

Kenya Data Protection Act 2019, s. 35

Parliament of Kenya; Office of the Data Protection Commissioner · KE · 1 provision encoded · verified against the official source as of 2026-10-03.

Informational data, not legal advice. Summaries and rules have not been reviewed by a lawyer: always verify official law text for decisions. A suggested guard is intended to address each rule; adding it is not a statement of compliance to that law.

AI-adjacent law General privacy or biometric law, included only where AI data flows trigger it; reported apart from AI-specific law.

Official text: www.odpc.go.ke.

Trust and provenance 2 official sources · last verified 3 Oct 2026 · not reviewed by a lawyer · 1 of 1 provision audit-grade · release 2026.10.03.3

Where this instrument's data comes from, how current it is, and what has and has not been checked. Each provision below has its own panel.

Official sources
Lanes
Binding law — in force 1
Verification
Sources last verified 3 Oct 2026; each provision states how.
Data release
Data release 2026.10.03.3, data as of 3 Oct 2026, schema 0.3.9.
Legal review
None of the 1 provision has been reviewed by a lawyer; no TwinEthos rule has been legally reviewed yet. Treat each as research to check against the official text; it is not legal advice. Open questions for counsel on them: 1.
Audit standard
1 of 1 provision audit-grade. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors
1 detector, all experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify. Each provision lists its detectors' known limits.
Changes
  • 2026.10.03.3 (3 Oct 2026): 1 provision added

Each data release records which provisions changed; the full list is on Changes.

Binding law — in force AI-adjacent law

Solely automated significant decisions need written notice and, on request, reconsideration or a new decision with human involvement (Kenya DPA s. 35)

s. 35(1) (right not to be subject to solely automated decisions) · official text · In force: applies since 25 Nov 2019 · KE

Kenya's Data Protection Act, 2019 gives every data subject a right not to be subject to a decision based solely on automated processing, including profiling, that produces legal effects or significantly affects them (s. 35(1)), except where necessary for a contract, authorised by law with safeguards, or based on consent (s. 35(2)). Where such a decision is taken, the controller or processor must notify the person in writing as soon as reasonably practicable, and the person may ask it to reconsider the decision or take a new decision not based solely on automated processing (s. 35(3)); the request must be considered and complied with, and the person told in writing of the steps and outcome (s. 35(4)). The 2021 General Regulations (reg. 22(2)) add: inform people of automated decision-making, give meaningful information about the logic, explain its significance and consequences, prevent errors, eliminate discriminatory effects and ensure the person can obtain human intervention and express a view. Detect a model output that becomes a decision about a person with no automated-decision notice and reconsideration route, and no human decision.

Trust and provenance not reviewed by a lawyer · audit-grade · source verified 3 Oct 2026 · release 2026.10.03.3
Lane
Binding law — in force In force: applies since 25 Nov 2019
Official source
s. 35(1) (right not to be subject to solely automated decisions) · captured 3 Oct 2026 · anchor hash (SHA-256) 59f008ec08ae… · 9 more anchors in the data release
Verification
Quoted text found word for word in the captured official document (3 Oct 2026). Source last verified 3 Oct 2026: checked against the captured official document; not in the weekly watcher's list; checked against the captured document.
Data release
Data release 2026.10.03.3, data as of 3 Oct 2026, schema 0.3.9.
Legal review
Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
Audit standard
Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors

1 detector (data flow), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.

Known limits:

  • The logic explanation and error-prevention duties of reg. 22(2) are not detected
  • Decisions without legal or significant effect are outside s. 35; the notice may be sent by a separate letters service.

Who it applies to

  • Duty falls on: controller, processor
  • Systems covered: automated decision, consequential decision
  • Data controllers and processors established or ordinarily resident in Kenya processing there, or not established there but processing personal data of data subjects located in Kenya (s. 4(b)), that take decisions with legal or significant effects based solely on automated processing. In force from 2019-11-25 (date of commencement printed in the Act); reg. 22 of the 2021 Regulations (gazetted 31 December 2021) adds duties. Whether the s. 35(3) notice and reconsideration apply also to decisions taken under a s. 35(2) exception is a counsel question.
  • Not covered:
    • Processing by an individual in a purely personal or household activity, processing necessary for national security or public interest, and disclosure required by law or court order (s. 51(2))
  • Whether it applies depends on facts outside the code; a person has to decide.

The guard to add

Route significant automated decisions through meaningful human review, or wire in an automated-decision notice, reasons, human intervention, a way to give a view, and contest.

At the point where model output becomes a significant decision about a person (approve, deny, underwrite, set_status), either queue the case for a reviewer who weighs the evidence and can change the outcome before it takes effect (review_queue.enqueue, requires_human_review), or, where the decision stays solely automated, record the permitted basis for that decision type and wire the safeguards in. Those safeguards are a notice in the decision message that it was made by automated processing, reasons the person can read, and request_human_review or contest routes where the person can give their view and have a human reconsider. A reviewer who approves every case without examining it does not make the decision non-automated, so the review records reviewer identity, the evidence viewed, and the outcome.

Where it goes: 1 application source code, 9 AI output handling, 15 agent action surface, 14 user-facing text.

What this provision adds:

  • Notify the person in writing, as soon as reasonably practicable, that the decision was based solely on automated processing.
  • On request, reconsider the decision or take a new one not based solely on automated processing, then tell the person in writing the steps taken and the outcome.
  • Give meaningful information about the logic involved and ensure the person can obtain human intervention and express a view (reg. 22(2)).

Example (Python + OpenAI SDK), before:

verdict = client.chat.completions.create(model=MODEL, messages=msgs).choices[0].message.content
if verdict.strip() == 'deny':
    deny(applicant)
    send_decision_email(applicant, 'Your application was not approved.')

After:

out = client.chat.completions.create(model=MODEL, messages=msgs,
                                     response_format={'type': 'json_object'})
result = json.loads(out.choices[0].message.content)
if result['decision'] == 'deny':
    if requires_human_review('credit'):                 # a person decides
        review_queue.enqueue(applicant.id, proposal=result)
    else:                                               # solely automated, recorded basis
        deny(applicant, basis=DECISION_BASIS['credit'], reasons=result['reasons'])
        send_decision_email(applicant, render('adm_denial.txt', notice=ADM_NOTICE,
            reasons=result['reasons'], contest_url=f'{BASE}/decisions/{applicant.id}/contest'))

Control: Solely-automated significant decision without human-intervention safeguards. The same guard addresses 15 items with binding law in 15 jurisdictions. Engineering guidance, not legal advice.

Related incidents

No guardrail sits on this exact control; these incidents are cited by guardrails on related controls.

Rule id ke-dpa-s35.automated-decision-notice-and-reconsideration · review status: primary source derived

Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.