Skip to content
MMS Advocates

Can the Kenyan Government Monetise eCitizen Data Without Violating Privacy Rights?

Maureen Mutai··4 min read

Kenya’s increasing transition into a digital government has significantly expanded the amount of citizen data collected through platforms such as eCitizen and other State-managed systems. From birth registration and immigration records to tax compliance, business registration and land transactions, the Government now holds vast amounts of information capable of revealing not only individual identities, but also behavioural, financial and demographic patterns of the population. Recent indications that the Government intends to commercialise anonymised or non-personal public datasets have therefore raised important legal and constitutional questions regarding privacy, consent and ownership of citizen data.

At face value, the proposal appears commercially sensible. Data has become one of the world’s most valuable economic resources, and governments globally are increasingly exploring ways to utilise public-sector data to support research, innovation, artificial intelligence development and economic growth. In Kenya’s case, monetisation of public datasets is being presented as part of the country’s broader digital economy strategy. However, the legal concerns begin where the distinction between “personal” and “non-personal” data becomes less certain in practice.

The assumption that anonymised data ceases to carry privacy implications is no longer entirely convincing in the age of artificial intelligence and advanced data analytics. Modern AI systems are capable of cross-referencing datasets from multiple sources and, in some cases, re-identifying individuals from information that was previously considered anonymous. Demographic information, location patterns, transactional records and behavioural trends can collectively reveal identities when analysed alongside publicly available or privately held datasets. This means that anonymisation may reduce privacy risks, but it does not necessarily eliminate them altogether.

This exposes one of the limitations within Kenya’s current data protection framework. The Data Protection Act, 2019 primarily regulates the processing of personal data and establishes obligations relating to lawful collection, consent, storage and disclosure. However, the Act was enacted before the rapid advancement of generative AI and large-scale machine learning systems that now possess the capability to infer or reconstruct personal identities from fragmented data points. Consequently, while the law provides an important foundation for privacy protection, it does not comprehensively address emerging risks associated with AI-driven re-identification or the commercial exploitation of large-scale public datasets.

Equally significant is the question of consent. Most Kenyans who submit information through eCitizen and other government platforms do so for specific administrative purposes such as obtaining identification documents, paying taxes, registering businesses or accessing public services. It is difficult to argue that citizens meaningfully contemplated or consented to secondary commercial use of that information by the State. Consent under data protection law is intended to be informed, specific and voluntary. Where citizens are compelled to provide data in order to access essential government services, the imbalance of power between the State and the individual raises legitimate concerns about whether any subsequent commercial use can truly be said to rest on free and informed consent.

These concerns are closely tied to Article 31 of the Constitution, which guarantees every person the right to privacy, including the right not to have information relating to their family or private affairs unnecessarily required or revealed. Privacy under the Constitution is not limited to protection from unlawful disclosure alone; it also extends to informational autonomy and the legitimate expectation that personal information collected for one purpose will not be repurposed beyond reasonable public expectation without proper legal safeguards.

The debate also raises an unresolved question regarding ownership of public-sector data. While the Government may exercise custodial control over information collected through State systems, that does not necessarily translate into unrestricted proprietary rights over citizen-generated data. There remains a compelling argument that individuals retain residual informational rights over data derived from their identities, activities and interactions with public institutions. In that sense, the State functions less as an owner and more as a trustee or custodian obligated to manage such information in a manner consistent with constitutional values and public interest obligations.

The commercialisation of public data further risks transforming citizens into involuntary subjects of economic extraction within the digital economy. Citizens provide information to the State primarily because the law requires it, not because they seek participation in a data marketplace. If government-held data becomes a revenue-generating asset without adequate transparency, accountability and safeguards, there is a danger that citizens may effectively become “data subjects of commerce” without meaningful participation in decisions regarding how their information is monetised or shared.

There is also the broader concern of surveillance capitalism within government structures. Historically, surveillance capitalism has largely been associated with private technology companies that monetise user behaviour and digital activity. However, when governments begin aggregating, analysing and commercialising population-scale datasets, similar risks emerge within the public sector itself. Without strict legal limitations, oversight mechanisms and transparency obligations, the monetisation of public data may gradually blur the line between digital governance and state-enabled surveillance economies.

Kenya’s digital transformation agenda is both necessary and inevitable. The challenge, however, lies in ensuring that innovation and economic policy do not outpace constitutional protections. The commercial use of public-sector data cannot be approached solely as a technological or revenue-generation issue. It is fundamentally a constitutional question touching on dignity, autonomy, consent and the relationship between citizens and the State in the digital era. Before any large-scale data monetisation framework is implemented, there is need for clearer legislation, stronger safeguards on anonymisation standards, transparent public participation and more robust accountability structures capable of protecting citizens from misuse of their information in an increasingly data-driven society.

Bring us the facts.

We will tell you what the law does with them.