Kenya - Media Data Governance Guide

Data Governance Guide for Media Practice in Kenya (Media Council of Kenya draft)

Kenya

RAI-KE-NA-DGGMPXX-2025
Draft(Being written or scoped)
GuidelineData Protection and PrivacyGovernance and OversightAccountability and Documentation
Export PDF

A Media Council of Kenya (MCK) draft providing guidance to media organisations on responsible handling of data, the ethical use of AI and algorithms in journalism, and alignment with Kenya's Data Protection Act, 2019. The document was released for public comment in January 2025 and aims to set baseline governance, transparency and accountability measures for media practice in Kenya.

Overview

The Media Council of Kenya (MCK) has produced a draft "Data Governance Guide for Media Practice in Kenya" as part of a suite of media-focused documents on AI, data and social media. The draft was prepared by an MCK technical committee and released for public comment in January 2025 to provide sector-tailored guidance on responsible handling of personal and non-personal data in journalistic practice, and on the ethical application of automated tools. The guide is explicitly designed to help newsrooms align editorial decision-making with legal obligations under the Data Protection Act, 2019 and related regulations while safeguarding press freedoms and public interest journalism. It combines operational measures (data inventories, retention schedules, breach reporting) with higher-level governance (oversight, roles and responsibilities) and provides sector-specific examples to support implementation by small and large media houses alike.

Definitions

The draft establishes working definitions tailored to media practice: "personal data" and "special categories" as per the Data Protection Act; "data processing" to include collection, storage, analysis and publication for reporting; "data controller" (typically the media house or publisher determining purposes) and "data processor" (third-party vendors and cloud providers used by media); "anonymisation" and "pseudonymisation" as risk-mitigation techniques; and "automated decision making" referencing algorithmic tools used in verification, content recommendation or audience analytics.

Governance and Institutional Framework

The guide recommends a governance model combining editorial oversight with a formal data governance function. It advises appointing a data focal person or Data Protection Officer where organisational scale requires, establishing a governance committee that includes editorial, legal and technical representation, and maintaining documented policies for data retention, access control and breach response. The draft positions the MCK as a convening authority for standards and training while recognising statutory enforcement by the Office of the Data Protection Commissioner (ODPC). It also recommends formal memoranda of understanding with technical vendors and templates for processor contracts to ensure alignment with the Data Protection Act, 2019 and associated regulations.

Key Focus Areas

The draft concentrates on several core domains: (1) Legal compliance and editorial decision-making: assessing legitimate interests and public interest exceptions when handling sensitive information; (2) Data lifecycle management: inventorying datasets, purpose limitation, retention and secure disposal; (3) Technical and organisational security: encryption, access controls, secure transfer and vendor governance; (4) Algorithmic systems and AI: requirement for safety testing, documentation of model inputs/outputs, and human oversight for automated verification or recommendation tools; (5) Transparency and audience engagement: disclosure of methods, data sources and use of automation; (6) Data subject rights: mechanisms to respond to correction, deletion and objections; and (7) Capacity-building: training, accredited trainers and community of practice for media professionals. Practical annexes include editorial checklists, breach-notification flowcharts and sample consent and data-sharing text for sourcing material.

Implementation Framework

The guide proposes a phased approach: initial gap analysis and data inventory; short-term fixes (policies, basic security, incident response); medium-term measures (DPIAs, contractual updates, staff training); and long-term embedding (audits, certified processes, periodic review). It emphasises proportionate measures for smaller outlets and prescribes scaled governance commensurate with processing risk. The draft encourages collaboration with the ODPC for technical guidance and cross-sector standards and suggests that MCK develop accredited training modules and a register of certified data and AI trainers to support roll-out.

Monitoring and Evaluation

MCK's draft sets out monitoring mechanisms including regular internal audits, publication of transparency reports, and submission of anonymised compliance summaries to MCK for peer benchmarking. It suggests indicators such as number of DPIAs completed, incidents reported and time to resolve data subject requests. Where appropriate the guide recommends independent assessments or external audits for high-risk processing and proposes an MCK-led peer review mechanism to foster continuous improvement.

Penalties, Liability, and Appeals

As a non-statutory sector guide, MCK's draft itself does not create criminal sanctions but makes clear that non-compliant conduct may attract enforcement under the Data Protection Act, 2019 and other laws. The guide outlines disciplinary and editorial remedies a media house may use for breaches of internal policy and recommends escalation paths to the ODPC where statutory breaches occur. It also explains rights of appeal and remedies for data subjects under existing legislation and encourages media houses to maintain insurance and legal support for potential liability arising from data handling and publication.

Relationship to Other Instruments

The draft situates itself alongside the Data Protection Act and regulations, the Kenyan Constitution's protections for freedom of expression and access to information, sectoral laws such as the Kenya Information and Communications Act, and national digital strategies. It recommends cross-references to national AI strategy and to international standards and guidance (for example those developed by UNESCO and international press freedom bodies) to ensure media practice remains consistent with broader policy frameworks.

International Alignment

The guide references international norms for data protection and ethical AI and proposes alignment with widely accepted principles like transparency, human oversight and non-discrimination. It highlights Kenya's participation in regional and global fora and suggests adoption of comparative practices (e.g., risk assessments, impact assessments and documentation) used in other jurisdictions to facilitate cross-border data sharing for investigative journalism while protecting rights.

Implementation Timeline

PhaseActionsIndicative timeframe
Phase 1Publication of draft; public consultation; gap analysis by media housesJan - Mar 2025
Phase 2Policy adoption, basic training, appointment of focal personsApr - Sep 2025
Phase 3Conduct DPIAs, vendor contract updates, implement monitoringOct 2025 - Mar 2026
Phase 4External audit, peer review, revisions to guideApr - Dec 2026

Compliance Checklist

RequirementYes/NoNotes
Data inventory completed
Retention policy in place
Designated data focal person/DPO
Processor contracts compliant
DPIA completed for high-risk systems
Incident response plan and logs
Transparency disclosures for automated systems

Sources and References

SourceType
CALL FOR COMMENTS ON DATA GOVERNANCE GUIDELINES FOR MEDIA PRACTICE IN KENYA (Media Council of Kenya)Primary Source
MCK Receives AI Taskforce Reports (Media Council of Kenya)Primary Source
Data Protection Act, 2019 (Kenya Law)Primary Source
Office of the Data Protection Commissioner (ODPC)Primary Source
Plain English

This Media Council of Kenya (MCK) draft guide helps media organisations in Kenya responsibly manage data and ethically use artificial intelligence (AI) and algorithms in journalism, ensuring they comply with the country's Data Protection Act, 2019.

The guide applies to all media organisations in Kenya, from small outlets to large media houses, including their third-party data processors like cloud providers. It aims to set baseline governance, transparency, and accountability measures for journalistic practice. Media houses must establish a formal data governance function, potentially appointing a data focal person or Data Protection Officer (DPO), and maintain documented policies for data retention, access control, and breach response. They are also expected to manage the entire data lifecycle, from inventorying datasets and limiting their use to specific purposes, to ensuring secure disposal when no longer needed. Robust technical and organisational security measures, such as encryption and access controls, are required, and vendor contracts must align with data protection laws. For algorithmic systems and AI, the guide requires safety testing, documentation of model inputs and outputs, and human oversight for automated verification or content recommendation tools. Finally, media organisations must be transparent with audiences about data sources, methods, and any use of automation in reporting.

This document is currently a draft, published for public comment in January 2025, with a submission deadline later that month. While the guide itself doesn't have a formal effective date, it proposes a phased implementation timeline for media houses starting April 2025, following public consultation.

As a guideline, this document doesn't create new penalties. However, failing to follow its recommendations could lead to enforcement actions and significant fines under Kenya's Data Protection Act, 2019, enforced by the Office of the Data Protection Commissioner (ODPC). Media houses might also face internal disciplinary actions for breaches of their own policies. A practical pitfall is that the guide's strong emphasis on human oversight and transparency for AI tools, alongside the need for detailed documentation, might be a new and demanding area for many newsrooms.

Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.

What you must do — compliance checklist

0 / 12 marked complete

Plain-English obligations under Kenya - Media Data Governance Guide. Not legal advice — verify against the official text before relying on it.

  1. #1CriticalGovernance and Institutional FrameworkSep 30, 2025

    Applies to: Media organizations processing personal data.

    advises appointing a data focal person or Data Protection Officer where organisational scale requires
  2. #2CriticalKey Focus AreasMar 31, 2025

    Applies to: Media organizations handling data.

    Data lifecycle management: inventorying datasets, purpose limitation, retention and secure disposal
  3. #3CriticalGovernance and Institutional FrameworkSep 30, 2025

    Applies to: Media organizations processing data.

    maintaining documented policies for data retention, access control and breach response
  4. #4CriticalGovernance and Institutional FrameworkMar 31, 2026

    Applies to: Media organizations using third-party data processors.

    recommends formal memoranda of understanding with technical vendors and templates for processor contracts to ensure alignment with the Data Protection Act, 2019
  5. #5CriticalImplementation FrameworkMar 31, 2026

    Applies to: Media organizations undertaking high-risk data processing.

    medium-term measures (DPIAs, contractual updates, staff training)
  6. #6CriticalKey Focus AreasSep 30, 2025

    Applies to: Media organizations processing data.

    Technical and organisational security: encryption, access controls, secure transfer and vendor governance
  7. #7CriticalGovernance and Institutional FrameworkSep 30, 2025

    Applies to: Media organizations processing data.

    maintaining documented policies for data retention, access control and breach response
  8. #8CriticalKey Focus Areas

    Applies to: Media organizations processing personal data.

    Data subject rights: mechanisms to respond to correction, deletion and objections
  9. #9ImportantKey Focus Areas

    Applies to: Media organizations using algorithmic systems and AI.

    requirement for safety testing, documentation of model inputs/outputs, and human oversight for automated verification or recommendation tools
  10. #10ImportantKey Focus Areas

    Applies to: Media organizations using automated tools or AI.

    Transparency and audience engagement: disclosure of methods, data sources and use of automation
  11. #11ImportantKey Focus AreasSep 30, 2025

    Applies to: Media organizations.

    Capacity-building: training, accredited trainers and community of practice for media professionals.
  12. #12RecommendedMonitoring and Evaluation

    Applies to: Media organizations.

    MCK's draft sets out monitoring mechanisms including regular internal audits

© Regulations.AI — created on 13-Jun-2026