Kenya - Media Data Governance Guide
Data Governance Guide for Media Practice in Kenya (Media Council of Kenya draft)
Kenya
RAI-KE-NA-DGGMPXX-2025A Media Council of Kenya (MCK) draft providing guidance to media organisations on responsible handling of data, the ethical use of AI and algorithms in journalism, and alignment with Kenya's Data Protection Act, 2019. The document was released for public comment in January 2025 and aims to set baseline governance, transparency and accountability measures for media practice in Kenya.
Summary
Read full text ↗Plain English
Overview
The Media Council of Kenya (MCK) has produced a draft "Data Governance Guide for Media Practice in Kenya" as part of a suite of media-focused documents on AI, data and social media. The draft was prepared by an MCK technical committee and released for public comment in January 2025 to provide sector-tailored guidance on responsible handling of personal and non-personal data in journalistic practice, and on the ethical application of automated tools. The guide is explicitly designed to help newsrooms align editorial decision-making with legal obligations under the Data Protection Act, 2019 and related regulations while safeguarding press freedoms and public interest journalism. It combines operational measures (data inventories, retention schedules, breach reporting) with higher-level governance (oversight, roles and responsibilities) and provides sector-specific examples to support implementation by small and large media houses alike.
Definitions
The draft establishes working definitions tailored to media practice: "personal data" and "special categories" as per the Data Protection Act; "data processing" to include collection, storage, analysis and publication for reporting; "data controller" (typically the media house or publisher determining purposes) and "data processor" (third-party vendors and cloud providers used by media); "anonymisation" and "pseudonymisation" as risk-mitigation techniques; and "automated decision making" referencing algorithmic tools used in verification, content recommendation or audience analytics.
Governance and Institutional Framework
The guide recommends a governance model combining editorial oversight with a formal data governance function. It advises appointing a data focal person or Data Protection Officer where organisational scale requires, establishing a governance committee that includes editorial, legal and technical representation, and maintaining documented policies for data retention, access control and breach response. The draft positions the MCK as a convening authority for standards and training while recognising statutory enforcement by the Office of the Data Protection Commissioner (ODPC). It also recommends formal memoranda of understanding with technical vendors and templates for processor contracts to ensure alignment with the Data Protection Act, 2019 and associated regulations.
Key Focus Areas
The draft concentrates on several core domains: (1) Legal compliance and editorial decision-making: assessing legitimate interests and public interest exceptions when handling sensitive information; (2) Data lifecycle management: inventorying datasets, purpose limitation, retention and secure disposal; (3) Technical and organisational security: encryption, access controls, secure transfer and vendor governance; (4) Algorithmic systems and AI: requirement for safety testing, documentation of model inputs/outputs, and human oversight for automated verification or recommendation tools; (5) Transparency and audience engagement: disclosure of methods, data sources and use of automation; (6) Data subject rights: mechanisms to respond to correction, deletion and objections; and (7) Capacity-building: training, accredited trainers and community of practice for media professionals. Practical annexes include editorial checklists, breach-notification flowcharts and sample consent and data-sharing text for sourcing material.
Implementation Framework
The guide proposes a phased approach: initial gap analysis and data inventory; short-term fixes (policies, basic security, incident response); medium-term measures (DPIAs, contractual updates, staff training); and long-term embedding (audits, certified processes, periodic review). It emphasises proportionate measures for smaller outlets and prescribes scaled governance commensurate with processing risk. The draft encourages collaboration with the ODPC for technical guidance and cross-sector standards and suggests that MCK develop accredited training modules and a register of certified data and AI trainers to support roll-out.
Monitoring and Evaluation
MCK's draft sets out monitoring mechanisms including regular internal audits, publication of transparency reports, and submission of anonymised compliance summaries to MCK for peer benchmarking. It suggests indicators such as number of DPIAs completed, incidents reported and time to resolve data subject requests. Where appropriate the guide recommends independent assessments or external audits for high-risk processing and proposes an MCK-led peer review mechanism to foster continuous improvement.
Penalties, Liability, and Appeals
As a non-statutory sector guide, MCK's draft itself does not create criminal sanctions but makes clear that non-compliant conduct may attract enforcement under the Data Protection Act, 2019 and other laws. The guide outlines disciplinary and editorial remedies a media house may use for breaches of internal policy and recommends escalation paths to the ODPC where statutory breaches occur. It also explains rights of appeal and remedies for data subjects under existing legislation and encourages media houses to maintain insurance and legal support for potential liability arising from data handling and publication.
Relationship to Other Instruments
The draft situates itself alongside the Data Protection Act and regulations, the Kenyan Constitution's protections for freedom of expression and access to information, sectoral laws such as the Kenya Information and Communications Act, and national digital strategies. It recommends cross-references to national AI strategy and to international standards and guidance (for example those developed by UNESCO and international press freedom bodies) to ensure media practice remains consistent with broader policy frameworks.
International Alignment
The guide references international norms for data protection and ethical AI and proposes alignment with widely accepted principles like transparency, human oversight and non-discrimination. It highlights Kenya's participation in regional and global fora and suggests adoption of comparative practices (e.g., risk assessments, impact assessments and documentation) used in other jurisdictions to facilitate cross-border data sharing for investigative journalism while protecting rights.
Implementation Timeline
| Phase | Actions | Indicative timeframe |
|---|---|---|
| Phase 1 | Publication of draft; public consultation; gap analysis by media houses | Jan - Mar 2025 |
| Phase 2 | Policy adoption, basic training, appointment of focal persons | Apr - Sep 2025 |
| Phase 3 | Conduct DPIAs, vendor contract updates, implement monitoring | Oct 2025 - Mar 2026 |
| Phase 4 | External audit, peer review, revisions to guide | Apr - Dec 2026 |
Compliance Checklist
| Requirement | Yes/No | Notes |
|---|---|---|
| Data inventory completed | ||
| Retention policy in place | ||
| Designated data focal person/DPO | ||
| Processor contracts compliant | ||
| DPIA completed for high-risk systems | ||
| Incident response plan and logs | ||
| Transparency disclosures for automated systems |
Sources and References
| Source | Type |
|---|---|
| CALL FOR COMMENTS ON DATA GOVERNANCE GUIDELINES FOR MEDIA PRACTICE IN KENYA (Media Council of Kenya) | Primary Source |
| MCK Receives AI Taskforce Reports (Media Council of Kenya) | Primary Source |
| Data Protection Act, 2019 (Kenya Law) | Primary Source |
| Office of the Data Protection Commissioner (ODPC) | Primary Source |
This Media Council of Kenya (MCK) draft guide helps media organisations in Kenya responsibly manage data and ethically use artificial intelligence (AI) and algorithms in journalism, ensuring they comply with the country's Data Protection Act, 2019.
The guide applies to all media organisations in Kenya, from small outlets to large media houses, including their third-party data processors like cloud providers. It aims to set baseline governance, transparency, and accountability measures for journalistic practice. Media houses must establish a formal data governance function, potentially appointing a data focal person or Data Protection Officer (DPO), and maintain documented policies for data retention, access control, and breach response. They are also expected to manage the entire data lifecycle, from inventorying datasets and limiting their use to specific purposes, to ensuring secure disposal when no longer needed. Robust technical and organisational security measures, such as encryption and access controls, are required, and vendor contracts must align with data protection laws. For algorithmic systems and AI, the guide requires safety testing, documentation of model inputs and outputs, and human oversight for automated verification or content recommendation tools. Finally, media organisations must be transparent with audiences about data sources, methods, and any use of automation in reporting.
This document is currently a draft, published for public comment in January 2025, with a submission deadline later that month. While the guide itself doesn't have a formal effective date, it proposes a phased implementation timeline for media houses starting April 2025, following public consultation.
As a guideline, this document doesn't create new penalties. However, failing to follow its recommendations could lead to enforcement actions and significant fines under Kenya's Data Protection Act, 2019, enforced by the Office of the Data Protection Commissioner (ODPC). Media houses might also face internal disciplinary actions for breaches of their own policies. A practical pitfall is that the guide's strong emphasis on human oversight and transparency for AI tools, alongside the need for detailed documentation, might be a new and demanding area for many newsrooms.
Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.
What you must do — compliance checklist
0 / 12 marked completePlain-English obligations under Kenya - Media Data Governance Guide. Not legal advice — verify against the official text before relying on it.
- #1CriticalGovernance and Institutional Framework⏰ Sep 30, 2025
Applies to: Media organizations processing personal data.
“advises appointing a data focal person or Data Protection Officer where organisational scale requires”
- #2CriticalKey Focus Areas⏰ Mar 31, 2025
Applies to: Media organizations handling data.
“Data lifecycle management: inventorying datasets, purpose limitation, retention and secure disposal”
- #3CriticalGovernance and Institutional Framework⏰ Sep 30, 2025
Applies to: Media organizations processing data.
“maintaining documented policies for data retention, access control and breach response”
- #4CriticalGovernance and Institutional Framework⏰ Mar 31, 2026
Applies to: Media organizations using third-party data processors.
“recommends formal memoranda of understanding with technical vendors and templates for processor contracts to ensure alignment with the Data Protection Act, 2019”
- #5CriticalImplementation Framework⏰ Mar 31, 2026
Applies to: Media organizations undertaking high-risk data processing.
“medium-term measures (DPIAs, contractual updates, staff training)”
- #6CriticalKey Focus Areas⏰ Sep 30, 2025
Applies to: Media organizations processing data.
“Technical and organisational security: encryption, access controls, secure transfer and vendor governance”
- #7CriticalGovernance and Institutional Framework⏰ Sep 30, 2025
Applies to: Media organizations processing data.
“maintaining documented policies for data retention, access control and breach response”
- #8CriticalKey Focus Areas
Applies to: Media organizations processing personal data.
“Data subject rights: mechanisms to respond to correction, deletion and objections”
- #9ImportantKey Focus Areas
Applies to: Media organizations using algorithmic systems and AI.
“requirement for safety testing, documentation of model inputs/outputs, and human oversight for automated verification or recommendation tools”
- #10ImportantKey Focus Areas
Applies to: Media organizations using automated tools or AI.
“Transparency and audience engagement: disclosure of methods, data sources and use of automation”
- #11ImportantKey Focus Areas⏰ Sep 30, 2025
Applies to: Media organizations.
“Capacity-building: training, accredited trainers and community of practice for media professionals.”
- #12RecommendedMonitoring and Evaluation
Applies to: Media organizations.
“MCK's draft sets out monitoring mechanisms including regular internal audits”
Related Regulations
Media Handbook for Reporting on Artificial Intelligence in Kenya (Media Council of Kenya draft)
Kenya95% similar
Guide on the Use of Social Media and the Internet for Media Practice in Kenya (Media Council of Kenya draft)
Kenya95% similar
DKS 3007:2024 Information technology — Artificial Intelligence — Code of Practice for AI Applications
Kenya89% similar
Motion on the Formulation of a Regulatory Framework on Artificial Intelligence (National Assembly Motion)
Kenya88% similar
Guidelines for the Responsible Use of Artificial Intelligence in Media
Ukraine87% similar
© Regulations.AI — created on 13-Jun-2026