AI for NGOs in Kenya 2026: ODPC Rules and a 6-Step Checklist

Laptop keyboard, representing AI for NGOs in Kenya and data protection rules

Short answer: yes, Kenyan NGOs can use AI tools, but if the tool touches personal data (beneficiary lists, case notes, donor records, CVs), the Data Protection Act 2019 already applies, and the Office of the Data Protection Commissioner (ODPC) has now said how. Its draft AI Guidance Note, dated July 2026 and open for public comment from 1 to 17 August 2026, expects registration, a lawful basis for every processing step, human review of automated decisions and a written contract with each AI vendor. This guide turns that into a practical checklist for a small or mid-sized organisation.

As of October 2026. The note is still described as a draft in policy trackers, so confirm its final status on the ODPC website before you rewrite any policies.

By the NGOs.ke Editorial Team.

What does the ODPC AI Guidance Note actually cover?

The note applies to AI systems that process the personal data of people in Kenya. It reaches developers, but also organisations that deploy or buy AI products. That last group is where most NGOs sit: you are probably not building a model, you are pasting text into one or switching on an AI feature in software you already pay for.

Area What the draft expects
Registration Entities deploying AI that processes personal data register with the ODPC as data controllers or processors
Lawful basis Every processing operation linked to an AI system needs a valid basis under Section 30 of the Act (consent, contract, legal obligation, vital interests, public interest or legitimate interests)
Transparency Privacy notices say AI is used, what data it handles, and what any automated decision means for the person
Impact assessment A DPIA before high-risk uses: large-scale profiling, systematic monitoring, sensitive data, children’s data
Automated decisions No decision with significant effect made solely by a machine (Section 35); people can ask for human review and an explanation
Vendors Written processor agreements: no use beyond your instructions, security measures, deletion on termination
Cross-border transfers Assess and document data protection in the destination country; add contractual safeguards where adequacy is unclear
Breaches Notify the ODPC within 72 hours; notify affected people where the risk is high

The note lists credit scoring, health diagnostics, biometric recognition, employment screening, education involving children and generative AI among its high-risk categories, which call for a DPIA, human review and regular audits. It sets no implementation deadline, and enforcement runs through the existing 2021 complaints and enforcement regulations, which allow administrative fines and enforcement notices.

Why does this matter more for NGOs than for a typical business?

Because of whose data you hold. Programme records often include health status, displacement history, children’s details and survivor information. Under the Act, that is sensitive data, and the draft says it needs explicit consent or a specific legal basis. A privacy slip is also not only a compliance problem: it can put a beneficiary at risk and cost you donor trust.

Reports in early August 2026 also said the ODPC wants tighter oversight of offshore AI providers, so that they can be held to account for breaches that happen abroad. If your tool runs on servers outside Kenya, the transfer assessment is not optional paperwork.

Where do Kenya’s national AI strategy and sector guidance fit?

Kenya launched its National AI Strategy 2025-2030 on 27 March 2025, built on three pillars: AI digital infrastructure, a data ecosystem, and AI research and innovation. It was developed with civil society among the stakeholders consulted, with support from the EU and Germany’s BMZ through GIZ. It signals direction; the ODPC note is what tells you how to behave on Monday morning.

On the sector side, the Humanitarian Leadership Academy and NetHope published a quick-start guide on organisational AI readiness in March 2026. Its advice is refreshingly unglamorous: set guardrails first, write an AI policy with a list of approved tools so staff do not drift into “shadow AI”, build skills, test small and share results, and put data governance in place before you scale. It points to NetHope’s Humanitarian AI Code of Conduct, AI Suitability Toolkit and Data Governance Toolkit.

How do you start using AI responsibly? A 6-step checklist

  1. List what staff already use. Ask, without blame. Free chatbots, transcription apps and AI features in your CRM all count.
  2. Draw a red line on data. No names, ID numbers, health details or case notes in tools you have not vetted. Anonymise first, or keep the task off AI entirely.
  3. Approve a short tool list. For each: where data is stored, whether it trains on your inputs, and whether you can sign a processor agreement.
  4. Check your ODPC registration. If you handle personal data and are not registered, fix that before adding AI to the mix.
  5. Run a DPIA for anything high-risk. Eligibility scoring, screening applicants or analysing case files fall here. Keep a human making the final call.
  6. Update your privacy notice and train staff. Say plainly that you use AI and for what. Then review quarterly, because tools change faster than policies.

What are good low-risk uses for a small NGO?

  • Drafting and editing public-facing text such as newsletters and event notices, with no personal data pasted in.
  • Summarising published reports and donor guidelines.
  • Brainstorming proposal structures before you write with your own programme facts, as in our grant proposal guide.
  • Translating public information into Kiswahili or local languages, then checking it with a fluent speaker.

Higher-risk uses, such as triaging beneficiary applications or analysing survivor testimonies, need the full safeguards above, and sometimes the honest answer is not to use AI at all.

Frequently asked questions

Is the ODPC AI Guidance Note law?

Not by itself. It is guidance under the Data Protection Act 2019, and policy trackers list it as a draft that went through consultation in August 2026. The Act’s duties, including lawful basis and breach notification, already bind you.

Does my small NGO need to register with the ODPC?

If you process personal data you generally need to be registered as a data controller or processor. The draft note repeats that for AI deployers. Check the ODPC site for current thresholds and exemptions.

Can I paste beneficiary information into ChatGPT or similar tools?

Treat that as a no unless you have a lawful basis, a vendor agreement and a documented transfer assessment. The safer habit is to remove identifying details before using any general-purpose tool.

Do I need a Data Protection Officer?

The draft strongly recommends one where you do large-scale monitoring or handle sensitive data, particularly for high-risk AI. Even a small team should name someone accountable.

What if there is a breach involving an AI tool?

Notify the ODPC within 72 hours of becoming aware, and tell affected people where the risk to them is high.

This article is general information, not legal advice. For your own obligations, speak to a data protection lawyer or the ODPC directly.

Related reading: our data protection compliance guide for NGOs and the digital fundraising tools guide.

Leave your comment

Your email address will not be published. Required fields are marked *