Skip to content

Data Privacy and Protection in Election Systems

By Linet Kwamboka · · 8 min read

0sharesX
Data Privacy and Protection in Election Systems
To qualify as a voter in a Kenyan election, one must be a Kenyan citizen, be above the age of 18, hold a national ID or passport, and register as a voter. After registration, voters are encouraged to verify their details through the online and mobile systems set up by the Independent Electoral and Boundaries Commission (IEBC), as required under the elections laws. The details collected include a voter's ID or passport number, name, age, gender, and birthdate — the same details verified through the online and mobile checks. Under Kenya's Data Protection Act, 2019, several of these fall squarely into the category of personal — and in some cases sensitive — data: date of birth, gender, and any identifying number such as a national ID or passport number. In 2017, this was exactly the category of data collected on 19,687,563 Kenyans, roughly 40% of the population at the time. Ten years on, the IEBC is preparing to register up to 28.5 million voters for 2027, more than 6 million above the 22.1 million on the roll in 2022. As of August 2026, about 2.9 million people had signed up since Continuous Voter Registration began in September 2025, and the commission is also doubling diaspora voter registration from 12 to 26 countries — meaning voter data will, for the first time at this scale, be collected, transmitted, and stored across borders. The volume of personal data at stake has only grown. The question this post asks is whether the safeguards around it have grown with it. The 2017 Case Study: A Cautionary Baseline The 2017 election cycle offers a case study in what happens when a system holding this much personal data is not built with data protection as a first principle. It's worth restating because much of it remains the baseline against which 2027 should be measured. No captcha. The initial voter verification system had no captcha — no mechanism to distinguish a human visitor from an automated script. Anyone reasonably competent with code could write a program to harvest the register at scale. A captcha was only added after public pressure, and even then, the system continued to return multiple layers of a citizen's personal data in exchange for nothing more than a single, guessable ID number. A database sold for $200. Systems in many developing-country contexts are porous enough to allow different datasets to be cross-referenced and stitched into a fuller identity profile. That the entire voters' register could reportedly be purchased for as little as $200 meant this data could be reconstructed into detailed individual profiles — the kind of profile that enables targeted, unconsented outreach to voters. This is precisely what played out in practice: a text message from a political aspirant that correctly identified the recipient and named their exact polling station, sent without consent and with no clear lawful basis for using that data that way. No meaningful access controls. Anyone with a mobile phone or an internet connection could, with enough persistence, retrieve most of the voter register. There was no friction requiring that a requester already know something about the voter before being handed the rest. The core lesson from 2017 was simple: data belonging to 40% of the country was collected under a legal framework — the Access to Information Act, 2016 — that named gender, age, birthdate, and identifying numbers as data warranting protection, yet the system built to hold that data did not reflect that standard. What's Changed — and What Hasn't — Ahead of 2027 Kenya's legal environment is genuinely stronger than it was in 2017. The Data Protection Act, 2019 is now in force, Article 31(c) of the Constitution still guarantees the right not to have information about one's private affairs unnecessarily required or revealed, and the Office of the Data Protection Commissioner (ODPC) has moved from a standing-up phase into active enforcement: draft Conduct of Compliance Audit regulations now formalise both announced and unannounced inspections, the regulator has begun issuing compensation orders to data subjects whose rights were breached, and a court has already ordered the deletion of biometric data collected without adequate consent or a data protection impact assessment. A Data Protection (Amendment) Bill, 2025 is also on the table, proposing new obligations around AI governance, algorithmic impact assessments, and cross-border data transfers. On paper, the accountability structure that was missing in 2017 now exists. But three developments specific to this election cycle show that the underlying risks haven't disappeared — they've changed shape. 1. System downtime is back on the agenda In July 2025, the IEBC's voter verification portal and its SMS shortcode (70000) went down for several days, locking out roughly 22 million registered voters from checking their own details. The commission attributed it to infrastructure migration meant to "enhance performance and security," but offered no timeline and little explanation while the outage was live. Civil society groups pointed to the silence itself as the problem: a system holding this much personal data going dark, with no public account of what was happening to that data during the migration, is not a reassuring way to build public trust ahead of 2027. Separately, a Public Procurement Administrative Review Board challenge has frozen tenders for both ballot papers and the Integrated Elections Management System, the technology backbone that will process this data — a reminder that the vendors entrusted with citizen data, and how they're vetted, matter as much as the systems themselves. 2. AI has changed what a data leak can be used for The 2017 breach was damaging because leaked data enabled targeted, unconsented political messaging — a single text message naming a voter's exact polling station. In 2026, the tools available to anyone wanting to do that at scale are dramatically more capable. Research tracking disinformation ahead of the 2027 polls has identified over a dozen coordinated campaigns using deepfakes, forged official documents, and fabricated newspaper front pages, some individual campaigns reaching well over 100,000 views, deployed to target specific politicians, ethnic communities, and civil society figures. The IEBC itself has now named "artificial intelligence-driven misinformation and deepfakes" alongside cyberattacks as one of the biggest risks to the 2027 election, and Kenya's national cyber incident response team recorded more than 3.36 billion cyber threat events in a single three-month window, with attackers increasingly using AI to make attacks harder to detect. The connection to citizen data protection is direct: the more precisely a bad actor can identify who you are, where you vote, and what you look and sound like, the more convincing an AI-generated forgery or a micro-targeted message becomes. A 2017-style breach combined with 2026-level generative AI is a materially more dangerous combination than either risk on its own — which is exactly why data minimisation and access control matter more now, not less. 3. The commission is naming these risks itself To its credit, the IEBC's Election Operations Plan 2025–27 lists countermeasures that didn't exist in 2017: an ICT Security and Network Operations Centre, upgraded server and backup infrastructure, an independent forensic audit of the voter register before it's certified for use, staff training on privacy and cybersecurity, and an explicit commitment to review its data protection framework. That the commission is naming cybersecurity and AI-driven disinformation as top-tier risks, rather than treating a breach as an unforeseeable event, is progress. The open question is whether these commitments are executed and independently verified before polls open, or whether they remain items on a plan. Recommendations for 2027 Citizen data is critical for national and subnational planning, and its integrity — not just its confidentiality — has to be protected. Several of the original recommendations from 2017 still hold, and a few new ones follow directly from what's changed. Streamline the data lifecycle. Collection, storage, access, and dissemination should follow one documented, auditable process rather than being handled piecemeal across departments and vendors, especially now that diaspora registration spans 26 countries and cross-border data transfer rules apply. Train the custodians. Everyone with access to voter data — IEBC staff, contracted vendors, ICT partners — needs to understand not just how to use the data but how to avoid introducing errors or duplications that make the register itself unreliable for decision-making. Limit access to those with a clear mandate. Article 31(c) of the Constitution still applies: citizens have a right not to have their private affairs unnecessarily revealed. Bulk access to the register should require documented clearance, not just a working internet connection. Anonymise for any mass-access use case. Public verification tools should confirm a person's own registration status without exposing enough detail to reconstruct someone else's profile — the exact failure mode that made the 2017 database valuable to resell. Bring the IEBC itself inside the ODPC's audit net. The ODPC's current enforcement priorities name finance, telecoms, health-tech, and digital platforms as high-risk sectors; a body holding sensitive data on up to 28.5 million citizens should be treated as at least as high a priority, with regular independent audits made public, not just referenced in a plan. Run a data protection impact assessment on the biometric register specifically, given that a Kenyan court has already ordered deletion of biometric data collected without one — the IEBC's own register should not be found to have the same gap. Communicate proactively during system downtime. The 2025 outage showed that silence during a maintenance window does as much damage to public confidence as the outage itself. A public status page and a defined communication protocol cost little and prevent a technical issue from becoming a trust crisis. Build a rapid-response verification capacity for AI-generated content targeting candidates, officials, or ordinary voters, in coordination with media houses and platforms, before the campaign period intensifies rather than after damage is done. Push the Data Protection (Amendment) Bill's AI and cross-border transfer provisions through before 2027, not after. In 2017, the recommendation was to get the data protection law right before it became law. That law now exists — the same discipline should apply to closing its remaining gaps before the next election, not in the post-mortem that follows it.
0sharesX

Newsletter

New essays, straight to your inbox

Occasional writing on data, AI and policy in Africa. No spam, unsubscribe anytime.

Data Governance & Privacy

Privacy in The Era of Big Data

‘Data is the currency we use to access free services’ In an age where the Internet does not forget, access to technology and technological devices is not only easy but cheap. People are using all kinds of tech products and services and most users sign on to these services without reading through the fine print […]

· Linet Kwamboka · 2 min read

Digital Economy

The Political Economy of Skills in the AI World.

The tech bros have over the past year or so made one message very clear. AI will replace most of our jobs in the very near future. Top of the chopping board in this messaging has been the replacement of computing and engineering jobs that just a few years ago were the crown jewel of […]

· Linet Kwamboka · 3 min read

AI & Africa

Unite and Conquer – How Africa Can Beat the Odds to Become an AI Hub

A few weeks ago, in his keynote to Kenyans, the president of Kenya admitted that building AI data centers in Kenya (as it is in many countries) is a pipe dream. This followed an agreement signed between Microsoft, The Government of Kenya and G42. He admitted that, to build an efficient data center requires about […]

· Linet Kwamboka · 4 min read