Article

The Advocate as Data Controller? AI Tools and Their Implications Under the Data Protection Act, 2019

August 7, 2026 · T.M.M & Partners Advocates

By Brian Mabeya

Confidentiality Is Not the Only Question

There are two different legal regimes in the room whenever a Kenyan advocate engages with and uses AI tools, and most advocates are thinking about only one of them.

Confidentiality is a duty owed to the client. The client can/may waive it. Data protection is a duty owed to the data subject — and in a great many of an advocate’s files, the data subject is not the advocate’s client at all. It is the opposing party. It is the witness. It is the child named in the custody file. None of them instructed the advocate. None of them can waive anything on the advocate’s behalf.

That asymmetry is where the exposure sits. And it may not be theoretical.

1. Prompting AI can be deemed as a processing act

Section 2 of the Data Protection Act (Cap. 411C) defines “processing” to include disclosure by transmission, dissemination, or otherwise making available. Pasting a witness statement, a demand letter, an affidavit or a due-diligence bundle into a chatbot may amount to a disclosure to a third-party AI platform. It requires a lawful basis under section 30.

It is worth reading section 72(1) slowly. A data controller who, without lawful excuse, discloses personal data in a manner incompatible with the purpose for which it was collected commits an offence. Under section 73, the general penalty is a fine of up to KES 3 million, imprisonment of up to ten years, or both.

2. An advocate’s files are full of sensitive personal data — more than is often assumed.

Section 2 defines “sensitive personal data” as data revealing a person’s race, health status, ethnic social origin, conscience, belief, genetic data, biometric data, property details, marital status, family details including the names of the person’s children, parents, spouse or spouses, sex or sexual orientation.

Read that list against an ordinary Kenyan practice:

Section 45(c)(i) of the DPA Act may provide a ground for processing sensitive personal data where it is necessary for the establishment, exercise or defence of a legal claim. Litigators are not without a basis. But that is a ground for processing the data in the conduct of the matter. It is not a standing licence to route it through any AI tool, and — as set out below — it does not answer the export question at all.

3. Cross-border transfers

Section 25(h) makes it a principle of data protection that personal data is not transferred outside Kenya unless there is proof of adequate safeguards or consent from the data subject. Section 48 then sets out when a transfer may lawfully occur: where the controller or processor has given proof to the Data Commissioner of appropriate safeguards, including jurisdictions with commensurate data protection laws, or where the transfer is necessary on one of the listed grounds.

Note the wording. Not “has documented internally”. Not “is satisfied that”. Has given proof to the Data Commissioner.

Then section 49(1), which is the provision I would put in front of every managing partner in the country: “The processing of sensitive personal data out of Kenya shall only be effected upon obtaining consent of the data subject and on obtaining confirmation of appropriate safeguards.”

Both limbs. Consent and safeguards.

Now put that next to Part 2 above. If an advocate uploads a succession file, a matrimonial file or a medical report to a foreign-hosted AI platform, section 49(1) requires the consent of the data subject. In an adversarial matter, the data subject may be the person on the other side of the case.

And the transfer happens whether or not it was intended. There is no contract to sign, no border to cross, no export declaration. Using a foreign-hosted AI platform is the transfer. It should also be said plainly that there is no publicly available list of jurisdictions the Data Commissioner has assessed as commensurate, and no approved model clauses. The obligation is strict; the compliance toolkit is still being built.

4. The Sole Practitioner Is Not Exempt From the Export Regime

Regulation 13(2) exempts a controller or processor from mandatory registration where it has an annual turnover or revenue below KES 5 million and fewer than ten employees. Both limbs. A firm with twelve employees and modest revenue is not exempt. A firm with six employees and KES 6 million in revenue is not exempt. If either threshold is crossed, the firm must register.

Second — and this is the part that matters here — regulation 13(3) provides that even an exempt firm must still comply with Part IV and Part VI of the Act. Part IV is the principles and obligations. Part VI is transfer of personal data outside Kenya.

So the sole practitioner who is genuinely below both thresholds, and who is genuinely exempt from registration, is still bound by sections 48 to 50 every time she uses a foreign AI tool on a client file. The exemption from registration is not an exemption from the export regime.

A related point: “provision of legal services” does not appear in the Third Schedule of sectors requiring registration regardless of turnover. But item 7 does read “property management including the selling of land” — and a conveyancing practice should at minimum take a view on whether that captures it. Note also that a firm may need to register twice, once as a controller and once as a processor, under regulation 4(3).

5. An AI platform qualifies as a Data Processor. Is There a Contract?

Section 42(2)(b) requires that a data controller and a data processor enter into a written contract providing that the processor acts only on the controller’s instructions and is bound by the controller’s obligations. Section 42(2)(a) requires the controller to opt for a processor giving sufficient guarantees.

A tick-box consumer licence does not do this. It does not bind the vendor to the firm’s instructions, retention limits, security standard or audit rights.

Point of Note: Free and consumer tiers commonly retain inputs for model training. Paid professional and enterprise tiers with contractual non-training guarantees, encryption and controlled retention are a different proposition. And tool selection is the advocate’s professional responsibility.

6. An Inadequate Impact Assessment Has Already Stopped a Company in Kenya

Section 31(1) requires a data protection impact assessment before processing that is likely to result in a high risk to the rights and freedoms of a data subject. Section 31(5) requires that the report be submitted 60 days before processing. Adopting an AI system that will handle sensitive personal data is a textbook trigger.

If that sounds like paperwork, consider Republic v Tools for Humanity Corporation (US) & others; Katiba Institute & others [2025] KEHC 5629 (KLR), delivered 5 May 2025. The High Court issued judicial review orders restraining further collection, processing or transfer of biometric data collected in Kenya where this was done without an adequate section 31 assessment, or on consent obtained through inducement, or — for certain respondents — without registering as data controllers or processors in Kenya.

An inadequate DPIA was not treated as a technicality. It was a ground for prohibition.

7. Could a Firm Notify a Breach in 72 Hours?

Section 43(1)(a) requires a controller to notify the Data Commissioner within seventy-two hours of becoming aware of a personal data breach carrying real risk of harm. Section 43(3) requires a processor to notify its controller within forty-eight hours. So: if an AI vendor notified a firm tomorrow of a breach at the model provider, could it tell the Data Commissioner whose data was exposed?

If AI tools are used, very few Kenyan law firms maintain a register of which tools have been used, and on which matters. Without an AI register, a firm cannot scope the breach, let alone notify it within three days.

8. The Practice Directions Are on the Way

In March 2026, the High Court at Milimani struck out a notice of motion and its supporting affidavit, Justice Bahati Mwamuye finding both to be machine-generated and non-compliant with Order 51 rule 13 and Order 19 rules 4 and 5 of the Civil Procedure Rules. The court’s position was that, as the law stands, AI output is not a proper substitute for a human-drawn document. The applicant there was self-represented, and the ruling turned on procedural defects rather than fabricated authorities.

The Judiciary has circulated a draft AI Policy and draft Practice Directions for comment, proposing a risk-tiered approach in which legal research tools require verification and disclosure, and AI-assisted filings carry a certificate of human verification. Read them now. They are a preview of the standard advocates will be held to.

9. The ODPC Draft Guidance Note on Artificial Intelligence, July 2026

In July 2026 the Office of the Data Protection Commissioner circulated a draft Guidance Note on Artificial Intelligence. It confirms the position set out above. A firm that uses an AI tool is an AI deployer within the scope of the Act; the lawful basis must be identified and documented before processing begins; repurposing operational data for AI training without a fresh basis is not permitted; a written processing agreement is required with any third-party AI provider; and transfers to offshore AI processors require a lawful transfer basis.

The Note remains in draft. Advocates should read it now, while it can still be shaped.

Six notable takeaways for Advocates using AI platforms

  1. Check your registration position against regulation 13(2) — both limbs — and consider whether you need to register as both controller and processor.
  2. Build an AI-use register: which tools, which matters, which categories of data, which jurisdiction. You cannot notify a breach you cannot scope.
  3. Adopt a written firm policy prohibiting client-identifying and sensitive personal data in consumer and free-tier services. Extend it expressly to pupils, paralegals and consultants.
  4. Obtain a section 42(2)(b) written contract with any tool that touches client data — or stop using it on client data.
  5. Run a section 31 assessment before adoption, not after a complaint. Diarise the sixty days.
  6. Verify every authority against Kenya Law or an official report. That duty cannot be delegated to a machine.