Briefly

Kenya Accountants and Secretaries National Examinations Board (KASNEB) Biometric Registration of Students

circularKenya·KASNEB·Briefly Analysis

Abstract

The Kenya Accountants and Secretaries National Examinations Board (KASNEB) has introduced a Biometric Registration and Identification System (BRIS) for its students, requiring facial images and fingerprints for examination administration. This initiative, while aimed at enhancing examination integrity and efficiency, raises significant legal considerations under Kenya's Data Protection Act, 2019 (DPA). Biometric data is classified as sensitive personal data, necessitating strict adherence to principles of lawful basis, informed consent, purpose limitation, data minimisation, and robust security safeguards. Legal professionals must advise KASNEB and affected students on compliance with the DPA and its subsidiary regulations, particularly in light of recent High Court pronouncements on biometric data collection in Kenya.

Introduction

The Kenya Accountants and Secretaries National Examinations Board (KASNEB), a key examination body in Kenya, recently issued a notice announcing the mandatory biometric registration of its students. This initiative, termed the Biometric Registration and Identification System (BRIS), aims to bolster examination integrity, security, and efficiency by capturing students' facial images and fingerprints for identification throughout the examination cycle.

This development is of critical importance to practising attorneys and legal professionals, particularly those specialising in data protection, privacy law, and administrative law. The collection and processing of biometric data, classified as sensitive personal data under Kenyan law, triggers a host of legal obligations and rights. This article will delve into the legal framework governing biometric data in Kenya, analyse KASNEB's initiative against these provisions, and highlight the implications for students and the institution, drawing parallels with recent judicial interpretations.

Background

KASNEB operates as a State Corporation under the National Treasury and Economic Planning, established by the Government of Kenya. Its core mandate includes the development of syllabuses, conduct of professional, diploma, and certificate examinations, and the certification of candidates in various accountancy, finance, and governance disciplines. The introduction of BRIS falls within its broader objective of ensuring the credibility and integrity of its qualifications.

The overarching legal framework for data protection in Kenya is the Data Protection Act, 2019 (DPA), which came into force on 25th November 2019. The DPA gives effect to Article 31(c) and (d) of the Constitution of Kenya, 2010, which guarantees the right to privacy. Under the DPA, biometric data, encompassing fingerprints, facial recognition data, and iris scans, is explicitly categorised as sensitive personal data. This classification mandates a higher level of protection and more stringent conditions for its processing compared to ordinary personal data. Further elaborating on the DPA are the Data Protection (General) Regulations, 2021, which detail the rights of data subjects, obligations of data controllers and processors, and requirements for data protection impact assessments (DPIAs).

Analysis

KASNEB, in implementing BRIS, acts as a data controller and must therefore comply with the principles and obligations stipulated in the DPA and its regulations. The DPA requires that the processing of personal data, especially sensitive personal data like biometrics, must have a lawful basis. While KASNEB's stated purpose of enhancing examination integrity and security may be considered a legitimate interest or a statutory obligation related to its mandate, the specific legal justification for mandating biometric collection must be clearly articulated and align with Section 30 of the DPA.

A critical aspect is the requirement for informed consent. KASNEB has indicated that candidates must complete and sign a consent form prior to data collection. However, the DPA specifies that consent must be specific, informed, freely given, and unambiguous. Given the mandatory nature of the registration for selected examinations, questions may arise regarding the 'freely given' aspect of consent, particularly if students perceive it as a prerequisite without which they cannot sit for exams. The High Court, in *Katiba v Tools for Humanity and others* (the Worldcoin case), notably held that consent loses its legal basis when a meaningful reward (or, by extension, a penalty like exclusion from examinations) is a condition for providing sensitive data. This precedent underscores the need for KASNEB to ensure that consent is truly voluntary and that alternatives, if any, are clearly communicated.

Furthermore, the DPA mandates adherence to principles such as purpose limitation and data minimisation. KASNEB has assured that all biometric data will be handled with strict confidentiality and used solely for examination administration and related official purposes. This aligns with the purpose limitation principle, which dictates that data can only be used for the specific purpose for which it was collected. The principle of data minimisation requires that only the minimum necessary biometric data should be collected. KASNEB's plan to capture facial images and at least two fingerprints appears to be in line with typical biometric identification systems, but the necessity of each specific data point should be justifiable.

Another crucial obligation for KASNEB, as a data controller processing sensitive personal data on a large scale, is to conduct a Data Protection Impact Assessment (DPIA). A DPIA assesses the impact of processing operations on data subjects' rights and freedoms and is mandatory for high-risk activities, including the processing of biometric data. The *Kenya Union of Journalists v Kenya Broadcasting Corporation (KBC)* case highlighted the legal requirement for a DPIA for new technologies carrying high risk to data subjects, quashing a facial recognition system implemented without one. KASNEB must also implement robust security safeguards, including encryption and access controls, to protect the sensitive biometric data from breaches. The Office of the Data Protection Commissioner (ODPC) has also issued specific Guidance Notes for the Education Sector, which emphasise lawful, fair, and transparent processing, purpose limitation, and the need for parental consent when processing children's data, which may be relevant for younger students.

Finally, KASNEB, as a data controller, is required to register with the Office of the Data Protection Commissioner (ODPC). The ODPC's role extends to providing guidance, investigating complaints, and enforcing compliance with the DPA. The High Court's decision in the *Nubian Rights Forum & 2 others v. Attorney General & 6 others* case, which conditioned the implementation of a national biometric ID system on the enactment of a robust data protection law and clear regulatory framework, underscores the judiciary's commitment to safeguarding privacy in the context of large-scale biometric data collection.

Conclusion

KASNEB's introduction of a biometric registration system for students represents a significant step towards enhancing examination security and efficiency. However, it simultaneously places substantial obligations on the institution under Kenya's Data Protection Act, 2019. Legal practitioners advising educational institutions and students must ensure that the implementation of BRIS strictly adheres to the DPA's principles, particularly concerning the collection and processing of sensitive personal data.

Practitioners should scrutinise the consent mechanisms to ensure they are truly informed and freely given, advise on the necessity of a comprehensive Data Protection Impact Assessment, and verify the adequacy of security measures for biometric data. Students, as data subjects, retain rights of access, rectification, and erasure, which KASNEB must facilitate. The evolving jurisprudence from the Kenyan High Court, particularly in cases involving biometric data, signals a strong judicial stance on data protection. Therefore, continuous monitoring of KASNEB's implementation, engagement with the Office of the Data Protection Commissioner, and proactive legal advice will be crucial to navigate this intersection of technology, education, and privacy rights effectively.

Citations

  1. 1.Constitution of Kenya, 2010
  2. 2.Data Protection Act, No. 24 of 2019
  3. 3.Data Protection (General) Regulations, 2021
  4. 4.Nubian Rights Forum & 2 others v. Attorney General & 6 others; Child Welfare Society & 9 others (Interested Parties) [2020] eKLR, High Court of Kenya
  5. 5.Accountants Act, No. 15 of 2008
  6. 6.Certified Public Secretaries of Kenya Act, Cap 534 of 1988
  7. 7.Investment and Financial Analysts Act, No. 13 of 2015
  8. 8.Office of the Data Protection Commissioner (ODPC) Guidance Note on Biometric Data (2025)
  9. 9.Office of the Data Protection Commissioner (ODPC) Guidance Note for the Education Sector
AI Business Impact

How does this affect your business?

Get an AI analysis of this article grounded in your jurisdictions, practice areas, and any policy documents you've uploaded to Wansom.

Kenya Accountants and Secretaries National Examinations Board (KASNEB) Biometric Registration of Students | Briefly | Briefly