No ID, no entry into a building? What data protection law says on refusing to share personal details

Security guards at malls, office blocks and even government buildings routinely demand personal details such as names, national ID numbers and phone contacts before allowing entry. But under Kenyan law, refusing to share personal data does not automatically give a building the right to deny access, according to data protection lawyers.

‘Denial of entry is not automatic or arbitrary,’ says Mary Audi, a senior associate advocate at Muri Mwaniki Thige and Kageni Advocates.

‘A building may only deny entry where the data requested is lawful, necessary and proportionate. Refusal alone does not justify exclusion.’

Her colleague, Fridah Muriithi, an associate advocate at the firm, says the starting point is the Constitution.

‘Article 31 of the Constitution guarantees the right to privacy, including the right not to have information relating to one’s private affairs unnecessarily required or revealed,’ she says.

The legal threshold, however, differs depending on whether the premises are privately or publicly owned.

Private buildings such as malls, office towers and residential complexes may impose reasonable access conditions as an exercise of property rights. Government buildings, on the other hand, are subject to stricter constitutional scrutiny and must justify any limitation on access.

‘Any restriction imposed by a State agency must be lawful, reasonable and consistent with constitutional rights,’ Ms Audi says.

The primary law governing personal data collection in such situations is the Data Protection Act, 2019 (DPA), read together with Article 31 of the Constitution. The Act regulates how personal data is collected, processed, stored and shared and applies to any entity that processes personal data, including building owners and security managers.

‘The Data Protection Act requires that data processing be lawful, fair and transparent,’ Ms Muriithi says.

‘A building collecting visitor information qualifies as a data controller or data processor and must comply with the Act.’

Not all personal data is treated equally under the law. According to the advocates, buildings may lawfully request basic identification details, but only where justified by a legitimate purpose such as security.

‘Information such as a visitor’s name, national ID or passport number, vehicle registration details, and time of entry and exit may be lawful if genuinely necessary for security,’ Ms Audi says.

However, the law draws a clear line when it comes to sensitive personal data.

‘Biometric data such as fingerprints or facial recognition, as well as health information or religious and political affiliation, requires explicit consent and a much higher standard of protection,’ Ms Muriithi says.

‘Routine or blanket collection of such data is unlawful.’

Crucially, refusing to provide personal data does not, on its own, give a building the right to lock someone out.

‘Denial of entry must be reasonable, proportionate and justifiable,’ Ms Audi says. ‘Blanket policies that demand non-essential data as a condition of entry are unlikely to meet the legal test.’

Consent, once given, is also not permanent. Under the Data Protection Act, individuals have the right to withdraw consent at any time.

‘Once consent is withdrawn, processing must stop unless there is another lawful basis for retaining the data,’ Ms Muriithi says.

Buildings that collect visitor data carry significant legal obligations. The Act requires data controllers to implement appropriate technical and organisational measures to safeguard personal data against unauthorised access, loss or misuse.

Depending on the scale and nature of processing, they may also be required to register with the Office of the Data Protection Commissioner (ODPC) and appoint a Data Protection Officer.

Failure to comply can attract serious penalties. The Data Protection Act empowers the ODPC to impose administrative fines of up to Sh5 million or 1 per cent of an entity’s annual turnover, or both.

‘In addition to regulatory penalties, individuals who suffer damage, including financial loss, distress or reputational harm, are entitled to compensation,’ Ms Muriithi says.

Certain violations may also attract criminal sanctions.

Buildings often justify data collection on security grounds, but the advocates caution that security is not a blank cheque.

‘Personal data may only be collected for security purposes where there is a legitimate and lawful security interest, such as crime prevention or public safety,’ Ms Audi says.

She adds: ‘The data must still be relevant, proportionate and limited to what is strictly necessary.’

While no Kenyan court has directly ruled on denial of entry solely due to refusal to share personal data, regulators have issued guidance.

The ODPC has warned that demanding excessive information, such as phone numbers, home addresses or occupations, as a condition of entry violates the Data Protection Act.

Individuals who believe they have been unlawfully denied entry have several avenues for redress. They may lodge a complaint with the ODPC, petition the High Court for violation of the constitutional right to privacy, or seek judicial review where a government agency is involved.

For members of the public, the advocates advise caution: Visitors should ask why their data is required, provide only the minimum information necessary and request to see a building’s privacy notice. Upon exiting, they may formally request deletion of their entry records once the security purpose has been fulfilled.

‘Privacy is not a courtesy extended by buildings,’ Ms Audi says. ‘It is a constitutional right, and any limitation must meet strict legal standards.’

Leave a Reply

Your email address will not be published. Required fields are marked *