This Practice Note treats AI procurement as a governance decision rather than an information-technology purchase, and sets out the due diligence, contractual protections, and governance oversight Kenyan organisations should apply before deploying an AI system. It situates procurement practice against Section 41 of the Data Protection Act, 2019, the Artificial Intelligence Bill, 2026, and the constitutional obligations confirmed in Wangai & 2 Others v Cabinet Secretary for ICT & Another.
AI procurement is a governance decision, not merely an information-technology purchase: the contractual terms agreed at the procurement stage largely determine an organisation's ability to comply with Section 41 of the Data Protection Act, 2019. Kenya has no dedicated AI statute yet, but the Artificial Intelligence Bill, 2026 would impose a risk-based regime on top of existing data protection obligations. A Data Protection Impact Assessment carried out before a vendor is selected, not after go-live, is the clearest evidence of Section 41 compliance an organisation can produce.
- AI procurement is a governance decision, not merely an information-technology purchase: the contractual terms agreed at the procurement stage largely determine an organisation's ability to comply with Section 41 of the Data Protection Act, 2019.
- Kenya has no dedicated AI statute yet, but the Artificial Intelligence Bill, 2026 — a Senate Bill sponsored by Nominated Senator Karen Nyamu, which received its first reading on 2 April 2026 — would impose a risk-based regime on top of existing data protection obligations.
- A High Court petition certified as urgent in February 2026 (Wangai & 2 Others v Cabinet Secretary for ICT & Another) confirms that the absence of AI-specific legislation does not suspend organisations' existing constitutional and statutory obligations when procuring or deploying AI.
- A Data Protection Impact Assessment carried out before a vendor is selected, not after go-live, is the clearest evidence of Section 41 compliance an organisation can produce.
1. INTRODUCTION AND SCOPE
1.1 Purpose of this Practice Note
Artificial Intelligence is rapidly transforming how Kenyan organisations deliver services, make decisions, manage operations, and engage customers. Generative AI assistants, predictive analytics, automated recruitment tools, fraud-detection platforms, and intelligent customer service systems promise real gains in efficiency and competitiveness. Procuring these systems, however, raises legal and governance questions that differ fundamentally from those raised by conventional software procurement. AI systems frequently process large volumes of personal data, rely on models whose internal logic is not fully transparent even to their developers, generate autonomous outputs, and continue to learn and change after deployment. These characteristics raise complex questions of privacy, cybersecurity, intellectual property, contractual liability, regulatory compliance, algorithmic transparency, bias, and accountability that a standard software licence rarely addresses. This Practice Note sets out the legal, privacy, cybersecurity, and governance considerations that Kenyan organisations should work through before acquiring an AI system. It is written for boards, procurement professionals, legal advisers, compliance officers, information security teams, and Data Protection Officers who share responsibility for ensuring that AI adoption is lawful, secure, and consistent with sound corporate governance.
“AI procurement is not an information-technology acquisition. It is a strategic governance decision requiring coordinated oversight by legal, procurement, technology, security, compliance, and executive leadership.”
1.2 The Governing Legal Landscape
Kenya has not yet enacted a dedicated AI statute. Organisations remain subject to the existing framework: the Constitution of Kenya, 2010 (in particular Article 31, the right to privacy); the Data Protection Act, 2019 and its 2021 subsidiary regulations; the Computer Misuse and Cybercrimes Act, 2018; consumer protection and employment legislation; sector-specific regulatory regimes; and the general law of contract and tort. This is changing. The Artificial Intelligence Bill, 2026 is now before the Senate, and the National Artificial Intelligence Strategy 2025– 2030 and the Kenya Bureau of Standards' voluntary code of practice, KS 3007:2025, already shape how regulators, procurement officers, and boards are expected to approach AI risk. International instruments — the OECD AI Principles, the UNESCO Recommendation on the Ethics of Artificial Intelligence, the ISO/IEC 42001 AI Management System Standard, and the NIST AI Risk Management Framework — provide additional benchmarks that Kenyan procurement teams increasingly draw upon, whether or not they are legally binding.
Kenya Privacy Law Review · Practice Note No. 004 · Page 6
WHY THIS MATTERS
The contractual commitments made at the procurement stage will often determine an organisation's practical ability to comply with the Data Protection Act, manage cybersecurity risk, protect confidential information, preserve intellectual property, and respond effectively to a regulatory investigation or a High Court petition of the kind now shaping Kenya's AI landscape. Boards and senior management should require that every significant AI procurement undergo structured legal, privacy, cybersecurity, and risk assessment before any contractual commitment is made. Failure to do so exposes an organisation to unlawful processing of personal data, discriminatory automated decision-making, regulatory enforcement, cybersecurity vulnerabilities, contractual disputes over liability, loss of intellectual property, vendor lock-in, operational disruption, and reputational harm.
COMMON MISTAKE
Many organisations evaluate AI solutions primarily on functionality, implementation timelines, and cost, and only later discover unresolved questions about ownership of AI-generated outputs, cross-border transfers of training and operational data, vendor access to confidential information, algorithmic transparency, security of the underlying model infrastructure, allocation of liability, audit rights, and compliance with the Data Protection Act. These issues are far more expensive to remediate after deployment than to negotiate before signature.
1.3 Scope of this Practice Note
This Practice Note examines: the legal and regulatory framework governing AI procurement in Kenya; privacy and data protection obligations that arise at the procurement stage; procurement due diligence; vendor risk assessment; cybersecurity requirements; contractual protections; intellectual property considerations; algorithmic accountability and the emerging right to explanation; governance and board oversight; sector-specific considerations; and practical recommendations, including a procurement checklist, for responsible AI adoption.
Kenya Privacy Law Review · Practice Note No. 004 · Page 7
2. THE LEGAL AND REGULATORY FRAMEWORK FOR AI PROCUREMENT
2.1 Constitutional and Statutory Foundations
Article 31 of the Constitution of Kenya, 2010 guarantees the right to privacy. The Data Protection Act, 2019 (the “DPA”) gives effect to that right and remains the most mature and directly applicable component of Kenya's AI governance landscape, since almost every AI system procured by a Kenyan organisation processes personal data at some stage of its lifecycle, whether as training data, operational input, or output. The Computer Misuse and Cybercrimes Act, 2018 supplies the principal cybersecurity and criminal-law backstop, addressing unauthorised access, interference with computer systems, and misuse of data, all of which are directly relevant to the security posture an organisation should demand of an AI vendor.
2.2 The Artificial Intelligence Bill, 2026
The Artificial Intelligence Bill, 2026 (Senate Bill No. 4 of 2026), sponsored by Nominated Senator Karen Nyamu, received its first reading in the Senate on 2 April 2026 and was referred to the Senate Standing Committee on Information, Communication and Technology. If enacted, the Bill would establish a risk-based regulatory regime modelled in part on the European Union's AI Act, classifying AI systems into four tiers, unacceptable, high, limited, and minimal risk, with the most stringent governance, transparency, data protection, and record-keeping obligations reserved for high-risk systems used in sectors such as healthcare, finance, education, security, employment, and public administration. The Bill proposes a three-tier institutional structure: an Office of the Artificial Intelligence Commissioner as the primary enforcement body, responsible for registering AI systems, conducting audits, and investigating breaches; an Artificial Intelligence Authority tasked with national strategy, research, and technical standards; and an Artificial Intelligence Advisory Council providing expert consultative input. The Bill also proposes new individual rights relevant to procurement, including a right to explanation of AI-driven decisions with significant effects, and a right to request human review, alongside mandatory disclosure obligations for AI-generated or synthetic content, and criminal penalties for harmful deepfakes. Critically for procurement teams, the Bill expressly ties AI governance to the existing Data Protection Act, requiring providers and deployers of high-risk AI systems to comply with that Act in relation to personal data processing, including the conduct of Data Protection Impact Assessments. Commentators have noted that this layering risks creating overlapping and, in places, duplicative compliance obligations across the ODPC, a prospective AI Commissioner, and existing sectoral regulators such as the Central Bank of Kenya and the Communications Authority of Kenya, a coordination problem that well-drafted vendor contracts can help an organisation manage even before the Bill's final form is settled. As at the date of this Practice Note, the Bill remains before the Senate and, because it touches matters affecting county governments, must also be considered by the National Assembly before it can be presented for presidential assent. Procurement teams should treat its current provisions as a strong indicator of the direction of travel, particularly the risk-tiering approach and the emphasis on explainability and human oversight, rather than as settled law.
Kenya Privacy Law Review · Practice Note No. 004 · Page 8
CASE IN FOCUS W & 2 Others v Cabinet Secretary for Information, Communication and the Digital Economy & Another High Court of Kenya at Kirinyaga, Constitutional Petition (Ruling of 5 February 2026, Muriithi J) 3.1 Facts The petitioners, JW, PA, and AM sought urgent conservatory orders restraining the Cabinet Secretary and Principal Secretary for the Ministry of Information, Communication and the Digital Economy from deploying, authorising, or operationalising AI systems, pending the hearing of a petition contending that the government's continued deployment of “high-risk” AI systems, including automated decision-making tools, algorithmic content moderation, biometric systems, facial recognition, and AI-enhanced surveillance, without a comprehensive legal or regulatory framework violated constitutional rights to privacy, equality, dignity, and fair administrative action. 3.2 Holding Justice Edward M. Muriithi declined to grant conservatory orders at the ex parte stage, holding that a request of such wide-reaching effect could not be issued without hearing the respondents. The Court nonetheless certified the matter as urgent and set it down for an inter partes hearing, directing that the application be served on the Ministry of ICT, the Attorney General, and Parliament. 3.3 Significance The ruling does not establish that AI deployment in Kenya is presently unlawful. It does confirm, however, that the absence of AI-specific legislation is now the subject of active constitutional litigation, and that organisations, public and private, cannot treat the regulatory gap as a safe harbour. Procurement teams should read this case alongside the Artificial Intelligence Bill, 2026 as evidence that Kenya's courts and legislature are converging, in the same window, on the view that high-risk AI deployment requires demonstrable legal and institutional safeguards.
2.3 National AI Strategy 2025–2030 and KS 3007:2025
The National Artificial Intelligence Strategy 2025–2030, launched in March 2025, sets Kenya's policy direction for AI adoption under the Ministry of Information, Communications and the Digital Economy, which chairs a National AI Steering Committee. While not binding law, the Strategy shapes public procurement priorities and signals the responsible-AI principles against which government and increasingly private-sector vendors will be assessed. The Kenya Bureau of Standards has published KS 3007:2025, a voluntary code of practice for AI applications, which procurement teams can reference as an objective technical benchmark when assessing vendor maturity, alongside the internationally recognised ISO/IEC 42001 AI Management System Standard.
2.4 International Standards
The OECD AI Principles and the UNESCO Recommendation on the Ethics of Artificial Intelligence provide widely referenced governance benchmarks for trustworthy AI, emphasising transparency, accountability, human oversight, and fairness. ISO/IEC 42001 offers a certifiable management-system standard that a Kenyan organisation can require of an AI vendor as a proxy for governance maturity, in the same way ISO/IEC 27001 is now commonly required for information security. Kenyan organisations exporting services to the European Union, or partnering with EU businesses, should also note that the EU AI Act applies extraterritorially to providers placing AI systems on the EU market and to deployers whose AI output is used in the EU, a relevant consideration for any Kenyan business with European customers or investors.
Kenya Privacy Law Review · Practice Note No. 004 · Page 9
3. PRIVACY AND DATA PROTECTION OBLIGATIONS IN AI PROCUREMENT
3.1 Privacy by Design Applied to Vendor Selection
Section 41 of the DPA requires every data controller and data processor to implement appropriate technical and organisational measures designed to give effect to the data protection principles, and to integrate necessary safeguards into processing by default. Where an organisation procures rather than builds an AI system, Section 41 does not disappear, it is discharged, or fails to be discharged, through the terms on which the vendor is engaged. A procurement process that does not interrogate a vendor's data handling, retention, and safeguard practices before contracting cannot later demonstrate that privacy was considered “by design.”
3.2 The DPIA as a Pre-Procurement Gate
Section 31 of the DPA requires a Data Protection Impact Assessment before processing likely to result in a high risk to data subjects' rights and freedoms. Regulation 49 of the General Regulations identifies automated decision-making or profiling with legal or similar effects, large-scale processing, processing of biometric or genetic data, and the use of innovative technology as high-risk triggers, criteria that a large share of AI procurements will meet. Where the DPIA indicates a residual high risk that cannot be adequately mitigated, the data controller must consult the ODPC, and Regulation 49 requires submission of the DPIA report sixty days before such processing begins. The practical implication for procurement teams is that the DPIA should be initiated during vendor evaluation, not after a contract is signed, a sequencing point the ODPC and the High Court have both emphasised in recent data protection matters.
3.3 Automated Decision-Making
Section 35 of the DPA restricts decisions based solely on automated processing, including profiling, that produce legal or similarly significant effects on a data subject, and confers rights of human intervention, explanation, and contestation. AI procurement contracts for systems used in credit scoring, recruitment screening, insurance underwriting, or similar high-stakes decisions should expressly preserve an organisation's ability to comply with Section 35, for example, by ensuring the vendor's system supports meaningful human review and produces outputs that can be explained to an affected individual in intelligible terms.
3.4 Data Minimisation and Purpose Limitation
Section 41(2) requires that, by default, only personal data necessary for a specific purpose is processed. AI systems, particularly those built on large pre-trained models, can create tension with this principle where training data was collected for a different purpose or from a different jurisdiction. Procurement teams should require vendors to disclose, so far as reasonably ascertainable, the provenance of training data, and should resist broad vendor rights to reuse an organisation's operational data for further model training absent a clear lawful basis and, where relevant, consent.
3.5 Cross-Border Transfers and Data Localisation
Many AI vendors process or host data outside Kenya. The DPA regulates cross-border transfers, permitting transfer to jurisdictions with adequate data protection frameworks, and otherwise requiring safeguards such as data subject consent, standard contractual clauses, or binding corporate rules. Kenya and the European Union have an ongoing adequacy dialogue, the first of its kind on the African continent, but no adequacy decision has yet been reached. Procurement teams handling sensitive categories of data, health or financial records in particular, should also note the ODPC's December 2024 Cloud Policy, which encourages data localisation for sensitive government and critical infrastructure data, and should confirm where an AI vendor's infrastructure and sub-processors are actually located, not merely where the vendor is incorporated.
Kenya Privacy Law Review · Practice Note No. 004 · Page 10
4. PROCUREMENT DUE DILIGENCE
Before any AI vendor is shortlisted, procurement teams should assemble a due diligence file addressing, at minimum:
- What personal data the system will process, and whether that processing meets the DPIA threshold under Regulation 49;
- The provenance and lawful basis for any training data, including whether the model was trained on data the organisation itself will supply;
- The system's architecture, including whether it relies on third-party sub-processors, foundation-model providers, or cloud infrastructure outside Kenya;
- The vendor's security certifications (ISO/IEC 27001, SOC 2, or equivalent) and, where available, AI-specific governance certification against ISO/IEC 42001 or KS 3007:2025;
- The vendor's incident history, including any prior data breaches or regulatory findings in any jurisdiction;
- Whether the system is continuously learning post-deployment, and if so, how model updates are validated, tested, and documented;
- Whether the vendor can support the human-review and explainability obligations the organisation needs to meet its own Section 35 obligations. This diligence should be documented and retained. In the event of an ODPC investigation or a complaint, a documented due diligence record is significant evidence that an organisation approached its Section 41 obligations proactively rather than reactively,the same distinction the ODPC has repeatedly drawn in its enforcement practice.
5. VENDOR RISK ASSESSMENT
Organisations should adopt a risk-tiering approach to AI vendors that mirrors the classification structure proposed under the Artificial Intelligence Bill, 2026, unacceptable, high, limited, and minimal risk, even before that structure becomes binding law. A system used to make or materially inform decisions about employment, credit, healthcare, or access to public services should be treated as high risk regardless of its label in the vendor's own marketing material, and should be subject to the most rigorous pre-contract diligence, the strongest contractual protections, and ongoing postdeployment monitoring, including periodic re-assessment as the vendor's model or its uses evolve. Vendor risk assessment should not end at signature. AI systems change: models are retrained, fine-tuned, or swapped for newer versions by the vendor without necessarily triggering a formal contract amendment. Organisations should build a review cadence, at minimum annually, and immediately upon any material change the vendor disclose, into their vendor governance programme.
6. CYBERSECURITY REQUIREMENTS
The Computer Misuse and Cybercrimes Act, 2018 criminalises unauthorised access to, and interference with, computer systems and data, and underpins the security expectations an organisation should place on an AI vendor as a matter of law, not merely good practice. Section 41(3) of the DPA separately requires pseudonymisation and encryption of personal data, timely access to data following a physical or technical incident, verification that safeguards are effectively implemented, and continual updating of those safeguards in response to new risks. AI systems introduce security considerations beyond conventional software: model-specific risks such as prompt injection, data poisoning, model inversion (where an attacker attempts to reconstruct training data from a model's outputs), and adversarial manipulation of inputs. Procurement contracts should require the vendor to disclose its approach to these risks, to notify the organisation of security incidents within a defined and short timeframe, and to permit security testing or independent audit of the system before and periodically after deployment.
Kenya Privacy Law Review · Practice Note No. 004 · Page 11
7. CONTRACTUAL PROTECTIONS
At minimum, an AI procurement contract should address:
1. A data processing agreement compliant with the DPA, clearly designating the parties' respective roles as controller and processor, and the purposes and categories of personal data involved; 2. Restrictions on the vendor's use of the organisation's data for further model training, absent explicit, informed authorisation; 3. Audit rights, allowing the organisation (or an independent third party) to verify the vendor's technical and organisational safeguards; 4. Security and breach notification obligations, with defined timeframes consistent with the organisation's own regulatory notification duties; 5. Clear allocation of liability for harm arising from biased, inaccurate, or unlawful AI outputs, including appropriate indemnities; 6. Warranties regarding the lawful provenance of training data and non-infringement of third-party intellectual property; 7. Provisions addressing sub-processors and cross-border data flows, consistent with the DPA's transfer requirements; 8. Termination and data-return or deletion obligations, including confirmation that model weights or derivatives trained on the organisation's data do not survive termination without agreement; 9. Service levels and change-management obligations addressing model updates, deprecations, and version changes.
8. INTELLECTUAL PROPERTY CONSIDERATIONS
Kenyan copyright law, as confirmed by the Copyright Tribunal in Aryeh Movement Limited v. Cynthia Beldina Akoth Okello (COPTA/E001/2025), requires demonstrable human creative input for copyright protection to attach; works generated autonomously by AI, without sufficient human intervention, do not meet the originality threshold under Section 22(3) of the Copyright Act. Procurement contracts should therefore not assume that an organisation automatically owns the outputs an AI system generates for it; ownership, or at minimum a clear and sufficiently broad licence, should be expressly negotiated, with particular attention to documenting the human authorship or editorial contribution needed to sustain a copyright claim. Equally important is protection against the reverse risk, that training data underlying a vendor's model infringes third-party intellectual property rights, exposing the deploying organisation to downstream claims. Vendors should be required to warrant the lawful provenance of training data and to indemnify the organisation against thirdparty IP claims arising from the vendor's model.
Kenya Privacy Law Review · Practice Note No. 004 · Page 12
9. ALGORITHMIC ACCOUNTABILITY AND THE RIGHT TO EXPLANATION
Section 35 of the DPA already gives data subjects rights in relation to automated decisions with legal or similarly significant effects. The Artificial Intelligence Bill, 2026 would go further, proposing an explicit right to explanation of how an AI system reached a decision affecting an individual, and a right to request human review. Even before the Bill is enacted, procurement teams should require vendors to demonstrate that their systems can produce outputs that are explainable in terms a non-technical person can understand, and should document how bias testing was conducted, particularly for systems used in lending, recruitment, or other contexts where discriminatory outcomes could give rise to both DPA and employment or consumer-protection liability. The consequences of inadequate diligence in this area are not hypothetical. In March 2026, the Milimani High Court struck out a legal filing that had been substantially generated by a generative AI tool and contained citations to nonexistent cases, a vivid illustration, even outside the AI procurement context specifically, of the reputational and professional risk that follows from deploying AI outputs without adequate human verification. The Judiciary has since released a draft AI policy adopting the same risk-tiered approach as the pending AI Bill, requiring mandatory human oversight for higherrisk uses.
10. GOVERNANCE AND BOARD OVERSIGHT
Boards should treat significant AI procurement decisions as they would any other material risk decision, with defined approval gates rather than delegation to IT or business-unit sponsors alone. A practical governance structure typically includes: a cross-functional AI procurement review (legal, privacy, security, and the relevant business owner) before any vendor is shortlisted; sign-off by the Data Protection Officer, appointed under Section 24 of the DPA, on the DPIA and data processing terms before contracting; periodic post-deployment review reporting to the board or a designated board committee; and a clear internal escalation path if a deployed system's behaviour, accuracy, or risk profile changes materially after go-live.
11. SECTOR-SPECIFIC CONSIDERATIONS
11.1 Financial Services
Financial institutions deploying AI for credit scoring, fraud detection, or algorithmic trading remain subject to Central Bank of Kenya prudential and conduct requirements in addition to the DPA, and should expect these obligations to be reinforced, not replaced, by any AI-specific legislation that is eventually enacted.
11.2 Healthcare
AI-assisted diagnostic tools are already in clinical use in Kenya; one Nairobi-based primary care provider reported measurable reductions in diagnostic and treatment error rates in a 2025 study using an AI tool developed with an international partner. Kenya's Pharmacy and Poisons Board is separately drafting regulations specific to AI tools used in clinical settings, and the Artificial Intelligence Bill, 2026 designates healthcare as a high-risk sector. Procurement of clinical AI tools should anticipate both DPA and forthcoming sector-specific regulatory requirements.
11.3 Legal and Professional Services
The Judiciary's draft AI policy and the March 2026 Milimani filing incident underline that professional service firms, including law firms, adopting AI tools for research or drafting carry their own verification and disclosure obligations, independent of whether the firm is itself procuring the tool for client-facing use or internal efficiency.
Kenya Privacy Law Review · Practice Note No. 004 · Page 13
12. PRACTICAL RECOMMENDATIONS AND PROCUREMENT CHECKLIST
Organisations should treat the following as a minimum baseline before committing to any material AI procurement:
- Frame the decision as a governance question first: should this system be deployed, and under what legal, privacy, security, and ethical conditions?
- Complete a DPIA before, not after, vendor selection, where the processing meets the Regulation 49 high-risk threshold.
- Document due diligence on training data provenance, sub-processors, and security certification.
- Classify the vendor and use case by risk tier, and scale contractual protections accordingly.
- Negotiate explicit terms on data use restrictions, IP ownership, audit rights, liability, and termination before signature.
- Confirm the system can support Section 35 human-review and explainability obligations.
- Assign board-level or board-committee oversight and a defined post-deployment review cadence.
- Track the Artificial Intelligence Bill, 2026 as it moves through Parliament, and build contractual flexibility to accommodate obligations it may introduce.
13. CONCLUSION
Artificial Intelligence procurement in Kenya currently sits at the intersection of a mature data protection framework and an AI-specific legal regime still taking shape. The Data Protection Act, 2019 already imposes real, enforceable obligations on any organisation procuring an AI system that touches personal data, and the ODPC's enforcement record shows a regulator willing to act on design and procurement failures. The Artificial Intelligence Bill, 2026 and the February 2026 High Court petition both confirm that Kenya's courts and legislature are moving, in the same window, toward treating AI governance as a matter of binding legal obligation rather than voluntary best practice. Organisations that build legal, privacy, cybersecurity, and governance diligence into AI procurement — rather than treating it as an afterthought to be resolved post-deployment — are best placed to realise the benefits of AI while maintaining regulatory compliance and stakeholder trust as Kenya's framework continues to develop.
Summary Table Legal Basis Section 41 of the DPA requires privacy by design and by default in any system, including procured AI systems
Regulation 49 requires a DPIA before high-risk processing, including most AI-driven DPIA Trigger automated decision-making and profiling
Pending Legislation Artificial Intelligence Bill, 2026 (Senate Bill No. 4) — risk-based regime, AI Commissioner, first reading 2 April 2026
Wangai & 2 Others v CS ICT & Another (High Court, Kirinyaga, February 2026) — Judicial Signal certified urgent petition on AI regulatory delay
Section 35 DPA — rights to human intervention, explanation, and contestation for Automated Decisions significant automated decisions
Kenya Privacy Law Review · Practice Note No. 004 · Page 14
Computer Misuse and Cybercrimes Act, 2018 and Section 41(3) DPA safeguards — Cybersecurity encryption, pseudonymisation, incident response
Contractual Protections Data processing terms, audit rights, liability allocation, IP warranties, termination and datareturn obligations
Standards ISO/IEC 42001, KS 3007:2025, OECD AI Principles, UNESCO AI Ethics Recommendation, NIST AI RMF
Disclaimer: This Practice Note is for guidance purposes only and does not constitute legal advice. Organisations should seek independent legal advice on specific compliance matters. Legislative and judicial developments referenced in this Practice Note, including the Artificial Intelligence Bill, 2026 and pending litigation, remain subject to change as the legislative and judicial process continues.