MP Muchangi Patrick& Associates Advocates
Talk to an Expert
Practice Areas Case Digest Knowledge Centre Insights About Contact Talk to an Expert
Knowledge Centre/Practice Notes/Employee Monitoring
Cover of Employee Monitoring
KPLR/PN/002/2026 Practice Note Employment
Practice Note Series

Employee Monitoring

Balancing Employer Oversight and Employee Privacy Rights under the Data Protection Act, 2019

Author
Patrick Muchangi
Published
July 2026
Last Updated
July 2026
Reading Time
None min
Version
1.0
Editorial Status
Published
DOI
Pending assignment
Language
English
Abstract

This Practice Note maps the legal boundary between lawful employer oversight and unlawful employee surveillance under the Data Protection Act, 2019. Drawing on four recent decisions — K v Dig Deep (Africa), KUJ v KBC, M v ABSA Bank Kenya PLC, and an ODPC enforcement action against Liquid Telecommunications — it identifies what separated employers who stayed within the law from those who did not, and sets out the compliance posture that keeps an employer on the right side of that line.

Executive Summary

Employers may lawfully monitor company-owned devices and accounts where a clear policy has already put employees on notice, but biometric monitoring requires informed consent, a DPIA, and staff consultation. Private investigation of an employee's life outside work is not a lawful substitute for direct engagement, and recorded meetings must be deleted on request. Consent is often the wrong legal basis for workplace monitoring given the employer-employee power imbalance; legitimate interest or legal obligation is usually the safer footing.

Key Takeaways
  • Employers can lawfully monitor company-owned devices and accounts, but only where a clear policy, such as a staff handbook, already put employees on notice (K v Dig Deep).
  • Biometric monitoring, including facial recognition attendance systems, is unlawful without informed consent, a Data Protection Impact Assessment, and staff consultation (KUJ v KBC).
  • Hiring a private investigator to look into an employee's life outside work is not a lawful substitute for simply raising the concern with the employee directly (M v ABSA Bank Kenya PLC).
  • Recording a digital meeting and keeping that recording after a participant asks for its deletion breaches the Data Protection Act, whatever business interest is claimed (Liquid Telecommunications, ODPC).
  • Consent is often the wrong legal basis for workplace monitoring in the first place. Given the power imbalance between employer and employee, legitimate interest or legal obligation is usually the safer footing.

1. Introduction and Scope

1.1 Purpose of this Practice Note

This Practice Note sets out the legal framework governing employee monitoring in Kenya. It addresses the intersection of employer oversight practices, employee privacy rights under the Constitution, and the requirements of the Data Protection Act, 2019 (the “DPA”). The guidance draws on recent judicial decisions and ODPC enforcement actions that have clarified the boundaries of permissible employee monitoring.

The legal framework for employee monitoring in Kenya draws from three primary sources.

Article 31 of the Constitution of Kenya, 2010 guarantees every person the right to privacy, including protection of personal information and communications from unauthorised access or exposure. As the High Court held in KUJ v. KBC, the right to privacy “is not aspirational but an enforceable constitutional guarantee.”

The DPA operationalises that constitutional right by regulating the processing of personal data. The provisions most relevant to employee monitoring are Section 25 (lawfulness, fairness and transparency), Section 29 (duty to notify), Section 31 (Data Protection Impact Assessment), Section 32 (consent), and Section 41 (data protection by design and default). Section 25 in particular requires employers to collect data fairly, lawfully, and transparently.

The Employment Act, 2007 provides the framework for employment relations generally, including disciplinary procedure, but it is notably silent on employee data protection. That silence leaves the DPA as the cornerstone for regulating workplace surveillance.

Taken together, these three instruments require an employer to balance its legitimate interest in monitoring workplace activity against its employees' constitutional and statutory privacy rights.

2. The Constitutional Foundation of Employee Privacy

2.1 Article 31 of the Constitution

Article 31 of the Constitution of Kenya, 2010 provides that every person has the right to privacy, including the right not to have information relating to their family or private affairs unnecessarily required or revealed, and the right not to have the privacy of their communications infringed. This right extends to employees in the workplace and underlies the data protection protections that follow.

The Employment and Labour Relations Court gave this principle a memorable articulation in M v. ABSA Bank Kenya PLC.

Protecting privacy is necessary if an individual is to lead an autonomous, independent life, enjoy mental happiness, develop a variety of diverse interpersonal relationships, formulate unique ideas, opinions, beliefs and ways of living and participate in a democratic, pluralistic society. The importance of privacy to the individual and society certainly justifies the conclusion that it is a fundamental social value, and should be vigorously protected in law. M v. ABSA Bank Kenya PLC, M v. ABSA Bank Kenya PLC (Cause E065 of 2023) [2024] KEELRC 2399 (KLR)

2.2 The Right to Privacy in Employment

The Court in M vs. ABSA Bank Kenya PLC Case went on to hold that even within an employment relationship, protecting an employee's privacy remains imperative. Where an employee's privacy has been breached, an employer cannot simply assert that the matter fell outside the court's jurisdiction, and must instead address whether there was any real need to collect personal data unrelated to the employment in the first place.

That right is not absolute. The DPA sets out its limitations. The practical question for any employer is when legitimate workplace monitoring tips over into an unlawful intrusion on employee privacy, and the four decisions that follow answer that question from four different directions.

3. The K v. Dig Deep (Africa) Decision

Employer monitoring of digital communications. K v. Dig Deep (Africa) (Cause 1644 of 2017) [2025] KEELRC 2753 (KLR) (9 October 2025). Employment and Labour Relations Court at Nairobi. L. Ndolo, J.

3.1 Facts

R K, the Claimant, was employed as a Project Officer by Dig Deep (Africa), the Respondent. Her employment was terminated after allegations that she had communicated with a former employee who was under investigation. The Respondent accessed the Claimant's official email account and relied on evidence obtained from her office computer to justify her dismissal. The Claimant challenged the fairness of her termination on several grounds, including that the evidence had been obtained in violation of her constitutional right to privacy.

The Respondent argued that the investigation had used company-owned systems and infrastructure, consistent with known employment terms, and emphasised that personal use of its systems was understood to be subject to monitoring, with disciplinary action a possible consequence of any breach.

3.2 Holdings

The Court held that the employer had not violated the Claimant's right to privacy by accessing data on the office computer. It reaffirmed that electronic communication systems and equipment issued at the workplace remain the property of the employer, who retains the right to monitor their use provided that monitoring is lawful and consistent with internal policy.

The Court found that the Respondent's staff handbook provided a legitimate basis for digital monitoring, and pointed to established jurisprudence supporting employer access to workplace emails and devices. It emphasised that the Claimant could not claim privacy over personal information stored or transmitted through office equipment.

3.3 Significance

Kendagor establishes several principles employers can rely on.

First, employer oversight must still be balanced against employee privacy rights. The Court upheld the employer's right to monitor company-owned systems, but did so on the strength of a clear policy, the staff handbook, of which employees were already aware.

Second, employees are not entitled to assume absolute privacy when using employer-issued devices or systems. As the Court noted, depending on the circumstances, an employee has no expectation of privacy over personal information stored or transmitted using office computers or official email systems.

Third, compliance with the DPA and constitutional safeguards is what allows an employer to defend its policies successfully. The Court's determination reinforces the underlying principle that workplaceissued electronic systems remain the property of the employer, who may monitor their use provided that monitoring is lawful and consistent with internal policy

3.4 Practical Implications for Employers

Based on Kendagor, employers should: 1. Establish and communicate clear policies on digital monitoring, including the scope and conditions under which employee communications may be accessed. 2. Limit access to private communications to instances where consent has been obtained or such access is expressly permitted by contract or policy. 3. Ensure that monitoring practices comply with the DPA and constitutional privacy protections, and are conducted in a lawful, necessary, and proportionate manner.

4. The KUJ v. KBC Decision

Biometric surveillance in the workplace. Kenya Union of Journalists (KUJ) v. Kenya Broadcasting Corporation (KBC) (JR No. E366 of 2025). High Court of Kenya. Aburili, J.

4.1 Facts

KBC introduced a mandatory facial recognition attendance system for all employees. The Kenya Union of Journalists challenged the rollout, arguing that KBC had introduced the system without obtaining staff consent, without conducting a Data Protection Impact Assessment (DPIA), without engaging employees, and without providing full disclosure of the purpose, risks, and third-party handling of the data collected.

KUJ further argued that KBC had ignored repeated requests for engagement and transparency, including letters sent in July and October 2025 calling for a consultative meeting before the system was enforced. The rollout put sensitive employee information at risk, including data about staff with medical conditions, and the identity of the third-party service provider handling the biometric system remained undisclosed.

4.2 Holdings

The Court held that the rollout violated Article 31 of the Constitution and provisions of the DPA, reaffirming that the right to privacy is not aspirational but an enforceable constitutional guarantee.

The Court made four key findings. Consent is mandatory for biometric data processing, and KBC had failed to obtain informed consent from employees. Data Protection Impact Assessments are mandatory for new technologies involving sensitive data such as biometrics, and KBC had not conducted one. Transparency and disclosure are essential for lawful processing, and KBC had not provided key information about the system or its vendor. Staff engagement is required before implementing intrusive technologies, and KBC had ignored repeated requests for consultation.

The Court's orders were correspondingly firm. It declared the rollout unconstitutional and unlawful for having proceeded without consent, consultation, or a DPIA, restrained KBC from implementing the system without proper consent and full transparency, directed KBC to delete and destroy all biometric

data already collected and to file an affidavit confirming compliance, and instructed the Data Commissioner to supervise the deletion process.

4.3 Significance

This decision is a clear warning to any organisation considering, or already operating, intrusive technologies such as facial recognition, iris scanning, voice biometrics, or AI-powered surveillance. No organisation is exempt from the mandatory safeguards of express informed consent, DPIAs, transparency, legitimate purpose, and robust technical and organisational measures for data protection.

The decision effectively sets a mandatory compliance checklist for any employer monitoring staff through biometric systems.

REQUIREMENT APPLICATION

Express Informed Employees must give explicit, informed consent before biometric data is Consent collected.

A DPIA must be conducted before any biometric system is deployed. Data Protection Impact Assessment

Transparency and Employees must be fully informed of the purpose, risks, and third-party Disclosure handling of their data.

Staff Engagement Employees and their representatives must be consulted.

Robust Safeguards Technical and organisational measures for data protection must be implemented.

5. The M v. ABSA Bank Kenya PLC Decision

Private investigations and employee privacy. M v. ABSA Bank Kenya PLC (Cause E065 of 2023) [2024] KEELRC 2399 (KLR) (1 October 2024). Employment and Labour Relations Court at Mombasa. M. Mbaru, J.

5.1 Facts

The claimant was employed as a branch manager and later promoted to senior branch manager. On 17 March 2023 he was suspended over alleged involvement in irregular, unauthorised overdraft facilities. Disciplinary proceedings followed, and he was eventually terminated.

During his suspension, the respondent engaged a private investigator to look into his personal and private conduct. The investigator followed the claimant in public, in restaurants and pubs, and sought information about him from various establishments, all without his knowledge.

5.2 Holdings

The Court held that the respondent's conduct in commissioning an investigation into the claimant's private life was not justified, and that engaging in private investigations of that kind, without ever raising the underlying concerns with the claimant directly, was similarly unjustified. His rights under Article 31 of the Constitution had been breached.

The Court awarded general damages of KES 5,000,000 for the breach of the claimant's privacy rights.

5.3 Significance

M vs. ABSA Bank Kenya PLC Case establishes that an employer cannot engage private investigators to look into an employee's private life without justification. The Court's reasoning points to two practical lessons.

First, protection of an employee's privacy remains imperative even within an employment relationship, and an employer cannot justify collecting personal data or information unrelated to that employment.

Second, where an employer has concerns about an employee's conduct outside working hours, the proper course is to raise those concerns with the employee directly, not to commission a private investigation without the employee's knowledge. As the Court's own language makes clear, an intrusion of that kind is demeaning not only to the dignity of the individual concerned but to the integrity of society more broadly.

6. The Liquid Telecommunications Kenya Ltd ODPC Decision

Recording of digital meetings.

Liquid Telecommunications Kenya Ltd, Data Privacy Breach [2025] ODPC 14/2025.

6.1 Facts

Liquid Telecommunications Kenya Ltd recorded a Zoom meeting with a former employee without obtaining consent, and retained the recording despite a deletion request from that employee. The company argued that it had a legitimate interest in keeping the recording in case of potential disputes.

6.2 Holdings

The ODPC held that consent is mandatory before processing personal data, including recordings of digital meetings, and that retaining a recording without lawful justification violates the DPA. Employees have the right to request deletion, and that request must be honoured promptly.

The ODPC awarded Ksh 700,000 in compensation, a clear signal that privacy rights are not to be set aside for operational convenience.

6.3 Significance

The decision applies equally whether the platform is Zoom, Teams, or something else entirely. Employee privacy is a legal obligation, not a courtesy, and organisations must comply with the applicable consent requirements, retention rules, and deletion rights regardless of the platform in use.

7. Best Practices for Employers

7.1 Develop Clear Monitoring Policies

Employers should implement clear, comprehensive monitoring policies that address the scope of monitoring (what is monitored, when, and for what purpose), the legal basis for it under the DPA (employers should generally rely on legitimate interests or legal obligations, ensuring monitoring is necessary and proportionate), employee rights (how employees can exercise data subject rights, including access, rectification, and deletion), data retention (how long monitoring data will be kept and how it will eventually be deleted), and data protection safeguards more generally.

These policies should be incorporated into employment contracts or staff handbooks. For remote workers, employers should give written notice, ideally at the point of hiring, and keep the policy readily accessible.

Where monitoring genuinely relies on consent, employers should give clear, plain-language explanations of what is being monitored, explain its purpose and scope, disclose any third-party transfers, allow employees to withdraw consent at any time, and avoid financial inducements that could undermine the freely given nature of that consent.

Because of the inherent power imbalance between employer and employee, consent given in this context may not always be truly free, since an employee may feel compelled to agree simply to avoid repercussions. For that reason, employers are generally better placed relying on legitimate interests or legal obligations for monitoring, ensuring it remains necessary and proportionate, rather than leaning on consent alone.

7.3 Conduct Data Protection Impact Assessments

Before implementing intrusive monitoring systems, particularly those involving biometric data or new technology, employers should conduct a Data Protection Impact Assessment. The DPIA should address the necessity and proportionality of the monitoring, identify risks to employees' rights, and set out mitigation measures.

7.4 Ensure Transparency

Section 29 of the DPA requires employers to notify employees of the purpose of data collection, the legal basis for processing, any third parties to whom data will be transferred, and the rights available to the data subject.

7.5 Implement Data Protection by Design and Default

Section 41 of the DPA requires data controllers and processors to implement appropriate technical and organisational safeguards to protect the right to privacy. “By design” means data protection principles must be considered from the outset whenever a monitoring system is developed, while “by default” means the highest privacy standard applies automatically, without an employee needing to ask for it.

7.6 Train Staff and Managers

Employers should provide regular training to employees and managers on data protection obligations and the ethical use of monitoring tools.

8. Conclusion

Employee monitoring in Kenya calls for a careful balance between an employer's operational needs and an employee's constitutional and statutory privacy rights. Kendagor establishes that an employee cannot claim absolute privacy when using employer-issued devices or systems, provided a clear policy is already in place. KUJ v. KBC establishes that biometric monitoring introduced without consent, a DPIA, or transparency is unlawful. M vs. ABSA Bank Kenya PLC Case establishes that an employer cannot engage a private investigator to look into an employee's private life without justification. The Liquid Telecommunications ODPC decision establishes that recording digital meetings without consent violates the DPA.

Employers should adopt a proactive compliance posture: implement clear policies, obtain valid consent only where it is genuinely the appropriate basis, conduct DPIAs before deploying intrusive systems, and keep robust documentation of all of it.

Disclaimer: This Practice Note is provided for general informational purposes and does not constitute legal advice. Reading this publication does not create an advocate-client relationship with Muchangi Patrick & Associates Advocates. For advice on a specific matter, please book a consultation. Spotted an error or an update we should reflect? Let us know.
MP

Patrick Muchangi

Advocate of the High Court of Kenya · Founder, Muchangi Patrick & Associates Advocates

Patrick Muchangi is an Advocate of the High Court of Kenya and founder of Muchangi Patrick & Associates Advocates, a boutique Nairobi practice specialising in data protection, privacy, AI governance, and technology law. He is a Certified Professional Mediator, holds an LL.B from the University of Nairobi and a Post-Graduate Diploma from the Kenya School of Law, and edits the Kenya Privacy Law Review.

Take the Next Step

Employee monitoring programmes usually reveal wider gaps in what personal data an organisation holds and why. Our Data Audit Checklist is the practical next step.

Open the Data Audit Checklist →