Every admission season in Kenya, schools proudly celebrated their top performing students. Their photographs appeared on school websites, colourful billboards line busy roads, and congratulatory advertisements fill the pages of national newspapers. Not forgetting sporting, coding and competitive billboards showcasing the school’s extra curricular edge! For decades, this was viewed as both a celebration of academic excellence and an effective way of attracting prospective parents.
Today, however, the legal landscape has changed. The enactment of the Data Protection Act, 2019, together with the growing enforcement role of the Office of the Data Protection Commissioner (ODPC), has fundamentally altered how schools must think about the personal information they collect and use. Practices that were once considered routine are now subject to legal scrutiny. What many schools still regard as ordinary administrative practice may, in fact, expose them to regulatory investigations, compensation claims, enforcement notices, and significant financial penalties.
Perhaps the greatest challenge is that many institutions do not realise they are carrying these risks until a complaint is filed.
Data Protection Is No Longer an Administrative Exercise
For many years, data protection was treated as an ICT issue or simply another compliance requirement tucked away in school policies. That approach is no longer sufficient.
The Data Protection Act places schools in a position of considerable legal responsibility because they process large volumes of personal information belonging to children, parents, guardians, teachers, and staff. Every admission form, report card, photograph, CCTV recording, medical record, transport register, payment system, and communication platform forms part of a school's data ecosystem.
Children's personal information enjoys heightened legal protection under Kenyan law.
Where a school fails to process that information lawfully, fairly, and transparently, the consequences can be substantial. The ODPC has the authority to issue enforcement notices, require corrective measures, award compensation to affected individuals, and, where appropriate, impose administrative fines of up to KSh 5 million or one percent of an organisation's annual turnover, whichever is lower.
Recent decisions demonstrate that educational institutions are firmly within the regulator's focus.
The Nairobi Academy decision illustrates this clearly. The ODPC in January 2026 ordered the school to pay KSh 637,500 after it published a student's KCSE examination results together with the learner's name in a national newspaper for promotional purposes without obtaining explicit parental consent. The Commissioner found that examination results constitute personal data and cannot simply be used as marketing material because a student performed exceptionally well.
Similarly, in 2025 Nova Pioneer was ordered to pay KSh 500,000 after sharing a student's passport details, nationality, and date of birth with external organisations despite the parent having withdrawn the child from the school trip. The case serves as a powerful reminder that collecting information for one purpose does not automatically permit its use for another.
In another notable matter involving Friends School Keveye Girls High School, the ODPC intervened after the recording and storage of a disciplinary video involving a student. The decision reinforced the principle that school disciplinary authority does not automatically create a lawful basis for recording, retaining, or distributing images and videos involving children.
Taken together, these decisions show that the regulator expects schools to place children's privacy at the centre of their decision making rather than treating it as an afterthought.
The Problem With a Single Signature
One of the most common weaknesses found in school admission processes is the reliance on a single declaration signed by a parent at the bottom of an admission form.
Many schools continue to include broad statements requiring parents to agree to school policies, technology platforms, publicity activities, third party services, communication systems, and future initiatives through one signature.
While this may appear administratively convenient, it does not reflect the standards required by the Data Protection Act.
Section 33 recognises that the processing of children's personal information requires additional safeguards. Consent must be specific, informed, freely given, and capable of being withdrawn. It should also relate to a clearly defined purpose.
A parent who consents to using the school's Learning Management System has not automatically agreed to the publication of their child's photographs on social media.
Likewise, providing a mobile phone number for fee payment notifications does not automatically authorise the school to send promotional messages about extracurricular programmes, school merchandise, or commercial partnerships.
Consent cannot be bundled simply because it appears on the same admission form.
Schools should adopt separate consent options for distinct activities, allowing parents to make informed decisions about each type of processing.
This approach is not merely good practice, it reflects one of the fundamental principles upon which modern data protection law is built.
Understanding the School's Legal Position
The rapid adoption of educational technology has transformed the way schools operate. Student Information Systems (SIS), Learning Management Systems (LMS), biometric attendance solutions, online payment platforms, transport applications, communication tools, and cloud storage have become part of everyday school administration.
Yet technology has also introduced a legal misunderstanding that many institutions continue to overlook.
The school remains the Data Controller.
This means the school determines why personal information is collected, what information is collected, how long it is retained, and who has access to it.
Technology companies generally operate as Data Processors, processing personal information on behalf of the school under contractual instructions.
This distinction is important, however, if a technology provider experiences a data breach or mishandles student information, parents are unlikely to distinguish between the software company and the school. More importantly, the law places primary responsibility on the institution that decided to collect and process the information in the first place.
For this reason, schools should ensure that every technology provider is governed by a comprehensive Data Processing Agreement (DPA) that clearly outlines security obligations, confidentiality requirements, breach notification procedures, and accountability measures.
Equally important is the principle of purpose limitation.
Personal information collected for one legitimate purpose should not quietly evolve into another without an appropriate legal basis.
Respecting that principle strengthens both legal compliance and parental trust.
Building Schools That Parents Can Trust
Data protection is no longer simply about avoiding regulatory action. At its core, it is about protecting children and strengthening confidence between schools and the families they serve.
Parents entrust schools with some of the most sensitive information imaginable. They disclose medical histories, learning challenges, family contacts, financial details, photographs, behavioural records, and academic performance because they believe those institutions will exercise care and responsibility.
Schools that review their admission forms, introduce purpose specific consent mechanisms, audit their technology providers, and establish internal accountability systems are not simply complying with the law, they are demonstrating a commitment to responsible stewardship of children's information.
As educational institutions continue embracing digital transformation, privacy and innovation must grow together rather than compete with one another.
Schools should strengthen their data governance practices, as poor data handling can have serious consequences for their reputation, legal compliance, and financial stability.
In Part Two of this series, we will explore the modern school technology ecosystem, examining the software platforms commonly used by schools, the legal responsibilities attached to each, and the practical steps institutions can take to modernise without increasing compliance risks.
#EdTechKenya #DataProtection #ODPC #Privacy #SchoolLeadership #SchoolManagement #DigitalGovernance #KenyaEducation #ChildProtection