Digital lenders in Kenya increasingly approve or decline a loan application in seconds, based on a model that weighs mobile money transaction history, airtime top-up patterns, phone metadata and a borrower’s social graph rather than a conventional credit file. That speed is the product, but it also means a lending decision now turns on variables a rejected borrower cannot see and often cannot challenge. Kenyan law already regulates several pieces of this picture, even though no regulator has yet brought an enforcement action framed specifically around “algorithmic bias,” and lenders building or buying these models should not read that regulatory silence as an absence of risk.
The Data Protection Act’s Automated Decision-Making Provisions
Section 35 of the Data Protection Act, 2019 gives a data subject the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal effects concerning them or similarly significantly affects them, except in narrow circumstances such as where the decision is necessary for a contract or authorised by law with suitable safeguards. A credit decision generated entirely by a scoring model, with no meaningful human review of an individual application, sits squarely within what this provision targets. The Data Protection (General) Regulations, 2021 add specificity: regulation 22 requires a controller engaged in automated individual decision making to inform the data subject, explain the significance and envisaged consequences of the processing, use appropriate mathematical or statistical procedures, put technical and organisational measures in place to correct inaccuracies and minimise errors, process personal data in a way that eliminates discriminatory effects and bias, and ensure the data subject can obtain human intervention and express their point of view. A lending model whose variables function as a proxy for a protected characteristic, or that offers no real route to human intervention on a declined application, sits in tension with this regulation regardless of whether the lender intended any discriminatory effect.
The Banking (Credit Reference Bureau) Regulations: A Specific Denial Penalty
The Banking (Credit Reference Bureau) Regulations, 2020 speak directly to a related but narrower problem: an adverse decision driven by a single automated factor. Regulation 40(1) requires a credit score to function as one factor among several in a lending decision rather than the sole basis for it, regulation 40(4) requires an institution to notify a declined applicant in writing of the decision and the reasons for it, and regulation 40(5) imposes a penalty of up to two million shillings on an institution that denies credit or any other financial service solely on the basis of a credit score. Their legal status has been contested: the High Court nullified them in 2022 for missing a statutory timeline for tabling before Parliament, restoring the 2013 Regulations, before the Court of Appeal suspended that judgment and reinstated the 2020 Regulations pending the Central Bank’s appeal. As matters stand they are in force and being applied, but a lender should note the litigation is not yet finally resolved. Either way, a workflow that auto-declines the moment a bureau score falls below a threshold, without any documented independent review step, is the precise conduct regulation 40(5) penalises.
The Central Bank’s Digital Credit Provider Framework
The Central Bank of Kenya (Digital Credit Providers) Regulations, 2022 require digital lenders to be licensed and to treat borrowers fairly, including a prohibition on unfair or deceptive practices in how credit terms are communicated and applied. The Regulations are, however, genuinely thin on the specific question this article is about: they do not prescribe a methodology a lender’s scoring model must follow, do not require model documentation to be filed with the CBK, and do not set out a testing or audit standard for detecting disparate impact across borrower groups. This is a real gap in the current framework, not one this article can paper over with a confident-sounding rule that does not exist. Lenders operating in this space are, in practice, working out their own model governance standards against a backdrop of general fair-dealing obligations rather than a specific algorithmic-lending rulebook.
Consumer Protection Act Obligations
The Consumer Protection Act, 2012 supplies a further backstop, prohibiting unfair and unconscionable practices in consumer transactions and requiring clear disclosure of the basis on which credit is extended or refused. A scoring practice that a court found opaque to the point of being fundamentally unfair to the consumer, for instance treating variables with no genuine bearing on creditworthiness as decisive, could in principle be challenged under this general consumer protection standard even without a bespoke algorithmic-lending rule to invoke directly.
The Honest State of Enforcement
As of this article’s publication, no published Kenyan enforcement action, whether by the Office of the Data Protection Commissioner, the Central Bank, or the courts, has specifically targeted algorithmic bias in credit scoring as such. This should not be read as regulatory comfort. The Data Commissioner has been increasingly active on automated processing and profiling generally, and a complaint from a rejected borrower under section 35 or regulation 22 would not require new legislation to succeed, only an application of existing provisions to a specific model’s design. Lenders should treat the current absence of a targeted enforcement case as a lag in regulatory capacity and litigation timing, not as a signal that the underlying conduct is unregulated.
Practical Governance Steps
Digital lenders should document the variables their scoring model uses and test whether any function as a proxy for a protected characteristic under regulation 22, maintain a genuine human review step for declined applications rather than a rubber-stamp override option nobody uses, keep records showing bureau-derived declines were independently verified as regulation 40(1) requires, and be able to give a declined applicant specific, comprehensible reasons for the decision rather than a generic “does not meet our criteria” response. Model documentation and periodic bias testing, while not yet mandated by name in Kenyan law, are the practical evidence a lender would want in hand if the Data Commissioner or a court ever tested a specific decision against section 35 and regulation 22.
How We Can Help
Clay & Associates Advocates advises digital lenders and fintech businesses on data protection, credit regulation and consumer protection compliance in Kenya. Our analysis of data protection compliance under the DPA covers the automated processing framework in more depth. Contact our Financial Services practice to review your lending model’s compliance posture.
Sources: The Data Protection Act, 2019, section 35; The Data Protection (General) Regulations, 2021, regulation 22; The Banking (Credit Reference Bureau) Regulations, 2020, regulation 40; The Central Bank of Kenya (Digital Credit Providers) Regulations, 2022; The Consumer Protection Act, 2012.
Frequently asked questions
Can a lender in Kenya legally decline a loan using a fully automated credit scoring model?
Section 35 of the Data Protection Act restricts decisions based solely on automated processing that significantly affect the data subject, so a fully automated decline with no meaningful human review carries real legal risk even without a specific enforcement precedent yet on point.
What penalty applies if a lender declines an application based only on a credit bureau score?
Regulation 40(5) of the Banking (Credit Reference Bureau) Regulations, 2020 imposes a penalty of up to two million shillings on an institution that denies credit or any other financial service solely on the basis of a credit score.
Does Kenyan law require lenders to test their credit scoring models for bias?
Not explicitly by that name. Regulation 22 of the Data Protection (General) Regulations, 2021 requires controllers carrying out profiling to prevent discriminatory effects and correct inaccuracies, which functions as a bias-prevention obligation even though no separate bias-testing rule exists.
Has any Kenyan regulator taken enforcement action over algorithmic bias in lending?
Not yet, as of this article’s publication. That absence reflects the newness of the issue and litigation timing rather than an absence of applicable law.



