Kenyan sports federations, clubs and anti-doping bodies now hold more personal data on athletes than ever before: membership registers, next-of-kin details, medical clearance records, and increasingly biometric identifiers used for stadium accreditation and doping-control whereabouts systems. All of it is subject to the Data Protection Act, No. 24 of 2019, regardless of what the anti-doping rules or federation statutes separately require. This article covers the data-protection compliance side of that picture: who counts as a data controller, what makes biometric and location data “sensitive,” when registration with the Office of the Data Protection Commissioner (ODPC) is mandatory, and what the ODPC’s own guidance expects of anyone running a biometric accreditation or tracking system.
Biometric Data Is Legally “Sensitive,” Not Just Confidential
Section 2 of the Data Protection Act defines “biometric data” as personal data resulting from specific technical processing based on physical, physiological or behavioural characteristics, including fingerprinting, retinal scanning, voice recognition and DNA analysis. The Act then classifies biometric data, together with health status, genetic data and several other categories, as “sensitive personal data.” This matters because sensitive personal data attracts a stricter processing regime under sections 44 and 45 than ordinary contact or membership information.
For sports bodies, this classification captures more than it might first appear. A federation issuing fingerprint-based accreditation for stadium access, an anti-doping panel maintaining an athlete’s health and testing history, and a club recording a player’s biometric data for a wearable fitness tracker are all processing sensitive personal data. A whereabouts system logging where an athlete will be each day for out-of-competition testing is not “biometric” in the strict sense, but it typically sits alongside health and testing records that are, and should be treated with the same care.
Who Is the Data Controller: The Federation, the Club or the Doctor?
The Act separates a “data controller,” who determines the purpose and means of processing, from a “data processor,” who processes data on the controller’s behalf. A federation that decides to run a biometric accreditation system, and sets the rules for who can access the data and why, is the controller for that system. A club doctor who forwards an athlete’s test results to the federation at the federation’s instruction is typically acting as a processor, not an independent controller, provided the doctor is not also deciding independently how that data will be used elsewhere.
Section 25 places the core compliance obligations, lawfulness, fairness, purpose limitation, data minimisation, accuracy and storage limitation, on both controllers and processors, and also restricts transferring personal data outside Kenya unless there is proof of adequate safeguards or the data subject’s consent. A federation hosting its membership or biometric database on a cloud server abroad, or sharing whereabouts data with an international federation, needs to check this before assuming the transfer is lawful.
Lawful Grounds for Processing Athlete Biometric and Whereabouts Data
Section 44 provides that no category of sensitive personal data may be processed unless the section 25 principles are satisfied, and section 45 then sets out the specific grounds on which such processing may proceed. One useful ground for membership organisations is that processing may proceed where it is carried out by a body with a defined membership and relates solely to the members of that body, or to persons who have regular contact with it in connection with its purposes. A federation processing the biometric or health data of its own registered players, coaches and match officials, for purposes connected to their membership, sits squarely within this ground. Sharing the same data with a sponsor or a betting operator does not.
Consent remains available as a separate ground, but the ODPC’s guidance on biometric data, discussed below, expects consent to be specific, informed and genuinely capable of being withdrawn, not a blanket clause buried in a registration form. Where an athlete is a minor, common in junior and school-level competition, parental or guardian consent is required.
Registration with the ODPC: Mandatory for Most Sports Bodies Handling This Data
Section 18 prohibits acting as a data controller or data processor unless registered with the Data Commissioner, though the Data Protection (Registration of Data Controllers and Data Processors) Regulations, 2021 exempt small non-profits, broadly those with fewer than ten employees and annual turnover below five million shillings. That exemption falls away, and registration becomes mandatory regardless of size, where processing includes health administration and patient care, or the processing of genetic data. An anti-doping body maintaining athlete health and testing records, or a federation running a genetic-testing programme, will typically fall into a mandatory-registration category even if otherwise small enough to qualify for the exemption. Fees are modest, starting at four thousand shillings for the smallest category, but operating without registration where it is required is itself a compliance failure, separate from how carefully the underlying data is handled.
Impact Assessments and Security: What the ODPC Actually Expects
Section 31 requires a data protection impact assessment before processing likely to pose a high risk to a data subject’s rights, submitted to the Commissioner sixty days before the processing begins. The ODPC’s Guidance Note on Biometric Data treats biometric processing as inherently high-risk and applies this directly to accreditation and tracking systems of the kind sports bodies run. The guidance sets out expectations beyond the bare text of the Act: technical and organisational safeguards including encryption and access controls, at least one full copy of biometric data stored in Kenya, breach notification to the ODPC within seventy-two hours, and mechanisms for athletes to access, correct or erase their own data. A federation building or procuring a new accreditation or whereabouts system should treat this guidance as the practical compliance checklist, not an optional extra.
How We Can Help
Clay & Associates Advocates advises sports federations, clubs and anti-doping bodies on data protection compliance, including ODPC registration, consent and privacy notices for athletes, and data-sharing arrangements with international federations and sponsors. Our guide to anti-doping compliance in Kenya covers the substantive testing and whereabouts obligations that generate much of this data, and our guide on registering a sports organisation in Kenya covers the parallel registration steps a federation needs at formation. Contact our Sports practice to review your data-handling systems before a breach or an ODPC complaint forces the issue.
Sources: Data Protection Act, No. 24 of 2019, sections 2, 18, 25, 31, 44 and 45; Data Protection (Registration of Data Controllers and Data Processors) Regulations, 2021, regulation 13; Office of the Data Protection Commissioner, Guidance Note on Biometric Data (2025).
Frequently asked questions
Does a small local sports club need to register with the ODPC?
Not necessarily. Non-profit clubs with fewer than ten employees and annual turnover below five million shillings are exempt from mandatory registration. That exemption does not apply if the club processes genetic data or runs health administration functions such as maintaining player medical records for treatment purposes, in which case registration is required regardless of size.
Is an athlete’s whereabouts information for doping control “sensitive personal data”?
Whereabouts data itself, meaning location and schedule information, is not one of the categories listed as sensitive personal data under section 2 of the Act, but it is almost always processed together with health and testing records that are. Anti-doping bodies should treat the whole record, not just the biometric component, as sensitive personal data and apply the section 44 and 45 conditions to it.
Can a federation share an athlete’s biometric data with an international federation abroad?
Only if the transfer meets the cross-border transfer conditions in section 25, which generally require proof of adequate data protection safeguards in the receiving country, or the athlete’s consent. This should be addressed directly in the federation’s data-sharing agreement with the international body, not assumed.
What happens if a federation processes biometric data without registering as required?
Operating as an unregistered data controller or processor where registration is mandatory is itself a breach of section 18, separate from any penalty that may follow from mishandling the data itself. The Data Commissioner can also impose administrative fines of up to five million shillings, or up to one per cent of annual turnover for an undertaking, for broader non-compliance.



