Constitution of Kenya, 2010, Article 31 (Right to Privacy, including privacy of communications)
ke-const-privacy · Act
Article 31 of the Constitution of Kenya 2010 guarantees the right to privacy and enumerates, among its components, the right not to have 'information relating to their family or private affairs unnecessarily required or revealed' (Article 31(c)) and the right not to have 'the privacy of their communications infringed' (Article 31(d)). The Constitution was promulgated on 27 August 2010. This provision is included in the Digital Rights library, rather than treated as a generic privacy clause, because it satisfies both limbs of the inclusion test: it contains specific language addressing private information and the privacy of communications, and it has been the subject of identifiable judicial interpretation in surveillance and digital-data contexts. Sub-articles 31(c) and (d) are the express constitutional anchors for two related fields: the protection of personal data and the regulation of communications surveillance. The Data Protection Act 2019 was enacted specifically to give effect to Articles 31(c) and (d), and the same provision is the benchmark against which interception powers, including those in the Computer Misuse and Cybercrimes Act 2018, are assessed. Like other rights in the Bill of Rights, the right is subject to limitation only under Article 24, which permits limitation by law to the extent reasonable and justifiable in an open and democratic society. Article 31 has been interpreted in clear digital and surveillance contexts. In Coalition for Reform and Democracy (CORD) v Republic of Kenya (2015), the High Court struck down provisions of the Security Laws (Amendment) Act 2014 that would have permitted mass surveillance and the interception of communications without sufficient safeguards, holding them inconsistent with the right to privacy. In litigation over the Communications Authority's proposed 'Device Management System', the plan to install equipment capable of monitoring subscribers' calls, messages and mobile-money transactions was held to threaten the constitutional right to privacy. More recently, the right has framed disputes over biometric and digital-identity data collection, including the proceedings concerning Worldcoin/Tools for Humanity and the Katiba Institute recorded in this library's Cases database. Article 31 therefore operates as a live, frequently litigated digital-rights provision, the apex norm above Kenya's data-protection and surveillance statutes, rather than a dormant general guarantee.
- Article 31: 'Every person has the right to privacy, which includes the right not to have, (a) their person, home or property searched; (b) their possessions seized; (c) information relating to their family or private affairs unnecessarily required or revealed; or (d) the privacy of their communications infringed.'
- Sub-articles (c) and (d) expressly protect private information and the privacy of communications, the constitutional basis for both data protection and limits on interception/surveillance.
- The Data Protection Act 2019 was enacted to give effect to Articles 31(c) and (d).
- Interpreted in CORD v Republic (2015): provisions of the Security Laws (Amendment) Act permitting mass surveillance and interception without adequate safeguards were found to violate the right to privacy.
- Interpreted in the 'Device Management System' litigation: the Communications Authority's plan to install equipment enabling monitoring of calls, messages and transactions was held to threaten subscribers' privacy.