
Just this morning, a link dropped in one of my Kenyan Whatsapp groups. Kenya’s government is planning to sell anonymized citizen data from the eCitizen platform, a government portal used by millions for passports, visas, business registrations, taxes and thousands of other services, to businesses, researchers and other approved buyers.
I hastily typed a three word response: This. Is. Insane.
I still think that reaction was reasonable. As someone who has surrendered all the minute details of my life to eCitizen, the headlines were truly alarming. But after spending the morning actually reading the Draft Final National Data Governance Policy, I’m now ready to offer a more constructive take.
The headline isn’t wrong, but it’s not the whole story
The policy does propose a national exchange where anonymized, aggregated, non-personal datasets can be licensed to approved users (researchers, businesses, civil society, etc.) with the government collecting revenue.
But the marketplace is a relatively small section of a much larger document whose primary concern is something more mundane: fixing Kenya’s genuinely chaotic data infrastructure. Government agencies currently collect the same information repeatedly, store it in incompatible systems, and rarely share it effectively. The policy’s core mission is to fix this plumbing to build interoperable systems, establish common standards, and reduce the spectacular duplication of effort that currently defines how the Kenyan state manages information.
The data monetization provisions are still deeply concerning
Still, acknowledging the broader ambitions of the policy does not make its commercialization provisions any less troubling.
When you use eCitizen, you don’t really have a choice. These aren’t voluntary transactions, they’re interactions with the state that you have to complete to function as a citizen. The policy’s answer to whether you’ve consented to your data being packaged and sold is essentially: it’s anonymized, so consent isn’t required. This may be a legally defensible position, but it a much less convincing ethical one.
Anonymization is also a much weaker protection than it sounds. Researchers have shown repeatedly that crossing two or three supposedly anonymized datasets can often allow you to re-identify specific individuals. The policy acknowledges this risk in passing but doesn’t engage with it seriously.
And then there’s a particularly alarming line buried in the commercialization section that explicitly includes AI models trained on public data. This means that whoever trains AI on government data and then commercializes those models is extracting substantial value from citizen-derived information. The benefit sharing-mechanisms proposed for this are vague.
The policy, which reads like a wish list for a new digital state, has a phased implementation starting July 2026. A new Council, a new Data Governance Office, data officers in every ministry and every county, a new API gateway, eventually a new Data Governance Law. Is that timeline remotely credible? Are these expansive administrative provisions feasible? What happens if the marketplace launches before the infrastructure and safeguards are in place?
The (very unsurprising) thing that surprised me the most
Alas, I persist in my credulity and naivety.
It turns out that the policy was substantially developed with EU and German technical assistance and funding. You can see it in the document’s vocabulary and architecture, which closely mirrors the EU’s own Data Governance Act. This itself isn’t surprising, a lot of African policies are funded and developed by external funders and their consultants.
But here’s where the irony rubs: a lot of this wouldn’t fly in Germany and the EU. The EU’s own data reuse framework explicitly prohibits public sector bodies from using data reuse as a revenue-maximizing activity. Germany’s constitutional framework enshrines informational self-determination as a fundamental right in ways that would make the Kenyan proposal legally and politically radioactive at home. The EU’s GDPR would place significant constraints around pseudo-anonymization and re-identification risks.
The result? The institutions that helped write this policy would struggle to pass it in their own countries.
The bigger question
Can government data be managed and used more effectively? Of course it can. Does data have economic value? Of course it does. What troubles me is the quiet shift in the role of the state from collecting data in order to govern and create public goods, toward collecting data that may also become a revenue-generating asset. Those are not necessarily the same thing, and they demand different forms of accountability.
Whether this becomes a genuinely progressive data governance framework or a mechanism for quietly monetizing citizen data without accountability will depend almost entirely on implementation. As written, there is ample cause for skepticism.

