Your Iris Is Not for Sale: Africa’s Fight to Keep Biometric Data a Right, Not a Resource
Biometric data is a new gold which various countries and corporate entities are seeking to extract profit from and exert control over populations across the world. The High Court of Kenya resisted this new extractivism and ordered the deletion of biometric data of several thousands of Kenyans whose economic difficulties had been exploited to obtain records of their iris.
On 5 May 2025, the High Court of Kenya ordered something that had never happened before on the continent: the permanent, court-supervised deletion of biometric data collected from hundreds of thousands of citizens.[1] The company was Tools for Humanity – an operator of the Worldcoin cryptocurrency project. Its method was simple and, for many Kenyans, irresistible: scan your iris, receive 25 free tokens worth about Sh7,000.[2] Within a week of launch, over 350,000 Kenyans, about 25% of Worldcoin’s entire global user base, had let a machine read their eyes in exchange for cash.[3] The court found the company had never registered as a data controller, never conducted the legally required impact assessment, and had obtained “consent” from people whose economic circumstances made refusal almost unthinkable.[4]
The Worldcoin case is not just a story about one company cutting corners. It is a preview of a much larger and quieter contest now unfolding across the continent, over what biometric data actually is, and whose rules should govern it when Chinese firms, financiers, and technology increasingly sit at the centre of Africa’s digital infrastructure.
Two Philosophies, One Fingerprint
Chinese companies have built an estimated 70 per cent of Africa’s 4G network and are central to the rollout of biometric-enabled “Safe City” surveillance systems across the continent.[5] Forty-nine African countries now use at least one form of biometric identification system.[6] Yet the rules governing what happens to that data, particularly when it passes through Chinese-built infrastructure or Chinese-run platforms, remain thin, fragmented, and largely untested in court.
At the heart of this gap sits a genuine philosophical disagreement. African constitutional law treats biometric data as an extension of the human body itself, something that cannot simply be bought, sold, or extracted, because it is inseparable from human dignity. Kenya’s Constitution enshrines this in Article 31, and the Data Protection Act was written specifically to give effect to that legal right, classifying biometric data as “sensitive” and subjecting it to the strictest protections in the law.[7]
China’s governing philosophy runs in the opposite direction. Since 2022, Beijing has formally classified data, including personal and biometric data, as a “factor of production,” ranked alongside land, labour, and capital as an input into economic growth.[8] China’s Personal Information Protection Law (PIPL) does offer real protections on paper. But those protections operate inside a system whose overriding purpose, as scholars of Chinese data governance have documented, is to serve economic growth and national security first, with individual protection as a secondary, instrumental concern.[9] A 2022 legal study for the European Data Protection Board went further, concluding that Chinese state access to personal data is barely constrained at all: concepts like “national security” are interpreted so broadly that they routinely override individual protections.[10]
This is not an abstract difference. It shapes what happens to an African’s fingerprint or iris scan once it enters a system built, financed, or operated by a Chinese partner: what it can be used for, who can access it, and what recourse a person has if something goes wrong. Scholars have coined a term for the risk this creates; “biometric coloniality,” the extraction of African biometric data through partnerships that quietly reproduce old, unequal power relationships in new, digital form.[11]
Africa Already has an Answer, on Paper
The good news is that Africa is not arriving at this contest empty-handed. Kenya’s Data Protection Act, the continent-wide Malabo Convention, and the newly adopted African Continental Free Trade Area (AfCFTA) Protocol on Digital Trade together form a real, rights-based legal architecture. The Malabo Convention requires that personal data may only be transferred to a foreign country if that country genuinely protects the privacy, freedoms and fundamental rights of the people whose data it is and not the mere existence of data laws.[12] The AfCFTA Digital Trade Protocol goes further, requiring every member state to maintain a functioning data protection authority and permitting cross-border data flows only on the condition that domestic safeguards are respected.[13]
The problem is not an absence of law. It is the risk of that law being quietly eroded, not through open confrontation but through the everyday pressure of doing business with a much larger, better-resourced partner. Under Article 66 of China's Personal Information Protection Law (PIPL), the Cyberspace Administration of China can levy massive administrative fines of up to RMB 50 million or 5% of annual turnover on corporate data processors for serious safety violations, the state's enforcement capacity is highly empirical.[14] Kenya’s Office of the Data Protection Commissioner, whatever its ambition, operates with a fraction of that capacity.[15] Chinese firms have built the physical infrastructure, the servers, the networks, the cameras, that African data now runs through, embedding Chinese technical standards at the foundation layer of African digital life.[16] And because no formal mechanism exists allowing China to recognise African data protection standards as adequate, the practical default in any dispute is for the African side to accommodate Chinese requirements. This default is driven by technical reliance. Since Chinese firms build 70 per cent of Africa’s digital core, cloud and data architectures are natively built on Chinese technical standards.[17] Lacking the massive enforcement budgets of the Cyberspace Administration of China, underfunded African regulators must pragmatically yield to these technical parameters to keep their infrastructure running.
When Courts Push Back
Kenya has shown, twice now, that its courts are willing to enforce a dignity-based framework against real power. Beyond Worldcoin, the High Court has repeatedly suspended the rollout of Maisha Namba, Kenya’s national digital identity programme, because the government failed to conduct the legally mandated assessment of its impact on citizens before collecting their biometric data at scale.[18] Together, these rulings establish a principle that matters enormously for any future Sino-African biometric infrastructure: it does not matter whether the actor is a private company or the state itself, and it should not matter whether the technology is imported. Kenyan constitutional standards apply.
China’s own courts have shown flashes of similar instinct. In the landmark Guo Bing case, a Chinese court ruled that businesses cannot force customers to submit to facial recognition when a less intrusive alternative exists.[19] But legal scholars who have studied the case note a critical limit: these protections restrain private companies far more than they restrain the state. Where facial recognition is deployed by the government for “public security,” the same restraints “function poorly.”[20] Under the Personal Information Protection Law of the People’s Republic of China (PIPL), private companies that misuse personal data face both civil and administrative penalties; state agencies that do the same face only administrative slaps on the wrist.[21] The lesson is not that China’s system offers African data subjects no protection at all. It is that whatever protection exists is calibrated to restrain commercial actors, not the state, which is precisely the actor whose reach African data subjects most need to be protected from when biometric infrastructure crosses borders.
What Needs to Hold
None of this means Sino-African digital partnership should be abandoned; the investment in connectivity and infrastructure is real and valuable. What it means is that African governments must insist, as a non-negotiable condition of any such partnership, that African constitutional standards form the floor of the arrangement, not a starting point to be negotiated downward.
Concretely, this means five things. First, no biometric enrolment scheme, whether run by a cryptocurrency start-up or a state digital ID programme, should be allowed to treat a person’s economic desperation as valid consent; Worldcoin’s tokens-for-iris-scans model should be the textbook example of what consent is not. Second, any data collected must be strictly limited to its stated purpose, with no room for it to be repurposed later as a generic economic asset. Third, any automated decision made using African biometric data, whether about identity, credit, or benefits, must come with a guaranteed right to meaningful human review. Fourth, African data protection authorities, not their better-resourced foreign counterparts, must retain supervisory authority over African data, regardless of where the servers sit. Fifth, and most importantly, any Chinese partner should be contractually required to disclose, upfront and on an ongoing basis, what legal obligations it has under Chinese law to hand that data over to Chinese state authorities. This does not stop that access; it simply ensures Africans know the risk they are living with when they share their biometric data, rather than discovering it after the fact.
The AfCFTA Digital Trade Protocol is the natural home for formalising these five principles into something like the EU’s Standard Contractual Clauses, a template that African states could require of any partner before biometric data crosses a border.[22] Kenya’s courts have already shown, twice, that they will not treat African data protection law as decorative. The task now is to make sure that principle survives contact with a partner whose own governing philosophy sees a person’s face and fingerprints not as an extension of who they are, but as a resource waiting to be put to use.
Robin Kipng'eno is a final year law student at Kabarak University School of Law, a researcher and mooter. He has a keen interest in Kenyan policing, human rights law, and the governance of emerging technologies, including artificial intelligence and data protection, and is drawn to research opportunities that can inform legal reform.
Endnotes
[1] Republic v Tools for Humanity Corporation (US) & 8 others; Katiba Institute & 4 others (Ex parte); Data Privacy & Governance Society of Kenya (Interested Party) (Judicial Review Application E119 of 2023) [2025] KEHC 5629 (KLR) (5 May 2025).
[2] Capital FM, “Revealed: Kenya Registered Highest Worldcoin Entries Globally at 350,000” (2023), https://www.capitalfm.co.ke/news/2023/08/revealed-kenya-registered-highest-worldcoin-entries-globally-at-350000/.
[3] CIPIT, “Kenya High Court’s Worldcoin Determination: Upholding Consent, Accountability and Data Sovereignty in Biometric Data Processing” (Strathmore University, September 2025), https://cipit.strathmore.edu/kenya-high-courts-worldcoin-determination-upholding-consent-accountability-and-data-sovereignty-in-biometric-data-processing/.
[4] Dennis Musau, 'Worldcoin Deletes Kenyans' Biometric Data after Court Order' (Business Daily, 21 January 2026) https://www.businessdailyafrica.com/bd/corporate/technology/worldcoin-deletes-kenyans-biometric-data-after-court-order-5333600
[5] Institute for Strategic Policy and Innovation (ISPI), “China’s Evolving Role in Africa’s Digitalisation” (December 2022), https://www.ispionline.it/en/publication/chinas-evolving-role-africas-digitalisation-building-infrastructure-shaping-ecosystems-31247.
[6] Citizenship Rights in Africa Initiative, Biometrics and Digital Identity in Africa: Assessment of Governance, Vendors, and Human Rights (2024) https://citizenshiprightsafrica.org/en/biometrics-and-digital-identity-in-africa-assessment-of-governance-vendors-and-human-rights/
[7] Constitution of Kenya 2010, art 31; Data Protection Act 2019 (Kenya), long title and part V
[8] CCP Central Committee and State Council, ‘Opinions on Building a Data Base System for Better Use of Data as a Factor of Production’ (2 December 2022) (the ‘20 Data Measures’); Alex He, ‘Data Marketplaces and Governance: Lessons from China’ https://www.cigionline.org/articles/data-marketplaces-and-governance-lessons-from-china/
[9] Xingqiang He, “State-Centric Data Governance in China,” Centre for International Governance Innovation, https://www.cigionline.org/publications/state-centric-data-governance-in-china/.
[10] European Data Protection Board, Government Access to Data in Third Countries – Final Report (January2022)
[11] Victor Chidubem Iwuoha and Martin Doevenspeck, ‘Biometric Coloniality: Digital Consensus and the Biometric State in Africa’
[12] African Union Convention on Cyber Security and Personal Data Protection (Malabo Convention), art 14(6).
[13] Protocol to the AfCFTA Agreement on Digital Trade (2024), arts 20, 21 and Annex on Cross-Border Data Transfers (2025).
[14] Personal Information Protection Law of the People's Republic of China 2021 (PIPL), art 66.
[15] Data Protection Act 2019 (Kenya), s5. On resource constraints facing African data protection authorities, see Oscar M Otele, ‘Kenya’s Data Protection Regime: Challenges and Future Prospects’ (2021) Journal of African Perspectives; Privacy International, ‘Analysis of Kenya’s Data Protection Act, 2019’; Graham Greenleaf and Bertil Cottier, ‘International and Regional Commitments in African Data Privacy Laws: A Comparative Analysis’ (2022) 44 Computer Law & Security Review 105638, 105648 https://doi.org/10.1016/j.clsr.2021.105638
[16] Tyler Venske, ‘Navigating Digital Sovereignty in Africa: A Review of Key Challenges and Constraints.’ Good Governance Africa, 2023, vol 1, no.4.
[17] Institute for Strategic Policy and Innovation (ISPI), “China’s Evolving Role in Africa’s Digitalisation” (December 2022)
[18] Haki na Sheria Initiative v Attorney General & 4 others (Petition 196 of 2023) [2024] KEHC 10021 (KLR) (Constitutional and Human Rights, Mugambi J, 12 August 2024) (Ruling) https://new.kenyalaw.org/akn/ke/judgment/kehc/2024/10021/eng@2024-08-12;
Republic v Kithure Kindiki, Cabinet Secretary Interior & Coordination of National Government & another; Katiba Institute (Ex parte) (Judicial Review Application E194 of 2023) [2024] KEHC 1649 (KLR) https://new.kenyalaw.org/akn/ke/judgment/kehc/2024/1649/eng@2024-02-23;
Future of Privacy Forum, 'How the Kenyan High Court (Temporarily) Struck Down the National Digital ID Card: Context and Analysis' (FPF, 2021)
[19] Guo Bing v Hangzhou Safari Park (Zhejiang Provincial High Court, 2021).
[20] Jyh-An Lee and Peng Zhou, ‘FRT Regulation in China’ in Rita Matulionyte and Monika Zalnieriute (eds), The Cambridge Handbook of Facial Recognition in the Modern State
[21] Personal Information Protection Law of the People’s Republic of China 2021 (PIPL), art 68.
[22] European Commission, Implementing Decision (EU) 2021/914 on Standard Contractual Clauses