
At 8.03 in the morning, an employee places a finger on a biometric reader. The attendance system records the time. Access control records entry into the building. CCTV may record movement through parts of the office. The HR system already contains leave records, performance information, disciplinary correspondence and perhaps health-related information supplied for legitimate employment purposes. Company devices and collaboration platforms may create yet another record of workplace activity.
None of those systems is automatically improper.
The more important question is what happens after the information has been collected. A biometric reader purchased to confirm attendance can gradually become something else. A manager starts using arrival records to comment on commitment. Access logs begin appearing in performance conversations. A system introduced for security is later treated as evidence of productivity.
That is where an ordinary technology decision becomes an HR governance question.
The difficult question is not whether employers can use technology.
Employers have legitimate reasons to collect and process employee information. Buildings need access controls. Organisations need attendance records. Security systems protect people and property. HR departments require employment information to administer contracts, payroll, leave, performance and statutory obligations. The serious question is therefore not whether technology belongs in the workplace. It is whether the organisation can explain, with precision, what each system collects, why that information is necessary and what decisions it is permitted to influence.
Kenya's Data Protection Act requires personal data to be processed lawfully, fairly and transparently. It also requires information to be collected for explicit, specified and legitimate purposes and restricts further processing that is incompatible with those purposes. The Act also requires organisations to limit collection to what is necessary and to avoid retaining identifiable personal data longer than the purpose requires. Those principles sound straightforward until they are applied to an actual office.
1. What employee information are you collecting?
Begin with an inventory, not a policy. Many organisations underestimate how much employee information exists because responsibility is fragmented across departments. HR holds one set of records. Security holds another. IT manages access logs. Finance holds payroll information. A benefits provider may process additional data. An outsourced HR or payroll platform may host records outside the physical office. Managers maintain spreadsheets and email attachments that are rarely included in the official data map. The first governance task is therefore simple but often uncomfortable.
List the systems.
List the information.
List the people each system can identify.
If the organisation cannot describe its employee-data environment, it cannot govern it properly.
2. Why was each system introduced?
This question is more important than it appears. An access-control system may have been introduced to secure restricted areas. A biometric attendance system may have been acquired to improve timekeeping. CCTV may have been installed for safety and security. Those purposes provide context for what information is necessary. The difficulty begins when a system quietly acquires new objectives. A fingerprint system installed to control entry into a secure building is one thing. Quietly turning the resulting attendance information into a measure of commitment, productivity or suitability for promotion is an entirely different management decision.
That is purpose creep.
Kenya's Data Protection Regulations expressly require organisations to specify the purpose of processing before designing the safeguards around it. They also require organisations to consider whether any new purpose is compatible with the original reason for which the information was collected. A new use should therefore never appear simply because the data happens to be available.
Availability is not purpose.
3. Have employees been properly informed?
Employees should not have to discover the purpose of a monitoring system during a disciplinary meeting. The Data Protection Act requires organisations, as far as practicable before collecting personal data, to inform the data subject that information is being collected, explain the purpose and provide information about matters including potential recipients and the controller or processor. For an employer, this means privacy information must reflect reality. A generic clause stating that the company "may process employee information for legitimate business purposes" is unlikely to be particularly useful if the organisation is operating several monitoring systems with materially different purposes.
If biometric attendance is used, explain why.
If CCTV is used, employees should understand the relevant purpose.
If activity information contributes to management or disciplinary decisions, that use deserves specific scrutiny and appropriate transparency.
Good governance should reduce surprises.
4. Who can access the information?
The existence of a legitimate purpose does not mean everybody in management needs access. A security officer may require particular access-control information. Payroll may require attendance information for a defined purpose. HR may require records relevant to employment administration. That does not mean every line manager needs unrestricted access to all of it.
The question should be role-based:
Who needs this information to perform a defined responsibility?
Who can download it?
Who can change it?
Which third-party vendors can see it?
Where is it stored?
What happens when an employee with privileged access leaves the organisation?
This becomes particularly important when employee data is processed through external software providers. The employer remains responsible for understanding the processing arrangement and ensuring that appropriate controls exist.
5. How long are you keeping it?
Digital storage makes it remarkably easy to confuse "we can keep it" with "we should keep it". Kenyan data-protection rules do not permit indefinite storage merely because deletion is inconvenient. The General Regulations require data controllers and processors to establish retention schedules that specify why information is retained, how long it will be retained and what action will occur when the retention period expires. This matters for employee monitoring because systems can generate enormous amounts of information.
Attendance histories accumulate.
CCTV footage accumulates.
Access logs accumulate.
Device records accumulate.
Without a retention decision, yesterday's operational record becomes tomorrow's permanent employee history by accident. That is not a retention policy; that's data accumulation.
6. Has information collected for one purpose quietly started being used for another?
This is the question I would place on the agenda of every HR Director introducing workforce technology. Imagine an organisation that installs biometric attendance to resolve disputes about arrival and departure times. Several months later, a senior manager begins asking HR to produce monthly lists of employees who arrive after a particular hour. Those reports then begin influencing conversations about attitude and commitment.
Nothing changed technically.
The device still records attendance.
But the organisation has made a new judgement about what the information signifies. That distinction is important because presence is not automatically performance. A person who arrives at 7.15 a.m. is not necessarily more productive than someone who arrives at 7.55 a.m. A green availability indicator on a collaboration platform does not, by itself, establish value created. A long period inside an office does not necessarily demonstrate good judgement, useful output or leadership. When organisations allow easy-to-measure behaviour to substitute for harder management judgement, technology can create the illusion of objectivity.
The data may be accurate.
The conclusion drawn from it may still be poor.
7. If the information affects an employment decision, can you defend that use?
This is where HR governance becomes most important. If workplace data contributes to disciplinary action, performance management, promotion, dismissal or another significant decision, management should be able to explain what role that data played and why its use was appropriate.
Where decisions are made solely through automated processing and significantly affect an individual, the Data Protection Act creates additional rights and safeguards. The General Regulations require transparency, meaningful information about the logic involved and opportunities for human intervention in relevant automated decision-making.
The principle is valuable even where a decision is not fully automated.
Technology should inform human judgement, not excuse the absence of it.
Kenya has already seen biometric attendance become a legal dispute.
This is no longer a theoretical workplace conversation. In Kenya Union of Journalists v Kenya Broadcasting Corporation, decided in November 2025, the High Court considered the rollout of a facial biometric attendance system. The Court issued orders declaring that the implementation, in the circumstances before it, had violated privacy and data-protection obligations and required the deletion of unlawfully collected biometric data. The judgement addressed failures, including transparency and the absence of a Data Protection Impact Assessment. That case should not be reduced to the simplistic conclusion that employers can never use biometric systems. The stronger lesson is that biometric technology is not merely an IT purchase.
Under Kenya's General Regulations, processing biometric data is specifically identified as a high-risk activity requiring a Data Protection Impact Assessment. A DPIA requires the organisation to examine the purpose, necessity, proportionality, risks and safeguards before the processing begins.
That should happen before implementation:
Not after employees object.
Not after HR begins using the records.
Not after a dispute reaches court.
The newest guidance makes the management issue even clearer.
The Office of the Data Protection Commissioner published emerging-technology guidance in July 2026 that expressly discusses employee monitoring in the context of commercial fleet telematics. Its example is useful beyond transport because it identifies the governance questions that appear whenever technology starts observing employee behaviour: proportionality, transparency, lawful basis, retention and the relationship between monitoring information and significant decisions. The guidance also cautions, in its fleet-monitoring example, against allowing monitoring data to drive automated disciplinary decisions without human review.
That is a useful principle for HR leaders.
Do not begin by asking how much the technology can measure; begin by deciding what the organisation has a legitimate reason to know.
Before buying another HR system, map the ones already watching.
Many companies are currently buying technology faster than they are updating policy.
One system measures attendance.
Another manages performance.
Another controls entry.
Another records communication activity.
Another stores employee records.
Individually, each system may have a legitimate purpose. The governance risk often appears when the information begins to travel between them. Before approving another biometric reader, employee-monitoring platform or workforce analytics system, conduct a proper employee-data map.
Identify the information collected.
Record the original purpose.
Confirm the lawful basis.
Establish who has access.
Identify third-party processors.
Set retention rules.
Ask whether the information is used in employment decisions.
Then examine whether the use still resembles the purpose employees were originally told about. That exercise will tell management far more than another paragraph in the staff handbook.
An organisation can know too much and govern too little.
Workplace technology is becoming more capable. That does not mean management judgement should become less demanding.
The danger is not simply surveillance. The greater danger is allowing information to acquire authority it was never meant to have.
Attendance becomes commitment.
Presence becomes productivity.
Activity becomes performance.
A system becomes a manager.
That is where HR leadership must intervene. The question is not whether an organisation should use technology. It should use technology where the business case is sound and the processing is lawful, necessary and proportionate.
The question is whether the organisation remains in control of what its technology is allowed to mean.
Before buying another HR or monitoring system, map the employee data you already collect. If management cannot explain why a dataset exists, who sees it, how long it stays and what decisions it influences, another system should not be the next purchase. Governance should be.
At Eagle HR Consultants, we support organisations introducing HR technology, biometric attendance, employee-monitoring systems and new workforce-data processes by strengthening the people-policy, employee-relations and HR-governance framework around those decisions.
Technology may collect the information. Management must still justify what the organisation chooses to do with it.




