AI for brokers

AI in a Kenyan broker inbox: automated decisions, the DPIA and the ODPC register

Section 35 of the Data Protection Act, the DPIA that automated decisions trigger, and the ODPC registration a small Kenyan brokerage cannot skip.

Published on 8 min readFCB.ai
Contents
  1. Three things the inbox does, and only one is a decision
  2. What section 35 requires when you do rely on an exception
  3. The DPIA that automated decisions trigger
  4. The registration box small brokerages tick wrongly
  5. Consent still governs who gets messaged
  6. A rollout order that keeps the Office out of it
  7. Frequently asked questions

A brokerage in Nairobi switches on the features every WhatsApp platform now ships with: the model labels each inbound reply, a score marks which clients look likely to lapse, and drafted answers appear for the team to send. Nobody in the office would describe that as a regulated activity. Under Kenyan law, at least two of those three things are processing that the Office of the Data Protection Commissioner has already written rules about, and one of them can require paperwork filed before you start.

This is not a reason to avoid automation. It is a reason to know which of your automated steps is a decision, because that single distinction determines almost everything the Data Protection Act 2019 asks of you.

Three things the inbox does, and only one is a decision

Separate them on paper before you separate them in the settings screen.

  • Classification. The model reads a reply and labels it — a renewal question, a complaint, a churn signal. That is profiling, but on its own it changes nothing for the client.
  • Scoring. A risk score or engagement score attaches a number to a person. Still an internal signal, still personal data, still capable of being wrong in a way the client would object to.
  • Acting. The system replies on its own, drops someone from a campaign, deprioritises a callback, or routes a client to a different service path. This is where a label becomes an effect on a human being.

Section 35 of the Act gives every data subject the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or significantly affects them. Two words carry the weight: solely and significantly. An adviser who reads a suggested draft, edits it and presses send has made a human decision, and section 35 does not bite. A rule that quietly removes clients above a score threshold from every renewal campaign is closer to the line than most brokerages assume.

What section 35 requires when you do rely on an exception

The right is not absolute. The Act allows a solely automated decision where it is necessary for entering into or performing a contract with the data subject, where it is authorised by a law that lays down suitable safeguards, or where the data subject has consented. If you rely on one of those, obligations follow rather than disappear: you must notify the person in writing, as soon as reasonably practicable, that a decision was taken on a solely automated basis; the person may then ask you to reconsider it or to take a decision that is not based solely on automated processing; and you must consider the request, comply with it, and tell them in writing what you did.

What the brokerage automatesSolely automated decision?What to do
Labelling an inbound message as a complaint or a churn signalNo — an internal signalKeep the label accurate and correctable; log it
Scoring lapse risk to order the call listNot usually — it ranks work, it does not decide outcomesShow the reason behind the score to the adviser
Auto-reply inside fixed rules, with escalation on negative sentimentNo, provided it does not decide anything about cover or moneyCap the number of auto-replies, escalate anything sensitive
Excluding a client from service messaging because a model marked them dormantArguably yes if it affects the service they getPut a human check in front of it, or run the section 35 process
Any automated step that changes cover, price or a claim outcomeYes — and it is not a broker function anywayDo not automate it; that decision belongs to the insurer, with a human

The cheapest compliance posture is also the best operational one: keep a person in the loop wherever the output touches the client, and the notification-and-reconsideration machinery never has to be built.

The DPIA that automated decisions trigger

The Data Protection (General) Regulations 2021 list the processing operations treated as high risk for the purposes of section 31 of the Act. First on that list is automated decision making with legal or similar significant effect that includes the use of profiling or algorithmic means, or the use of sensitive personal data to determine access to services. If your automation crosses into that territory, a data protection impact assessment is not optional, and the Act contemplates consulting the Data Commissioner before the processing starts.

The regulations also set out what happens next: a controller may consult the Office on whether the identified risks and mitigations are viable, the Data Commissioner may recommend changes to be incorporated before processing begins, and where no communication is received within sixty days of submitting the report, processing may commence and the assessment is taken to have been approved. A brokerage may publish its assessment on its website if it wishes.

For a five-person firm this is a short document, not a project: what the model does, what data goes in, what decision comes out, who checks it, what happens when it is wrong, how a client objects, and how long the records are kept. Write it once, review it when the configuration changes.

The registration box small brokerages tick wrongly

Many small firms read the exemption and stop there. Under the Data Protection (Registration of Data Controllers and Data Processors) Regulations 2021, a controller or processor is exempt from mandatory registration only where it has an annual turnover below five million shillings and fewer than ten employees. Both conditions, not either.

Then comes the part that catches intermediaries. That exemption does not apply where the data is processed for the purposes listed in the Third Schedule, and the schedule includes the provision of financial services and businesses that are wholly or mainly in direct marketing. A brokerage that reaches its book by campaign messaging should assume it is in, register, and stop debating it. A certificate of registration runs for twenty-four months, and the fees are set out in the regulations — four thousand shillings to register a micro or small controller and two thousand to renew. Exempt firms still have to comply with the substantive obligations; the exemption is from the register, not from the Act.

None of the AI work changes the underlying rule for outbound: section 37 prohibits using personal data for commercial purposes without consent or another lawful basis, the regulations define commercial use broadly enough to cover most campaign messaging, and an opt-out route has to exist and be honoured. The ODPC has issued penalty notices over exactly this kind of processing, and the Act allows penalties up to five million shillings or one percent of annual turnover. Where the model chooses the audience, the model has inherited a consent problem — so the opt-in record and the opt-out list must sit upstream of any scoring, not downstream. On timing and payment channels for the messages themselves, our guide to premium reminders in Kenya covers the ground, and the Kenya country page summarises the wider market rules brokers work under, including the Insurance Regulatory Authority's remit.

A rollout order that keeps the Office out of it

  1. Write down every automated step and mark each one as label, score or action.
  2. Put a human approval in front of every action that touches a client, and keep it there until you have evidence the model is reliable on your own traffic.
  3. Register with the ODPC unless you are certain both exemption limits apply and the Third Schedule does not.
  4. Complete a DPIA for anything that survives step two as a solely automated decision, and file it before the processing starts.
  5. Check the consent and opt-out state before any audience is built, not after.
  6. Keep the audit trail: what the model suggested, who approved it, what was sent, and when a client objected.

That order is close to how ORIS is built to run: the classifier labels inbound messages and updates risk scores, drafted replies are held for a human unless a rule explicitly allows an automatic answer, negative sentiment always escalates to a person, opt-outs cut both queued messages and running journeys, and the audit log records the sequence. The comparable South African analysis of scoring under POPIA section 71 reaches the same conclusion from a different statute: supervision is the control that makes the rest of it defensible. Want to see it against your own book? Book a demo.

Frequently asked questions

Does using AI to draft replies make our brokerage a data controller for the AI vendor's processing?

You remain the controller for your clients' personal data, and the platform processing it on your instructions is a processor. That means a written processing arrangement, a clear position on where data is processed and transferred, and enough detail in your privacy notice for a client to understand that automated analysis happens. Bringing a tool in does not move the accountability off your firm.

Do we need consent specifically for the AI analysis?

Consent is one lawful basis among several, and for service messaging about an existing policy the performance of a contract is often the better fit. Commercial or marketing use is different: section 37 requires consent or another lawful basis, and the burden of showing it sits with you. Do not fold a marketing permission into an onboarding tick-box and hope it carries both.

Our scoring only ranks the call list. Is that a section 35 decision?

Ranking work for advisers who then decide what to do is not usually a decision taken solely by automated means, because a human still chooses the outcome. It becomes one when the ranking silently determines who gets a service at all. The test is whether a person exercised real judgement, not whether a person was technically able to intervene.

Must the DPIA be sent to the Data Commissioner before we start?

Where the assessment shows high risk, the Act requires consultation with the Data Commissioner before processing, and the regulations set a sixty-day window: if no communication comes back within sixty days of submission, processing may begin and the report is taken to have been approved. Keep the submission proof with the assessment.

We are a four-person brokerage. Do we really have to register?

Probably yes. The turnover and headcount exemption applies only if both limits are met, and it falls away entirely for the purposes in the Third Schedule, which include the provision of financial services and businesses wholly or mainly in direct marketing. Registration lasts twenty-four months and is cheap compared with an enforcement notice.

See ORIS in action

Shared WhatsApp inbox, client records, follow-ups and opportunities for the whole brokerage. 15-minute demo.

Book a demo
Book a demo