In late March 2026, Kenya's Office of the Data Protection Commissioner opened an own-motion investigation into Ray-Ban Meta smart glasses, examining how footage recorded by the devices is collected, who consents to it, and how it is used to train Meta's AI systems (Daily Nation; Techweez).

The trigger was specific. A joint investigation by Swedish outlets Svenska Dagbladet and Göteborgs-Posten found that recordings from the glasses, including bathroom visits, bank card details and intimate moments, were being reviewed by human contractors at outsourcing firm Sama's Nairobi facility, labelling what they saw to train Meta's systems. On 6 March 2026, The Oversight Lab, a Nairobi digital-rights organisation, formally asked the ODPC to investigate; the regulator opened the probe on its own motion three weeks later, and more than 150 organisations and individuals signed a letter backing an open process. The UK's ICO is scrutinising the same devices, and Meta faces related litigation in the United States.

The Worldcoin baseline. Kenya has been here before, and the precedent is on the books. In Republic v Tools for Humanity Corporation [2025] KEHC 5629, the High Court held that Worldcoin's iris-scanning operation violated the Data Protection Act 2019 and the Constitution: consent obtained through crypto inducement was not valid consent, a proper data protection impact assessment was mandatory before biometric collection at scale, and the court ordered unlawfully collected data permanently deleted under ODPC supervision. Our full analysis of the Worldcoin ruling sets out the holdings. The smart-glasses probe applies the same doctrine to a harder fact pattern: the people whose data the Orb took at least stood in front of it. The people captured by camera glasses on a Nairobi street never made any choice at all, and that bystander problem is precisely what the ODPC has flagged.

Why it matters. This is the ODPC acting suo moto against a consumer product category, not adjudicating a complaint. Taken with Worldcoin, the register is clear: biometric and always-on capture technologies get proactive scrutiny in Kenya, and the AI-training supply chain behind them (device, cloud, labelling contractor) is inside the frame. The Sama angle matters commercially: Kenya is a global hub for data-labelling outsourcing, which means Kenyan processors sit in the compliance chain of AI systems trained anywhere.

Who is affected. Manufacturers, importers and retailers of any wearable with recording or biometric sensors sold in Kenya; platforms whose AI training pipelines ingest footage of identifiable people; and the outsourcing firms doing annotation work on that footage from Kenyan floors, who are processors under the DPA with their own obligations.

What to do now:

  1. If you sell recording-capable devices in Kenya, complete a DPIA that addresses bystander capture, not just user consent. Worldcoin makes the DPIA obligation explicit for high-risk processing.
  2. If you commission or perform data-labelling work in Kenya, paper the processor relationship: processing agreements, purpose limits, and security and access controls the ODPC can inspect.
  3. Audit your consent story end to end. A recording indicator LED is a design feature; it is not a lawful basis for processing the faces, voices and card numbers of people who never opted in.