On 5 May 2025, the High Court of Kenya declared Worldcoin's operations unlawful and unconstitutional. In Republic v Tools for Humanity Corporation & 9 others; Katiba Institute & 4 others (ex parte) [2025] KEHC 5629, Justice Roselyne Aburili held that the collection, processing and transfer of Kenyans' biometric data by the Worldcoin project violated the Data Protection Act 2019 and Article 31 of the Constitution, and ordered the unlawfully collected data permanently deleted under ODPC supervision within seven days (Kenya Law; ICLG).
The facts made Kenya the global test case. Tools for Humanity enrolled Kenyans at scale by scanning irises with the Orb device in exchange for cryptocurrency worth about $50 per person (roughly KSh 7,000, per the judgment). The ODPC cancelled Worldcoin's registration as a data controller in September 2023; the judicial review, brought by Katiba Institute and others, ended with the court upholding the regulator on every substantive point.
The holdings that travel beyond this case:
- Consent obtained by inducement is not consent. Offering tokens for iris scans defeated the requirement that consent be free and informed. Any onboarding model that pays, rewards or gates services on biometric enrolment now has a Kenyan authority squarely against it.
- A DPIA is a precondition, not paperwork. Collecting biometric data at scale without a prior data protection impact assessment was itself a violation. The assessment must come before the Orb ships, not after the regulator asks.
- Accountability follows the controller, not the corporate structure. Tools for Humanity, a US corporation operating through affiliates, was held to the DPA's controller standards for Kenyan operations, with the cross-border transfer of biometric data a central defect.
- Deletion is a real remedy. Permanent deletion under regulator supervision, on a seven-day clock, is now on the menu of Kenyan relief. For a machine-learning business, deletion of training data is the most expensive order a court can make.
No appeal by Tools for Humanity had been reported as of July 2026. IAPP called the ruling "a watershed moment for Kenya data protection" (IAPP); CIPIT's analysis remains the fullest academic treatment (CIPIT).
Why it matters now. The judgment is doing active doctrinal work. The ODPC's smart-glasses investigation opened in March 2026 applies the same consent and DPIA framework to always-on wearables, and the reasoning reaches every biometric deployment in the market: fingerprint KYC at fintechs, facial recognition at building entrances, iris or face verification in national programmes. South African practitioners should note the read-across to POPIA's special personal information regime; the frameworks differ, the logic does not.
Who is affected. Any organisation processing biometric data in Kenya: banks and fintechs running biometric KYC, employers with fingerprint attendance systems, schools and hospitals with biometric registers, and global AI or identity ventures that treat African markets as enrolment territory.
What to do now:
- If you process biometrics in Kenya without a documented, pre-deployment DPIA, you are on the wrong side of a High Court judgment. Commission the assessment before the next enrolment, not after.
- Strip inducements out of consent flows for biometric enrolment. Discounts, tokens and service-gating all sit in the shadow of the inducement holding.
- Map where biometric data goes after capture. Cross-border transfer of biometrics without safeguards was a core violation, and it is the pattern most multinationals replicate by default through centralised cloud infrastructure.
Sources: Republic v Tools for Humanity, Kenya Law · ICLG · IAPP · CIPIT