Handling biometric data under African data protection laws
All three laws treat biometric data as a special category. Nigeria names facial images and limits sensitive data to listed grounds, Kenya treats biometric processing as high risk, and POPIA prohibits it unless an authorisation applies. Plan a lawful ground, a DPIA and minimisation.

Charles Archibong, Co-founder
· 6 min read

Key takeaways
- Nigeria, Kenya and South Africa all place biometric data in a special, more protected category.
- Nigeria's NDPA definition of biometric data expressly includes facial images.
- Kenya's 2021 General Regulations list processing biometric data as high risk, which calls for a DPIA.
- POPIA prohibits processing biometric information unless an authorisation such as consent applies.
Nigeria, Kenya and South Africa all treat biometric data as a special category that needs more than an ordinary legal basis. Nigeria's Data Protection Act names facial images in its definition of biometric data and allows sensitive data to be processed only on listed grounds. Kenya lists biometric data as sensitive and, by regulation, treats its processing as high risk. South Africa's POPIA starts from a prohibition on processing biometric information and then sets out when it is allowed.
For a selfie and liveness check, that means three things to settle before launch: which lawful ground you rely on in each country, a documented impact assessment, and a design that collects and keeps no more biometric data than the check needs. Requirements differ by jurisdiction and change over time, and this article is general information, not legal advice. Take advice on your own position.
Is a verification selfie biometric data?
Very likely, once it is processed to identify someone, though the wording differs by country.
Nigeria | Kenya | South Africa | |
|---|---|---|---|
Law | Nigeria Data Protection Act 2023 | Data Protection Act 2019 | Protection of Personal Information Act 2013 |
Definition | "Biometric data": personal data from specific technical processing of physical, physiological or behavioural characteristics which allow or confirm unique identification, "including without limitation ... facial images" (s.65) | "Biometric data": personal data from specific technical processing based on physical, physiological or behavioural characterisation, listing blood typing, fingerprinting, DNA, earlobe geometry, retinal scanning and voice recognition (s.2) | "Biometrics": a technique of personal identification based on physical, physiological or behavioural characterisation, listing blood typing, fingerprinting, DNA analysis, retinal scanning and voice recognition (s.1) |
Special category | "Sensitive personal data" includes biometric data "for the purpose of uniquely identifying a natural person" (s.65) | "Sensitive personal data" includes biometric data (s.2) | "Special personal information" includes biometric information (s.26) |
Nigeria's Act is the only one of the three that names facial images expressly. Kenya's and South Africa's lists are examples rather than closed lists, and Kenya's Data Protection (General) Regulations 2021 (opens in a new tab) refer to "biometric technology, including voice or facial recognition" (regulation 6(1)(e)). Whether a face template or a match score is biometric data in each country is a question for your lawyers; a cautious programme assumes it is.
What does Nigeria require?
The Nigeria Data Protection Act 2023 (opens in a new tab) says a controller shall not process sensitive personal data unless one of the grounds in section 30(1) applies. They include consent "for the specific purpose or purposes for which it will be processed", processing necessary for a legal claim, and processing necessary "for reasons of substantial public interest, on the basis of a law" with suitable safeguards. Section 30(1) contains no general "legal obligation" ground of the kind many teams assume, so the choice of ground needs care.
Section 28 requires a data privacy impact assessment (DPIA) before processing "likely to result in high risk". Section 37 gives people a right not to be subject to decisions based solely on automated processing with legal or similarly significant effects, subject to exceptions, and requires safeguards including the right to human intervention and to contest the decision.
The Nigeria Data Protection Commission's General Application and Implementation Directive (GAID) 2025 (opens in a new tab) was issued on 20 March 2025 and, according to the Commission's Annual Report 2025 (opens in a new tab), came into force on 19 September 2025. Two provisions matter here:
Article 18(1)(b) says consent is required "for the processing of sensitive personal data".
Article 28(3) makes a DPIA mandatory, and to be filed with the Commission, in listed circumstances, including "when sensitive or highly personal data is involved" and "financial services involving the processing of personal data through digital devices".
A fintech running selfie checks in Nigeria is likely to meet both of those DPIA triggers.
What does Kenya require?
Under the Data Protection Act 2019 (opens in a new tab), sensitive personal data may be processed only where the principles in section 25 are met (section 44), and section 45 sets the permitted grounds. They include processing necessary for a legal claim and processing necessary "for the purpose of carrying out the obligations and exercising specific rights of the controller or of the data subject". Unlike Nigeria and South Africa, section 45 does not list consent as a ground for sensitive data, so the ground for a selfie check in Kenya needs particular care. Section 31 requires a data protection impact assessment before processing likely to result in high risk, and section 35 restricts decisions based solely on automated processing.
The General Regulations 2021 remove any doubt about the DPIA: regulation 49(1)(c) lists "processing biometric or genetic data" among the operations considered high risk for section 31.
What does South Africa require?
POPIA (opens in a new tab) section 26 says a responsible party may not process biometric information, subject to section 27. Section 27(1) lifts that prohibition in listed cases, including processing with the data subject's consent and processing "necessary for the establishment, exercise or defence of a right or obligation in law". Section 33(1) adds an authorisation for responsible parties "who have obtained that information in accordance with the law".
Two further provisions affect verification programmes:
Section 57(1)(d) requires prior authorisation from the Information Regulator before transferring special personal information to a third party in a foreign country that does not provide an adequate level of protection.
Section 71 restricts decisions with legal or substantial effects based solely on automated processing, with exceptions tied to contracts or law.
What should a verification programme do?
Across the three countries the practical work is similar.
Pick and record a lawful ground per country. Consent is listed in Nigeria (where GAID Article 18(1)(b) also requires it for sensitive data) and in South Africa. Kenya's section 45 does not list consent, so identify which section 45 ground you rely on there. Write down why each ground applies.
Make consent and notices specific. State that a selfie and short video will be used to check the person matches their ID and is present, who processes it, and for how long it is kept.
Complete a DPIA before launch, and file it in Nigeria where GAID Article 28 requires it.
Collect only what the check needs. Decide separately whether you need ongoing face re-authentication and duplicate-face checks, and cover each in your notices and DPIA.
Set retention periods for selfies, liveness videos and any stored face data, and delete on schedule.
Keep a human in the loop for adverse decisions, so customers can contest a failed face match.
Map cross-border transfers, including where your verification provider processes data.
Where Myaza Trust fits
Identity Verification collects a selfie with active liveness and records a short liveness video for server-side review (SDK documentation). Biometric re-authentication of returning users requires enrolment. Face-reuse search compares new selfies only with your own organisation's verified customers, never with other organisations', and the rule that sends matches to review is one you turn on in a workflow. Workflows let you set consent copy and send adverse outcomes to human review. Our approach to security and data handling is described on the security page; your DPIA should cover how you use these features and where the data is processed.
Checklist
Lawful ground for biometric processing recorded for Nigeria, Kenya and South Africa.
Consent screen names the selfie, the video, the purpose and the retention period.
DPIA completed, and filed with the NDPC where required.
Retention and deletion schedule set for every biometric artefact.
Human review available for failed or contested matches.
Cross-border transfers mapped, with POPIA section 57 assessed.
Sources

Charles Archibong
Co-founder
Charles Archibong co-founded Myaza Trust. He writes about identity verification, financial technology, and the practical work of building trusted digital services.


