In the last months before the 2022 general election, a campaign team in Nairobi had a spreadsheet. It held tens of thousands of phone numbers, grouped by ward, and nobody in the room could tell you with confidence where it had come from. Someone had been given it by someone. It was used to send bulk SMS. This was not an unusual arrangement. It was closer to standard practice.
The conventional reading of that scene is a privacy story: a campaign behaving badly with personal data. I think that reading is incomplete, and the incompleteness matters, because it points at the wrong fix.
In plain terms: campaigns build improvised, undocumented data operations because no legitimate alternative has been built for them. The absence of proper campaign infrastructure does not produce campaigns without data. It produces campaigns with untraceable data.
The real diagnosis
2022 was the first Kenyan general election conducted under the Data Protection Act, 2019. The Act applies squarely to electoral activity — voter registration, inspection of the register, party recruitment, and political campaigning all fall within it — and the Office of the Data Protection Commissioner has oversight of how election-related personal data is processed.
The law, in other words, is not the missing piece. It exists, it is reasonably clear, and it arrived before the election it needed to govern.
What does not exist is infrastructure that makes complying with it the path of least resistance. A campaign that wants to do this properly has to assemble consent management, provenance tracking, retention limits, and subject-access handling out of nothing, in a compressed timeline, usually with volunteer technical staff. A campaign that does not care simply buys a list. The compliant path is dramatically harder than the non-compliant one, and the outcome is exactly what you would predict.
This is the same argument this body of work has made about procurement, about PBO compliance, and about constituency offices: where a well-specified legal framework exists but the operational layer to satisfy it does not, non-compliance becomes a structural output rather than a moral failing. The fourteen clauses of the PBO Act were a checklist software could satisfy. The Data Protection Act's requirements on electoral data are the same kind of checklist.
What BungeConnect is for
BungeConnect is campaign-facing infrastructure: the operational tooling a candidate's team needs to run a campaign — contact management with real provenance, field-team coordination, ward-level organisation, issue tracking that survives the campaign and becomes a constituency office's case backlog.
That is a commercial product sold to political actors, and I want to be direct about why that is defensible rather than pretend the tension is not there.
Flux's entire thesis rests on being neutral infrastructure that institutions on all sides can trust. An election is the most demanding possible test of that claim. If BungeConnect becomes understood as the tool that helped one side win, the neutrality that everything else depends on is gone — not just for BungeConnect but for PBOMaster, for AccessWASH, for every institutional relationship this lab has.
So the constraints are not a compliance appendix bolted onto a product. They are the product's central design commitment, and they are costly on purpose.
Four commitments
Identical terms for every candidate. Same price, same features, same support, regardless of party, incumbency, or the size of the seat. No negotiated deals, no exclusivity, no capacity reserved for anyone. A candidate for a ward seat in Turkana gets what a presidential campaign gets. If demand exceeds what we can serve, the queue is first-come and the queue is public.
A published client list. Every campaign using BungeConnect is disclosed on a public page, updated as clients join. This is the commitment that makes the others enforceable: it converts our neutrality from a promise into something anyone can audit. It also means we cannot quietly serve one side, which is precisely the point. Campaigns that will not be named cannot be clients.
No voter-data products, ever. We do not sell, license, broker, enrich, or append voter data. We do not build audience segments. We do not offer micro-targeting, psychographic modelling, or lookalike audiences. The product manages a campaign's own lawfully obtained contacts with documented provenance. It does not help anyone acquire more.
This is the commitment that costs the most revenue, and it is the one I would most expect a competitor to break. It is also the one that most directly separates useful campaign infrastructure from the machinery that produced Cambridge Analytica's involvement in Kenyan politics in 2013 and 2017 — a history that is precisely why this product has to be explicit rather than merely well-intentioned.
Data Protection Act compliance as a default, not a setting. Consent capture and provenance on every contact record. Retention limits enforced by the system rather than by discipline. Subject-access and deletion requests handled as a first-class feature. A campaign using BungeConnect should find that the compliant way of working is simply how the software works, and that circumventing it requires deliberate effort.
Why the constraints are the product
The obvious commercial objection is that every one of these commitments reduces revenue. That is true and it is not an accident.
Consider what a campaign is actually buying. Political technology in this region has a credibility problem earned over more than a decade: vendors who appear during election season, handle enormous quantities of personal data with no accountability, and disappear. A campaign that adopts such a vendor takes on real legal exposure under the Data Protection Act and real reputational exposure if the arrangement surfaces.
Infrastructure that publishes its client list, refuses to touch voter data, and enforces the Act by construction is not making a moral gesture. It is offering a campaign something it cannot otherwise buy: the ability to run a serious data operation without inheriting a liability. The self-binding is the differentiator, in the same way that a bank's regulatory constraints are the reason anyone deposits money there.
There is also a longer argument. A constituency office that inherits a campaign's issue tracker on day one starts with a case backlog and a real map of what its constituents asked for. The most valuable thing a campaign produces is not a mailing list; it is a structured record of what people said they needed. Under current practice that record dies on election night, or lives on in a spreadsheet nobody can source. Democracy Is Infrastructure argued that constituency offices fail for lack of operational infrastructure. This is where that infrastructure could plausibly begin.
What I am not claiming
I am not claiming this makes elections fairer. Tooling available to everyone on identical terms does not equalise campaigns; better-resourced campaigns will use it better, and the same is true of every neutral utility.
I am not claiming neutrality is automatic. A published client list constrains us; it does not make us immune to pressure, and the first genuinely hard test will be a client we would rather not name. The commitment is worth exactly as much as our willingness to honour it at that moment.
I am not claiming the 2027 timeline is comfortable. Electoral infrastructure has to be in place and trusted well before the campaign period, which means the work is now, not in 2026.
And I am not claiming a right to be trusted on any of this. These commitments are testable. The client list is either published or it is not. The voter-data product either exists or it does not. That is the point of writing them down before the product is in market rather than after.
What follows
If this argument is right, the useful intervention in electoral technology is not more oversight of how campaigns handle data, and not another round of civic-education apps. It is building the compliant path and making it the easiest one available.
The specific test for 2027 is narrow and falsifiable: whether a Kenyan campaign can run a full field operation without at any point holding personal data it cannot account for. Nobody has demonstrated that yet. If it can be demonstrated once, at any level of seat, the argument that untraceable data is simply how campaigns work loses its last practical defence.