Data protection is no longer the only obligation in play. A separate cybersecurity regime now runs alongside it, with its own reporting clocks and its own penalties.

Organisations that have built a data protection compliance programme sometimes assume it covers their obligations in relation to digital systems generally. It does not. Kenya now has two overlapping regimes, and an incident can trigger duties under both at once.

The two frameworks

The first is the Data Protection Act, 2019, which gives effect to the right to privacy in Article 31 of the Constitution and is supervised by the Office of the Data Protection Commissioner. It is principles-based and concerned with how personal data is collected, used, shared and secured.

The second is the Computer Misuse and Cybercrimes Act, 2018, which addresses offences against and through computer systems. It was amended by the Computer Misuse and Cybercrimes (Amendment) Act, assented to in October 2025, targeting threats including SIM-swap fraud, phishing, identity theft and online harassment, and raising penalties for serious offences considerably. Separate rules apply to operators of critical information infrastructure.

A ransomware incident at a Kenyan company can therefore engage a data protection breach notification duty, a cybercrime reporting question, and — if the organisation is designated critical infrastructure — a materially tighter reporting window.

The clocks do not run at the same speed

  • Under the Data Protection Act, a controller must notify the ODPC within 72 hours of becoming aware of a personal data breach, and must notify affected data subjects where there is a real risk of harm.
  • A processor must notify its controller within 48 hours.
  • For operators within the critical information infrastructure rules, the reporting obligation is shorter.

These are not alternatives. An organisation may owe all three, to different recipients, on different timetables, while simultaneously trying to contain the incident.

Penalty exposure is being reconsidered

The administrative penalty under section 63 of the Data Protection Act is presently capped at KES 5 million or 1% of annual turnover, whichever is lower. A Data Protection (Amendment) Bill has been proposed which would change that to whichever is higher.

For a small organisation the change would make little difference. For a large one it would be transformative: a turnover-based penalty with no monetary ceiling is a materially different risk from a KES 5 million cap. Organisations of scale should be modelling that exposure now rather than after the Bill is enacted, and should be aware that the Bill's progress may alter the position described here.

Data localisation

One requirement that continues to catch organisations using foreign cloud infrastructure: cross-border transfers require proof of adequate safeguards to the ODPC, and a data controller must store at least one serving copy of personal data on a server located within Kenya. An architecture hosted entirely offshore does not satisfy this, however secure it is.

Our view

The organisations that handle incidents well are not the ones with the longest policies. They are the ones that have decided in advance who declares an incident, who assesses whether it is notifiable under each regime, who drafts the notifications and who has authority to send them — and have rehearsed it at least once.

Seventy-two hours sounds generous until an incident begins on a Friday evening. We recommend an annual tabletop exercise covering a realistic scenario, run jointly by IT, legal and management, with the notification drafts prepared in advance as templates. The legal analysis is much easier to do calmly in advance than under pressure with a live intrusion.

Note. This article is general commentary on Kenyan law as at the date of publication and is not legal advice. The law in these areas changes, and several of the matters discussed remain subject to appeal. For advice on your own circumstances, please contact us.
Njiule M. Wakoli, DPO

Njiule M. Wakoli, DPO

Partner — Data Protection and Advisory

Njiule leads the firm and practises across intellectual property, data protection, corporate governance, mergers and acquisitions, regulatory compliance and dispute resolution.

← Previous article All resources
Mitchelson Law LLP AdvocatesMitchelson Law LLP AdvocatesMitchelson Law LLP AdvocatesMitchelson Law LLP AdvocatesMitchelson Law LLP AdvocatesMitchelson Law LLP Advocates