Security audits, penetration testing, and compliance for organizations operating in Kenya, under the Data Protection Act 2019 and the Computer Misuse and Cybercrimes Act.
Last updated — August 22, 2026
Kenya's framework rests on two core texts. The Data Protection Act 2019 governs the processing of personal data under the oversight of the Office of the Data Protection Commissioner (ODPC). The Computer Misuse and Cybercrimes Act addresses offenses related to computer systems, with the National KE-CIRT/CC (NC4) coordinating national-level cybersecurity incident response.
Engagement mode
On-site missions in Nairobi, remote delivery for the rest of the territory
Working language
English
Regulatory coordination
Dedicated contact for interactions with the ODPC and NC4
The Office of the Data Protection Commissioner (ODPC), which enforces the Data Protection Act 2019.
The National KE-CIRT/CC, Kenya's national cybersecurity incident response team, which coordinates the handling of incidents affecting information systems in the country.
The registration requirement depends on the volume and nature of data processed; we assess this based on your activity.
It addresses offenses related to unauthorized access to computer systems, computer fraud, and data integrity breaches.
Yes, this sector is a priority given its economic weight and exposure to fraud risk.
The Data Protection Act 2019 sets specific notification timelines; we help you meet them from the moment an incident is detected.
Yes, as part of our governance, risk and compliance service.