Suspect a breach? Report it immediately — response within 1 hour.Report an incident

Cybersecurity and Compliance in Kenya

Security audits, penetration testing, and compliance for organizations operating in Kenya, under the Data Protection Act 2019 and the Computer Misuse and Cybercrimes Act.

Last updatedAugust 22, 2026

The local regulatory framework

Kenya's framework rests on two core texts. The Data Protection Act 2019 governs the processing of personal data under the oversight of the Office of the Data Protection Commissioner (ODPC). The Computer Misuse and Cybercrimes Act addresses offenses related to computer systems, with the National KE-CIRT/CC (NC4) coordinating national-level cybersecurity incident response.

Concrete obligations

Registration with the ODPC for data controllers and processors handling personal data

Conducting data protection impact assessments for high-risk processing activities

Notifying personal data breaches to the ODPC within the timelines set by the Data Protection Act 2019

Implementing appropriate security measures to prevent offenses covered by the Computer Misuse and Cybercrimes Act

Cooperating with the NC4 in the event of a cybersecurity incident affecting systems of national importance

Priority sectors

Financial services and mobile moneyTelecommunicationsTechnology and digital services

Delivery modalities

Engagement mode

On-site missions in Nairobi, remote delivery for the rest of the territory

Working language

English

Regulatory coordination

Dedicated contact for interactions with the ODPC and NC4

Local FAQ

Which authority oversees data protection in Kenya?

The Office of the Data Protection Commissioner (ODPC), which enforces the Data Protection Act 2019.

What is the NC4?

The National KE-CIRT/CC, Kenya's national cybersecurity incident response team, which coordinates the handling of incidents affecting information systems in the country.

Do all companies need to register with the ODPC?

The registration requirement depends on the volume and nature of data processed; we assess this based on your activity.

What does the Computer Misuse and Cybercrimes Act cover?

It addresses offenses related to unauthorized access to computer systems, computer fraud, and data integrity breaches.

Do you work with Kenyan mobile money providers?

Yes, this sector is a priority given its economic weight and exposure to fraud risk.

What is the deadline to notify the ODPC of a data breach?

The Data Protection Act 2019 sets specific notification timelines; we help you meet them from the moment an incident is detected.

Do you support data protection impact assessments (DPIAs)?

Yes, as part of our governance, risk and compliance service.

Get in touch