Computer Misuse and Cybercrimes Act, 2018, unauthorised access
Computer Misuse and Cybercrimes Act, 2018 (No. 5 of 2018), s. 14 (unauthorised access)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force since 30 May 2018.
A computer misuse rule binding public and private bodies.
As of 5 September 2026.
What it requires
- Do not gain access to a computer system by infringing a security measure, knowing the access is unauthorised, including to copy, transfer or output data from it.
- Reading a public, unauthenticated page without defeating any access control has not itself been held to violate this section.
If you get it wrong
Criminal exposureYes
Private right of actionNo
Criminal exposure note
A fine of up to KES 5,000,000 or imprisonment of up to three years, or both, on conviction (s. 14(1)).
Penalty structure
Fine only; the same subsection also allows imprisonment of up to three years instead of or in addition to the fine.
- Rule
- Fixed only
- As of
- 5 September 2026
- Currency
- KES
- Fixed cap
- 5,000,000
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Section 14 prohibits causing a computer system to perform a function, by infringing a security measure, with intent to gain access, knowing the access is unauthorised, and defines access broadly to include copying, transferring, altering or outputting data. The offence carries a fine of up to KES 5,000,000 or imprisonment of up to three years, or both.
Because the offence's trigger is infringing a security measure, a scraper reading a public, unauthenticated page without defeating any access control falls outside a plain reading of the provision.
When LexLint raises it
crawls_webtrains_models
Read the law
official consolidated Act text, Kenya Law (National Council for Law Reporting)