Law / Kenya

Computer Misuse and Cybercrimes Act, 2018, unauthorised access

Computer Misuse and Cybercrimes Act, 2018 (No. 5 of 2018), s. 14 (unauthorised access)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force since 30 May 2018.

A computer misuse rule binding public and private bodies.

As of 5 September 2026.

What it requires

  • Do not gain access to a computer system by infringing a security measure, knowing the access is unauthorised, including to copy, transfer or output data from it.
  • Reading a public, unauthenticated page without defeating any access control has not itself been held to violate this section.

If you get it wrong

Criminal exposureYes

Private right of actionNo

Criminal exposure note

A fine of up to KES 5,000,000 or imprisonment of up to three years, or both, on conviction (s. 14(1)).

Penalty structure

Fine only; the same subsection also allows imprisonment of up to three years instead of or in addition to the fine.

Rule
Fixed only
As of
5 September 2026
Currency
KES
Fixed cap
5,000,000

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Section 14 prohibits causing a computer system to perform a function, by infringing a security measure, with intent to gain access, knowing the access is unauthorised, and defines access broadly to include copying, transferring, altering or outputting data. The offence carries a fine of up to KES 5,000,000 or imprisonment of up to three years, or both.

Because the offence's trigger is infringing a security measure, a scraper reading a public, unauthenticated page without defeating any access control falls outside a plain reading of the provision.

When LexLint raises it

  • crawls_web
  • trains_models

Read the law

official consolidated Act text, Kenya Law (National Council for Law Reporting)

Back to the example  ·  Lint your app