Law / Kenya

Kenya

14 of 16 named instruments researched to a stage, across all six areas of law we track: 11 in force and 3 proposed. As of 14 September 2026.

When they take effect10 of 14 carry a date, 4 do not. Earlier is before 2014.
Before 2014: 1 instrument (1 in force) earlier 2014: 0 instruments 2015: 0 instruments ’15 2016: 0 instruments 2017: 0 instruments 2018: 2 instruments (2 in force) 2019: 6 instruments (6 in force) 2020: 0 instruments ’20 2021: 0 instruments 2022: 1 instrument (1 in force) 2023: 0 instruments 2024: 0 instruments 2025: 0 instruments 2026: 0 instruments ’26 today

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

  1. AI law 3
  2. Privacy law 7
  3. Scraping law 1
  4. Cybersecurity law 1
  5. Age gating law 1
  6. News aggregation law 1

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

AI law3 instruments, 3 proposed

Research summary (110 words)

Kenya has not enacted an AI-specific statute. The Artificial Intelligence Bill, 2026, a Senate bill gazetted 19 February 2026 and read a first time in the Senate on 2 April 2026, would classify systems by risk, prohibit unacceptable-risk systems outright, and impose transparency, human-oversight and synthetic-media-labelling duties on providers and deployers of higher-risk systems, but it binds nobody yet.

Kenya's National Artificial Intelligence Strategy 2025-2030, launched by the Ministry of Information, Communications and the Digital Economy on 27 March 2025, is a policy document guiding future legislation rather than a source of enforceable obligations, and the Kenya Bureau of Standards' draft AI code of practice remains an unconfirmed, voluntary standard.

AI prohibited practices

Artificial Intelligence Bill, 2026, risk classification and prohibited systems

Artificial Intelligence Bill 2026 (Senate Bills No. 4), s. 25 (classification of artificial intelligence systems; unacceptable-risk prohibition)official Bill text, Kenya Gazette Supplement, Kenya Law (new.kenyalaw.org)

Proposed: draft date not recorded. Binds public and private bodies.

What this law does

This measure is a Senate bill and binds nobody yet. As drafted, the Cabinet Secretary would classify artificial intelligence systems into unacceptable-risk, high-risk, limited-risk and minimal-risk categories on the recommendation of the Artificial Intelligence Commissioner, and a system classified as unacceptable risk would be prohibited outright.

What it requires

AI risk obligations

Artificial Intelligence Bill, 2026, high-risk system obligations

Artificial Intelligence Bill, 2026 (Senate Bills No. 4), ss. 26-27 (obligations for high-risk artificial intelligence systems; register)official Bill text, Kenya Gazette Supplement, Kenya Law (new.kenyalaw.org)

Proposed: draft date not recorded. Binds public and private bodies.

What this law does

This measure is a Senate bill and binds nobody yet. As drafted, a provider or deployer of a high-risk system would have to conduct a risk assessment and a human-rights impact assessment before deployment, ensure transparency, traceability and explainability of the system's decision-making, keep records of training data and performance for at least five years, and obtain explicit consent before generating or manipulating a person's image, voice or likeness.

The Artificial Intelligence Commissioner would maintain a public register of high-risk systems, including those used by county governments.

What it requires

AI transparency

Artificial Intelligence Bill, 2026, transparency, disclosure and synthetic-media labelling

Artificial Intelligence Bill, 2026 (Senate Bills No. 4), ss. 28, 35(1)(i) (transparency and safeguards; synthetic-media offence)official Bill text, Kenya Gazette Supplement, Kenya Law (new.kenyalaw.org)

Proposed: draft date not recorded. Binds public and private bodies.

What this law does

This measure is a Senate bill and binds nobody yet. As drafted, a provider or deployer of any artificial intelligence system would have to disclose to users and affected persons its nature, purpose and limitations, the extent to which its outputs are automated, and its bias-mitigation measures, and a provider of a high-risk system would have to submit annual compliance reports.

Generating, deploying or distributing synthetic media using a person's image, voice or likeness without their explicit consent, in a way likely to cause harm, misinformation, defamation or an invasion of privacy, would be an offence carrying a fine of up to KES 5,000,000 or imprisonment of up to two years, or both.

What it requires

Privacy law7 instruments, 7 in force

Research summary (195 words)

Kenya's comprehensive personal-data regime is the Data Protection Act, 2019, which establishes the Office of the Data Protection Commissioner and binds every data controller or processor operating in Kenya or handling the data of a person located in Kenya, whether or not the underlying personal data is otherwise publicly accessible.

The Act treats biometric, genetic, health and several other categories as sensitive personal data carrying heightened processing conditions, requires a controller to verify a child's age and obtain a parent or guardian's consent before processing a child's personal data, and gives every data subject a right against a decision based solely on automated processing that produces a legal or similarly significant effect.

Cross-border transfer requires proof of safeguards to the Commissioner or the data subject's consent, and the Cabinet Secretary may compel certain categories of processing onto a server located in Kenya.

The Data Protection (General) Regulations, 2021 add operational detail on personal data breach notification, data protection impact assessments and data-subject-request timelines, and the Commissioner may impose an administrative fine of up to five million Kenya shillings, or one per cent of an undertaking's annual turnover if lower, alongside criminal penalties for specific offences.

Breach notification

Data Protection (General) Regulations, 2021

Data Protection (General) Regulations, 2021 (Legal Notice No. 263 of 2021), regs. 7, 10, 37, 49-50official consolidated Regulations text, Kenya Law (National Council for Law Reporting)

In force since 14 January 2022. Binds public and private bodies.

What this law does

The Data Protection (General) Regulations, 2021 elaborate the Act's breach-notification duty and add operational detail on data-subject requests, including a fourteen-day deadline to notify a data subject in writing of a refused restriction request and a seven-day deadline for a refused rectification request.

Regulation 49 requires a data protection impact assessment before processing that includes automated decision-making or profiling with a legal or similarly significant effect, among other high-risk processing operations.

What it requires

Data Protection Act, 2019, personal data breach notification

Data Protection Act, 2019 (No. 24 of 2019), s. 43 (notification and communication of breach)official consolidated Act text, Kenya Law (National Council for Law Reporting)

In force since 25 November 2019. Binds public and private bodies.

What this law does

Where personal data has been accessed or acquired by an unauthorised person and there is a real risk of harm, a data controller must notify the Data Commissioner without delay, and in any event within seventy-two hours of becoming aware of the breach, giving reasons for any later notification.

A data processor that becomes aware of a breach must notify the data controller within forty-eight hours where reasonably practicable, and the controller must communicate the breach to the affected data subject in writing within a reasonably practical period unless their identity cannot be established.

What it requires

Comprehensive regime

Data Protection Act, 2019

Data Protection Act, 2019 (No. 24 of 2019), ss. 1-30 (establishment, principles and obligations)official consolidated Act text, Kenya Law (National Council for Law Reporting)

In force since 25 November 2019. Binds public and private bodies.

What this law does

The Data Protection Act, 2019 establishes the Office of the Data Protection Commissioner and requires every data controller or processor to process personal data lawfully, fairly and transparently, and only for an explicit and legitimate purpose that is proportionate to what is collected.

A data controller or processor must register with the Data Commissioner where the prescribed threshold is met, and must not process a child's personal data unless a parent or guardian has consented and the controller has implemented a mechanism to verify the child's age. A data subject's consent may be withdrawn at any time, without affecting the lawfulness of processing already carried out before the withdrawal.

What it requires

Cross border transfer

Data Protection Act, 2019, transfer of personal data outside Kenya

Data Protection Act, 2019 (No. 24 of 2019), Part VI (ss. 48-54)official consolidated Act text, Kenya Law (National Council for Law Reporting)

In force since 25 November 2019. Binds public and private bodies.

What this law does

A data controller or processor may transfer personal data outside Kenya only where it has given the Data Commissioner proof of appropriate safeguards, or another condition such as the data subject's consent applies, and the Commissioner may prohibit, suspend or condition a transfer to protect data subjects' rights.

The Cabinet Secretary may prescribe that certain processing, on grounds of strategic state interest or protection of revenue, be carried out only through a server or data centre located in Kenya.

What it requires

Data subject rights

Data Protection Act, 2019, rights of data subjects and automated decision-making

Data Protection Act, 2019 (No. 24 of 2019), ss. 26, 33-38 (rights of data subjects, including automated individual decision-making, s. 35)official consolidated Act text, Kenya Law (National Council for Law Reporting)

In force since 25 November 2019. Binds public and private bodies.

What this law does

Every data subject has a right to be informed of the use of their personal data, to access it, to object to its processing, and to correction or deletion of false or misleading data.

Section 35 gives a data subject a right not to be subject to a decision based solely on automated processing, including profiling, that produces a legal effect or significantly affects them, and requires the controller to notify the subject in writing and allow them to seek reconsideration or a new decision not based solely on automated processing.

A data subject also has a right to data portability in a structured, commonly used and machine-readable format, and a controller must comply with a portability request within thirty days.

What it requires

Enforcement supervision

Data Protection Act, 2019, enforcement, penalties and compensation

Data Protection Act, 2019 (No. 24 of 2019), Part VIII (ss. 56-65, 72-74)official consolidated Act text, Kenya Law (National Council for Law Reporting)

In force since 25 November 2019. Binds public and private bodies.

What this law does

A data subject may complain to the Data Commissioner, who may issue a penalty notice and, on appeal, be reviewed by the High Court. A person who suffers damage from a contravention of the Act is entitled to compensation from the controller or processor. Unlawful disclosure of personal data and giving false or misleading information to the Data Commissioner are separate criminal offences, and any other contravention with no specific penalty carries a general criminal penalty.

What it requires

Sensitive categories

Data Protection Act, 2019, sensitive personal data

Data Protection Act, 2019 (No. 24 of 2019), Part V (ss. 44-47)official consolidated Act text, Kenya Law (National Council for Law Reporting)

In force since 25 November 2019. Binds public and private bodies.

What this law does

Sensitive personal data, defined to include biometric data, genetic data, health status and several other categories, may only be processed on a specific permitted ground: legitimate not-for-profit activity with appropriate safeguards, data manifestly made public by the data subject, or necessity for a legal claim or to protect vital interests. Health data may only be processed by or under a health-care provider or a person bound by professional secrecy.

The Data Commissioner may prescribe further categories of sensitive personal data and the grounds on which they may be processed.

What it requires

Scraping law1 instrument, 1 in force

Research summary (244 words)

Kenya has no scraping-specific statute, so general law governs each dimension separately. The Computer Misuse and Cybercrimes Act, 2018 criminalises unauthorised access to a computer system, but section 14 requires infringing a security measure to gain access, so scraping a public, unauthenticated page without defeating an access control does not fit a plain reading of that requirement, and no reported case has tested the point.

No Kenyan court has ruled on the enforceability of a browsewrap or clickwrap terms-of-service against a scraper. The Copyright Act, 2001 permits fair dealing for scientific research, private use, criticism or review, and the reporting of current events, and gives a right to quote, but Kenya has not enacted a text-and-data-mining exception, so training a model on scraped copyrighted text rests only on the general fair-dealing ground if it can be characterised as scientific research.

Kenya's copyright statute confers no sui generis database right, and its related rights cover only broadcasts, sound recordings and performances.

The Data Protection Act, 2019 applies to personal data without a general carve-out for information that is publicly accessible, so scraping personal data from a public Kenyan website remains subject to the Act's lawful-basis, purpose-limitation and cross-border-transfer duties, and a narrower processing ground exists only for sensitive personal data the data subject has manifestly made public.

No Kenyan statute or reported case establishes a scraping-specific unfair-competition, misappropriation or trespass doctrine, and none assigns legal weight to a robots.txt directive or imposes an AI-training-specific rule.

Computer misuse

Computer Misuse and Cybercrimes Act, 2018, unauthorised access

Computer Misuse and Cybercrimes Act, 2018 (No. 5 of 2018), s. 14 (unauthorised access)official consolidated Act text, Kenya Law (National Council for Law Reporting)

In force since 30 May 2018. Binds public and private bodies.

What this law does

Section 14 prohibits causing a computer system to perform a function, by infringing a security measure, with intent to gain access, knowing the access is unauthorised, and defines access broadly to include copying, transferring, altering or outputting data. The offence carries a fine of up to KES 5,000,000 or imprisonment of up to three years, or both.

Because the offence's trigger is infringing a security measure, a scraper reading a public, unauthenticated page without defeating any access control falls outside a plain reading of the provision.

What it requires

Cybersecurity law1 instrument, 1 in force

Research summary (601 words)

Kenya's Computer Misuse and Cybercrimes Act, 2018 (Act No. 5 of 2018, Cap. 79C) sets a general cyber-incident reporting duty, in section 40, on any person who operates a computer system or a computer network in Kenya, whether public or private: within twenty-four hours of an attack, intrusion, or other disruption to the functioning of another computer system or network, the operator must inform the National Computer and Cybercrimes Co-ordination Committee, and failing to do so is itself an offence carrying a fine of up to two hundred thousand shillings, imprisonment of up to two years, or both.

Because that duty binds any operator of a computer system rather than a licensed or sector-specific status, it reaches an ordinary developer operating a website, app, or online service with a Kenya nexus, and the row is filed and flagged on that basis.

Separately, Part II of the same Act (sections 4 through 13) creates Kenya's critical-information-infrastructure regime: the Director of the Committee designates, by Gazette notice, which systems are "critical infrastructure", meaning a system whose disruption would interrupt a life-sustaining service, harm the economy, cause massive casualties, disrupt the money market, or severely affect national security; only the owner or operator of a system so designated carries the Act's further critical-infrastructure duties, including an annual compliance report and audit under section 13, with a penalty on conviction of a fine of up to two hundred thousand shillings or imprisonment of up to five years, or both, for an owner who fails to file or cooperate.

The Computer Misuse and Cybercrime (Critical Information Infrastructure and Cybercrime Management) Regulations, 2024 (Legal Notice No. 44 of 2024) operationalise that regime: an owner of designated critical information infrastructure must conduct an annual cyber-risk assessment and business impact analysis, submit a risk register to the Committee, designate a Chief Information Security Officer, and report a cybersecurity incident to the relevant Sectoral Cybersecurity Operations Centre within twenty-four hours of becoming aware of it.

Because that whole regime binds only an owner or operator the Director has individually designated by Gazette notice into one of the Regulations' named critical-infrastructure sectors, rather than a status any declared LexLint activity can express, it is recorded here rather than raised against a declared activity, the same treatment this profile gives Singapore's critical-information-infrastructure regime, Japan's designated critical-infrastructure operators, and New York's Department of Financial Services Part 500 covered entities.

The State Corporations (National Cybersecurity Agency) Order, 2026 (Legal Notice No. 89 of 2026, in effect from 15 May 2026) separately establishes a new National Cybersecurity Agency as the autonomous body coordinating national cybersecurity policy and auditing the cybersecurity resilience of designated critical information infrastructure; its own text creates no duty running to an undesignated private business, so it is named here as background rather than filed as an instrument.

No enacted Kenyan statute sets security requirements a software product or connected device must meet before or after it is placed on the market, so the product-requirements research dimension is a researched absence.

No general reasonable-security or information-security-programme statute reaches a business simply because it holds personal data; the nearest analogue is the Data Protection Act, 2019 sections 41 and 42, the technical-and-organisational-measures duty inside that comprehensive regime, an article this jurisdiction's privacy row already researches, the same architecture as General Data Protection Regulation (GDPR) Article 32, so it is not repeated here.

The same Act's breach-notification duty, section 43 (notice to the Data Commissioner within seventy-two hours and to the affected data subject), is likewise this jurisdiction's privacy-topic finding rather than restated here. No published enforcement record specific to section 40 is confirmed in the primary text.

Vulnerability and incident reporting

Computer Misuse and Cybercrimes Act, Reporting of Cyber Threat

Computer Misuse and Cybercrimes Act (No. 5 of 2018), s. 40Official consolidated Act text, National Council for Law Reporting (Kenya Law)

In force since 30 May 2018. Binds public and private bodies.

What this law does

Any person who operates a computer system or a computer network in Kenya, whether public or private, must immediately inform the National Computer and Cybercrimes Co-ordination Committee of an attack, intrusion, or other disruption to the functioning of another computer system or network, within twenty-four hours of the attack, intrusion, or disruption.

The report must include a summary of how the breach occurred, an estimate of the number of people affected, an assessment of the risk of harm to them, and an explanation of any circumstance delaying their notification. The Committee may propose isolating a suspected system pending resolution. Failing to report under this duty is itself an offence, punishable by a fine of up to two hundred thousand shillings, imprisonment of up to two years, or both.

What it requires

Age gating law1 instrument, 1 in force

Research summary (124 words)

Kenya has not enacted a law that specifically imposes age-verification duties on adult-content services, social media platforms or app stores, and has no age-appropriate design code enacted as a statute.

The Communications Authority of Kenya has instead issued Industry Guidelines for Child Online Protection and Safety, made under its consumer-protection regulations, which direct every ICT product and service provider whose products or services children may access, including social media and internet services, to develop and implement age-verification mechanisms without prescribing a particular method.

Separately, the Data Protection Act, 2019 requires a data controller or processor to obtain a parent or guardian's consent and to implement an age-verification mechanism before processing a child's personal data, a general data-protection duty rather than a platform-specific age-gating regime.

Age-appropriate design code

Industry Guidelines for Child Online Protection and Safety in Kenya

Industry Guidelines for Child Online Protection and Safety in Kenya (Communications Authority of Kenya, April 2025 edition), cll. 6-8, 14official guidelines text, Communications Authority of Kenya (ca.go.ke)

In force. Binds private bodies.

What this law does

The Communications Authority of Kenya requires every licensee and every ICT product or service provider whose offerings children may access, including content, e-commerce, application and social media services, to develop and implement age-verification mechanisms and to publish a child online protection and safety policy.

The guidelines took effect on execution and publication by the Authority and gave licensees six months to come into compliance, but the document does not itself state the day of that execution or publication. The guidelines do not prescribe a specific age-verification method, define a child as a person under eighteen years, and are enforced through complaints to the Authority and quarterly compliance reporting rather than a stated fine or criminal penalty.

Note and primary source

News aggregation law1 instrument, 1 in force

Research summary (90 words)

Kenya has no press-publisher neighbouring right, no compelled platform-to-publisher bargaining regime, no reported hot-news or misappropriation doctrine, and no linking or framing case law reaching a news aggregator.

The general exception available to an aggregator is the Copyright Act, 2001's fair-dealing and quotation exception, which permits reproduction for scientific research, private use, criticism or review, and the reporting of current events, and gives a standalone right to quote, but Kenya has not enacted a machine-readable text-and-data-mining opt-out, so an aggregator's indexing is not addressed by any text and data mining (TDM)-specific rule either way.

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.