On 6 March 2026, the Communications Authority of Kenya brought commercial data centres under telecom licensing for the first time, via Gazette Notice No. 3335 and the Revised Telecommunications Market Structure. The message then was that data centres are network facilities, and the Network Facilities Provider framework was where they belonged. Six months later, the message has changed. On 8 September 2026, the CA opened a public consultation on a proposal that would pull colocation data centres out of that framework entirely and give them their own licence category, a standalone Data Centre licence.
This is not a routine rule tweak. It is the regulator formally acknowledging that the classification it chose in March was a compromise, and that the compromises that fit telecom network builders do not necessarily fit companies whose business is floor space, power, cooling, and physical security. For the roughly nineteen operational facilities across Nairobi and Mombasa, and for the investors backing the much larger pipeline behind them, the consultation window that opened on 8 September is the moment to shape the rules they will live under.
What the CA Actually Proposed
The proposal is precise about what would change. Colocation data centres would be removed from the Network Facilities Provider Tier 2 (NFP-T2) licensing category, where the March 2026 framework placed them, and rehosted under a new, dedicated Data Centre licence. Stakeholders have 30 days from 8 September 2026 to review and comment on the proposed framework, which puts the comment deadline at approximately 8 October 2026 through the CA's open consultations portal.
The CA's own stated reasoning is worth reading carefully. The Authority said the current classification was intended to give it visibility over data centre operations (a real gap before March 2026) but places facilities within a licensing category primarily designed for companies that establish and operate telecommunications network infrastructure. In other words: the March framework solved a visibility problem, but at the cost of forcing data centres into rules written for a different kind of business. The consultation is an attempt to keep the visibility while dropping the misfit.
Why the NFP Framework Never Quite Fit
A network facilities provider builds towers, runs transmission backbone, and sells connectivity. A colocation data centre provides a building: secure floor space, redundant power, precision cooling, and cross-connects to the networks that customers bring with them. The facility itself does not deliver telecom services to end users, its tenants do. Under the proposed framework, the CA explicitly recognises this, describing the licence as reflecting the role data centres play in providing "colocation, power, cooling, storage and computing infrastructure rather than telecommunications services directly to end users."
The distinction is not academic. Licence obligations designed for network operators, things like coverage rollouts, quality-of-service metrics for voice and data services, or universal service contributions tied to network revenue, translate awkwardly onto a facility whose revenue is rack space and power. The CA's fuller statement is worth quoting: "The proposed approach is intended to provide regulatory clarity, enhance visibility over data centre operations, support investment in digital infrastructure, and align Kenya's framework with proportionate approaches adopted in comparable jurisdictions." The Authority also scoped the licence to cover "entities that provide colocation data centre services, including the attendant supporting services", language that pulls the power, cooling and physical-security envelope into the licence's core definition rather than treating it as incidental. The "proportionate approaches" phrase is the tell: the Authority has benchmarked how comparable regulators treat data centres, and concluded the telecom regime over-applies here. That phrasing also suggests the Authority has been listening to the operators it regulates, several of whom have spent 2026 building out GPU-ready capacity for AI workloads under rules written for Telecoms Act compliance.
The Numbers: Fees, Validity, and Who Is Exempt
The proposed fee structure is modest by licensing standards, and that is a deliberate signal. The application fee would be KES 5,000, with an initial licence fee of KES 100,000. Annual operating fees would be KES 80,000 or 0.4% of annual gross turnover, whichever is higher, meaning the flat fee covers smaller facilities, while the turnover-based tier scales for large commercial operations. Licences would be valid for 15 years, giving operators a long runway for the kind of capital investment data centre campuses require.
The contrast with the current NFP-T2 regime is stark, and it is the strongest evidence yet that the consultation is an investment-climate document as much as a regulatory one. Under NFP-T2 as it stands, an operator pays the same KES 5,000 application fee but then a 15-year licence fee of KES 15 million, or 0.4% of gross annual turnover, whichever is higher. The proposed standalone licence cuts that upfront commitment to KES 100,000: a reduction of more than 99% for a pure-play operator, while keeping the same 0.4% turnover test at the annual tier. One cost line belongs in every operator's model, though: the Universal Service Fund levy still applies on top of licence fees (presently 0.5% of annual gross revenue) and the consultation leaves room for that figure to change before the framework is finalised.
Two carve-outs matter for the broader market. Entities already holding NFP licences would be permitted to establish and operate data centres without obtaining the separate Data Centre licence, so large integrated players keep their existing path. The same exemption extends to Application Service Provider (ASP) licence holders. In practice, the standalone licence targets pure-play colocation operators: the companies whose entire business is hosting other people's servers. That is the segment that grew from a handful of facilities to the nineteen-plus operational sites the industry counts today, and the segment most exposed to a licence category that was never designed for it.
The Roadmap: Consultation Now, Implementation Later
The CA is not promising a quick flip. The proposed data centre regime is scheduled to be finalised and implemented across two financial years. During FY2026/27, the roadmap calls for the consultation and finalisation of the framework (the 30-day window that opened on 8 September is the start of that process) and, in the same financial year, the consequential revision of the telecommunications market structure itself. During FY2027/28, the new regime would be implemented, with facilities migrating to the new category.
That sequencing is worth pausing on, because press coverage at the time got it wrong. Early reports placed the consequential market-structure changes in FY2027/28 alongside implementation; the consultation document's own roadmap table puts them in FY2026/27, the same year as finalisation, with only the go-live in FY2027/28. This correction came out of capturing the regulator's full document on 24 September 2026 - the table reads: framework (FY2026/2027), public consultation (FY2026/2027), finalisation (FY2026/2027), consequential revision of the market structure (FY2026/2027), implementation (FY2027/2028).
For operators, the practical reading is that NFP-T2 remains the licence of record through at least FY2026/27, and anyone entering the market now should still plan around the March 2026 framework while tracking the consultation's outcome. The two-step roadmap also means the market structure documents themselves get amended between finalisation and implementation. That is where transition mechanics (existing licence holders, renewal dates, fee harmonisation) will be settled.
Where the ODPC Fits In
A standalone CA licence licenses the building, not the data. The Data Protection Act 2019 runs in parallel and applies to the same facility regardless of what the Communications Authority decides: the operator is typically a data processor (and often a controller for its own staff and security data), and tenants are controllers of the personal data on their racks. In practice three DPA obligations land on the facility first. Registration with the Office of the Data Protection Commissioner (ODPC) where thresholds are met. Breach notification duties, where a facility that suffers a security incident must notify affected customers promptly so controllers can meet their own 72-hour ODPC notification window. And Section 48 transfer restrictions, which govern what tenants may do with personal data that leaves the country, rules our Data Protection Act explainer unpacks in full.
For the consultation, the intersection is mostly about what the new licence does NOT settle. Data residency commitments, audit access and cross-transfer safeguards live in customer contracts and DPA compliance, not in CA licence conditions, and regulated tenants (banks under CBK guidance, SACCOs under SASRA) will keep demanding contractual in-country storage regardless of which regime licenses the rack. There is also a convergence point worth watching: both regulators now collect information about the same facilities, the CA for visibility over data centre operations, the ODPC through registration and breach reporting. Operators responding to the consultation may reasonably ask the Authority to align data-related conditions with ODPC requirements rather than invent parallel ones. For the sovereignty backdrop behind all of this, see our data localisation deep dive.
What It Means for Operators and Investors
The direction of travel is regulatory clarity, and clarity is what investors have asked for since the AI investment cycle reached Kenya. Business Daily's reporting framed the move within the government's ambition to position Kenya as the digital gateway for Eastern and Central Africa, citing PwC's 2026 outlook work on data centre investment, the same research that projects Africa attracting $255 billion of cumulative data centre capex through 2050. A regulator that splits data centres out of a telecom framework into a purpose-built licence is making the market easier to underwrite: licence conditions matched to the business, fees scaled to facility economics, and a 15-year validity period that survives political cycles.
The risks in the transition are real but manageable. Facilities licensed under NFP-T2 since March will face a migration process whose mechanics are not yet public. Operators with mixed businesses (connectivity plus colocation) will need advice on whether the NFP exemption already covers them or whether a separate application is cleaner. And the turnover-based annual fee introduces a revenue-visibility obligation that some private operators may push back on during comments. None of these are reasons against the reform; they are exactly the kind of detail the 30-day consultation exists to settle.
What Is Not Clear Yet
Reading the full consultation document sharpens some questions and exposes others that the seven pages simply do not answer. The scope phrase "attendant supporting services" is the biggest: it pulls power, cooling and physical security into the licence's core definition, but nothing in the document says where the boundary sits. A facility offering managed services, private cloud, or disaster-recovery seats could read itself in or out of that phrase, and the answer changes who must hold the licence.
Migration mechanics are likewise unstated. Facilities that took an NFP-T2 licence after March 2026 face a transition whose shape (mid-term migration, fee credit for licence already paid, renewal alignment) is nowhere in the document. The Universal Service Fund treatment is cited to statute but not restated for the new category. And there is a dating discrepancy worth flagging in comments: the document describes the current market structure as "revised in April 2026", while the gazette record we hold dates the Revised Telecommunications Market Structure to 6 March 2026 - either a drafting slip or a reference to a later effective revision, and worth asking the Authority to clarify in writing. None of these gaps argue against the reform; they are the questions a serious submission would put on the record while the window is open.
How to Participate
The consultation is open through the CA's consultations portal at ca.go.ke, with comments due within 30 days of 8 September 2026. Operators, industry bodies, tenants, and investors with Kenyan data centre exposure all have standing to comment. For context on the framework being revised, see our full explainer on Kenya's data centre licensing framework, and for the facilities this licence will cover, browse the Kenya data centre directory.
Sources: Communications Authority of Kenya open consultations; CA Proposed Licensing Framework for Data Centres (September 2026, Consultation Version) captured in full text on 24 September 2026; Developing Telecoms (9 September 2026); Business Daily (8 September 2026); TechAfrica News (8 September 2026); The Star (8 September 2026); w.media (September 2026). Facts verified against multiple independent outlets on 10 September 2026; fee comparison and Universal Service Fund detail verified against w.media on 12 September 2026; ODPC intersection section added 16 September 2026. On 24 September 2026 the regulator's consultation document was captured in full and every fee figure, the 15-year term, the NFP/ASP exemption and the roadmap were verified exact against it; the roadmap sequencing above was corrected on the same date (consequential market-structure revision sits in FY2026/27, not FY2027/28), and the document's "April 2026" dating of the current market structure was flagged as an open discrepancy against the 6 March 2026 gazette record.
