When Kenya's Data Protection Act came into effect in November 2019, it fundamentally changed the legal landscape for any organisation that handles personal data, and that includes every data centre operator and every customer who places servers in a Kenyan facility. The Act, modelled closely on the European Union's General Data Protection Regulation (GDPR), established rights for individuals, obligations for organisations, and enforcement powers for the Office of the Data Protection Commissioner (ODPC) that, in principle, match the standards set by the world's most comprehensive data protection laws.
In practice, Kenya's data protection regime is still maturing. The ODPC, established in 2020, has been building its institutional capacity gradually. Enforcement actions have been limited, guidance documents are still being developed, and many organisations remain unclear on exactly what compliance requires. But the law is the law, and for data centre operators and their customers, understanding the Data Protection Act is not optional, it is a legal obligation with financial penalties for non-compliance of up to KES 5 million or 1% of annual turnover, whichever is higher.
How the Act Classifies Data Centre Participants
The Data Protection Act uses two key roles that map directly onto the data centre industry. The data controller is the entity that determines the purposes and means of processing personal data. In a data centre context, the data controller is typically the customer, the bank that decides what customer data to store, how to process it, and why. The data processor is the entity that processes personal data on behalf of the controller. The data centre operator, which provides the physical infrastructure to store and process the controller's data, is a data processor.
This distinction matters because the Act imposes different obligations on controllers and processors. The controller bears the primary responsibility for ensuring lawful processing, obtaining consent, respecting data subject rights, and conducting data protection impact assessments. The processor must process data only as instructed by the controller, implement appropriate security measures, and support the controller's compliance obligations.
A data centre operator's obligations as a processor are defined by its contract with the customer. A well-drafted data processing agreement (DPA) between a data centre and its customer should specify what data the data centre may access, what security measures it must implement, what happens in the event of a breach, and what happens to the data when the contract ends. Without a DPA, both parties are exposed to legal risk.
Key Obligations for Data Centre Operators
Security Measures
The Act requires data processors to implement "appropriate technical and organisational measures" to protect personal data. For a data centre, this translates directly into the security infrastructure discussed in our security guide: physical access controls (biometrics, mantraps, CCTV), network security (firewalls, intrusion detection, encryption), and environmental controls (fire suppression, climate control). A data centre that cannot demonstrate these measures is not just a security risk, it is a compliance risk. ISO 27001 certification, covered in our ISO 27001 for Kenyan data centres guide, is the most widely accepted way to demonstrate exactly this.
Processing Only as Instructed
A data centre must not access, copy, or process customer data beyond what is necessary to provide the contracted services. When a technician performs remote hands services (physically pressing a button or checking a status light on a customer's server) they must not access the data on that server. Data centre operators enforce this through access controls (technicians cannot log into customer servers), monitoring (CCTV and access logs record all physical access to equipment), and contractual provisions (the master service agreement and DPA prohibit unauthorised access).

Supporting Breach Notification
If a data centre experiences a security incident that affects customer data, whether a physical breach (unauthorised access to the server room), a cyber attack, or an equipment failure that exposes data, it must notify the affected customer promptly. The customer, as data controller, then has 72 hours to assess whether the breach poses a risk to data subjects and, if so, to notify the ODPC. A data centre that delays notifying its customer, or fails to detect a breach in the first place, could jeopardise the customer's ability to meet the 72-hour notification requirement.
Sub-processor Management
If a data centre engages third parties (security contractors, cleaning staff, maintenance technicians) who may have access to areas where personal data is stored or processed, it must ensure those sub-processors provide equivalent data protection. The data centre remains liable to its customer for the actions of its sub-processors, so vetting, contracting, and monitoring third parties is a compliance requirement, not just a security best practice.
Cross-Border Data Transfers
One of the most practically significant aspects of the Data Protection Act for data centre customers is the restriction on cross-border data transfers. Section 48 of the Act provides that personal data shall not be transferred outside Kenya unless the recipient country has been assessed by the ODPC as having an adequate level of data protection, or unless one of several exceptions applies (the data subject has consented, the transfer is necessary for a contract, the transfer is necessary for important reasons of public interest, or the transfer is made through binding corporate rules or approved codes of conduct).

As of 2025, the ODPC has not published a comprehensive list of countries deemed to have adequate data protection. The EU (via GDPR), the United Kingdom (via UK GDPR), and several other jurisdictions would likely qualify, but the absence of a formal adequacy determination creates uncertainty. In practice, many Kenyan organisations interpret this requirement conservatively and choose to keep personal data within Kenya's borders, which drives demand for Kenyan data centre capacity.
For data centre operators, this provision is a commercial opportunity. The Data Protection Act creates a regulatory incentive for organisations to use Kenyan data centres rather than hosting in South Africa, Europe, or the cloud. A colocation facility that can demonstrate compliance with the Act, including through certifications like ISO 27001, becomes more attractive to customers who need to keep data in Kenya for regulatory reasons.
Data Subject Rights and Their Impact on Data Centres
The Act grants Kenyan data subjects several rights that, while primarily the responsibility of the data controller, can affect data centre operations.
The right of access means a data subject can request a copy of their personal data. If the data is stored on servers in a data centre, the controller may need the data centre's assistance to access and extract it. The right to erasure ("the right to be forgotten") means a data subject can request deletion of their personal data. When data is stored on physical drives in a data centre, secure deletion requires the data centre's cooperation, either by the customer remotely wiping the data, or by the data centre performing physical drive destruction or secure erasure on the customer's instructions.
The right to data portability means data subjects can request their data in a structured, commonly used format. For data stored in a data centre, this may involve the data centre providing access to the physical drives or supporting the transfer of data to a different facility. These rights create operational obligations for data centres that go beyond simply providing power, cooling, and connectivity.
Registration and Compliance
The Data Protection Act requires data controllers and processors to register with the ODPC. Data centre operators must register as data processors, and their customers (banks, telcos, government agencies) must register as data controllers. Registration involves providing details about the organisation, the types of data processed, the purposes of processing, and the security measures in place.

Beyond registration, compliance requires several ongoing activities. Data protection impact assessments (DPIAs) must be conducted for processing activities that are likely to result in a high risk to data subjects. Records of processing activities must be maintained. Staff who handle personal data must receive data protection training. And data centres must maintain documentation of their security measures, breach response procedures, and sub-processor agreements.
The Practical Reality
Kenya's Data Protection Act is well-drafted legislation that, on paper, provides protections comparable to GDPR. The practical reality is that enforcement is still developing, many organisations are in early stages of compliance, and the ODPC has limited resources relative to the scale of its mandate. However, this is changing. The ODPC has issued guidance notices, conducted compliance assessments of government agencies, and is building its enforcement capacity.
For data centre operators, the message is clear: compliance is not a future concern, it is a current obligation. The operators that invest in compliance now (through ISO 27001 certification, robust data processing agreements, staff training, and security measures) will have a competitive advantage as enforcement intensifies. Those that treat compliance as an afterthought will face increasing legal, commercial, and reputational risk. The Data Protection Act is not just a legal requirement; it is becoming a market differentiator in Kenya's data centre industry.
