Computer Misuse and Cybercrimes
This Act may be cited as the Computer Misuse and Cybercrimes Act.
- Jurisdiction
- Kenya
- Instrument
- Act or statute
- Citation
- Cap. 79C
- Version
- 31 Dec 2022
- Language
- en
- Official source
- View official record ↗
Source attribution: Source: Kenya Law
Statute overview
About this statute
This Act may be cited as the Computer Misuse and Cybercrimes Act. Defines: "alters, modifies or erases a program or data or any aspect related to the program or data in the computer system." Protects the confidentiality, integrity and availability of computer systems, programs and data. The Committee must consult owners and submit recommendations to the National Security Council identifying entities to be gazetted as critical information infrastructures; it also lists assessments and recommendations the Committee carries out regarding threats, harms, preparedness, risk factors and security methods. Owners or operators of designated critical infrastructure must report incidents likely to be computer and cybercrime attacks and the actions they will take to the Committee; the National Security Council must provide technical assistance on receipt of such reports; the Director may investigate and may secure infrastructure and must submit periodic reports to the National Security Council.
Search within this statute
Search all stored provisions in this version.
Legal text
Provisions of Computer Misuse and Cybercrimes
Showing 70 of 70
Part I
PRELIMINARY
- 1 Verify source ↗
PRELIMINARY - 1. Short title
This Act may be cited as the Computer Misuse and Cybercrimes Act.
Section 1. Short title Section This Act may be cited as the Computer Misuse and Cybercrimes Act. - 2 Verify source ↗
PRELIMINARY - 2. Interpretation
Defines: "alters, modifies or erases a program or data or any aspect related to the program or data in the computer system."
Section 2. Interpretation Section alters, modifies or erases a program or data or any aspect related to the program or data in the computer system; - 3 Verify source ↗
PRELIMINARY - 3. Objects of the Act
Protects the confidentiality, integrity and availability of computer systems, programs and data.
Section 3. Objects of the Act Section protect the confidentiality, integrity and availability of computer systems, programs and data;
Part II
THE NATIONAL COMPUTER AND CYBERCRIMES CO-ORDINATION COMMITTEE
- 10 Verify source ↗
THE NATIONAL COMPUTER AND CYBERCRIMES CO-ORDINATION COMMITTEE - 10. Protection of critical information infrastructure
The Committee must consult owners and submit recommendations to the National Security Council identifying entities to be gazetted as critical information infrastructures; it also lists assessments and recommendations the Committee carries out regarding threats, harms, preparedness, risk factors and security methods.
Section 10. Protection of critical information infrastructure Section 10(1) The Committee shall within reasonable time and in consultation with the owner or a person in control of an identified critical information infrastructure, submit to the National Security Council its recommendations of entities to be gazetted as critical information infrastructures. Section 10(2)(a) conduct an assessment of the threats, vulnerabilities, risks, and probability of a cyberattack across all critical infrastructure sectors; Section 10(2)(b) determine the harm to the economy that would result from damage or unauthorized access to critical infrastructure; Section 10(2)(c) measure the overall preparedness of each sector against damage or unauthorized access to critical infrastructure including the effectiveness of market forces driving security innovation and secure practices. Section 10(2)(d) identify any other risk-based security factors appropriate and necessary to protect public health and safety, or national socio-economic security; and Section 10(2)(e) recommend to the owners of systems designated as critical infrastructure, methods of securing their systems against cyber threats. - 11 Verify source ↗
THE NATIONAL COMPUTER AND CYBERCRIMES CO-ORDINATION COMMITTEE - 11. Reports on critical information infrastructure
Owners or operators of designated critical infrastructure must report incidents likely to be computer and cybercrime attacks and the actions they will take to the Committee; the National Security Council must provide technical assistance on receipt of such reports; the Director may investigate and may secure infrastructure and must submit periodic reports to the National Security Council.
Section 11. Reports on critical information infrastructure Section 11(1) The owner or operator of a system designated as critical infrastructure shall report to the Committee any incidents likely to constitute a threat in the nature of an attack that amounts to a computer and cybercrime and the action the owner or operator intends to take to prevent the threat. Section 11(2) Upon receipt of a report by the Committee, under subsection (1), the National Security Council shall provide technical assistance to the owner or operator of a critical infrastructure to mitigate the threat. Section 11(3) The Director may institute an investigation of a computer and cybercrime attack on his or her own volition and may take necessary steps to secure any critical infrastructure without reference to the entity. Section 11(4) The Director shall submit a report on any threat in the nature of a computer and cybercrime reported by the owners or operators of critical infrastructure periodically to the National Security Council. - 12 Verify source ↗
THE NATIONAL COMPUTER AND CYBERCRIMES CO-ORDINATION COMMITTEE - 12. Information sharing agreements
Private entities may enter into information-sharing agreements with public entities on critical information infrastructure; parties to such agreements must review and remove unrelated personal details before sharing; persons must not share others' health status without prior written consent.
Section 12. Information sharing agreements Section 12(1) A private entity may enter into an information sharing agreement with a public entity on critical information infrastructure. Section 12(2)(a) to ensure cyber security; Section 12(2)(b) for the investigation and prosecution of crimes related to cyber security; Section 12(2)(c) for the protection of life or property of an individual; and Section 12(2)(d) to protect the national security of the country. Section 12(3) Prior to the sharing of information under subsection (1), a party to an agreement shall review the information and ascertain whether the information contains personal details that may identify a specific person not directly related to a threat that amounts to a computer and cybercrime and remove such information. Section 12(4) A person shall not, under this Part, share information relating to the health status of another person without the prior written consent of the person to whom the information relates. - 13 Verify source ↗
THE NATIONAL COMPUTER AND CYBERCRIMES CO-ORDINATION COMMITTEE - 13. Auditing of critical information infrastructures to ensure compliance
The owner or person in control of a critical information infrastructure must annually submit a compliance report to the Committee in line with a critical infrastructure framework; the Director must monitor, evaluate and report on audits and has power to request additional information within a specified period.
Section 13. Auditing of critical information infrastructures to ensure compliance Section 13(1) The owner or person in control of a critical information infrastructure shall annually submit a compliance report on the critical information infrastructure to the Committee in line with a critical infrastructure framework in order to evaluate compliance. Section 13(2)(a) the date on which an audit is to be performed; and Section 13(2)(b) the particulars and contact details of the person who is responsible for the overall management and control of the audit. Section 13(3) The Director shall monitor, evaluate and report on the adequacy and effectiveness of any audit. Section 13(4) The Director may request the owner or person in control of a critical information infrastructure to provide such additional information as may be necessary within a specified period in order to evaluate the issues raised from the audit. Section 13(5)(a) fails to file a compliance report and fails to cooperate with an audit to be performed on a critical information infrastructure in order to evaluate compliance with the directives issued; Section 13(5)(b) fails to provide to the Director such additional information as may be necessary within a specified period in order to evaluate the report of an audit in line with the critical infrastructure after he or she has been requested to do so to the Director; Section 13(5)(c) hinders, obstructs or improperly attempts to influence any member of the Committee, person or entity to monitor, evaluate and report on the adequacy and effectiveness of an audit; Section 13(5)(d) hinders, obstructs or improperly attempts to influence any person authorized to carry out an audit; Section 13(5)(e) fails to co-operate with any person authorized to carry out an audit; or Section 13(5)(f) fails to assist or provide technical assistance and support to a person authorized to carry out an audit. Section 13(6)(a) has been authorized in writing by the Director to perform such audit; or Section 13(6)(b) is in possession of a certificate of appointment, in the prescribed form, issued by the Director, which certificate must be submitted to the owner or person in control of a critical information infrastructure at the commencement of the audit. - 4 Verify source ↗
THE NATIONAL COMPUTER AND CYBERCRIMES CO-ORDINATION COMMITTEE - 4. Establishment of Committee
Establishes the National Computer and Cybercrimes Co-ordination Committee.
Section 4. Establishment of Committee Section There is established the National Computer and Cybercrimes Co-ordination Committee. - 5 Verify source ↗
THE NATIONAL COMPUTER AND CYBERCRIMES CO-ORDINATION COMMITTEE - 5. Composition of the Committee
Lists the members of the National Computer and Cybercrimes Co-ordination Committee, names the Director as secretary (non-voting), and requires the Committee to report to the Cabinet Secretary responsible for internal security.
Section 5. Composition of the Committee Section 5(1)(a) the Principal Secretary responsible for matters relating to internal security or a representative designated and who shall be the chairperson; Section 5(1)(b) the Principal Secretary responsible for matters relating to information, communication and technology or a representative designated in writing by the Principal Secretary responsible for information, communication and technology; Section 5(1)(c) the Attorney-General or a representative designated in writing by the Attorney-General; Section 5(1)(d) the Chief of the Kenya Defence Forces or a representative designated in writing by the Chief of the Kenya Defence Forces; Section 5(1)(e) the Inspector-General of the National Police Service or a representative designated in writing by the Inspector-General of the National Police Service; Section 5(1)(f) the Director-General of the National Intelligence Service or a representative designated in writing by the Director-General of the National Intelligence Service; Section 5(1)(g) the Director-General of the Communications Authority of Kenya or a representative designated in writing by the Director-General of the Communications Authority of Kenya; Section 5(1)(h) the Director of Public Prosecutions or a representative designated in writing by the Director of Public Prosecutions; Section 5(1)(i) the Governor of the Central Bank of Kenya or a representative designated in writing by the Governor of the Central Bank of Kenya; and Section 5(1)(j) the Director who shall be the secretary of the Committee and who shall not have a right to vote. Section 5(2) The Committee shall report to the Cabinet Secretary responsible for matters relating to internal security. - 6 Verify source ↗
THE NATIONAL COMPUTER AND CYBERCRIMES CO-ORDINATION COMMITTEE - 6. Functions of the Committee
The Committee has multiple functions including advising Government and the National Security Council on cyber matters, coordinating security organs, receiving and acting on reports, developing frameworks and standards for critical information infrastructure, cooperating with response teams, managing PKI and training frameworks, and regulating its own procedure.
Section 6. Functions of the Committee Section 6(1)(a) advise the Government on security related aspects touching on matters relating to blockchain technology, critical infrastructure, mobile money and trust accounts; Section 6(1)(b) advise the National Security Council on computer and cybercrimes; Section 6(1)(c) co-ordinate national security organs in matters relating to computer and cybercrimes; Section 6(1)(d) receive and act on reports relating to computer and cybercrimes; Section 6(1)(e) develop a framework to facilitate the availability, integrity and confidentiality of critical national information infrastructure including telecommunications and information systems of Kenya; Section 6(1)(f) co-ordinate collection and analysis of cyber threats, and response to cyber incidents that threaten cyberspace belonging to Kenya, whether such threats or incidents of computer and cybercrime occur within or outside Kenya; Section 6(1)(g) co-operate with computer incident response teams and other relevant bodies, locally and internationally on response to threats of computer and cybercrime and incidents; Section 6(1)(h) establish codes of cyber security practice and standards of performance for implementation by owners of critical national information infrastructure; Section 6(1)(i) develop and manage a national public key infrastructure framework; Section 6(1)(j) develop a framework for training on prevention, detection and mitigation of computer and cybercrimes and matters connected thereto; and Section 6(1)(k) perform any other function conferred on it by this Act or any other written law. Section 6(2) Subject to the provisions of this Act, the Committee shall regulate its own procedure. - 7 Verify source ↗
THE NATIONAL COMPUTER AND CYBERCRIMES CO-ORDINATION COMMITTEE - 7. Secretariat of the Committee
Establishes a Secretariat that comprises a Director and public officers; the Cabinet Secretary responsible for internal security (in consultation with the ICT Cabinet Secretary) may deploy public officers to the Secretariat subject to the Committee's approval. The Director is the head of the Secretariat, is responsible to the Committee for day-to-day administration and implementing Committee decisions, and has duties including administration, staff management, financial record-keeping, budget preparation and other duties assigned by the Committee. The Director is appointed for a single four-year term and is not eligible for reappointment.
Section 7. Secretariat of the Committee Section 7(1) There shall be a Secretariat which shall comprise of the Director and such number of public officers that, subject to the approval of the Committee, the Cabinet Secretary responsible for matters relating to internal security in consultation with the Cabinet Secretary responsible for matters relating to information, communications and technology may deploy to the Secretariat. Section 7(2)(a) the head of the Secretariat; and Section 7(2)(b) responsible to the Committee for the day to day administration of the affairs of the Secretariat and implementation of the decisions arising from the Committee. Section 7(3)(a) the implementation of the decisions of the Committee; Section 7(3)(b) the efficient administration of the Secretariat; Section 7(3)(c) the management of staff of the Secretariat; Section 7(3)(d) the maintenance of accurate records on financial matters and resource use; Section 7(3)(e) the preparation and approval of the budget for the required funding of the operational expenses of the Secretariat; and Section 7(3)(f) the performance of any other duties as may be assigned to him or her by the Committee. Section 7(4) The Director shall be appointed for a single term of four years and shall not be eligible for reappointment. - 8 Verify source ↗
THE NATIONAL COMPUTER AND CYBERCRIMES CO-ORDINATION COMMITTEE - 8. Reports by the Committee etc
The Committee must submit quarterly reports to the National Security Council.
Section 8. Reports by the Committee etc Section The Committee shall submit quarterly reports to the National Security Council. - 9 Verify source ↗
THE NATIONAL COMPUTER AND CYBERCRIMES CO-ORDINATION COMMITTEE - 9. Critical information infrastructure
The Director must designate systems as critical infrastructure by Gazette notice and must inform owners/operators of the reasons within a reasonable time; owners/persons in control must comply with directives within the specified period.
Section 9. Critical information infrastructure Section 9(1) The Director shall, by notice in the Gazette , designate certain systems as critical infrastructure. Section 9(2)(a) the interruption of a life sustaining service including the supply of water, health services and energy; Section 9(2)(b) an adverse effect on the economy of the Republic; Section 9(2)(c) an event that would result in massive casualties or fatalities; Section 9(2)(d) failure or substantial disruption of the money market of the Republic; and Section 9(2)(e) adverse and severe effect of the security of the Republic including intelligence and military services. Section 9(3) The Director shall, within a reasonable time of designating a system as critical infrastructure, inform the owner or operator of the system the reasons for the designation of the system as a critical infrastructure. Section 9(4)(a) the classification of data held by the critical information infrastructure; Section 9(4)(b) the protection of, the storing of and archiving of data held by the critical information infrastructure; Section 9(4)(c) cyber security incident management by the critical information infrastructure; Section 9(4)(d) disaster contingency and recovery measures, which must be put in place by the critical information infrastructure; Section 9(4)(e) minimum physical and technical security measures that must be implemented in order to protect the critical information infrastructure; Section 9(4)(f) the period within which the owner, or person in control of a critical information infrastructure must comply with the directives; and Section 9(4)(g) any other relevant matter which is necessary or expedient in order to promote cyber security in respect of the critical information infrastructure.
Part III
OFFENCES
- 14 Verify source ↗
OFFENCES - 14. Unauthorised access
Causing a computer system to perform a function by infringing security measures with intent to gain unauthorised access is an offence punishable by a fine up to five million shillings, imprisonment up to three years, or both.
Section 14. Unauthorised access Section 14(1) A person who causes, whether temporarily or permanently, a computer system to perform a function, by infringing security measures, with intent to gain access, and knowing such access is unauthorised, commits an offence and is liable on conviction, to a fine not exceeding five million shillings or to imprisonment for a term not exceeding three years, or to both. Section 14(2)(a) that person is not entitled to control access of the kind in question to the program or data; or Section 14(2)(b) that person does not have consent from any person who is entitled to access the computer system through any function to the program or data. Section 14(3)(a) any particular program or data; Section 14(3)(b) a program or data of any kind; or Section 14(3)(c) a program or data held in any particular computer system. - 15 Verify source ↗
OFFENCES - 15. Access with intent to commit further offence
It is an offence for a person who commits an offence under section 14 to do so with intent to commit or facilitate a further offence; on conviction they may be fined up to ten million shillings, imprisoned up to ten years, or both.
Section 15. Access with intent to commit further offence Section 15(1) A person who commits an offence under section 14 with intent to commit a further offence under any law, or to facilitate the commission of a further offence by that person or any other person, commits an offence and is liable, on conviction, to a fine not exceeding ten million shillings or to imprisonment for a term not exceeding ten years, or to both. Section 15(2) For the purposes of subsection (1), it is immaterial that the further offence to which this section applies is committed at the same time when the access is secured or at any other time. - 16 Verify source ↗
OFFENCES - 16. Unauthorised interference
It is an offence for a person to intentionally and without authorisation cause an unauthorised interference with a computer system, program or data; conviction may lead to a fine not exceeding ten million shillings, imprisonment not exceeding five years, or both.
Section 16. Unauthorised interference Section 16(1) A person who intentionally and without authorisation does any act which causes an unauthorised interference to a computer system, program or data, commits an offence and is liable on conviction, to a fine not exceeding ten million shillings or to imprisonment for a term not exceeding five years, or to both. Section 16(2)(a) is not entitled to cause that interference; Section 16(2)(b) does not have consent to interfere from a person who is so entitled. Section 16(3)(a) results in a significant financial loss to any person; Section 16(3)(b) threatens national security; Section 16(3)(c) causes physical injury or death to any person; or Section 16(3)(d) threatens public health or public safety, Section 16(4)(a) any particular computer system, program or data; Section 16(4)(b) a program or data of any kind; or Section 16(4)(c) a program or data held in any particular computer system. Section 16(5) For the purposes of this section, it is immaterial whether an unauthorised modification or any intended effect of it is permanent or temporary. - 17 Verify source ↗
OFFENCES - 17. Unauthorised interception
Unauthorised interception of data transmitted to or from a computer system over a telecommunication system is an offence punishable by fines or imprisonment; aggravated cases attract higher maximum penalties.
Section 17. Unauthorised interception Section 17(1) A person who intentionally and without authorisation does any act which intercepts or causes to be intercepted, directly or indirectly and causes the transmission of data to or from a computer system over a telecommunication system commits an offence and is liable, on conviction, to a fine not exceeding ten million shillings or to imprisonment for a term not exceeding five years, or to both. Section 17(2)(a) results in a significant financial loss; Section 17(2)(b) threatens national security; Section 17(2)(c) causes physical or psychological injury or death to any person; or Section 17(2)(d) threatens public health or public safety, is liable, on conviction to a fine not exceeding twenty million shillings or to imprisonment for a term not exceeding ten years, or to both. Section 17(3)(a) a telecommunication system; Section 17(3)(b) any particular computer system data; Section 17(3)(c) a program or data of any kind; or Section 17(3)(d) a program or data held in any particular computer system. Section 17(4) For the purposes of this section, it is immaterial whether an unauthorised interception or any intended effect of it is permanent or temporary. - 18 Verify source ↗
OFFENCES - 18. Illegal devices and access codes
It is an offence for a person to knowingly make available or possess programs, passwords, access codes or similar data intended primarily to commit offences under this Part; penalties include fines or imprisonment.
Section 18. Illegal devices and access codes Section 18(1) A person who knowingly manufactures, adapts, sells, procures for use, imports, offers to supply, distributes or otherwise makes available a device, program, computer password, access code or similar data designed or adapted primarily for the purpose of committing any offence under this Part, commits an offence and is liable, on conviction, to a fine not exceeding twenty million shillings or to imprisonment for a term not exceeding ten years, or to both. Section 18(2) A person who knowingly receives, or is in possession of, a program or a computer password, device, access code, or similar data from any action specified under subsection (1) and intends that it be used to commit or assist in commission of an offence under this Part commits an offence and is liable on conviction, to a fine not exceeding ten million shillings or to imprisonment for a term not exceeding five years, or to both. Section 18(3)(a) any act intended for the authorised training, testing or protection of a computer system; or Section 18(3)(b) the use of a program or a computer password, access code, or similar data Section 18(4)(a) possession of a computer system which contains the program or a computer password, access code, or similar data; Section 18(4)(b) possession of a data storage device in which the program or a computer password, access code, or similar data is recorded; or Section 18(4)(c) control of a program or a computer password, access code, or similar data that is in the possession of another person. - 19 Verify source ↗
OFFENCES - 19. Unauthorised disclosure of password or access code
A person who knowingly and without authority discloses any password, access code or other means of gaining access to computer data commits an offence and is liable on conviction to a fine not exceeding five million shillings or to imprisonment for up to three years, or both.
Section 19. Unauthorised disclosure of password or access code Section 19(1) A person who knowingly and without authority discloses any password, access code or other means of gaining access to any program or data held in any computer system commits an offence and is liable, on conviction, to a fine not exceeding five million shillings or to imprisonment for a term not exceeding three years, or to both. Section 19(2)(a) for any wrongful gain; Section 19(2)(b) for any unlawful purpose; or Section 19(2)(c) to occasion any loss, - 20 Verify source ↗
OFFENCES - 20. Enhanced penalty for offences involving protected computer system
If a person commits any of the offences in sections 14–17 on a protected computer system, they are liable on conviction to a fine up to twenty five million shillings or imprisonment up to twenty years, or both.
Section 20. Enhanced penalty for offences involving protected computer system Section 20(1) Where a person commits any of the offences specified under sections 14 , 15, 16 and 17 on a protected computer system, that person shall be liable, on conviction, to a fine not exceeding twenty five million shillings or imprisonment for a term not exceeding twenty years or both. Section 20(2)(a) the security, defence or international relations of Kenya; Section 20(2)(b) the existence or identity of a confidential source of information relating to the enforcement of a criminal law; Section 20(2)(c) the provision of services directly related to communications infrastructure, banking and financial services, payment and settlement systems and instruments, public utilities or public transportation, including government services delivered electronically; Section 20(2)(d) the protection of public safety including systems related to essential emergency services such as police, civil defence and medical services; Section 20(2)(e) the provision of national registration systems; or Section 20(2)(f) such other systems as may be designated relating to the security, defence or international relations of Kenya, critical information, communications, business or transport infrastructure and protection of public safety and public services as may be designated by the Cabinet Secretary responsible for matters relating to information, communication and technology. - 21 Verify source ↗
OFFENCES - 21. Cyber espionage
Section 21 criminalises gaining access to or intercepting data in critical databases or national critical information infrastructure to benefit a foreign state, and sets imprisonment and fine penalties including up to life imprisonment where the offence causes death.
Section 21. Cyber espionage Section 21(1)(a) gain access, as provided under section 14 , to critical data, a critical database or a national critical information infrastructure; or Section 21(1)(b) intercept data, as provided under section 17 , to, from or within a critical database or a national critical information infrastructure, with the intention to directly or indirectly benefit a foreign state against the Republic of Kenya, Section 21(2) A person who commits an offence under subsection (1) which causes physical injury to any person is liable, on conviction, to imprisonment for a term not exceeding twenty years. Section 21(3) A person who commits an offence under subsection (1) which causes the death of a person is liable, on conviction, to imprisonment for life. Section 21(4) A person who unlawfully and intentionally possesses, communicates, delivers or makes available or receives, data, to, from or within a critical database or a national critical information infrastructure, with the intention to directly or indirectly benefit a foreign state against the Republic of Kenya, commits an offence and is liable on conviction to imprisonment for a period not exceeding twenty years or to a fine not exceeding ten million shillings, or to both. Section 21(5) A person who unlawfully and intentionally performs or authorizes, or allows another person to perform a prohibited act as envisaged under this Act in order to gain access, as provided under section 14 , to or intercept data, as provided under section 17 , which is in possession of the State and which is exempt information in accordance with the law relating to access to information, with the intention to directly or indirectly benefit a foreign state against the Republic of Kenya, commits an offence and is liable, on conviction, to a fine not exceeding five million shillings or to imprisonment for a period not exceeding ten years, or to both. - 22 Verify source ↗
OFFENCES - 22. False publications
Publishing false, misleading or fictitious data (with intent that it be acted on as authentic) is an offence punishable on conviction by a fine not exceeding five million shillings, or by imprisonment for a term not exceeding two years, or both.
Section 22. False publications Section 22(1) A person who intentionally publishes false, misleading or fictitious data or misinforms with intent that the data shall be considered or acted upon as authentic, with or without any financial gain, commits an offence and shall, on conviction, be liable to a fine not exceeding five million shillings or to imprisonment for a term not exceeding two years, or to both. Section 22(2)(a) propagate war; or Section 22(2)(a)(i) propagate war; or Section 22(2)(a)(ii) incite persons to violence; Section 22(2)(b) constitutes hate speech; Section 22(2)(c) constitutes ethnic incitement, vilification of others or incitement to cause harm; or Section 22(2)(c)(i) constitutes ethnic incitement, vilification of others or incitement to cause harm; or Section 22(2)(c)(ii) is based on any ground of discrimination specified or contemplated in Article 27(4) of the Constitution; or Section 22(2)(d) negatively affects the rights or reputations of others. - 23 Verify source ↗
OFFENCES - 23. Publication of false information
It is an offence for a person to knowingly publish false information in print, broadcast, data or over a computer system that causes panic, chaos, violence, or is likely to discredit someone; on conviction the person may be fined up to five million shillings or imprisoned up to ten years, or both.
Section 23. Publication of false information Section A person who knowingly publishes information that is false in print, broadcast, data or over a computer system, that is calculated or results in panic, chaos, or violence among citizens of the Republic, or which is likely to discredit the reputation of any person commits an offence and shall on conviction, be liable to a fine not exceeding five million shillings or to imprisonment for a term not exceeding ten years, or to both. - 24 Verify source ↗
OFFENCES - 24. Child pornography
Section 24 prohibits publishing, producing, downloading, distributing, transmitting, circulating, delivering, exhibiting, selling, letting on hire, offering, making available, or possessing child pornography via computer systems or computer data storage; it also lists defences and categories of images covered.
Section 24. Child pornography Section 24(1)(a) publishes child pornography through a computer system; Section 24(1)(b) produces child pornography for the purpose of its publication through a computer system; Section 24(1)(c) downloads, distributes, transmits, disseminates, circulates, delivers, exhibits, lends for gain, exchanges, barters, sells or offers for sale, lets on hire or offers to let on hire, offers in another way, or make available in any way from a telecommunications apparatus pornography; or Section 24(1)(d) possesses child pornography in a computer system or on a computer data storage medium, Section 24(2) It is a defence to a charge of an offence under subsection (1) that a publication which is proved to be justified as being for the public good on the ground that such book, pamphlet, paper, writing, drawing, painting, art, representation or figure is in the interest of science, literature, learning or other objects of general concerns. Section 24(3)(a) a child engaged in sexually explicit conduct; Section 24(3)(b) a person who appears to be a child engaged in sexually explicit conduct; or Section 24(3)(c) realistic images representing a child engaged in sexually explicit conduct; Section 24(3)(a) distribute, transmit, disseminate, circulate, deliver, exhibit, lend for gain, exchange, barter, sell or offer for sale, let on hire or offer to let on hire, offer in any other way, or make available in any way; Section 24(3)(b) having in possession or custody, or under control, for the purpose of doing an act referred to in paragraph (a); or Section 24(3)(c) print, photograph, copy or make in any other manner whether of the same or of a different kind or nature for the purpose of doing an act referred to in paragraph (a). - 25 Verify source ↗
OFFENCES - 25. Computer forgery
It is an offence for a person to intentionally input, alter, delete or suppress computer data so it becomes inauthentic with intent it be treated as authentic; on conviction the person may be fined up to ten million shillings or imprisoned for up to five years, or both.
Section 25. Computer forgery Section 25(1) A person who intentionally inputs, alters, deletes, or suppresses computer data, resulting in inauthentic data with the intent that it be considered or acted upon for legal purposes as if it were authentic, regardless of whether or not the data is directly readable and intelligible commits an offence and is liable, on conviction, to fine not exceeding ten million shillings or to imprisonment for a term not exceeding five years, or to both. Section 25(2)(a) for wrongful gain; Section 25(2)(b) for wrongful loss to another person; or Section 25(2)(c) for any economic benefit for oneself or for another person, - 26 Verify source ↗
OFFENCES - 26. Computer fraud
Makes computer fraud an offence by unlawfully gaining, causing loss, or obtaining an economic benefit through specified acts involving computer systems, programs or data.
Section 26. Computer fraud Section 26(1)(a) unlawfully gains; Section 26(1)(b) occasions unlawful loss to another person; or Section 26(1)(c) obtains an economic benefit for oneself or for another person, through any of the means described in subsection (2), Section 26(2)(a) an unauthorised access to a computer system, program or data; Section 26(2)(b) any input, alteration, modification, deletion, suppression or generation of any program or data; Section 26(2)(c) any interference, hindrance, impairment or obstruction with the functioning of a computer system; Section 26(2)(d) copying, transferring or moving any data or program to any computer system, data or computer data storage medium other than that in which it is held or to a different location in any other computer system, program, data or computer data storage medium in which it is held; or Section 26(2)(e) uses any data or program, or has any data or program output from the computer system in which it is held, by having it displayed in any manner. - 27 Verify source ↗
OFFENCES - 27. Cyber harassment
Section criminalizes cyber harassment (causing fear, detriment, or indecent/offensive communications), creates offences with fines and imprisonment, allows interim orders and compels subscriber information, permits intermediary and persons to apply for orders, and provides hearing and timeliness rules.
Section 27. Cyber harassment Section 27(1)(a) is likely to cause those persons apprehension or fear of violence to them or damage or loss on that persons' property; or Section 27(1)(b) detrimentally affects that person; or Section 27(1)(c) is in whole or part, of an indecent or grossly offensive nature and affects the person. Section 27(2) A person who commits an offence under subsection (1) is liable, on conviction, to a fine not exceeding twenty million shillings or to imprisonment for a term not exceeding ten years, or to both. Section 27(3)(a) engaging or attempting to engage in; or Section 27(3)(b) enlisting the help of another person to engage in, any communication complained of under subsection (1). Section 27(4)(a) may grant an interim order; and Section 27(4)(b) shall hear and determine an application under subsection (4) within fourteen days. Section 27(5) An intermediary may apply for the order under subsection (4) on behalf of a complainant under this section. Section 27(6) A person may apply for an order under his section outside court working hours. Section 27(7) The Court may order a service provider to provide any subscriber information in its possession for the purpose of identifying a person whose conduct is complained of under this section. Section 27(8) A person who contravenes an order made under this section commits an offence and is liable, on conviction to a fine not exceeding one million shillings or to imprisonment for a term not exceeding six months, or to both. - 28 Verify source ↗
OFFENCES - 28. Cybersquatting
It is an offence for a person to intentionally take or make use of another person's name, business name, trademark, domain name or similar on the internet or any computer network without authority or right; on conviction the person may be fined up to two hundred thousand shillings or imprisoned for a term not exceeding two years, or both.
Section 28. Cybersquatting Section A person who, intentionally takes or makes use of a name, business name, trademark, domain name or other word or phrase registered, owned or in use by another person on the internet or any other computer network, without authority or right, commits an offence and is liable on conviction to a fine not exceeding two hundred thousand shillings or imprisonment for a term not exceeding two years or both. - 29 Verify source ↗
OFFENCES - 29. Identity theft and impersonation
It is an offence for a person to fraudulently or dishonestly use another person's electronic signature, password or other unique identification feature.
Section 29. Identity theft and impersonation Section A person who fraudulently or dishonestly makes use of the electronic signature, password or any other unique identification feature of any other person commits an offence and is liable, on conviction, to a fine not exceeding two hundred thousand shillings or to imprisonment for a term not exceeding three years or both. - 30 Verify source ↗
OFFENCES - 30. Phishing
It is an offence for a person to create or operate a website or to send a message via a computer system with the intention of inducing disclosure of personal information or to gain unauthorised access; on conviction the person may be fined up to three hundred thousand shillings or imprisoned for up to three years, or both.
Section 30. Phishing Section A person who creates or operates a website or sends a message through a computer system with the intention to induce the user of a website or the recipient of the message to disclose personal information for an unlawful purpose or to gain unauthorized access to a computer system, commits an offence and is liable upon conviction to a fine not exceeding three hundred thousand shillings or to imprisonment for a term not exceeding three years or both. - 31 Verify source ↗
OFFENCES - 31. Interception of electronic messages or money transfers
A person who unlawfully destroys or aborts electronic mail or processes conveying money or information commits an offence and faces a fine up to 200,000 shillings or imprisonment up to seven years or both.
Section 31. Interception of electronic messages or money transfers Section A person who unlawfully destroys or aborts any electronic mail or processes through which money or information is being conveyed commits an offence and is liable on conviction to a fine not exceeding two hundred thousand shillings or to a term of imprisonment not exceeding seven years or to both. - 32 Verify source ↗
OFFENCES - 32. Willful misdirection of electronic messages
A person who willfully misdirects electronic messages commits an offence and may be fined up to one hundred thousand shillings or imprisoned for up to two years, or both.
Section 32. Willful misdirection of electronic messages Section A person who willfully misdirects electronic messages commits an offence and is liable on conviction to a fine not exceeding one hundred thousand shillings or to imprisonment for a term not exceeding two years or to both. - 33 Verify source ↗
OFFENCES - 33. Cyber terrorism
It is an offence for a person to access (or cause access to) a computer, computer system or network to carry out a terrorist act; on conviction the person may face a fine not exceeding five million shillings, or imprisonment for a term not exceeding ten years, or both.
Section 33. Cyber terrorism Section 33(1) A person who accesses or causes to be accessed a computer or computer system or network for purposes of carrying out a terrorist act, commits an offence and shall on conviction, be liable to a fine not exceeding five million shillings or to imprisonment for a term not exceeding ten years, or to both. Section 33(2) For the purpose of this section, "terrorist act" shall have the same meaning as assigned under the Prevention of Terrorism Act (Cap. 59B). - 34 Verify source ↗
OFFENCES - 34. Inducement to deliver electronic message
It is an offence for a person to induce someone in charge of electronic devices to deliver electronic messages not meant for that person; on conviction the offender may be fined up to two hundred thousand shillings or imprisoned up to two years or both.
Section 34. Inducement to deliver electronic message Section A person who induces any person in charge of electronic devices to deliver any electronic messages not specifically meant for him commits an offence and is liable on conviction to a fine not exceeding two hundred thousand shillings or imprisonment for a term not exceeding two years or to both. - 35 Verify source ↗
OFFENCES - 35. Intentionally withholding message delivered erroneously
A person who intentionally hides or detains electronic mail, messages, electronic payments or cards found or delivered in error that should go to another person commits an offence and on conviction faces a fine up to 200,000 shillings or imprisonment up to two years or both.
Section 35. Intentionally withholding message delivered erroneously Section A person who intentionally hides or detains any electronic mail, message, electronic payment, credit and debit card which was found by the person or delivered to the person in error and which ought to be delivered to another person, commits an offence and is liable on conviction a fine not exceeding two hundred thousand shillings or imprisonment for a term not exceeding two years or to both. - 36 Verify source ↗
OFFENCES - 36. Unlawful destruction of electronic messages
A person who unlawfully destroys or aborts electronic mail or related processes that convey money or information commits an offence and faces a fine up to two hundred thousand shillings, imprisonment up to two years, or both.
Section 36. Unlawful destruction of electronic messages Section A person who unlawfully destroys or aborts any electronic mail or processes through which money or information is being conveyed commits an offence and is liable on conviction to a fine not exceeding two hundred thousand shillings or imprisonment for a term not exceeding two years, or to both. - 37 Verify source ↗
OFFENCES - 37. Wrongful distribution of obscene or intimate images
It is an offence for a person to transfer, publish, or disseminate the intimate or obscene image of another person; on conviction the person may be fined up to two hundred thousand shillings or imprisoned for up to two years, or both.
Section 37. Wrongful distribution of obscene or intimate images Section A person who transfers, publishes, or disseminates, including making a digital depiction available for distribution or downloading through a telecommunications network or though any other means of transferring data to a computer, the intimate or obscene image of another person commits an offence and is liable, on conviction to a fine not exceeding two hundred thousand shillings or imprisonment for a term not exceeding two years, or to both. - 38 Verify source ↗
OFFENCES - 38. Fraudulent use of electronic data
Makes knowingly and unauthorised alteration, erasure, inputting or suppression of computer data, materially misleading electronic messages, fraudulent handling of electronic messages/instructions, and manipulation of payment devices to short‑pay or overpay criminal offences punishable by a fine up to 200,000 shillings or imprisonment up to two years, or both; subsection (5) requires forfeiture of proprietary interest for convictions under subsection (4).
Section 38. Fraudulent use of electronic data Section 38(1) A person who knowingly and without authority causes any loss of property to another by altering, erasing, inputting or suppressing any data stored in a computer, commits an offence and is liable on conviction to a fine not exceeding two hundred thousand shillings or imprisonment for a term not exceeding two years, or to both. Section 38(2) A person who sends an electronic message which materially misrepresents any fact upon which reliance by another person is caused to suffer any damage or loss commits an offence and is liable on conviction to imprisonment for a fine not exceeding two hundred thousand shillings or imprisonment for a term not exceeding two years, or to both. Section 38(3) A person who with intent to defraud, franks electronic messages, instructions, subscribes any electronic messages or instructions, commits an offence and is liable on conviction a fine not exceeding two hundred thousand shillings or imprisonment for a term not exceeding two years, or to both. Section 38(4) A person who manipulates a computer or other electronic payment device with the intent to short pay or overpay commits an offence and is liable on conviction to a fine not exceeding two hundred thousand shillings or imprisonment for a term not exceeding two years, or to both. Section 38(5) A person convicted under subsection (4) shall forfeit the proprietary interest in the stolen money or property to the bank, financial institution or the customer. - 39 Verify source ↗
OFFENCES - 39. Issuance of false e-instructions
Anyone authorized to use electronic devices for financial transactions who issues false electronic instructions commits an offence and is liable on conviction to a fine not exceeding two hundred thousand shillings or imprisonment for a term not exceeding two years, or both.
Section 39. Issuance of false e-instructions Section A person authorized to use a computer or other electronic devices for financial transactions including posting of debit and credit transactions, issuance of electronic instructions as they relate to sending of electronic debit and credit messages or confirmation of electronic fund transfer, issues false electronic instructions, commits an offence and is liable, on conviction, a fine not exceeding two hundred thousand shillings or imprisonment for a term not exceeding two years, or to both. - 40 Verify source ↗
OFFENCES - 40. Reporting of cyber threat
Operators of computer systems or networks must immediately inform the Committee of attacks, intrusions or other disruptions to another system or network within twenty four hours; failure is an offence punishable by a fine not exceeding two hundred thousand shillings or imprisonment for up to two years, or both.
Section 40. Reporting of cyber threat Section 40(1) A person who operates a computer system or a computer network, whether public or private, shall immediately inform the Committee of any attacks, intrusions and other disruptions to the functioning of another computer system or network within twenty four hours of such attack, intrusion or disruption. Section 40(2)(a) information about the breach, including a summary of any information that the agency knows on how the breach occurred; Section 40(2)(b) an estimate of the number of people affected by the breach; Section 40(2)(c) an assessment of the risk of harm to the affected individuals; and Section 40(2)(d) an explanation of any circumstances that would delay or prevent the affected persons from being informed of the breach. Section 40(3) The Committee may propose the isolation of any computer systems or network suspected to have been attacked or disrupted pending the resolution of the issues. Section 40(4) A person who contravenes the provisions of subsection (1) commits an offence and is liable upon conviction a fine not exceeding two hundred thousand shillings or imprisonment for a term not exceeding two years, or to both. - 41 Verify source ↗
OFFENCES - 41. Employee responsibility to relinquish access codes
Employees must relinquish all codes and access rights to their employer's computer network or system immediately upon termination of employment, subject to any contractual agreement.
Section 41. Employee responsibility to relinquish access codes Section 41(1) An employee shall, subject to any contractual agreement between the employer and the employee, relinquish all codes and access rights to their employer's computer network or system immediately upon termination of employment. Section 41(2) person who contravenes the provision of this subsection (1) commits an offence and shall be, liable on conviction, to a fine not exceeding two hundred thousand shillings or imprisonment for a term not exceeding two years, or to both. - 42 Verify source ↗
OFFENCES - 42. Aiding or abetting in the commission of an offence
It is an offence for a person to knowingly and willfully aid or abet another to commit an offence, and it is also an offence to knowingly and willfully attempt or take preparatory acts toward committing an offence; on conviction the person is liable to a fine not exceeding seven million shillings or imprisonment not exceeding four years, or both.
Section 42. Aiding or abetting in the commission of an offence Section 42(1) A person who knowingly and willfully aids or abets the commission of any offence under this Act commits an offence and is liable, on conviction, to a fine not exceeding seven million shillings or to imprisonment for a term not exceeding four years, or to both. Section 42(2) A person who knowingly and willfully attempts to commit an offence or does any act preparatory to or in furtherance of the commission of any offence under this Act, commits an offence and is liable, on conviction, to a fine not exceeding seven million shillings or to imprisonment for a term not exceeding four years, or to both. - 43 Verify source ↗
OFFENCES - 43. Offences by a body corporate and limitation of liability
A body corporate is liable on conviction to a fine up to fifty million shillings; principal officers (or those acting similarly) are also deemed to have committed the offence unless they prove lack of consent or knowledge and that they exercised due diligence, and are liable on conviction to a fine up to five million shillings or imprisonment up to three years, or both.
Section 43. Offences by a body corporate and limitation of liability Section 43(1)(a) the body corporate is liable, on conviction, to a fine not exceeding fifty million shillings; and Section 43(1)(b) every person who at the time of the commission of the offence was a principal officer of the body corporate, or anyone acting in a similar capacity, is also deemed to have committed the offence, unless they prove that the offence was committed without their consent or knowledge and that they exercised such diligence to prevent the commission of the offence as they ought to have exercised having regard to the nature of their functions and to prevailing circumstances, and is liable, on conviction, to a fine not exceeding five million shillings or imprisonment for a term not exceeding three years, or to both. Section 43(2) If the affairs of the body corporate are managed by its members, subsection (1)(b) applies in relation to the acts or defaults of a member in connection with their management functions, as if the member was a principal officer of the body corporate or was acting in a similar capacity. - 44 Verify source ↗
OFFENCES - 44. Confiscation or forfeiture of assets
A court may order confiscation or forfeiture of assets obtained with proceeds from an offence; the court may also, on conviction, order restitution of assets in accordance with the Proceeds of Crime and Anti-Money Laundering Act (Cap. 59A).
Section 44. Confiscation or forfeiture of assets Section 44(1) A court may order the confiscation or forfeiture of monies, proceeds, properties and assets purchased or obtained by a person with proceeds derived from or in the commission of an offence under this Act. Section 44(2) The court may, on conviction of a person for any offence under this Act make an order of restitution of any asset gained from the commission of the offence, in accordance with the provisions and procedures of the Proceeds of Crime and Anti-Money Laundering Act (Cap. 59A). - 45 Verify source ↗
OFFENCES - 45. Compensation order
The court may order a person convicted of an offence (including those committed through use of a computer system) to pay a sum as compensation for resultant loss.
Section 45. Compensation order Section 45(1) Where the court convicts a person for any offence under this Part, or for an offence under any other law committed through the use of a computer system, the court may make an order for the payment by that person of a sum to be fixed by the court as compensation to any person for any resultant loss caused by the commission of the offence for which the sentence is passed. Section 45(2) Any claim by a person for damages sustained by reason of any offence committed under this Part is deemed to have been satisfied to the extent of any amount which they have been paid under an order for compensation, but the order shall not prejudice any right to a civil remedy for the recovery of damages beyond the amount of compensation paid under the order. Section 45(3) An order of compensation under this section is recoverable as a civil debt. - 46 Verify source ↗
OFFENCES - 46. Additional penalty for other offences committed through use of a computer system
A person who commits an offence under any other law through the use of a computer system commits an offence and is liable on conviction to a penalty similar to that under the other law.
Section 46. Additional penalty for other offences committed through use of a computer system Section 46(1) A person who commits an offence under any other law through the use of a computer system commits an offence and shall be liable on conviction to a penalty similar to the penalty provided under that law. Section 46(2)(a) the manner in which the use of a computer system enhanced the impact of the offence; Section 46(2)(b) whether the offence resulted in a commercial advantage or financial gain; Section 46(2)(c) the value involved, whether of the consequential loss or damage caused, or the profit gained from commission of the offence through the use of a computer system; Section 46(2)(d) whether there was a breach of trust or responsibility; Section 46(2)(e) the number of victims or persons affected by the offence; Section 46(2)(f) the conduct of the accused; and Section 46(2)(g) any other matter that the court deems fit to consider.
Part IV
INVESTIGATION PROCEDURES
- 47 Verify source ↗
INVESTIGATION PROCEDURES - 47. Scope of procedural provisions
Evidence that was generated, transmitted, seized from, or identified in a search of a computer system may be presented, relied upon or admitted in proceedings; such fact alone does not by itself prevent admission.
Section 47. Scope of procedural provisions Section 47(1)(a) criminal offences provided under this Act; Section 47(1)(b) other criminal offences committed by means of a computer system established under any other law; and Section 47(1)(c) the collection of evidence in electronic form of a criminal offence under this Act or any other law. Section 47(2) In any proceedings related to any offence, under any law of Kenya, the fact that evidence has been generated, transmitted or seized from, or identified in a search of a computer system, shall not of itself prevent that evidence from being presented, relied upon or admitted. Section 47(3)(a) the National Intelligence Service Act (Cap. 206); Section 47(3)(b) the National Police Service Act (Cap. 84); Section 47(3)(c) the Kenya Defence Forces Act (Cap. 199); and Section 47(3)(d) any other relevant law. - 48 Verify source ↗
INVESTIGATION PROCEDURES - 48. Search and seizure of stored computer data
Police officers or authorised persons may apply for a warrant to access, search and seize stored computer data for criminal investigations; they must present a copy of the warrant to the person against whom it is issued.
Section 48. Search and seizure of stored computer data Section 48(1)(a) is reasonably required for the purpose of a criminal investigation or criminal proceedings which may be material as evidence; or Section 48(1)(b) has been acquired by a person as a result of the commission of an offence, the police officer or the authorised person may apply to the court for issue of a warrant to enter any premises to access, search and similarly seize such data. Section 48(2)(a) identify the police officer or authorised person; Section 48(2)(b) direct the police officer or authorised person under paragraph (a) to seize the data in question; or Section 48(2)(c) search any person identified in the warrant; Section 48(2)(c)(i) search any person identified in the warrant; Section 48(2)(c)(ii) enter and search any premises identified in the warrant; or Section 48(2)(c)(iii) search any person found on or at such premises. Section 48(3) A search warrant may be issued on any day and shall be of force until it is executed or is cancelled by the issuing court. Section 48(4) A police officer or an authorised person shall present a copy of the warrant to a person against whom it is issued. Section 48(5)(a) obstructs the lawful exercise of the powers under this section; Section 48(5)(b) compromises the integrity or confidentiality of a computer system, data, or information accessed or retained under this section; or Section 48(5)(c) misuses the powers granted under this section, - 49 Verify source ↗
INVESTIGATION PROCEDURES - 49. Record of and access to seized data
Requires making a list of seized or rendered inaccessible items with the date and time of seizure, providing a copy of that list to the occupier or person in control of the computer system, and addresses custody, rights to seized data, acting on another's behalf, offences, and who may access or obtain copies of computer data.
Section 49. Record of and access to seized data Section 49(1)(a) make a list of what has been seized or rendered inaccessible, and shall specify the date and time of seizure; and Section 49(1)(b) provide a copy of the list to the occupier of the premises or the person in control of the computer system referred to under paragraph (a). Section 49(2)(a) had the custody or control of the computer system; Section 49(2)(b) has a right to any data or information seized or secured; or Section 49(2)(c) has been acting on behalf of a person under subsection (1)(a) or (b), Section 49(3)(a) constitute a criminal offence; or Section 49(3)(b) the investigation in connection with the search that was carried out; Section 49(3)(b)(i) the investigation in connection with the search that was carried out; Section 49(3)(b)(ii) an ongoing investigation; or Section 49(3)(b)(iii) any criminal proceeding that is pending or that may be brought in relation to any of those investigations. Section 49(4)(a) access and copy computer data on the system; or Section 49(4)(b) obtain a copy of the computer data. - 50 Verify source ↗
INVESTIGATION PROCEDURES - 50. Production order
A police officer or an authorised person may apply to a court for a production order where specified data or subscriber information in their possession or control is necessary or desirable for an investigation.
Section 50. Production order Section 50(1)(a) specified data stored in a computer system or a computer data storage medium is in the possession or control of a person in its territory; and Section 50(1)(b) specified subscriber information relating to services offered by a service provider in Kenya are in that service provider's possession or control and is necessary or desirable for the purposes of the investigation, the police officer or the authorised person may apply to court for an order. Section 50(2)(a) a specified person to submit specified computer data that is in that person's possession or control, and is stored in a computer system or a computer data storage medium; or Section 50(2)(b) a specified service provider offering its services in Kenya to submit subscriber information relating to such services in that service provider's possession or control. - 51 Verify source ↗
INVESTIGATION PROCEDURES - 51. Expedited preservation and partial disclosure of traffic data
Allows police officers or authorised persons to apply the powers in subsection (1) regardless of how many service providers were involved in transmitting the communication, and requires preservation and limited disclosure of traffic data for investigations with time and confidentiality limits.
Section 51. Expedited preservation and partial disclosure of traffic data Section 51(1)(a) any specified traffic data stored in any computer system or computer data storage medium or by means of a computer system is reasonably required for the purposes of a criminal investigation; and Section 51(1)(b) undertake expeditious preservation of such available traffic data regardless of whether one or more service providers were involved in the transmission of that communication; or Section 51(1)(b)(i) undertake expeditious preservation of such available traffic data regardless of whether one or more service providers were involved in the transmission of that communication; or Section 51(1)(b)(ii) disclose sufficient traffic data concerning any communication in order to identify the service providers and the path through which communication was transmitted. Section 51(2) The data specified in the notice shall be preserved and its integrity shall be maintained for a period not exceeding thirty days. Section 51(3)(a) an extension of preservation is reasonably required for the purposes of an investigation or prosecution; Section 51(3)(b) there is a risk or vulnerability that the traffic data may be modified, lost, destroyed or rendered inaccessible; and Section 51(3)(c) the cost of the preservation is not overly burdensome on the person in control of the computer system. Section 51(4)(a) for the period of notice for preservation and maintenance of integrity or for any extension thereof permitted by the court; and Section 51(4)(b) for the period of the preservation to keep confidential any preservation ordered under this section. Section 51(5)(a) respond expeditiously to a request for assistance, whether to facilitate requests for police assistance, or mutual assistance requests; and Section 51(5)(b) disclose as soon as practicable, a sufficient amount of the non-content data to enable a police officer or an authorised person to identify any other telecommunications providers involved in the transmission of the communication. Section 51(6) The powers of the police officer or an authorised person under subsection (1) shall apply whether there is one or more service providers involved in the transmission of communication which is subject to exercise of powers under this section. - 52 Verify source ↗
INVESTIGATION PROCEDURES - 52. Real-time collection of traffic data
Allows police officers or authorised persons to collect or record traffic data in real-time, sets court authorisation and limits, and prescribes confidentiality and penalties for service providers and their officers.
Section 52. Real-time collection of traffic data Section 52(1)(a) permit the police officer or authorised person to collect or record through the application of technical means traffic data, in real-time; Section 52(1)(b) to collect or record through application of technical means traffic data in real time; or Section 52(1)(b)(i) to collect or record through application of technical means traffic data in real time; or Section 52(1)(b)(ii) to cooperate and assist a police officer or an authorised person in the collection or recording of traffic data, in real-time, associated with specified communications in its jurisdiction transmitted by means of a computer system. Section 52(2)(a) state the grounds they believe the traffic data sought is available with the person in control of the computer system; Section 52(2)(b) identify and explain, the type of traffic data suspected to be found on such computer system; Section 52(2)(c) identify and explain the subscribers, users or unique identifier the subject of an investigation or prosecution suspected as may be found on such computer system; Section 52(2)(d) identify and explain the offences identified in respect of which the warrant is sought; and Section 52(2)(e) while maintaining the privacy of other users, customers and third parties; and Section 52(2)(e)(i) while maintaining the privacy of other users, customers and third parties; and Section 52(2)(e)(ii) without the disclosure of data to any party not part of the investigation. Section 52(3) Where the court is satisfied with the explanations provided under subsection (2), the court shall issue the order provided for under subsection (1). Section 52(4) For purposes of subsection (1), real-time collection or recording of traffic data shall be ordered for a period not exceeding six months. Section 52(5)(a) such extension of real-time collection or recording of traffic data is reasonably required for the purposes of an investigation or prosecution; Section 52(5)(b) the extent of real-time collection or recording of traffic data is commensurate, proportionate and necessary for the purposes of investigation or prosecution; Section 52(5)(c) despite prior authorisation for real-time collection or recording of traffic data, additional real-time collection or recording of traffic data is necessary and needed to achieve the purpose for which the warrant is to be issued; Section 52(5)(d) measures taken to prepare and ensure that the real time collection or recording of traffic data is carried out while maintaining the privacy of other users, customers and third parties and without the disclosure of information and data of any party not part of the investigation; Section 52(5)(e) the investigation may be frustrated or seriously prejudiced unless the real-time collection or recording of traffic data is permitted; and Section 52(5)(f) the cost of such preservation is not overly burdensome upon the person in control of the computer system. Section 52(6) A court may, in addition to the requirement specified under subsection (3) require the service provider to keep confidential the order and execution of any power provided under this section. Section 52(7)(a) where the service provider is a corporation, to a fine not exceeding ten million shillings; or Section 52(7)(b) in case of a principal officer of the service provider, to a fine not exceeding five million shillings or to imprisonment for a term not exceeding three years, or to both. - 53 Verify source ↗
INVESTIGATION PROCEDURES - 53. Interception of content data
Section 53 sets rules for real-time interception of content data: courts may order real-time collection or recording of specified communications by persons in control of computer systems if grounds are shown; courts must issue the order when satisfied with the grounds; orders cannot exceed nine months; courts may require confidentiality; fines and imprisonment may apply to service providers and their officers.
Section 53. Interception of content data Section 53(1)(a) permit the police officer or authorised person to collect or record through the application of technical means; Section 53(1)(b) to collect or record through the application of technical means; or Section 53(1)(b)(i) to collect or record through the application of technical means; or Section 53(1)(b)(ii) to co-operate and assist the competent authorities in the collection or recording of, content data, in real-time, of specified communications within the jurisdiction transmitted by means of a computer system. Section 53(2)(a) state the reasons he believes the content data being sought is in possession of the person in control of the computer system; Section 53(2)(b) identify and state the type of content data suspected to be found on such computer system; Section 53(2)(c) identify and state the offence in respect of which the warrant is sought; Section 53(2)(d) state if they have authority to seek real-time collection or recording on more than one occasion is needed, and shall specify the additional number of disclosures needed to achieve the purpose for which the warrant is to be issued; Section 53(2)(e) while maintaining the privacy of other users, customers and third parties; and Section 53(2)(e)(i) while maintaining the privacy of other users, customers and third parties; and Section 53(2)(e)(ii) without the disclosure of information and data of any party not part of the investigation; Section 53(2)(f) state how the investigation may be frustrated or seriously prejudiced unless the real time collection or recording is permitted; and Section 53(2)(g) state the manner in which they shall achieve the objective of the warrant, real time collection or recording by the person in control of the computer system where necessary. Section 53(3) Where the court is satisfied with the grounds provided under subsection (2), the court shall issue the order applied for under subsection (1). Section 53(4) For purposes of subsection (1), the real-time collection or recording of content data shall not be ordered for a period that exceeds the period that is necessary for the collection thereof and in any event not for more than a period of nine months. Section 53(5)(a) such extension of real-time collection or recording of content data is required for the purposes of an investigation or prosecution; Section 53(5)(b) the extent of real-time collection or recording of content data is proportionate and necessary for the purposes of investigation or prosecution; Section 53(5)(c) despite prior authorisation for real-time collection or recording of content data, further real-time collection or recording of content data is necessary to achieve the purpose for which the warrant is to be issued; Section 53(5)(d) measures shall be taken to prepare and ensure that the real-time collection or recording of content data is carried out while maintaining the privacy of other users, customers and third parties and without the disclosure of information and data of any party not part of the investigation; Section 53(5)(e) the investigation may be frustrated or seriously prejudiced unless the real-time collection or recording of content data is permitted; and Section 53(5)(f) the cost of such real-time recording and collection is not overly burdensome upon the person in control of the computer system. Section 53(6) The court may also require the service provider to keep confidential the order and execution of any power provided for under this section. Section 53(7)(a) where the service provider is a corporation, to a fine not exceeding ten million shillings; Section 53(7)(b) in case of an officer of the service provider, to a fine not exceeding five million shillings or to imprisonment for a term not exceeding three years, or to both. - 54 Verify source ↗
INVESTIGATION PROCEDURES - 54. Obstruction and misuse of power
Obstructing or misusing powers under this Part is prohibited and attracts a fine up to five million shillings or imprisonment up to three years, or both.
Section 54. Obstruction and misuse of power Section 54(1) A person who obstructs the lawful exercise of the powers under this Part, including destruction of data, or fails to comply with the requirements of this Part is liable, on conviction, to a fine not exceeding five million shillings or to imprisonment for a term not exceeding three years, or to both. Section 54(2) A police officer or an authorised person who misuses the exercise of powers under this Part commits an offence and is liable, on conviction, to a fine not exceeding five million shillings or to imprisonment for a term not exceeding three years, or to both. - 55 Verify source ↗
INVESTIGATION PROCEDURES - 55. Appeal
Any person aggrieved by a decision or order of the Court under this Part may appeal to the High Court or Court of Appeal within thirty days from the date of the decision or order.
Section 55. Appeal Section Any person aggrieved by any decision or order of the Court made under this Part, may appeal to the High Court or Court of Appeal as the case may be within thirty days from the date of the decision or order. - 56 Verify source ↗
INVESTIGATION PROCEDURES - 56. Confidentiality and limitation of liability
Service providers are not liable civilly or criminally unless they had actual notice/knowledge or willful malicious intent facilitating misuse; they are not liable for providing services or for disclosures required by law or powers under this Part.
Section 56. Confidentiality and limitation of liability Section 56(1) A service provider shall not be subject to any civil or criminal liability, unless it is established that the service provider had actual notice, actual knowledge, or willful and malicious intent, and not merely through omission or failure to act, had thereby facilitated, aided or abetted the use by any person of any computer system controlled or managed by a service provider in connection with a contravention of this Act or any other written law. Section 56(2) A service provider shall not be liable under this Act or any other law for maintaining and making available the provision of their service. Section 56(3) A service provider shall not be liable under this Act or any other law for the disclosure of any data or other information that the service provider discloses only to the extent required under this Act or in compliance with the exercise of powers under this Part.
Part V
INTERNATIONAL CO-OPERATION
- 57 Verify source ↗
INTERNATIONAL CO-OPERATION - 57. General principles relating to international cooperation
A requesting State may request mutual legal assistance from the Central Authority in any criminal matter for the purposes listed in subsection (2).
Section 57. General principles relating to international cooperation Section 57(1) This Part shall apply in addition to the Mutual Legal Assistance Act (Cap. 75A) and the Extradition (Contiguous and Foreign Countries) Act (Cap 76). Section 57(2)(a) undertaking investigations or proceedings concerning offences related to computer systems, electronic communications or data; Section 57(2)(b) collecting evidence of an offence in electronic form; or Section 57(2)(c) obtaining expeditious preservation and disclosure of traffic data, Section 57(3) A requesting State may make a request for mutual legal assistance to the Central Authority in any criminal matter, for the purposes provided in subsection (2). Section 57(4)(a) grant the legal assistance requested; or Section 57(4)(b) refuse to grant the legal assistance requested. Section 57(5)(a) keep the contents, any information and material provided in a confidential manner; Section 57(5)(b) only use the contents, information and material provided for the purpose of the criminal matter specified in the request; and Section 57(5)(c) use it subject to other specified conditions. - 58 Verify source ↗
INTERNATIONAL CO-OPERATION - 58. Spontaneous information
The Central Authority may, without prior request and subject to law, forward information from its investigations to a foreign State if it considers the information may assist that State; the Central Authority may request confidentiality before providing information; a foreign State that cannot meet conditions must notify the Central Authority, which may then decide whether to provide the information; if the foreign State accepts the conditions it is bound by them.
Section 58. Spontaneous information Section 58(1) The Central Authority may, subject to this Act and other relevant law, without prior request, forward to a foreign State information obtained within the framework of its own investigations when it considers that the disclosure of such information might assist the foreign State in initiating or carrying out investigations or proceedings concerning criminal offences or might lead to a request for co-operation by the foreign State under this Act. Section 58(2) Prior to providing the information under subsection (1), the Central Authority may request that such information be kept confidential or only subject to other specified conditions. Section 58(3) Where a foreign State cannot comply with the specified conditions specified under subsection (2), the State shall notify the Central Authority as soon as practicable. Section 58(4) Upon receipt of a notice under subsection (3), the Central Authority may determine whether to provide such information or not. Section 58(5) Where the foreign State accepts the information subject to the conditions specified by the Central Authority, that State shall be bound by them. - 59 Verify source ↗
INTERNATIONAL CO-OPERATION - 59. Expedited preservation of stored computer data
A requesting State may ask the Central Authority to obtain expedited preservation of computer-stored data located in Kenya; upon receiving such a request the Central Authority must take appropriate measures to preserve the specified data.
Section 59. Expedited preservation of stored computer data Section 59(1) Subject to section 57 , a requesting State which has the intention to make a request for mutual legal assistance for the search or similar access, seizure or similar securing or the disclosure of data, may request the Central Authority to obtain the expeditious preservation of data stored by means of a computer system, located within the territory of Kenya. Section 59(2)(a) the authority seeking the preservation; Section 59(2)(b) the offence that is the subject of a criminal investigation or proceedings and a brief summary of the related facts; Section 59(2)(c) the stored computer data to be preserved and its connection to the offence; Section 59(2)(d) any available information identifying the custodian of the stored computer data or the location of the computer system; Section 59(2)(e) the necessity of the preservation; and Section 59(2)(f) the intention to submit a request for mutual assistance for the search or similar access, seizure or similar securing or the disclosure of the stored computer data. Section 59(3) Upon receiving the request under this section, the Central Authority shall take the appropriate measures to preserve the specified data in accordance with the procedures and powers provided under this Act and any other relevant law. Section 59(4) A preservation of stored computer data effected under this section, shall be for a period of not less one hundred and twenty days, in order to enable the requesting State to submit a request for the search or access, seizure or securing, or the disclosure of the data. Section 59(5) Upon receipt for a request under this section, the data shall continue to be preserved pending the final decision being made with regard to that request. - 60 Verify source ↗
INTERNATIONAL CO-OPERATION - 60. Expedited disclosure of preserved traffic data
If an investigating agency, while executing a request under section 57 about a specified communication, finds that a service provider in another State was involved in transmission, the Central Authority must promptly disclose enough traffic data to identify that provider and the transmission path to the requesting State.
Section 60. Expedited disclosure of preserved traffic data Section Where during the course of executing a request under section 57 with respect to a specified communication, the investigating agency discovers that a service provider in another State was involved in the transmission of the communication, the Central Authority shall expeditiously disclose to the requesting State a sufficient amount of traffic data to identify that service provider and the path through which the communication was transmitted. - 61 Verify source ↗
INTERNATIONAL CO-OPERATION - 61. Mutual assistance regarding accessing of stored computer data
A requesting State may ask Kenya's Central Authority to search, seize or disclose computer-stored data within Kenya; the request must contain specified information; the Central Authority must obtain authorisation and provide results and seized evidence to the requesting State.
Section 61. Mutual assistance regarding accessing of stored computer data Section 61(1) Subject to section 57 , a requesting State may request the Central Authority to search or similarly access, seize or similarly secure, and disclose data stored by means of a computer system located within the territory of Kenya, including data that has been preserved in accordance with section 60 . Section 61(2)(a) give the name of the authority conducting the investigation or proceedings to which the request relates; Section 61(2)(b) give a description of the nature of the criminal matter and a statement setting-out a summary of the relevant facts and laws; Section 61(2)(c) give a description of the purpose of the request and of the nature of the assistance being sought; Section 61(2)(d) in the case of a request to restrain or confiscate assets believed on reasonable grounds to be located in the requested State, give details of the offence in question, particulars of the investigation or proceeding commenced in respect of the offence, and be accompanied by a copy of any relevant restraining or confiscation order; Section 61(2)(e) give details of any procedure that the requesting State wishes to be followed by the requested State in giving effect to the request, particularly in the case of a request to take evidence; Section 61(2)(f) include a statement setting out any wishes of the requesting State concerning any confidentiality relating to the request and the reasons for those wishes; Section 61(2)(g) give details of the period within which the requesting State wishes the request to be complied with; Section 61(2)(h) where applicable, give details of the property, computer, computer system or electronic device to be traced, restrained, seized or confiscated, and of the grounds for believing that the property is believed to be in the requested State; Section 61(2)(i) give details of the stored computer data, data or program to be seized and its relationship to the offence; Section 61(2)(j) give any available information identifying the custodian of the stored computer data or the location of the computer, computer system or electronic device; Section 61(2)(k) include an agreement on the question of the payment of the damages or costs of fulfilling the request; and Section 61(2)(l) give any other information that may assist in giving effect to the request. Section 61(3) Upon receiving the request under this section, the Central Authority shall take all appropriate measures to obtain necessary authorisation including any warrants to execute upon the request in accordance with the procedures and powers provided under this Act and any other relevant law. Section 61(4) Where the Central Authority obtains the necessary authorisation in accordance with subsection (3), including any warrants to execute the request, the Central Authority may seek the support and cooperation of the requesting State during such search and seizure. Section 61(5) Upon conducting the search and seizure request, the Central Authority shall, subject to section 59 , provide the results of the search and seizure as well as electronic or physical evidence seized to the requesting State. - 62 Verify source ↗
INTERNATIONAL CO-OPERATION - 62. Trans-border access to stored computer data with consent or where publicly available
Allows trans-border access to stored computer data with consent or where the data is publicly available.
Section 62. Trans-border access to stored computer data with consent or where publicly available Section access publicly available stored computer data, regardless of where the data is located geographically; or - 63 Verify source ↗
INTERNATIONAL CO-OPERATION - 63. Mutual assistance in the real-time collection of traffic data
A requesting State may ask the Central Authority to assist with real-time collection of traffic data for specified communications in Kenya.
Section 63. Mutual assistance in the real-time collection of traffic data Section 63(1) Subject to section 57 , a requesting State may request the Central Authority to provide assistance in real-time collection of traffic data associated with specified communications in Kenya transmitted by means of a computer system. Section 63(2)(a) the authority seeking the use of powers under this section; Section 63(2)(b) the offence that is the subject of a criminal investigation or proceedings and a brief summary of the related facts; Section 63(2)(c) the name of the authority with access to the relevant traffic data; Section 63(2)(d) the location at which the traffic data may be held; Section 63(2)(e) the intended purpose for the required traffic data; Section 63(2)(f) sufficient information to identify the traffic data; Section 63(2)(g) any further details relevant to the traffic data; Section 63(2)(h) the necessity for use of powers under this section; and Section 63(2)(i) the terms for the use and disclosure of the traffic data to third parties. Section 63(3) Upon receiving the request under this section, the Central Authority shall take all appropriate measures to obtain necessary authorisation including any warrants to execute upon the request in accordance with the procedures and powers provided under this Act and any other relevant law. Section 63(4) Where the Central Authority obtains the necessary authorisation including any warrants to execute upon the request, the Central Authority may seek the support and cooperation of the requesting State during the search and seizure. Section 63(5) Upon conducting the measures under this section the Central Authority shall, subject to section 57 , provide the results of such measures as well as real-time collection of traffic data associated with specified communications to the requesting State. - 64 Verify source ↗
INTERNATIONAL CO-OPERATION - 64. Mutual assistance regarding the interception of content data
A requesting State may ask the Central Authority to assist with real-time collection or recording of specified communications' content data in Kenya; the Central Authority must obtain required authorisation and, once authorised, may seek the requesting State's support and must provide the results and collected data to the requesting State, subject to section 57.
Section 64. Mutual assistance regarding the interception of content data Section 64(1) Subject to section 57 , a requesting State may request the Central Authority to provide assistance in the real-time collection or recording of content data of specified communications in the territory of Kenya transmitted by means of a computer system. Section 64(2)(a) the authority seeking the use of powers under this section; Section 64(2)(b) the offence that is the subject of a criminal investigation or proceedings and a brief summary of the related facts; Section 64(2)(c) the name of the authority with access to the relevant communication; Section 64(2)(d) the location at which or nature of the communication; Section 64(2)(e) the intended purpose for the required communication; Section 64(2)(f) sufficient information to identify the communications; Section 64(2)(g) details of the data of the relevant interception; Section 64(2)(h) the recipient of the communication; Section 64(2)(i) the intended duration for the use of the communication; Section 64(2)(j) the necessity for use of powers under this section; and Section 64(2)(k) the terms for the use and disclosure of the communication to third parties. Section 64(3) Upon receiving the request under this section, the Central Authority shall, take all appropriate measures to obtain necessary authorisation including any warrants to execute upon the request in accordance with the procedures and powers provided under this Act and any other relevant law. Section 64(4) Where the Central Authority obtains the necessary authorisation, including any warrants to execute upon the request, the Central Authority may seek the support and cooperation of the requesting State during the search and seizure. Section 64(5) Upon conducting the measures under this section the Central Authority shall subject to section 57 , provide the results of such measures as well as real-time collection or recording of content data of specified communications to the requesting State. - 65 Verify source ↗
INTERNATIONAL CO-OPERATION - 65. Point of contact
Establishes a designated point of contact that must provide technical advice, preserve data, collect evidence and perform related tasks within expeditious timelines; it must be resourced and have capacity to communicate securely and efficiently with counterparts and is empowered to coordinate international mutual assistance.
Section 65. Point of contact Section 65(1)(a) the provision of technical advice; Section 65(1)(b) the preservation of data pursuant to sections 59 and 60 ; Section 65(1)(c) the collection of evidence, the provision of legal information, and locating of suspects, within expeditious timelines to be defined by regulations under this Act. Section 65(2) The point of contact shall be resourced with and possess the requisite capacity to securely and efficiently carry out communications with other points of contact in other territories, on an expedited basis. Section 65(3) The point of contact shall have the authority and be empowered to coordinate and enable access to international mutual assistance under this Act.
Part VI
GENERAL PROVISIONS
- 66 Verify source ↗
GENERAL PROVISIONS - 66. Territorial jurisdiction
Courts of competent jurisdiction must try offences under this Act when the act or omission constituting the offence is committed in Kenya.
Section 66. Territorial jurisdiction Section 66(1) Any court of competent jurisdiction shall try any offence under this Act where the act or omission constituting the offence is committed in Kenya. Section 66(2)(a) a citizen of Kenya; or Section 66(2)(a)(i) a citizen of Kenya; or Section 66(2)(a)(ii) ordinarily resident in Kenya; and Section 66(2)(b) against a citizen of Kenya; Section 66(2)(b)(i) against a citizen of Kenya; Section 66(2)(b)(ii) against property belonging to the Government of Kenya outside Kenya; or Section 66(2)(iii) to compel the Government of Kenya to do or refrain from doing any act; or Section 66(2)(c) the person who commits the act or omission is, after its commission or omission, present in Kenya. - 67 Verify source ↗
GENERAL PROVISIONS - 67. Forfeiture
A court that convicts a person may order forfeiture of any apparatus, device or thing used in or constituting the subject matter of the offence, to the Authority.
Section 67. Forfeiture Section The court before which a person is convicted of any offence may, in addition to any other penalty imposed, order the forfeiture of any apparatus, device or thing to the Authority which is the subject matter of the offence or is used in connection with the commission of the offence. - 68 Verify source ↗
GENERAL PROVISIONS - 68. Prevailing Clause
If there is a conflict between this Act and any other law about cybercrimes, the provisions of this Act supersede the other law.
Section 68. Prevailing Clause Section Whenever there is a conflict between this Act and any other law regarding cybercrimes, the provisions of this Act shall supersede any such other law. - 69 Verify source ↗
GENERAL PROVISIONS - 69.Spent
The provision text is exactly the word "Spent" following the section heading.
Section 69.Spent
Part VII
PROVISIONS ON DELEGATED POWERS
- 70 Verify source ↗
PROVISIONS ON DELEGATED POWERS - 70. Regulations
The Cabinet Secretary may make regulations to give effect to the Act, including on specified areas of critical information infrastructure and subject to stated purposes, limits and principles.
Section 70. Regulations Section 70(1) The Cabinet Secretary may make regulations generally for the better carrying into effect of any provisions under this Act. Section 70(2)(a) designation of computer systems, networks, programs, data as national critical information infrastructure; Section 70(2)(b) protection, preservation and management of critical information infrastructure; Section 70(2)(c) access to, transfer and control of data in any critical information infrastructure; Section 70(2)(d) storage and archiving of critical data or information; Section 70(2)(e) audit and inspection of national critical information infrastructure; Section 70(2)(f) recovery plans in the event of disaster, breach or loss of national critical information infrastructure or any part of it; Section 70(2)(g) standard operating procedures for the conduct, search, seizure and collection of electronic evidence; and Section 70(2)(h) mutual legal assistance. Section 70(3)(a) the purpose and objective of delegation under this section is to enable the Cabinet Secretary to make regulations to provide for the better carrying into effect of the provisions of this Act and to enable the Authority to discharge its functions more effectively; Section 70(3)(b) the authority of the Cabinet Secretary to make regulations under this Act will be limited to bringing into effect the provisions of this Act and to fulfil the objectives specified under this section; Section 70(3)(c) the principles and standards applicable to the regulations made under this section are those set out in the Interpretation and General Provisions Act (Cap. 2) and the Statutory Instruments Act (Cap. 2A).
Provision text is displayed from LexChat’s stored statute record. Use the official source links to verify amendments, commencement, and current legal force.
Ask AI about this statute
Computer Misuse and Cybercrimes
Sign in to ask AI about this statute
Sign in to start authenticated, citation-grounded statute research.
Sign inLexChat organizes source-backed legal information for research. Verify amendments, commencement, and current legal force with the official publisher before relying on it.