Insights / Corporate & Commercial

If We Get Hacked, Is the Board Personally Liable?

By Clay & Associates Advocates · 2 min read ·

A padlock resting on a laptop keyboard

The honest answer is: usually not directly, but the exceptions are exactly the situations most boards are not prepared for. Kenya’s Data Protection Act, 2019 is written primarily to hold the company, the data controller, accountable, not to automatically place personal liability on individual directors the moment a breach happens. That does not mean the board is insulated. It means the real exposure runs through a different, and in some ways broader, legal route.

What the Data Protection Act actually targets

The Office of the Data Protection Commissioner can impose administrative fines of up to KES 5,000,000 or one percent of the company’s annual turnover, whichever is lower, and this is levied against the data controller, meaning the company, not against directors personally. Separately, section 73 of the Act sets a general criminal penalty, a fine of up to KES 3,000,000 or imprisonment of up to ten years, for a person who commits an offence under the Act. That provision can, in principle, reach an individual, but it requires that individual to have actually committed the offence, knowingly or recklessly processed data unlawfully, or obstructed the Commissioner, not merely to have been a director of a company that suffered a breach caused by a third party attacker.

Where personal exposure actually comes from

The more realistic route to personal liability runs through the Companies Act, not the Data Protection Act. Every director owes a duty under section 145 of the Companies Act to exercise reasonable care, skill and diligence, and a duty under section 143 to act in good faith to promote the company’s success. A board that was warned about inadequate security, ignored a known vulnerability, or never asked basic questions about cyber risk before a breach happened has a real exposure under these general duties, quite separate from anything the Data Protection Act itself imposes. This is a negligence-style claim the company or its shareholders could bring, not a data protection prosecution.

What actually protects a board

Being able to show that cyber risk was genuinely considered, not just delegated silently to an IT team with no board visibility, is what separates a defensible board from an exposed one. That means the board should be able to point to a record of having discussed the company’s cyber risk at a reasonable interval, having ensured a breach response plan exists that can meet the 72-hour notification deadline to the ODPC, and having asked, and gotten answers to, basic questions about what safeguards were actually in place before the incident, not only after it.

The practical takeaway

A breach itself is rarely what creates personal director liability. A board that never turned its mind to the risk beforehand, and cannot show it did, is in a materially worse position than one that considered the risk, made reasonable decisions, and happened to be breached anyway despite that. The distinction is entirely about what happened before the incident, not after.

Sources

&

Clay & Associates Advocates
This article is general information, not legal advice. For advice on your matter, speak to counsel.

Related Insights

Discover more