Insights / Corporate & Commercial

Cybersecurity Due Diligence in Kenyan M&A Transactions

By Clay & Associates Advocates · 7 min read ·

Legal and corporate team conducting cybersecurity due diligence review ahead of an M&A transaction in Kenya

Buyers routinely diligence a target’s financial statements, tax position and material contracts down to the last clause, then treat cybersecurity as a single question on a questionnaire: has the company ever had a data breach. That question is too narrow to catch what actually creates exposure. Kenya now has a real statutory framework attaching specific financial and criminal consequences to how a company has handled personal data and system security, and a buyer who does not diligence it properly can inherit liabilities that were never priced into the deal.

Two separate Kenyan statutes create the exposure a buyer needs to check. The Data Protection Act, 2019 governs how the target has handled personal data, with administrative fines the Data Commissioner can impose directly on the company. The Computer Misuse and Cybercrimes Act, 2018 creates criminal offences around unauthorised access to and interference with computer systems, with penalties that attach to the company itself as well as to individuals. A target can be exposed under either statute independently of the other, and a due diligence exercise that only asks about “data breaches” in the colloquial sense will miss the second entirely.

Data Protection Act Exposure: Security, Breach Notification and Registration

Section 41 of the Data Protection Act requires a controller or processor to build technical and organisational safeguards into its processing from the outset, calibrated to the volume and nature of the data involved, including the capacity to restore access after an incident and to test those safeguards regularly. Where a breach occurs, section 43 sets a strict timeline: a processor must notify the controller within forty eight hours of becoming aware of it, the controller must notify the Data Commissioner within seventy two hours and state its reasons if it misses that window, and affected data subjects must be told in writing within a reasonably practicable period. Section 63 lets the Data Commissioner impose an administrative fine of up to five million shillings, or up to one percent of annual turnover, whichever is lower. Separately, sections 18 to 22 require most controllers and processors to register, subject to a narrow exemption for entities with turnover under five million shillings and fewer than ten employees, one that never applies to telecommunications, financial services, health data or education sector entities regardless of size.

Computer Misuse and Cybercrimes Act Exposure: Criminal Liability That Follows the Company

The Computer Misuse and Cybercrimes Act creates a tiered set of offences for unauthorised access and interference with computer systems, with penalties that scale sharply where the target’s own systems are implicated. Unauthorised access under section 14 carries a fine of up to five million shillings, rising to ten million under section 15 where the access was made with intent to commit a further offence. Unauthorised interference with a system’s integrity, availability or confidentiality under section 16 carries a base fine of up to ten million shillings, rising to twenty million where the interference causes financial loss, threatens national security, or endangers health or life. Section 20 layers an enhanced penalty of up to twenty five million shillings onto any of these offences where they target a “protected computer system,” a category that includes banking, financial and communications infrastructure. Critically for a buyer, section 43 makes the body corporate itself liable to a fine of up to fifty million shillings, with its officers separately exposed to a fine of up to five million shillings or imprisonment of up to three years. A target that has suffered an intrusion, or whose own systems facilitated one, carries this exposure independently of anything the Data Protection Act reaches.

Building the Diligence Checklist

A buyer’s cybersecurity diligence should go beyond a breach history question and pull documentary evidence on each of the following. First, confirm the target’s registration status and request the current certificate, checking it is not wrongly relying on the small entity exemption in a sector where that exemption never applies. Second, request a breach disclosure schedule covering a three year lookback, with evidence that any breach was notified within the statutory timelines and copies of the resulting correspondence with the Data Commissioner; a late or unreported breach signals both live fine exposure and weak internal escalation. Third, request evidence of data protection impact assessments for any high risk processing, since Kenyan courts have already shown a willingness to enforce this requirement directly. Fourth, review whether the target has experienced any unauthorised access or system interference incident and whether its infrastructure would be classed as a protected computer system, which materially changes the penalty exposure under section 20. Finally, where the target sits in a sector likely to be treated as critical information infrastructure, check its relationship with Kenya’s newly established National Cybersecurity Agency, a second regulatory relationship worth understanding before signing.

Structuring the SPA Around What You Find

The findings from this diligence should shape specific, not generic, protection in the sale and purchase agreement. Standard representations should cover current registration, no unremedied or unreported breach, no pending Data Commissioner investigation, adequate technical and organisational safeguards, and no unauthorised access or interference incident under the Cybercrimes Act. Given the scale of potential exposure, a buyer should also negotiate a specific indemnity for pre closing incidents that sits outside the general warranty cap, rather than relying on the general basket to absorb what could be a fifty million shilling corporate fine under section 43 alone. Kenyan statute does not currently impose an explicit change of control notification duty to the Data Commissioner or affected data subjects, so this should not be assumed or represented as automatic, but the disclosure schedule itself, covering the registration certificate, DPO contact details, breach log, impact assessment reports and incident response policy, gives the buyer the paper trail needed to manage the risk going forward.

How We Can Help

Clay & Associates Advocates advises buyers and sellers on data protection and cybersecurity risk in Kenyan corporate transactions, from structuring the diligence request list through to negotiating the resulting warranties and indemnities. Our guide to Kenya’s new National Cybersecurity Agency covers the regulator a critical infrastructure target may now answer to, and our analysis of data protection compliance under the DPA addresses the underlying framework a target’s data practices are measured against. Contact our Corporate & Commercial practice to build cybersecurity risk properly into your next transaction.

Sources: The Data Protection Act, 2019, sections 18 to 22, 41, 43 and 63; The Computer Misuse and Cybercrimes Act, 2018, sections 14, 15, 16, 20 and 43.

Frequently asked questions

What is the maximum fine a target company faces for a data breach in Kenya?
Under the Data Protection Act, the Data Commissioner can impose an administrative fine of up to five million shillings or up to one percent of the target’s annual turnover, whichever is lower. Separately, if the breach also involved unauthorised access to or interference with a computer system, the Computer Misuse and Cybercrimes Act exposes the company itself to a fine of up to fifty million shillings.

Does a change of ownership trigger a duty to notify the Data Commissioner?
No specific statutory change of control notification duty currently exists under the Data Protection Act. A buyer should not assume closing itself creates a notification obligation, though registration and DPO details should be reviewed and updated post closing.

Is a small target exempt from Data Protection Act registration?
Only if it has annual turnover under five million shillings and fewer than ten employees, and even then the exemption does not apply to telecommunications, financial services, health data or education sector entities regardless of size. A target in one of those sectors must be registered whatever its scale.

What is a “protected computer system” and why does it matter for diligence?
It is a category under the Computer Misuse and Cybercrimes Act covering systems such as banking, financial and communications infrastructure. An offence targeting a protected computer system carries an enhanced fine of up to twenty five million shillings, so confirming whether a target’s systems fall into this category materially changes the buyer’s risk assessment.

&

Clay & Associates Advocates
This article is general information, not legal advice. For advice on your matter, speak to counsel.

Related Insights

Discover more