Insights / Regulatory & Compliance

Data Centre Colocation Contracts in Kenya: What Enterprise Customers Should Negotiate

By Clay & Associates Advocates · 6 min read ·

Enterprise professional reviewing a colocation services agreement on a laptop in a high-rise office, representing data centre contract negotiation in Kenya

An enterprise moving its servers into a Kenyan colocation facility is not just renting rack space, it is handing a third party physical custody of infrastructure that may carry customer data, financial records or systems the business cannot operate without. The colocation agreement is where the real risk allocation happens, and it is negotiated far too often as a standard-form lease rather than as the data protection and operational-continuity contract it actually needs to be.

What a Colocation Agreement Actually Covers

At minimum, a colocation contract should separately address the physical space and power being supplied, the connectivity and network access the customer will use, the security and access control regime governing who can physically reach the equipment, the service levels the operator commits to, and what happens to the customer’s equipment and data on exit. Providers commonly present these as a single bundled service description. An enterprise customer with meaningful data or uptime exposure should push to have each of these addressed as a distinct, separately enforceable commitment rather than folded into general marketing language about facility standards.

Uptime and Service Level Commitments

The headline uptime percentage in a colocation contract matters less than how it is measured and what happens when it is missed. Ask what counts as downtime for measurement purposes, whether planned maintenance windows are excluded from the calculation, and whether the remedy for a breach is a service credit, a right to terminate, or both. A service credit capped at a small percentage of the monthly fee is a weak remedy against the cost of a real outage to the customer’s own business, and should be negotiated up or paired with a termination right for repeated or extended breaches rather than accepted as the sole recourse.

Power and Redundancy Guarantees

Ask specifically what redundancy the facility commits to for power (commonly described using an “N+1” or “2N” configuration) and for cooling, and whether that redundancy is a contractual commitment or simply a description of the facility’s design intent. A facility that is built to a redundant standard but has not contractually committed to maintaining it is not offering the customer the protection the marketing material implies. The customer should also confirm who is responsible for the backup generation and fuel supply chain during an extended grid outage, an increasingly relevant question given how much of Kenya’s data centre capacity still depends on Kenya Power connections supplemented by on-site generation.

Data Protection: Is Your Provider a Processor?

Where the equipment hosted in the facility processes personal data, the colocation provider is very likely a data processor, or a sub-processor if the customer is itself processing data on behalf of its own clients. Section 42(2) of the Data Protection Act requires the data controller and the data processor to enter into a written contract providing that the processor acts only on the controller’s instructions and is bound by the controller’s own data protection obligations. A pure space-and-power lease that says nothing about this is not compliant if personal data is in fact being processed on the leased equipment, and the gap sits with the enterprise customer as controller, not with the facility operator. The contract should also specify who bears the Section 43 obligation to notify the Data Commissioner and affected data subjects within 72 hours of a security breach, since a facility-level physical security incident and a customer-level data breach can be the same event viewed from two different obligations, and both need a named owner in the contract rather than being left to be sorted out after the fact. Separately, confirm whether the facility operator itself needs to be registered as a data controller or processor with the Data Commissioner under Section 18, and ask for evidence of that registration if the thresholds the Commissioner has set would capture it.

Liability Caps, Exclusions and Force Majeure

Colocation providers routinely propose a liability cap set at some multiple of monthly fees paid, which is a fraction of the loss a customer could suffer from extended downtime or data loss. This is a commercial negotiation, not a fixed legal rule, and a customer with genuine exposure should push for a carve-out from the cap for the provider’s own security or data protection breaches, gross negligence, and wilful default, none of which should sit behind the same low cap that applies to ordinary service interruptions. Force majeure clauses deserve equal scrutiny, a definition broad enough to cover routine grid instability or a generic “government action” carve-out can eliminate the practical value of the uptime commitments negotiated elsewhere in the contract.

Exit, Termination and Data Portability

A colocation contract should specify the process and timeline for removing equipment and data on termination, including what happens if fees are disputed at the point of exit, since a provider with physical custody of a customer’s servers has significant practical leverage in that scenario. The contract should also address data destruction obligations once equipment leaves the facility or storage media is decommissioned, consistent with the customer’s own data protection obligations as controller. See our companion piece on structuring colocation, hyperscale and build-to-suit data centre investments in Kenya for the operator-side view of the same relationship.

How We Can Help

Clay & Associates Advocates advises enterprise customers on negotiating colocation and data centre services agreements in Kenya, including the data protection and service level provisions that generic facility contracts often leave incomplete. Contact our Technology & Startups or Regulatory & Compliance practice before signing a colocation or hosting agreement.

Sources: Data Protection Act, No. 24 of 2019, sections 18, 42 and 43; Communications Authority of Kenya, Open Consultations.

Frequently asked questions

Is a colocation provider automatically a data processor under Kenyan law?
Not automatically, but very often in practice. If personal data is processed on the equipment hosted at the facility, the provider is likely a processor or sub-processor, and Section 42(2) of the Data Protection Act requires a written contract reflecting that relationship.

Who has to report a data breach at a colocation facility, the customer or the provider?
The Section 43 notification obligation sits with the data controller, which is usually the enterprise customer rather than the facility operator. The contract should name who is responsible for detecting, escalating and reporting a breach within the 72-hour window regardless of where the underlying incident occurred.

Are service credits an adequate remedy for downtime?
Often not on their own. A service credit capped at a small percentage of monthly fees rarely reflects the real cost of an outage to the customer’s business, and should be paired with a termination right for repeated or extended breaches.

What happens to my equipment if I have a fee dispute with my colocation provider?
This depends entirely on what the contract says. Because the provider has physical custody of the equipment, the exit and dispute provisions should be negotiated before signing, not left to be resolved once a dispute has already arisen.

&

Clay & Associates Advocates
This article is general information, not legal advice. For advice on your matter, speak to counsel.

Related Insights

Discover more