Kenyan law does not prescribe a specific insurance package for a data centre. Only one element is actually mandatory, cover for employee workplace injury, and everything else is a commercial decision shaped by what a single incident could actually cost a facility carrying customers’ infrastructure, not a compliance checklist to work through.
The one cover that is not optional
The Work Injury Benefits Act, 2007 requires every employer to insure against liability for workplace injury to employees, and a data centre’s own physical operations, high-voltage electrical systems, backup generators, fuel storage, cooling plant, carry genuine injury risk for the technical staff maintaining them. This is not a discretionary line item. An employer operating without current WIBA cover is exposed to the full cost of a workplace injury claim directly, with no insurer standing behind it.
Property and equipment cover, sized to what is actually inside the building
Standard commercial property insurance rarely reflects the real replacement cost of a data centre’s contents. Servers, UPS systems, precision cooling plant and switchgear are specialised, often imported equipment with long lead times to replace, and a policy sized against the building’s construction cost rather than the value of what is actually racked inside it will leave a genuine gap exactly when it is tested. Confirm the policy specifically covers electrical and mechanical breakdown, not just fire and physical damage, since a cooling system failure or a switchgear fault is a more statistically likely loss event for this kind of facility than a fire.
Business interruption cover tied to what your contracts actually promise
If your colocation agreements commit to specific uptime service levels, an outage is not just a repair cost, it is a service credit or termination right your customers can actually invoke. Business interruption cover should be sized against this real exposure, lost revenue during the outage plus the service credits your own contracts obligate you to pay, rather than against a generic indemnity period that does not reflect how your specific customer agreements are actually structured.
Cyber insurance covers a different loss than property cover does
A data breach or a ransomware incident affecting customer systems hosted at your facility is not a property loss, and a standard commercial policy typically will not respond to it. A dedicated cyber policy should specifically address incident response costs, the cost of meeting your notification obligations to the Office of the Data Protection Commissioner within the Data Protection Act’s 72-hour window, and third-party liability where a security failure at your facility causes loss to a customer’s own business. Confirm the policy actually covers incidents originating in your physical infrastructure, not only in your own corporate IT systems, since these are treated differently by some insurers.
Liability cover for the people who visit, not just the people you employ
Public liability cover matters more for a facility that regularly hosts customer engineers, auditors and technicians on-site than for an ordinary office, given the genuine physical hazards a data floor presents to visitors unfamiliar with the facility. Where directors or senior managers are exposed to personal liability for governance failures, cyber incidents, or regulatory breaches, directors’ and officers’ cover is worth pricing separately rather than assumed to be folded into a general commercial package.
Building the programme around your actual contracts
The right insurance programme for a data centre is not a standard template, it is derived from what your specific colocation agreements actually promise customers, what your specific equipment would actually cost to replace, and what a specific security incident would actually cost to respond to and notify. Reviewing the insurance programme alongside the colocation agreements, rather than as two separate exercises handled by different advisers, is usually where the real gaps between what you have promised customers and what you are actually covered for get caught before an incident, rather than after one.



