A data centre concentrates exactly the conditions fire safety law is built around: continuous high electrical loads, dense cabling, backup fuel storage, and a building most people are told never to evacuate through the server hall. Kenyan workplace safety law does not treat this as a specialised regime separate from an ordinary office. It applies the same Occupational Safety and Health Act framework, with consequences that scale with how seriously the specific risks of the building are actually taken.
Registering the workplace is the first, easily missed step
The Occupational Safety and Health Act, 2007 requires every occupier to register their workplace with the Directorate of Occupational Safety and Health Services unless specifically excepted, and to carry out and submit risk assessments covering the safety and health of everyone working there. A data centre that has been operating for years without ever having formally registered as a workplace is not unusual, and it is a foundational gap that undermines everything built on top of it, since DOSHS inspection and enforcement activity assumes a registered workplace as the starting point.
The Fire Risk Reduction Rules set the actual operational requirements
The Factories and Other Places of Work (Fire Risk Reduction) Rules, 2007 are where the detailed, practical obligations actually sit: maintaining clear and properly identified assembly points, keeping fire extinguisher points and escape routes free of obstruction, conducting fire drills at least once every twelve months with a record kept of each one, and carrying out a periodic fire safety audit of the premises. For a data centre specifically, the highly flammable substance labelling requirements and ventilation provisions in the Rules apply directly to backup fuel storage and battery rooms, areas that are easy to treat as purely an engineering concern rather than a fire safety compliance point in their own right.
Fire suppression design is not just an engineering choice
A server hall’s fire suppression system, typically a gas-based clean-agent system rather than water sprinklers, given the obvious risk water poses to live equipment, needs to be designed and installed with the same regulatory sign-off as any other fire protection system in a commercial building. The National Building Code, 2024 governs the approval process for installing major fire-protection systems, and this approval sits alongside, not instead of, the ongoing DOSH obligations once the building is operating. Treating suppression system design purely as a vendor and engineering decision, without building code sign-off, is a gap that tends to surface at the worst possible moment, during an actual incident or an insurance claim following one.
Evacuation planning that accounts for how a server hall actually works
The Act’s general evacuation procedure requirements need to be adapted to the reality of a facility where staff are often working alone in a server hall on a rotating shift pattern, and where a gas-based suppression discharge is itself a hazard requiring evacuation before it activates, not just a response to a fire already burning. A generic evacuation plan copied from an office template will not address this, and DOSH inspectors reviewing a facility of this kind will expect to see a plan that actually reflects how people work inside it.
What good compliance actually looks like
A defensible position covers four things: a current DOSH workplace registration with an up-to-date risk assessment on file, a documented annual fire safety audit and a record of fire drills actually conducted, not merely scheduled, building code approval for the facility’s fire suppression system, and an evacuation plan written for how the specific building and its shift patterns actually operate. None of this is unusual for a commercial building of this scale, but a data centre’s specific hazards, backup fuel, dense electrical load, gas suppression, mean generic office-standard compliance is not actually enough, even where it looks complete on paper.



