Resources / Legal Guide
Data Centres and Digital Infrastructure Investment in Kenya
A working legal reference for investors and operators building data centre and digital infrastructure capacity in Kenya: how the facility gets licensed, what the Data Protection Act requires of the data itself, and every approval that stands between a site and a live rack.
Kenya’s Data Centre Opportunity
Kenya is not trying to become a regional data centre hub. On the connectivity and policy metrics that matter, it already is one, and the last eighteen months of regulatory activity are the state catching up to what operators have already built.
Mombasa is East Africa’s principal subsea cable gateway. Six international submarine systems land there: SEACOM, TEAMS, EASSy, LION, DARE1 and, most recently, PEACE, which came ashore in March 2022 and carries up to 192 Tbps of capacity on a route running from Pakistan to France with a branch to Singapore. That density of physical connectivity, more landing points than any other East African coastline, is the single biggest reason global colocation and cloud operators site regional capacity in Kenya rather than routing around it.
Capacity is being built to match. Independent market tracking put Kenya’s installed data centre capacity at roughly 20MW as of early 2025, with a further 150MW in the pipeline through 2028, led by Africa Data Centres, iColo (now part of Digital Realty), iXAfrica and the operator-owned facilities run by Safaricom and Telkom Kenya. iColo’s NBO2 facility, launched in September 2026, was designed for 6.5MW; iXAfrica’s NBOX1 opened with 4.5MW of phase-one capacity and an Oracle Cloud Infrastructure hosting arrangement. Government has moved in parallel: the Konza National Data Centre, run by the Konza Technopolis Development Authority against a Treasury allocation of KES 5.2 billion, holds Uptime Institute Tier III certification at both design and constructed-facility stage and was described by officials as East Africa’s largest at 1.6 petabytes of capacity when it came online.
The submarine cable count and PEACE cable specifications are confirmed against the Kenya News Agency and submarinenetworks.com reporting on the March 2022 landing. Capacity figures trace to independent data centre market tracking current to March 2025, and the Konza figures to Treasury allocation reporting and KoTDA’s published Tier III certification history. Treat the 150MW pipeline figure as a market estimate, not a regulatory or government-published number.
Policy has moved to support the build-out rather than gate it. In August 2023 the Cabinet Secretary responsible for ICT withdrew the 30% local shareholding requirement that the 2020 National ICT Policy Guidelines had applied to ICT sector players, by Gazette Notice, with immediate effect. A foreign investor can now hold a Kenyan data centre or network facilities company outright; no local equity partner is required at the ownership level, which is a materially different starting position from the land-holding restrictions that apply to hospitality or agricultural investment. Government has also published a National AI Strategy for 2025 to 2030 and is developing a Kenya Cloud Policy, both cited by officials as reasons compute and storage capacity needs to sit inside the country rather than be imported over a cable.
Licensing the Facility: CAK and the NFP Regime
A data centre in Kenya is a licensed telecommunications facility, not an ordinary commercial building with servers in it, and the licence category an operator falls into has been in active flux through 2026.
The position until mid-2026. Colocation data centres were licensed under the Communications Authority of Kenya’s Unified Licensing Framework as Network Facilities Providers, specifically the Tier 2 (NFP-T2) category, a category built for physical network infrastructure generally, towers and duct networks among them, rather than designed with data centres specifically in mind.
The June 2026 Revised Telecommunications Market Structure. The CA’s revised market structure formalised data centres inside the NFP tiers rather than creating a separate category for them. NFP-T1, the nationwide facilities tier, now carries a licence fee of KES 15 million for a 15-year term or KES 45 million for a 25-year term, plus an annual operating fee of 0.4% of gross turnover. NFP-T2 licensees, the tier under which most colocation data centres actually sit, pay KES 15 million for a 15-year term and the same 0.4% annual turnover fee, subject to a KES 800,000 floor. Both tiers were, as of that revision, explicitly permitted to establish and run commercial data centres without a further licence.
| Licence category | Coverage | Term / fee | Annual fee |
|---|---|---|---|
| NFP-T1 | Nationwide, exclusive national spectrum | 15yr / KES 15M or 25yr / KES 45M | 0.4% turnover |
| NFP-T2 | Countrywide, county-assigned spectrum | 15yr / KES 15M | 0.4% turnover, min. KES 800,000 |
| NFP-T3 | Up to three counties | KES 200,000 | 0.4% turnover |
The proposal now open for comment. On 8 September 2026 the CA opened a thirty-day public consultation on a further change: carving colocation data centres and their attendant support services out of NFP-T2 entirely and creating a dedicated, standalone data centre licence. The stated rationale is visibility over an infrastructure category the regulator now treats as critical, given that a data centre outage can stop government services, banking and retail systems at once, and alignment with how comparable jurisdictions license the sector. The consultation window runs into October 2026.
As at 15 September 2026 the standalone data centre licence is a published proposal out for public comment, not yet in force. Its final fee structure, tier definitions and transition arrangements for existing NFP-T1/T2 data centre operators are not yet settled. Any operator currently licensed, or applying to be licensed, under NFP-T2 should track this consultation and the CA’s eventual determination before fixing a long-term licensing budget, rather than assuming the June 2026 NFP-T1/T2 fee table above is the final word.
Whichever category ultimately applies, the sequencing is the same: incorporate the operating company, register with Business Registration Services, then apply to the CA for the relevant NFP licence before the facility can lawfully offer colocation, hosting or network facilities services to third parties. Development permission from the county (Chapter IV) is a practical precondition, since a licensed facility still needs a lawfully approved building to sit in.
The Data Protection Act: Registration, Localization and Cross-Border Transfer
A data centre operator is almost never itself the data controller for the personal data sitting on its racks, but it is squarely inside the Data Protection Act 2019’s registration net, and its customers’ localization and transfer obligations shape what the facility is asked to guarantee contractually.
ODPC registration. The Office of the Data Protection Commissioner requires registration of data controllers and data processors either above a general size threshold, an annual turnover of KES 5 million or more, or more than 10 employees, or, regardless of size, if the entity operates in one of a fixed list of sectors the ODPC treats as inherently higher-risk. That list names telecommunications explicitly, alongside financial services, health administration, property management and several others. A data centre or network facilities operator falls inside the telecommunications category and must register irrespective of its revenue or headcount. Registration is tiered by size, from KES 4,000 for a micro or small entity to KES 40,000 for a large one (100-plus employees or over KES 50 million turnover), with renewal every two years at a lower fee.
| Entity size | Registration fee | Renewal (2-yearly) |
|---|---|---|
| Micro/small (≤50 staff, ≤KES 5M turnover) | KES 4,000 | KES 2,000 |
| Medium (51–99 staff, KES 5M–50M) | KES 16,000 | KES 9,000 |
| Large (100+ staff, >KES 50M) | KES 40,000 | KES 25,000 |
What must stay in Kenya. The Data Protection (General) Regulations 2021 impose a specific localization rule, not a blanket one. Regulation 26 applies it to personal data processed for a defined set of strategic state interests: civil registration, elections, public finance administration, protected computer systems under the Computer Misuse and Cybercrimes Act, basic education, and primary or secondary healthcare. For data falling in one of those categories, the controller or processor must either process it through a server and data centre located in Kenya, or store at least one serving copy of it in a Kenya-located data centre. Outside that defined list, the Data Protection Act does not impose a general data-residency requirement; ordinary commercial personal data can be processed and transferred abroad, subject to the cross-border transfer conditions below.
What can transfer cross-border, and how. Regulation 40 requires a controller or processor to establish one of three bases before moving personal data out of Kenya: an adequacy finding for the destination, appropriate safeguards such as binding corporate rules or contractual clauses, or that the transfer is necessary for a recognised purpose (performance of a contract, a legal claim, vital interests, and similar grounds). Where none of those is available, Regulation 46 permits transfer on the basis of the data subject’s explicit, informed consent to that specific transfer, as a fallback rather than a default route.
The facility itself is rarely the controller making these calls, its customers are, but a Kenyan data centre selling colocation or cloud services to government, financial services or healthcare clients should expect Regulation 26’s in-country processing and serving-copy requirement to show up as a contractual term, and should be able to demonstrate a Kenya-located, redundant storage tier to win that class of customer. A facility marketed purely on cross-border capacity for ordinary commercial workloads is not affected by Regulation 26 at all.
Site, Physical Planning and NEMA Approval
A data centre is, at the planning and environmental level, a large industrial-scale commercial building with a heavy power and cooling footprint, and it is screened accordingly before a licence or a slab is poured.
County development permission. The Physical and Land Use Planning Act, 2019 requires development permission before any development begins, issued by the county government in whose area the site sits. An application is deemed approved if the county does not respond within 60 days. The Act names certain facility types that require express development permission rather than the standard process, including power generation plants and factories; a data centre’s on-site generation capacity is the feature most likely to bring it into that express-permission category, though this has not been confirmed against a published county practice note specific to data centres and should be checked with the relevant county planning department before design is finalised. Development permission is, by the Act’s own terms, a prerequisite for other licensing authorities issuing a licence for a commercial or industrial use, which places it ahead of the CAK licence application in practical sequencing, not behind it. Proceeding without permission carries criminal sanctions and exposes the developer to demolition of unapproved works.
NEMA environmental impact assessment. The Environmental Management and Co-ordination Act’s Second Schedule sets out the categories of project requiring a mandatory EIA, using both a general test, any activity out of character with its surroundings, any structure of a scale not in keeping with its surroundings, or a major change in land use, and a more specific list that includes urban development projects. NEMA in practice treats large commercial and industrial developments, which a data centre of any real scale is, as EIA-triggering, and classifies projects by risk under Legal Notices 31 and 32 of 2019: 5 working days review for a low-risk project, 45 for medium risk, and 90 for high risk, the last of which typically requires a full EIA study report rather than a lighter assessment. A data centre’s power and cooling infrastructure, and any on-site fuel storage for backup generation, make the 90-day full-study track the realistic planning assumption. NEMA’s licence fee, reinstated with effect from 1 June 2022, is 0.1% of total project cost, with a minimum of KES 10,000 and no upper cap, plus a separate KES 5,000 fee for any later surrender, transfer or variation of the licence.
The Physical and Land Use Planning Act’s development-permission mechanics, the NEMA risk classification and timelines under Legal Notices 31 and 32 of 2019, and the EIA fee schedule effective 1 June 2022 are confirmed against the Act itself, the Legal Notices, and NEMA’s published fee reinstatement. The Second Schedule’s precise listing of “data centre” or “ICT infrastructure” as a named category was not independently located in the Gazette text; what is confirmed is the general out-of-character/scale test and NEMA’s consistent practice of treating large commercial developments as EIA-triggering, which should be the working assumption for a data centre of institutional scale.
Power: PPAs, EPRA Licensing and Backup Generation
Power is the line item that decides whether a data centre project is bankable, and it runs through two separate regulatory tracks: the grid connection or bulk supply arrangement, and any on-site generation capacity for backup or resilience.
Grid supply. A facility drawing power from Kenya Power under a standard or negotiated bulk supply tariff does not itself need a generation licence; the regulatory relationship sits at the level of the supply agreement and Kenya Power’s own EPRA-issued distribution and supply licence. For a load of genuine data centre scale, engaging Kenya Power early on substation capacity and any dedicated feeder requirement is a scheduling issue as much as a legal one; grid capacity in the areas data centres actually want to be sited, Nairobi, Mombasa and Konza, is not unconstrained.
On-site and backup generation. Under the Energy Act, 2019, EPRA’s generation licensing threshold sits at 1MW: installations below that capacity are subject to a notification requirement rather than a full generation licence, while larger installations need to be licensed. A single data centre’s aggregate standby diesel capacity, sized to carry full IT and cooling load during a grid outage, will often exceed 1MW well before the facility reaches meaningful scale, which puts the backup power plant itself inside EPRA’s licensing regime on a straightforward reading of the threshold.
Whether standby-only generation capacity that never exports to the grid and runs solely during outages is treated the same as continuous or grid-connected generation for licensing purposes has not been confirmed against EPRA’s own published guidance, as distinct from the general 1MW threshold under the Energy Act. A proposed amendment under the Statute Law (Miscellaneous Amendment) Bill would in any event lower the notification threshold to 500kW. Confirm the current position for standby-only capacity, and the status of that amendment, with EPRA or the firm’s energy team before finalising the backup power design.
Diesel fuel storage on site brings its own layer of regulation, principally through NEMA (Chapter IV) and the county fire and petroleum storage licensing regime, both of which should be scoped alongside the generation licence rather than treated as an afterthought once the mechanical design is fixed.
Tax Treatment and the SEZ Question
Kenya does not currently operate a tax incentive written specifically for data centre operators. That is worth stating plainly, since it is easy to assume one exists given how central digital infrastructure is to current government messaging; the incentive regime a data centre investor actually uses is the general capital allowance and Special Economic Zone framework available to any qualifying capital-intensive project.
Standard corporate tax and capital allowances. Kenya’s standard corporate income tax rate is 30% for resident and non-resident companies alike. Capital expenditure on qualifying buildings and machinery, the categories a data centre’s shell, power and cooling infrastructure fall into, is depreciated under the Income Tax Act’s capital allowance regime at 50% in the first year of use and 25% per year thereafter. Separately, the Finance Act 2022 reintroduced an enhanced 150% investment deduction for qualifying capital expenditure outside Nairobi and Mombasa counties, where the cumulative investment reaches a stated minimum threshold.
Published figures for the minimum cumulative investment needed to unlock the 150% outside-Nairobi/Mombasa deduction are inconsistent across secondary sources at the time of writing, some citing KES 200 million, one specialist tax source citing KES 1 billion. This should be confirmed against the current Income Tax Act text (as amended) before it is quoted to a client as a specific number. A Konza-sited facility, being outside both Nairobi and Mombasa counties, is the clearest candidate to test this deduction against, whatever the confirmed threshold turns out to be.
Special Economic Zone status. The Special Economic Zones Act, 2015 designates an Information Communication Technology Park as one of its recognised zone categories, and a data centre licensed as an SEZ enterprise, developer or operator qualifies for a preferential corporate tax rate of 10% for its first ten years of operation and 15% for the next ten, VAT exemption on its own registration with zero-rating for supplies made to it, exemption from stamp duty on instruments relating to its business activities, and work permits for up to 20% of its full-time workforce (with scope for a higher proportion in specialised sectors). These benefits run for a period the Act caps at ten years from the date of licensing for most of the listed exemptions. The Act leaves the minimum qualifying investment amount to be set by the Cabinet Secretary on the SEZ Authority’s recommendation, rather than fixing a figure in the Act itself.
| Regime | Corporate tax | Key conditions |
|---|---|---|
| Standard company | 30% | Standard capital allowances; 150% deduction outside Nairobi/Mombasa above a minimum investment (threshold to confirm) |
| SEZ enterprise (ICT Park or gazetted zone) | 10% (yrs 1–10), 15% (yrs 11–20) | SEZ Authority licence; VAT exemption; stamp duty exemption; minimum investment set by the Cabinet Secretary |
The 30% standard rate, the 10%/15% SEZ rate, the SEZ VAT and stamp duty treatment, and the ICT Park zone category are confirmed against the Special Economic Zones Act 2015 (Section 35, Section 2 definitions) and PwC’s Worldwide Tax Summaries for Kenya, reviewed 17 July 2026. No data-centre-specific provision was found in the Income Tax Act, the Finance Act 2022 through 2025 amendments reviewed, or KRA’s own published investor incentive material.
Investment Facilitation Through KenInvest
Outside the tax regime, the Kenya Investment Authority is the practical front door for a foreign-owned data centre project, converting a capital commitment into the documentation the rest of the licensing chain relies on.
A foreign investor committing USD 100,000 or its equivalent (KES 1,000,000 for a local investor) qualifies for an Investment Certificate from KenInvest. The certificate is not itself a sector licence, it does not substitute for the CAK’s NFP licence or NEMA’s EIA approval, but it is the credential KenInvest issues after evaluating the project against its stated criteria: employment creation, skills transfer, tax revenue, technology transfer, foreign exchange generation and ICT adoption, all of which a data centre project scores well against on paper. Holding the certificate is what opens the path to investor-linked work permits and streamlines KRA PIN registration for the investing entity.
Since the removal of the ICT sector’s local shareholding requirement in August 2023 (Chapter I), the KenInvest and CAK processes for a data centre project run on parallel, ownership-neutral tracks: the same foreign-owned company that holds the Investment Certificate can also hold the NFP licence directly, without the two-entity structuring exercise that land-restricted sectors like hospitality or agriculture require.
Construction, Procurement and Technical Standards
Once the site, planning and environmental approvals are in place, construction procurement for a data centre carries two considerations that a conventional commercial building does not: the sequencing against the licensing chain in Chapters II and IV, and the technical standard the finished facility is expected to meet.
Because development permission is a prerequisite for other licences (Chapter IV), and because the NFP licence application typically expects a defined facility design rather than a concept, the practical build sequence runs planning approval, then EIA licence, then detailed design and procurement, then the CAK licence application, with construction itself able to proceed once planning and environmental approvals are secured rather than waiting for the CAK licence to issue. Procurement of power and cooling equipment, generators, UPS systems and switchgear, should be timed against the EPRA generation licensing step in Chapter V, since import lead times on this equipment commonly run longer than the licensing process itself.
Secondary commentary references a Government Data Centre Standard, published in 2023, setting redundancy, physical security, cabling and service-level benchmarks (including a 99.99% availability figure) for data centre facilities. This could not be independently verified against a primary Government of Kenya or ICT Authority publication in this review. Before designing to it, or citing it to a client as a binding standard, confirm its current text, its issuing authority, and whether it applies to privately operated commercial facilities or only to government-procured ones.
Whatever the applicable technical standard, procurement contracts of this scale should carry the ordinary safeguards a capital project of this size warrants: performance security tied to commissioning milestones, defects liability periods matched to manufacturer warranties on power and cooling plant, and clear allocation of responsibility for delay caused by import or customs clearance on specialised equipment.
Employment and Work Permits for Specialist Staff
A data centre’s day-to-day headcount is small relative to its capital cost, but the roles that matter most, mechanical and electrical engineering leads, network operations specialists, security architects, are exactly the ones most likely to be filled by a non-citizen in the early years of a Kenyan operation.
The relevant permit is the Class D employment permit, issued under Section 40 of the Kenya Citizenship and Immigration Act, 2011 and the Seventh Schedule to the Kenya Citizenship and Immigration Regulations, 2012. It carries a non-refundable KES 20,000 processing fee, a KES 500,000 annual issuance fee, and a KES 100,000 security bond once approved; East African Community nationals are exempt from these fees. Initial grants run for up to two years, renewable to a four-year maximum, and the application must name a Kenyan understudy for the role, with a training plan demonstrating skills transfer over the permit period, before Immigration will process it. Processing realistically takes two to five months depending on documentation completeness, which should be built into any specialist hire’s start-date planning rather than treated as a formality.
For roles specifically in the ICT sector, the Immigration Department routes applications through the ICT Authority for a sector clearance before the work permit itself is processed, with the ICT Authority’s own review taking around 14 working days once a complete application is submitted. This clearance step sits ahead of, not instead of, the standard Class D process, and should be sequenced into the hiring timeline for any foreign engineer or specialist the project needs on the ground before commissioning.
Because the local-understudy requirement and the ICT Authority clearance both take real time to assemble properly, a data centre project with confirmed foreign specialist hires should start the work permit process as soon as the individual is identified, in parallel with construction and licensing rather than after the facility is ready to commission.
Cybersecurity and Critical Infrastructure Obligations
A data centre sits inside a sector Kenya has now formally brought under a dedicated critical-infrastructure regime, separate from the CAK’s facilities licensing and separate from the Data Protection Act’s controller obligations.
The Computer Misuse and Cybercrimes Act, 2018 established the framework; the Computer Misuse and Cybercrime (Critical Information Infrastructure and Cybercrime Management) Regulations, 2024 operationalise it under the National Computer and Cybercrimes Coordination Committee (NC4). The Regulations identify a defined set of sectors, telecommunications, banking, energy and transport among them, as critical information infrastructure, and require that infrastructure classified as critical be localised within Kenya. Owners of designated critical information infrastructure must carry out an annual cyber-risk assessment and business impact analysis covering their relevant products, services and business functions, and must report a qualifying incident to the relevant Sectoral Cybersecurity Operations Centre within 24 hours, using the prescribed Form CMCA 7, with supporting detail on the threat, its type and its effect on operations.
The Regulations name telecommunications as a covered sector but the precise mechanism by which an individual data centre or network facility is formally designated as critical information infrastructure, whether designation is automatic for a licensed NFP operator, requires a specific gazettement, or is applied case by case by NC4, was not confirmed against a published designation list or process document in this review. An operator should confirm its designation status directly with NC4 rather than assume either way, since the 24-hour reporting and annual assessment obligations are only live once designation applies.
These obligations sit alongside, not instead of, the Data Protection Act obligations in Chapter III: a designated facility carrying regulated personal data can face both a 24-hour NC4 incident report and separate Data Protection Act breach-notification duties to the ODPC out of the same security incident, and its incident response plan should be built to satisfy both from the outset.
Pre-Investment Checklist
A working, at-a-glance version of the licensing and compliance chain in Chapters II through X: the items worth confirming before capital is committed to a specific site or facility design.
Confirm the applicable CAK licence category
Establish whether NFP-T1 or NFP-T2 applies today, and track the CA’s standalone data centre licence consultation before fixing a long-term licensing budget.
Register with the ODPC before processing personal data
Telecommunications-sector registration is mandatory regardless of size; confirm the correct size tier and fee before operations begin.
Screen customer data against the localization trigger
Identify whether any prospective customer’s data falls within Regulation 26’s strategic-interest categories, and design in-Kenya storage capacity accordingly.
Secure county development permission before other approvals
Development permission is a legal prerequisite for other licences; sequence it ahead of the NEMA and CAK applications, not behind them.
Budget for a full NEMA EIA study
Plan for the 90-day, full-study track and the 0.1%-of-project-cost fee as the realistic case for a facility of institutional scale.
Lock in the power supply and generation route early
Confirm Kenya Power grid capacity at the site, and check whether aggregate backup generation capacity crosses the EPRA 1MW licensing threshold.
Compare SEZ enterprise status against standard incorporation
Model the 10%/15% SEZ corporate tax rate and VAT/stamp duty exemptions against standard capital allowances before choosing a structure.
Obtain the KenInvest Investment Certificate if foreign-owned
Confirm the USD 100,000 threshold is met and file early, since the certificate underpins later work permit and PIN registration steps.
Start specialist work permits as soon as candidates are identified
Build in the ICT Authority clearance, the local-understudy plan, and the two-to-five-month Class D processing window ahead of commissioning.
Confirm critical infrastructure designation status with NC4
Establish whether the facility is, or will be, designated critical information infrastructure, and build 24-hour incident reporting into the operational plan regardless.
Why Clay & Associates Advocates
Four things distinguish how this firm handles a data centre or digital infrastructure investment matter.
Four mandates, one firm. Advocates, Notaries Public, Commissioners for Oaths, and Patent Agents under one roof, so a licensing application, a power purchase agreement, and a data protection compliance opinion do not need three separate relationships.
Fee transparency. Every fee we quote is drawn from our own published Schedule of Fees, not an estimate pulled from memory.
Primary-source rigour. Every legal point in this guide traces to a named Act, regulation, or regulator, and every figure still genuinely open, a licence fee under consultation, a threshold cited inconsistently elsewhere, is flagged as such rather than stated as settled.
Regulatory currency. Kenya’s data centre licensing framework changed twice in the three months before this guide was written. We track CAK, ODPC and NC4 regulatory activity as a standing part of how we advise this sector, not as a one-off research exercise.
Frequently Asked Questions
Does Kenya require data centre operators to keep all data inside the country?
No. The Data Protection Act’s localization rule under Regulation 26 applies only to a defined set of strategic state-interest categories: civil registration, elections, public finance, protected computer systems, basic education, and primary/secondary healthcare. Ordinary commercial personal data can be processed and transferred abroad under the Act’s cross-border transfer conditions in Chapter III.
What licence does a colocation data centre need from the Communications Authority?
As at September 2026, colocation data centres operate under the Network Facilities Provider Tier 2 (or Tier 1) licence, which was formally extended to cover commercial data centre operation in the CA’s June 2026 market structure revision. The CA has proposed carving data centres out into a dedicated standalone licence; that proposal is in public consultation and not yet in force.
Is there a dedicated tax incentive for building a data centre in Kenya?
No. Kenya does not currently have a tax provision written specifically for data centre operators. A data centre investor uses the same general regime available to any qualifying capital-intensive project: standard capital allowances, the enhanced investment deduction for qualifying investment outside Nairobi and Mombasa, or Special Economic Zone status if the facility is licensed as an SEZ enterprise, described in Chapter VI.
Can a foreign company own 100% of a Kenyan data centre operating company?
Yes. The 30% local shareholding requirement that previously applied to ICT sector players was withdrawn by Gazette Notice in August 2023. A foreign investor can hold both the operating company and the CAK network facilities licence directly, without a local equity partner.
Does a data centre need a NEMA environmental impact assessment licence?
In practice, yes, for a facility of any real scale. NEMA treats large commercial and industrial developments as EIA-triggering under the Environmental Management and Co-ordination Act’s general out-of-character and scale test, and a data centre’s power, cooling and fuel storage infrastructure makes the full 90-day study track the realistic planning assumption, described in Chapter IV.
What happens if my facility is designated critical information infrastructure?
A designated facility must carry out an annual cyber-risk assessment and business impact analysis, and report qualifying security incidents to its Sectoral Cybersecurity Operations Centre within 24 hours under the 2024 Critical Information Infrastructure Regulations. The exact process by which an individual facility is designated has not been fully confirmed in this guide and should be checked directly with NC4, described in Chapter X.
How We Can Help
We structure the licensing pathway, clear the environmental and planning approvals, and carry the data protection and cybersecurity compliance file end to end, one firm for the facility, the data, and the people who run it.
Mombasa Road, Nairobi, Kenya