ACT
The Computer Misuse and Cybercrimes Act 2018
The Computer Misuse and Cybercrimes Act, 2018 is Kenya's primary cybercrime law. It defines offences, sets investigation powers, establishes NC4 coordination…
Legal foundation and purpose: The Act was assented to on 16 May 2018 and commenced on 30 May 2018. It provides a legal framework for detection, prevention, investigation, prosecution and punishment of computer and cybercrimes, and supports international cooperation on cybercrime matters.
Core objectives: Section 3 states that the law protects confidentiality, integrity and availability of systems and data, prevents unlawful use of systems, supports investigation and prosecution of cybercrime, protects constitutional rights including privacy and expression, and enables cross-border cooperation.
National coordination structure: Part II establishes the National Computer and Cybercrimes Co-ordination Committee (NC4) and Secretariat. The Committee includes key security, justice, ICT and financial sector leadership and is mandated to coordinate threat analysis, incident response, cybersecurity standards, and public key infrastructure development.
Critical information infrastructure obligations: Sections 9 to 13 empower designation of critical infrastructure by Gazette notice, based on service interruption risk, economic impact, casualties risk, money-market disruption, and national security effects. Owners and operators are required to comply with directives on classification, protection, storage and archiving, incident management, disaster recovery, and minimum technical and physical controls.
Offences covered by the Act: Part III criminalizes a broad range of conduct including unauthorized access and interference, unauthorized interception, illegal devices and access codes, cyber espionage, false publications, child pornography online offences, forgery and fraud, cyber harassment, identity theft, phishing, interception and misdirection of electronic messages, cyber terrorism, and related aiding or abetting offences.
Reporting and accountability duties: Section 40 requires operators of public or private systems to report attacks, intrusions and disruptions to the Committee within 24 hours. The report must include breach details, estimated affected persons, risk assessment, and reasons for delayed notification where applicable.
Investigation and enforcement mechanisms: Part IV provides procedures for lawful search and seizure of stored computer data, production orders, expedited preservation and disclosure of traffic data, real-time collection of traffic data, and interception of content data, alongside safeguards on confidentiality, appeals and misuse of powers.
International and territorial reach: Part V aligns cooperation with mutual legal assistance and extradition frameworks, including expedited data preservation and cross-border assistance. Part VI also extends jurisdiction in defined circumstances where conduct outside Kenya targets Kenyan persons, property, or interests.
What this means for organizations and the public: The Act is not only an offence list; it is an operational framework for national cyber resilience. Institutions should implement strong controls, maintain incident response and evidence preservation procedures, and align governance with NC4 and sector directives.