Article

DATA PROTECTION OBLIGATIONS OF VIRTUAL ASSET SERVICE PROVIDERS IN KENYA

August 25, 2026 · T.M.M & Partners Advocates

By Brian Mabeya

This article explains what the Virtual Asset Service Providers Act, 2025 and the Virtual Asset Service Providers Regulations, 2026 require of licensees when they handle customer data — and how those duties sit alongside the Data Protection Act, 2019

At a glance: The Virtual Asset Service Providers Act, 2025 commenced on 4 November 2025. Existing providers must comply within one year of commencement — 4 November 2026. The Act creates no separate privacy code. Section 24(i) requires that the recording, storing, protecting and transmission of data processed by a licensee accord with the laws of Kenya, and section 46 routes personal data back to the Data Protection Act, 2019. The Regulations add operational detail: a cybersecurity and information technology policy at application, confidentiality controls in systems design, pre-transaction disclosure of data protection measures, and recurring penetration testing. A licensee answers to two supervisors on the same facts — the Central Bank of Kenya or the Capital Markets Authority, and the Office of the Data Protection Commissioner — and a single failure can be penalised under both regimes. The difficult questions are not about policy documents. They are about retention, on-chain metadata and offshore vendors.

1. What the Act says

The Act approaches personal data in three places.

First, it makes data handling an express condition of holding a licence. Section 24 sets out the additional requirements every licensee must meet at all times. Among them, at paragraph (i), the licensee must —

Section 24(i) of the Actensure that recording, storing, protecting and transmission of the data processed by it is in accordance with laws in Kenya”

The formulation is deliberately broad. It captures data at rest, data in transit, and the security applied to each. It is not confined to personal data, and it is not confined to customer data.

Second, the Act carries a standalone provision on personal data. Section 46, under the marginal note Compliance with the Data Protection Act, provides that any person processing personal data under the Act shall comply with the Data Protection Act. That is a referential provision, not a substitute regime. The whole architecture of the Data Protection Act therefore applies to virtual asset businesses — lawful basis, the data protection principles, data subject rights, impact assessments, breach notification and transfer restrictions.

Third, section 28(1) requires a licensee to have —

Section 28(1) of the Actappropriate and effective cyber security measures as prescribed or as provided for under the Computer Misuse and Cybercrimes Act (Cap. 79C)”

Security and privacy are treated as adjacent duties, each with its own supervisor and its own enforcement route.

Alongside these sits section 44(2), which requires a licensee to maintain a record of both its client and its own transactions at its principal place of business for not less than seven years from the date the transaction occurred.

2. What the Regulations add

The Regulations convert those duties into examinable requirements. They are cited here by subject matter.

At the application stage

An applicant must satisfy the relevant regulatory authority that it has cybersecurity, data protection and consumer protection measures appropriate to the scale and risk profile of its proposed activities. It must submit the operational policies that will guide the business, among them a cybersecurity and information technology policy, and must evidence technology resources that are secure and that maintain the confidentiality of the data they contain. Data protection is therefore a licensing fact before it is a compliance fact: an applicant that cannot evidence it does not get licensed.

In systems design

In maintaining its systems and controls, a licensee must have regard to confidentiality — the safe storage of information and the transmission of data under clear protocols, which may require firewalls within a system, restrictions on entry, and compliance with the data protection laws. Vulnerability assessment, risk assessment and penetration testing are required on a recurring cycle, twice in the first year of licensing and at least annually thereafter.

In customer disclosure

Before engaging in any transaction or providing any service, a licensee must disclose to the consumer the security protocols employed for transaction execution, consumer authentication and data protection. A privacy notice will not, without more, discharge this: the disclosure is owed before the first transaction and must address protocols, not merely purposes. It sits naturally alongside the duty to notify at section 29 of the Data Protection Act, which already requires a description of the technical and organisational security measures taken to ensure the integrity and confidentiality of the data (section 29(f)). One instrument, properly drafted, can carry both.

In internal conduct

A licensee must not take advantage of information obtained from providing services to a consumer for its own benefit, that of its employees, or that of another consumer. Where that risk arises, it must document procedures, erect information barriers between information technology systems, train employees on them, and obtain undertakings from employees that they will not use information gained from consumers for personal benefit.

In record keeping

Transaction records must be kept for at least seven years, and the Regulations specify that they include technical and contextual metadata on transactions — wallet addresses, transaction hashes, network or chain identifiers, high-precision timestamps, order-book and application programming interface interaction logs, and identifiers of cross-chain or bridge pathways.

In reporting

Major security breaches must be reported to the relevant regulatory authority on the periodic cycle the Regulations prescribe. That is separate from, and additional to, the notification owed to the Data Commissioner under section 43 of the Data Protection Act, and the two triggers are not the same. The regulatory report is engaged by a major security breach as such. Section 43(1) is engaged where personal data has been accessed or acquired by an unauthorised person, and there is a real risk of harm to the data subject; where that threshold is met, the Data Commissioner must be notified within seventy-two hours, and a notification made later must carry reasons for the delay (section 43(2)).

In governance

The cybersecurity strategy must be reviewed regularly and at least annually, and the results of that review submitted to the board within a month of the review. Contravention of the cybersecurity requirements carries an administrative penalty under the Regulations, imposed under the penalty-setting power in section 49 of the Act.

3. Three points of friction

Retention against minimisation

The Act and the Regulations mandate seven-year retention. Section 25(g) of the Data Protection Act requires that personal data be kept in a form which identifies the data subject for no longer than is necessary for the purposes for which it was collected, and section 39(1) requires retention only as long as reasonably necessary. The two are reconciled by section 39(1)(a), which permits retention that is required or authorised by law. The statutory mandate therefore supplies the answer — but only for the data the mandate actually covers, and only for the period it specifies. Section 39(2) requires everything else to be deleted, erased, anonymised or pseudonymised at the expiry of the retention period. Marketing profiles, abandoned onboarding attempts, chat transcripts and support call recordings are not transaction records. They do not inherit the seven-year period, and a blanket seven-year rule applied across the estate is itself a minimisation failure.

On-chain and technical metadata

The Regulations compel the logging of wallet addresses and chain identifiers. Where those identifiers are linked to an identified customer through customer due diligence, they are personal data. They belong in the record of processing activities, the privacy notice and the retention schedule. Pseudonymity at protocol level is not anonymity at law.

Offshore processing

Most licensees will use foreign custody technology, cloud hosting, blockchain analytics and identity verification vendors. Each engages the transfer provisions in Part VI of the Data Protection Act. Section 48 permits transfer only on proof to the Data Commissioner of appropriate safeguards, or on one of the listed necessity grounds. Section 49(1) is stricter for sensitive personal data, which may be processed out of Kenya only upon the consent of the data subject and confirmation of appropriate safeguards. Biometric data is sensitive personal data (section 2), so a licensee using offshore liveness or facial-match verification is in section 49(1) territory, not section 48. Section 50 reserves to the Cabinet Secretary the power to prescribe processing that may only be effected through a server or data centre located in Kenya.

The Regulations press from the other direction: a promoter of a virtual asset offering must state the location where the information required by the Regulations will be retained and will be accessible in Kenya.

4. The Worldcoin judgment

The interaction between novel virtual asset onboarding and the Data Protection Act has already been litigated. In Republic v Tools for Humanity Corporation (US) & 9 others; Katiba Institute & 4 others (Ex parte Applicants) (Judicial Review Application E119 of 2023) [2025] KEHC 5629 (KLR), delivered on 5 May 2025, the High Court found violations of data protection law by the first to fifth respondents in the collection of biometric data in Kenya using the device known as the Orb, in exchange for a cryptocurrency.

The Court issued an order of prohibition restraining those respondents and their agents from further collecting, processing or transferring the personal biometric data collected in Kenya using the Orb —

[2025] KEHC 5629 (KLR)without undertaking (or using an inadequate) Data Protection Impact Assessment contrary to section 31 of the Data Protection Act, 2019 or using consent obtained through inducement of a cryptocurrency—Worldcoin. And in the case of the 3rd to 5th Respondents, without registering as data processors or controllers in Kenya.”

Three propositions follow for a licensee designing an onboarding flow. An inadequate impact assessment is treated as no impact assessment. Consent procured by the inducement of a token is not consent — which section 32(4) anticipates, by directing attention to whether the provision of a service was made conditional on processing not necessary to it. And registration is a precondition of lawful processing, not an administrative afterthought — including for offshore group entities that touch the data.

5. What compliance looks like on paper

6. Consequences

The same failure can be sanctioned twice. Under section 63 of the Data Protection Act, the maximum penalty the Data Commissioner may impose in a penalty notice is KSh 5,000,000 or, in the case of an undertaking, up to 1% of its annual turnover of the preceding financial year, whichever is the lower. Failure to comply with an enforcement notice is a separate offence carrying a fine of up to KSh 5,000,000 or two years’ imprisonment (section 58(3)), and a data subject who suffers damage — including distress — may claim compensation from the controller or processor (section 65). Under the Regulations, a cybersecurity contravention attracts an administrative penalty in its own right, and the relevant regulatory authority retains its powers of suspension and revocation.

There is a third consequence, less often priced in. A data protection failure is a licensing fact. It bears on whether the applicant has the capability the Regulations require, and on the fit and proper assessment under section 18 of the Act of those who run the business.

7. Timing

Existing providers have until 4 November 2026. The data protection workstream is the one most often begun last and least capable of being compressed: a section 31 impact assessment must be submitted sixty days before the processing starts, and vendor transfer agreements are negotiated at the counterparty’s pace, not the licensee’s.

This is a practice note on the obligations arising under the Virtual Asset Service Providers Act, 2025, the Virtual Asset Service
Providers Regulations, 2026 and the Data Protection Act, Cap. 411C.

Published by T.M.M & Partners Advocates.