By Brian Mabeya
This article explains what the Virtual Asset Service Providers Act, 2025 and the Virtual Asset Service Providers Regulations, 2026 require of licensees when they handle customer data — and how those duties sit alongside the Data Protection Act, 2019
| At a glance: The Virtual Asset Service Providers Act, 2025 commenced on 4 November 2025. Existing providers must comply within one year of commencement — 4 November 2026. The Act creates no separate privacy code. Section 24(i) requires that the recording, storing, protecting and transmission of data processed by a licensee accord with the laws of Kenya, and section 46 routes personal data back to the Data Protection Act, 2019. The Regulations add operational detail: a cybersecurity and information technology policy at application, confidentiality controls in systems design, pre-transaction disclosure of data protection measures, and recurring penetration testing. A licensee answers to two supervisors on the same facts — the Central Bank of Kenya or the Capital Markets Authority, and the Office of the Data Protection Commissioner — and a single failure can be penalised under both regimes. The difficult questions are not about policy documents. They are about retention, on-chain metadata and offshore vendors. |
1. What the Act says
The Act approaches personal data in three places.
First, it makes data handling an express condition of holding a licence. Section 24 sets out the additional requirements every licensee must meet at all times. Among them, at paragraph (i), the licensee must —
| Section 24(i) of the Act “ensure that recording, storing, protecting and transmission of the data processed by it is in accordance with laws in Kenya” |
The formulation is deliberately broad. It captures data at rest, data in transit, and the security applied to each. It is not confined to personal data, and it is not confined to customer data.
Second, the Act carries a standalone provision on personal data. Section 46, under the marginal note Compliance with the Data Protection Act, provides that any person processing personal data under the Act shall comply with the Data Protection Act. That is a referential provision, not a substitute regime. The whole architecture of the Data Protection Act therefore applies to virtual asset businesses — lawful basis, the data protection principles, data subject rights, impact assessments, breach notification and transfer restrictions.
Third, section 28(1) requires a licensee to have —
| Section 28(1) of the Act “appropriate and effective cyber security measures as prescribed or as provided for under the Computer Misuse and Cybercrimes Act (Cap. 79C)” |
Security and privacy are treated as adjacent duties, each with its own supervisor and its own enforcement route.
Alongside these sits section 44(2), which requires a licensee to maintain a record of both its client and its own transactions at its principal place of business for not less than seven years from the date the transaction occurred.
2. What the Regulations add
The Regulations convert those duties into examinable requirements. They are cited here by subject matter.
At the application stage
An applicant must satisfy the relevant regulatory authority that it has cybersecurity, data protection and consumer protection measures appropriate to the scale and risk profile of its proposed activities. It must submit the operational policies that will guide the business, among them a cybersecurity and information technology policy, and must evidence technology resources that are secure and that maintain the confidentiality of the data they contain. Data protection is therefore a licensing fact before it is a compliance fact: an applicant that cannot evidence it does not get licensed.
In systems design
In maintaining its systems and controls, a licensee must have regard to confidentiality — the safe storage of information and the transmission of data under clear protocols, which may require firewalls within a system, restrictions on entry, and compliance with the data protection laws. Vulnerability assessment, risk assessment and penetration testing are required on a recurring cycle, twice in the first year of licensing and at least annually thereafter.
In customer disclosure
Before engaging in any transaction or providing any service, a licensee must disclose to the consumer the security protocols employed for transaction execution, consumer authentication and data protection. A privacy notice will not, without more, discharge this: the disclosure is owed before the first transaction and must address protocols, not merely purposes. It sits naturally alongside the duty to notify at section 29 of the Data Protection Act, which already requires a description of the technical and organisational security measures taken to ensure the integrity and confidentiality of the data (section 29(f)). One instrument, properly drafted, can carry both.
In internal conduct
A licensee must not take advantage of information obtained from providing services to a consumer for its own benefit, that of its employees, or that of another consumer. Where that risk arises, it must document procedures, erect information barriers between information technology systems, train employees on them, and obtain undertakings from employees that they will not use information gained from consumers for personal benefit.
In record keeping
Transaction records must be kept for at least seven years, and the Regulations specify that they include technical and contextual metadata on transactions — wallet addresses, transaction hashes, network or chain identifiers, high-precision timestamps, order-book and application programming interface interaction logs, and identifiers of cross-chain or bridge pathways.
In reporting
Major security breaches must be reported to the relevant regulatory authority on the periodic cycle the Regulations prescribe. That is separate from, and additional to, the notification owed to the Data Commissioner under section 43 of the Data Protection Act, and the two triggers are not the same. The regulatory report is engaged by a major security breach as such. Section 43(1) is engaged where personal data has been accessed or acquired by an unauthorised person, and there is a real risk of harm to the data subject; where that threshold is met, the Data Commissioner must be notified within seventy-two hours, and a notification made later must carry reasons for the delay (section 43(2)).
In governance
The cybersecurity strategy must be reviewed regularly and at least annually, and the results of that review submitted to the board within a month of the review. Contravention of the cybersecurity requirements carries an administrative penalty under the Regulations, imposed under the penalty-setting power in section 49 of the Act.
3. Three points of friction
Retention against minimisation
The Act and the Regulations mandate seven-year retention. Section 25(g) of the Data Protection Act requires that personal data be kept in a form which identifies the data subject for no longer than is necessary for the purposes for which it was collected, and section 39(1) requires retention only as long as reasonably necessary. The two are reconciled by section 39(1)(a), which permits retention that is required or authorised by law. The statutory mandate therefore supplies the answer — but only for the data the mandate actually covers, and only for the period it specifies. Section 39(2) requires everything else to be deleted, erased, anonymised or pseudonymised at the expiry of the retention period. Marketing profiles, abandoned onboarding attempts, chat transcripts and support call recordings are not transaction records. They do not inherit the seven-year period, and a blanket seven-year rule applied across the estate is itself a minimisation failure.
On-chain and technical metadata
The Regulations compel the logging of wallet addresses and chain identifiers. Where those identifiers are linked to an identified customer through customer due diligence, they are personal data. They belong in the record of processing activities, the privacy notice and the retention schedule. Pseudonymity at protocol level is not anonymity at law.
Offshore processing
Most licensees will use foreign custody technology, cloud hosting, blockchain analytics and identity verification vendors. Each engages the transfer provisions in Part VI of the Data Protection Act. Section 48 permits transfer only on proof to the Data Commissioner of appropriate safeguards, or on one of the listed necessity grounds. Section 49(1) is stricter for sensitive personal data, which may be processed out of Kenya only upon the consent of the data subject and confirmation of appropriate safeguards. Biometric data is sensitive personal data (section 2), so a licensee using offshore liveness or facial-match verification is in section 49(1) territory, not section 48. Section 50 reserves to the Cabinet Secretary the power to prescribe processing that may only be effected through a server or data centre located in Kenya.
The Regulations press from the other direction: a promoter of a virtual asset offering must state the location where the information required by the Regulations will be retained and will be accessible in Kenya.
4. The Worldcoin judgment
The interaction between novel virtual asset onboarding and the Data Protection Act has already been litigated. In Republic v Tools for Humanity Corporation (US) & 9 others; Katiba Institute & 4 others (Ex parte Applicants) (Judicial Review Application E119 of 2023) [2025] KEHC 5629 (KLR), delivered on 5 May 2025, the High Court found violations of data protection law by the first to fifth respondents in the collection of biometric data in Kenya using the device known as the Orb, in exchange for a cryptocurrency.
The Court issued an order of prohibition restraining those respondents and their agents from further collecting, processing or transferring the personal biometric data collected in Kenya using the Orb —
| [2025] KEHC 5629 (KLR) “without undertaking (or using an inadequate) Data Protection Impact Assessment contrary to section 31 of the Data Protection Act, 2019 or using consent obtained through inducement of a cryptocurrency—Worldcoin. And in the case of the 3rd to 5th Respondents, without registering as data processors or controllers in Kenya.” |
Three propositions follow for a licensee designing an onboarding flow. An inadequate impact assessment is treated as no impact assessment. Consent procured by the inducement of a token is not consent — which section 32(4) anticipates, by directing attention to whether the provision of a service was made conditional on processing not necessary to it. And registration is a precondition of lawful processing, not an administrative afterthought — including for offshore group entities that touch the data.
5. What compliance looks like on paper
- Registration with the Office of the Data Protection Commissioner. Section 18(1) provides that no person shall act as a data controller or data processor unless registered; the mandatory thresholds are prescribed by the Data Commissioner under section 18(2) and the Data Protection (Registration of Data Controllers and Data Processors) Regulations, 2021. Registration is required of each entity in the group that controls or processes the data, not only the licence applicant.
- A data protection impact assessment under section 31(1) where the processing is likely to result in high risk. The report is submitted sixty days prior to the processing (section 31(5)), and where the assessment indicates high risk, the Data Commissioner must be consulted before processing begins (section 31(3)). Biometric or liveness onboarding, large-scale identity verification and automated risk scoring will ordinarily qualify.
- A documented lawful basis for each processing purpose under section 30(1). Customer due diligence performed under the Regulations and the Proceeds of Crime and Anti-Money Laundering Act rests on compliance with a legal obligation under section 30(1)(b)(ii), not on consent — so the section 32(2) right to withdraw consent does not reach it. Where a licensee does rely on consent, it bears the burden of proving it (section 32(1)).
- A breach procedure that runs two clocks: seventy-two hours to the Data Commissioner under section 43(1)(a) where the section 43(1) threshold is met, and the periodic report of major security breaches owed to the relevant regulatory authority. A processor must notify the controller without delay and, where reasonably practicable, within forty-eight hours (section 43(3)). Communication to the data subject is not required where appropriate security safeguards, which may include encryption of the affected data, were implemented (section 43(6)).
- A written contract with every processor, providing that the processor acts only on the controller’s instructions and is bound by the controller’s obligations (section 42(2)(b)). A vendor that processes outside those instructions is deemed a controller in respect of that processing (section 42(3)) — which is how an analytics or verification vendor becomes a regulated party in its own right, and how the licensee loses control of the position.
- Technical and organisational measures designed to implement the principles and integrate safeguards into the processing, applied both when the means of processing are determined and at the time of processing (section 41(1) and (2)), with pseudonymisation and encryption among the measures to be considered (section 41(4)(c)).
- Express consent before any use of customer data for commercial purposes, unless the use is authorised by written law and the customer was informed of it at collection (section 37(1)). Cross-selling from onboarding data is not covered by the anti-money laundering basis that justified collecting it.
- A data protection officer. Section 24(1) is framed permissively — a controller or processor may designate one where the core activities involve regular and systematic monitoring of data subjects or the processing of sensitive categories of data — but both limbs describe the ordinary licensee, and the functions in section 24(7) have to be discharged by someone. Where the role is filled, section 24(2) requires that any other duties held do not create a conflict of interest, which is the same discipline the Regulations impose on the compliance officer.
- A retention schedule that distinguishes mandated transaction records from everything else.
6. Consequences
The same failure can be sanctioned twice. Under section 63 of the Data Protection Act, the maximum penalty the Data Commissioner may impose in a penalty notice is KSh 5,000,000 or, in the case of an undertaking, up to 1% of its annual turnover of the preceding financial year, whichever is the lower. Failure to comply with an enforcement notice is a separate offence carrying a fine of up to KSh 5,000,000 or two years’ imprisonment (section 58(3)), and a data subject who suffers damage — including distress — may claim compensation from the controller or processor (section 65). Under the Regulations, a cybersecurity contravention attracts an administrative penalty in its own right, and the relevant regulatory authority retains its powers of suspension and revocation.
There is a third consequence, less often priced in. A data protection failure is a licensing fact. It bears on whether the applicant has the capability the Regulations require, and on the fit and proper assessment under section 18 of the Act of those who run the business.
7. Timing
Existing providers have until 4 November 2026. The data protection workstream is the one most often begun last and least capable of being compressed: a section 31 impact assessment must be submitted sixty days before the processing starts, and vendor transfer agreements are negotiated at the counterparty’s pace, not the licensee’s.
This is a practice note on the obligations arising under the Virtual Asset Service Providers Act, 2025, the Virtual Asset Service
Providers Regulations, 2026 and the Data Protection Act, Cap. 411C.
Published by T.M.M & Partners Advocates.