TerraLex Cross-Border Guide to Global Crisis Management Regulatory Guide

Welcome to the TerraLex global crisis management regulatory guide

When a crisis hits your organisation, you need to take action quickly. What practical steps can you and your team take to minimize the impact on your business? What are your reporting requirements in the relevant jurisdiction(s)? What legislation applies there?

Our guide provides you with the answers to these questions in relation to key jurisdictions and it supports your understanding of the relevant local legal framework. It also provides high level practical guidance for those crucial first 72 hours, together with contact details of the local TerraLex firm for when you need specialist advice.

A crisis, by its nature, is both serious and unexpected and your response and actions within the first 72 hours will most likely define its impact on your organisation.

It is therefore important to have in place robust procedures that, if followed, will help minimize the adverse consequences.

The crisis checklist below includes next steps which are common across all jurisdictions. Please refer to the chapter for the relevant jurisdiction for more detailed guidance on your obligations in that country.

How to Use: You can use the tools below to create bespoke reports for the jurisdiction(s) and topic(s) covered. Click into single jurisdiction for one location or use the compare tool to compare multiple jurisdictions. Select the jurisdictions and topics of interest to create your unique report. You also have the option to print or download using the ellipsis button in the top right corner.

Kenya Global Crisis Management Regulatory Guide Guide

Date posted:
30/04/2026
Last update:
15/07/2023

Data breach

On discovering a data breach, which regulators or other government agencies should be notified?

The Data Protection Act 2019 defines a data breach as a breach of system security that leads to the deletion, destruction, alteration, or unauthorised access to personal data. The Act provides for the notification and communication of data breaches to a few concerned parties after the fact, most crucially the Office of the Data Protection Commissioner (ODPC). The Act applies to data controllers and data processors who are established and processing data in Kenya; as well as those who are not established in Kenya but are handling data from data subjects located in Kenya.

Data controllers are encouraged to notify the ODPC as soon as possible after they become aware of a personal data breach that poses a “real risk of harm” to the data subjects. This typically entails information that discloses personal or identifying information e.g., mobile phone numbers. Any notification that is made more than 72 hours before the relevant breach must be accompanied by an explanation for the delay. The notification process can be carried out online, on the Data Protection Commissioner’s website.

A data processor shall notify their relevant data controller “without delay” as soon as they become aware of a breach of personal data under their control. The Act encourages- but does not require- data processors to do this within 48 hours of discovering the breach.

Data controllers may further be required to notify data subjects directly, depending on the severity of the intrusion and the status of the breach. This communication would include information on the breach and mitigation measures.

The Act creates an offence of “unlawful disclosure of personal data”, which also encompasses unauthorised access to personal data. This is a criminal offence, punishable by a fine of Kenya Shillings 3,000,000/- (approx. $25,000) or imprisonment for up to 10 years, or both.

Section 11(3)(V) of the Capital Markets Act requires the Capital Markets Authority to ensure that processing of personal data in the operations of the capital markets is in accordance with the principles set out under the Data Protection Act, 2019.

The Capital Markets Licensing Requirements Regulations under Section 35(j) also requires a data protection policy in compliance with the relevant laws as an eligibility requirement for grant of a license to Intermediary Service Platforms.

Although the Capital Markets Act does not explicitly impose a duty to report data breaches these regulations indirectly require such reporting according to the Data Protection Act. The Data Protection Act in turn requires reporting of data breaches to the Data Commissioner within 72 hours.

What legislation, relating to both criminal offences and civil wrongs, covers such a breach?

The Data Protection Act, 2019 lays the statutory basis for data protection in Kenya, establishing the Office of the Data Protection Commissioner and laying regulations for the administration and protection of personal data in Kenya.

The Act creates a criminal offence of “unlawful disclosure of personal data”, which encompasses unauthorised access to personal data. This is punishable by a fine of Kenya Shillings 3,000,000/- (approx. $25,000) or imprisonment for up to 10 years, or both.

The ODPC can issue Enforcement Notices to direct data controllers/processors to comply with the Act. This mechanism may be used where a minor transgression is observed or anticipated. Failure to comply with an enforcement notice is a criminal offence, and offenders can face up to two years’ imprisonment or a fine not exceeding Kenya Shillings 5,000,000 (about $40,000). The ODPC can directly punish transgressions through Penalty Notices, which allow it to impose fines of up to Kenya Shillings 5,000,000/- (approx. $40,000) or one percent of the target’s turnover in the previous year, whichever is the lower. Enforcement and Penalty notices can be appealed through the High Court.

Furthermore, the Act’s complaints system allows aggrieved data subjects to bring complaints directly to the Data Commissioner for administrative action, including those affected by a personal data breach. A complaint may lead to an enforcement or penalty notice being issued.

The Act affirms a right to compensation available to persons who suffer damage resulting from any contravention of the Act, including data breaches. This civil liability may accrue to data controllers or data processors, and is drawn widely, to encompass non-financial loss e.g., emotional distress.

The Computer Misuse and Cybercrimes Act, 2018 labels systems of particular importance to the nation’s security, health, infrastructure, or economy as ‘critical information infrastructure’. Where a system has been designated so, the system controller must report incidents that threaten the system to the Computer and Cybercrimes Coordination Committee, established under the Act. They must also submit an annual compliance report to the Committee, detailing their compliance with a critical infrastructure framework. Failing to file a compliance report is a criminal offence punishable by a fine, jail time, or both.

"Dawn" raids

What agencies have the power to conduct dawn raids on private sector companies? What legislation gives those agencies the power to undertake those inspections?

A ‘dawn raid’ is defined as an unannounced visit by a law enforcement or regulatory body to a business premises when the business is unprepared. The law on dawn raids in Kenya is predicated on the powers of individual agencies, and in all cases framed by the rights and guarantees of the Constitution of Kenya.

The Constitution balances the fundamental right to privacy- including rights to not be searched without cause and to fair administrative action- with the duty of the State to guarantee national security and protect the rights and property of all the State’s subjects. In exercising their duties, agencies are bound to follow the law and to act upon specific legal provisions, ensuring that all searches are executed on a statutory basis.

Broadly, the Competition Authority of Kenya, the National Intelligence Service, the Kenya Revenue Authority, the Ethics and Anti-Corruption Commission, the Communications Authority of Kenya and the National Police Service- including detectives of the Directorate of Criminal Investigations (DCI)- have the authority to carry out raids on corporate premises for the purposes of satisfying their internal investigations or enforcing and deterring criminal acts. These agencies are enabled by the Competition Act 2010 (for the Competition Authority of Kenya), the National Intelligence Service Act, 2012 (for the National Intelligence Service); the National Police Service Act, Police Act, Criminal Procedure Code and Evidence Act (for the National Police and DCI detectives), the Tax Procedures Act (for revenue officers of KRA), the Kenya Information and Communications Act (for the Communications Authority of Kenya) and the Anti-Corruption and Economic Crimes Act (for anti-corruption officials).

Statutes often give investigative staff police powers to search and seize with a warrant. Broadly, this power includes the right to petition a Court for a warrant, the right to enter and search premises, and the right to seize certain articles and documents. Search powers must generally be exercised in accordance with (i) the provisions of the Criminal Procedure Code (CPC)- which regulates criminal procedure across law enforcement agencies- and (ii) the Act that facilitates their execution (i.e., for the Competition Authority, the Competition Act must be complied with).

Warrants issued under the CPC must contain certain information and obliges search officers to produce the warrant before commencing the search. Warrants must be executed “between sunrise and sunset” i.e., during daylight hours, although this condition can be varied by the issuing Court on the face of the warrant. It is prudent to ask for a copy of the authorising warrant when faced with a raid.

Officers are protected in the course of their duty by their respective Acts, which invoke the crime of obstruction of an officer. Criminal liability may accrue to those found guilty of assaulting, resisting, or wilfully obstructing an officer in the course of their duties, and cooperation with authorities is usually the best course of action during a search.

The Competition Authority of Kenya has power to conduct dawn raids on private sector companies. Further, the Competition Authority is empowered to carry out a search without a warrant pursuant to section 32 of the Competition Act No. 12 of 2010. If the Searching Officer (SO), or any other authorized person by the Authority or court, is satisfied upon receiving information that he has reasonable cause to believe that by reason of delay in obtaining a search warrant, the evidence would be adversely tampered with, removed, destroyed or damaged, the SO or any other authorized person may enter the premises and conduct the search in a manner as if he was authorized by the court to do so. They can only do this with a Search Order issued by the Director General of the Authority and must specify the intended date of the search, identify the place or persons to be searched, and specify the offence or circumstances in relation to which the search is being done.

The National Police Service Act 2012 also provides that (s. 57) a police officer may carry out a search of premises without a warrant where they reasonably believe that an offense is being committed and the delay in procuring a warrant may imperil an ongoing investigation. It further provides (at s. 60) that an investigating or senior officer may- without warrant- search any premises for and seize anything they suspect was used in committing a crime, where they believe that the delay involved in getting a search warrant would imperil the investigation.

Under the Capital Markets Act, the Capital Markets Authority has the power to conduct investigations and inspections to ensure compliance with the law. Section 11(3)(j) provides the Authority with power to conduct inspection of the activities, books and records of any person approved or licensed by the Authority.

Kenya Bureau of Standards through authorized inspectors. Section 14 of the Standards Act Cap 496 authorizes inspectors to enter upon any premises at which there is, or is suspected to be a commodity in relation to which any standard specification or standardization mark exists to inspect and take samples of a commodity or inspect any process or operation carried out in those premises in connection with the manufacture, production, processing or treatment of any commodity in relation to which a standard specification or a standardization mark exists.

Under section 30 of the Food, Drugs and Chemical Substances Act Cap 254, authorized officers under the Act may at any hour reasonable for the performance of their duty enter in any premises where any food, drug, cosmetic, device or chemical substance and any labeling or advertising materials in respect thereof; or (b)anything used for the preparation, preservation, packing or storing of any food, drug, cosmetic, device or chemical substance is prepared, preserved, packaged, stored or conveyed and examine any such article and take samples thereof, and (b) examine anything that he believes is used or capable of being used for such preparation, preservation, packaging or storing or conveying examine an prevent the alteration of food, drugs and chemical substances.

Under the Public Health Act Cap 242, Section 132 authorizes any medical officer of health, or other person duly authorized by the health authority in writing, at any time between 6am and 6pm to enter any premises used for the sale or preparation for sale or storage of food to inspect and examine any food therein which he has reason to believe is intended to be used as human food, and where such food appears to such officer to be unfit for such use, he has authority to seize the food.

Section 45 (2) of the Pharmacy and Poisons Act Cap 244 gives power to an authorized officer, if he has reasonable cause to believe that an offence against any provisions of the Act is being or has been committed on or in any premises, and if delay which would occur in obtaining a search warrant would tend to, defeat the purpose of the Act, to without such warrant to enter and search any such premises.

The National Environmental Management Authority (NEMA) has limitations to carrying out such searches by the Environmental Management and Co-ordination Act No. 8 of 1999 (EMCA).

On what bases, including privilege and/or confidentiality, may organisations refuse to permit the seizure of documents?

An organisation may refuse to permit the seizure of documents that are subject to legal professional privilege. Advocate client privilege codified in the Evidence Act, Cap 80, protects the concerned documents in the course of the investigation, which includes documents and communications made in confidence between the lawyer and the organisation for the primary reason of obtaining legal advice. The privilege applies equally to an Advocate’s servants and clerks. However, any communication made in furtherance of any illegal purpose; or (b) any fact observed by any advocate in the course of his employment as such, showing that any crime or fraud has been committed since the commencement of his employment is not protected from disclosure under the Evidence Act Cap 80.

Documents/translations created by an interpreter in the course of their work also attract the same privilege as those of Advocates.

The Competition Authority of Kenya Search and Seizure Guidelines provide that the Authority will be guided by the provisions of section 134 of the Evidence Act which provide for attorney client privilege when conducting searches.

Public interest/secrecy is another ground for refusing to produce documents, though this often requires some justification. Some statutes, like the Public Officers Ethics Act and the Official Secrets Act, criminalise the sharing of confidential information, and resisting production of documents deemed confidential by law is permitted.

Confidentiality is the weakest ground to resist production of documents, particularly where law enforcement officers are involved. They may consider such documents part of the scope of the investigation, and therefore included in the terms of a warrant.

The Anti-Corruption and Economic Crimes Act expressly provides that the subject of a search under that Act cannot be compelled to produce documents protected by advocates’ privilege. The Tax Procedures Act, under which Kenya Revenue Authority officers may search for and seize documents, expressly permits the seizure of documents notwithstanding their privileged, public interest or confidential status.

Under Section 33(D)(4) of the Capital Markets Act, the power in respect of any documents held by a bank when it comes to search and seizure are limited to the making of copies or extracts. Banks may refuse to permit seizure of documents on this basis.

Whistleblowing

What are the circumstances under which an employee is entitled to protection when reporting an alleged wrongdoing?

No single statute deals exclusively and exhaustively with whistleblower protections. The role of protecting informants, informers and whistleblowers Is shared among a range of other statutes, often on an offence-specific basis (bribery, corruption etc.). The most general legal provision for whistleblowers is contained in The Access to Information Act 2016 (‘the Act’). The Act enacts and enforces citizens’ right of access to information held by the state or information they require for the purposes of justice.

Section 16 of the Act protects those who disclose confidential information from penalty provided the disclosure is in the public interest ‘Public interest is specified as: “violations of the law, including human rights violations; mismanagement of funds; conflict of interest; corruption; abuse of public office; and dangers of public health, safety and the environment”. The law applies to both actual and prospective/potential disclosures, and to public and private entities. The disclosure must be made in good faith i.e., the informer must have a “reasonable belief in the veracity of the information. This is the only general basis on which a private-entity whistleblower can rely for protection for their disclosures, provided the information is about one of the specified violations.

The Bribery Act defines a whistleblower as “a person who makes a report to the [Ethics and Anti-Corruption] Commission or the law enforcement agencies on acts of bribery or other forms of bribery.” It applies to the public, public officers, and private entities. Although the starting point for whistleblower protection under the Bribery Act is the actual reporting to law enforcement agencies, the Act thereafter protects the whistleblower from essentially any intimidation or harassment resulting from the fact of their testimony, including through the Witness Protection Agency.

Under the provisions of the Anti-Corruption and Economic Crimes Act No. 3 of 2003, any person who discloses information or provides assistance to the Ethics and Anti-Corruption Commission or an authorized investigator in the course of their investigations is entitled to protection. The aforementioned law however states that this protection does not apply with respect to a statement made by a person who did not believe it to be true.

Therefore, under the provisions of the Anti-Corruption and Economic Crimes Act No. 3 of 2003, an employee who discloses information or aids the Ethics and Anti-Corruption Commission or an authorized investigator is the course of their investigations is entitled to protection as long as they believed the statements that they were making were true.

Further protections for those testifying before court or reporting to law enforcement agents as witnesses can be found in the Witness Protection Act, administered and enforced by the Witness Protection Agency.

Two ‘Whistleblower Protection Bills’- which propose extending and consolidating statutory protections for whistleblowers -have been in Parliament as members’ bills since at least 2021. They are unlikely to progress further without substantive government support.

Under the Capital Markets (Whistleblower) Regulations 2022 employees who report wrongdoings related to the capital markets are entitled to protection. To be entitled to this protection they must:

  1. Report in good faith and must have reasonable grounds for believing the alleged reported misconduct has occurred or will occur.
  2. Report conduct that is considered reportable misconduct under the regulations which includes failure to comply with legal and regulatory obligations as required under the Capital Markets Act and Regulations or conduct that amounts to capital markets fraud.
  3. Report information that is new and timely, authentic, complete, and relevant in that it makes a fact more probable than it would without.
  4. Certify to the best of their knowledge that the information provided is true and acknowledge awareness that it is an offence to submit false information.

Note that the Occupational Safety and Health Act No. 15 of 2007 states that an occupier shall not dismiss an employee, injure the employee or discriminate against or disadvantage an employee in respect of the employee’s employment, or alter the employee’s position to the detriment of the employee by reason only that the employee (a) makes a complaint about a matter which the employee considers is not safe or is a risk to his health; (b) is a member of a safety and health committee established pursuant to this Act; or (c) exercises any of his functions as a member of the safety and health committee.

What legislative protection does that employee enjoy?

The Bribery Act No. 47 of 2016 states that all persons, including employers are prohibited from dismissing, demoting, admonishing, or transferring whistle blowing employees to unfavorable working areas or otherwise harassing them and that contravention of this requirement constitutes an offence with such offender being liable upon conviction to a fine not exceeding one million shillings or to imprisonment for a term not exceeding one year or to both.

In addition to this, The Bribery Regulations, 2022 passed pursuant to the Act require private entities to establish appropriate measures for the protection from retaliation, reprisal or victimization of any person who reports, in good faith, any knowledge or suspicion of an act of bribery or corruption.

Furthermore, the Act as read together with the provisions Witness Protection Act 16 of 2006 states that a whistle blower shall be entitled to protection to such extent as may be determined by the witness protection agency. Such protection may include but is not limited to physical and armed protection; relocation within or outside Kenya; change of identity; or any other measure necessary to ensure the safety of a protected person.

The Act also states that every law enforcement agency shall put in place reasonable mechanisms to protect the identity of informants and any person who knowingly or negligently discloses the information of such informants and a result of which such informant is harassed or intimidated commits an offence and shall be liable upon conviction to a fine not exceeding one million shillings or to imprisonment for a term not exceeding one year or to both.

The Occupational Safety and Health Act protects whistleblowing employees by making it an offence for an employer to stating that discriminate against or disadvantage an employee in respect of a reporting made pursuant to the provisions of the Occupational Safety and Health Act.

The Employment Act No. 11 of 2007 states that no employer shall harass or directly or indirectly discriminate against an employee on any grounds or other matters arising out of employment. This may be read to include discrimination on account of an employee reporting of the irregularities/misconduct which take place during the course of their employment.

The Capital Markets (Whistleblower) Regulations 2022 provide protection to employees who report alleged wrongdoing in the capital markets. Specifically, Section 10 provides that a whistleblower’s identity and such other confidential information shall not be disclosed unless required by law or an order of the court and in accordance with the Witness Protection Act.

Section 16 of the Access to Information Act allows whistleblowers to bring a claim in tort where they are “penalised” as a result of their disclosure. ‘Penalty’ is widely drawn to include dismissal, discrimination, reprisal, adverse treatment, or denial of an appointment/promotion/benefit. The Bribery Act protects whistleblowers from being “intimidated or harassed” for providing information to law enforcement or from testifying in a court of law. This includes adverse treatment by an employer. Offenders may be jailed for up to a year and/or fined up to Kshs. 1,000,000/- (Approx. US $8,000). The Act requires every entity, public or private, to make appropriate policies and procedures for the handling of bribery and corruption-related complaints, which encompasses protection of whistleblowers. Failure to do so is a criminal offence, punishable with jail time or a fine for the controllers of the entity. Guidance published by the Ethics and Anti-Corruption Commission (EACC) recommends the adoption of specific procedures to maintain the confidentiality of whistleblowers; establish internal and external reporting channels; tackle retribution/threats against whistleblowers and engage the Witness Protection Agency, if required.

The Anti-Corruption and Economic Crimes Act (ACECA) protects whistleblowers from any “action or proceeding- including a disciplinary action” arising as a result of their collaboration with or disclosure of information to the Commission or other law enforcement body. This effectively extends near-total immunity to whistleblowers. Notably, the Act has extra-territorial effect; its jurisdiction extends to any act committed by a Kenyan citizen, regardless of where that act took place. Furthermore, informants’ identities are protected by ACECA, and no person may be compelled to give information that leads to the identification of an informant. There is a positive duty on Courts to remove any information from proceedings that may reveal an informant’s identity.

Anti-bribery and corruption

What are the main anti-corruption laws and regulations in your jurisdiction?

In Kenya, there are various laws/regulations/policies that address anti-corruption laws. They are as follows: 1. The Constitution of Kenya sets broad governance, anti-corruption, and ethics requirements, which apply to most public and private entities. 2. Anti-Corruption and Economic Crimes Act No 3 of 2003 of the Laws of Kenya. The main aim of the Act is to provide for the prevention, investigation and punishment of corruption, economic crime and related offences and other matters incidental thereto. The Act provides for the formation of the Kenya Anti-Corruption Advisory Board consisting of various members to be nominated from various bodies such as the Law Society of Kenya, the 3. Federation of Kenya Employers, the Central Organisation of Trade Unions among others. 3. The Ethics and Anti-Corruption Commission Act No 22 of 2011 of the Laws of Kenya –The Act provides for the functions and powers of the Ethics and Anti-Corruption Commission. The Act provides for the formation of the Ethics and Anti-Corruption Commission (EACC) tasked with, among other things, creating a code of ethics to be adhered to by public and state officers, receiving complaints on the breach of the code of ethics by public officers and recommending to the Director of Public Prosecutions appropriate action to be taken against State or public officers alleged to have engaged in unethical conduct. 4. The Bribery Act No. 47 of 2016 of the Laws of Kenya. The Act is to provide for the prevention, investigation, and punishment of bribery and for connected purposes. The Act establishes bribery offences in both the public and private sectors and applies to the public, public officers, and private entities. It further imposes a duty on private entities to have in place procedures that prevent bribery. 5. Proceeds of Crimes and Anti-Money Laundering Act No 9 of 2009 of the Laws of Kenya. The Act is to provide for the offence of money laundering and to introduce measures for combating the offence, to provide for the identification, tracing, freezing, seizure, and confiscation of the proceeds of crime, and for connected purposes. 6. The Public Officers Ethics Act sets standards for public officers in office through codes of conduct and identifies the commissions responsible for enforcing the codes in each area of government. It also requires certain officers to make disclosures of wealth and interests, boosting transparency.

Does the legislation have extra-territorial effect?

Yes, several of Kenya’s anti-corruption statutes are designed to catch acts outside Kenya. These include the Bribery Act, the Anti-Corruption and Economic Crime Act (ACECA) and the Proceeds of Crime and Anti Money Laundering Act.

According to Section 67 of the Anti-Corruption and Economic Crimes Act and Section 15 of the Bribery Act, the conduct by a citizen of Kenya or by a private or public entity which take place outside of Kenya shall constitute an offence if the conduct would constitute an offence under the Acts if it took place in Kenya. This provision is applicable to the conduct of private entities incorporated under the laws of Kenya in so far as the offence is committed outside the country.

The Proceeds of Crime and Anti Money Laundering Act permits the Attorney General of Kenya to request the cooperation of appropriate foreign agencies in anti-corruption investigations and proceedings, including collecting evidence, serving witnesses, and following illicit funds. These requests are made under the principles of mutuality and reciprocity, making it unlikely that they will be denied by a foreign state once made.

What are the main enforcement bodies?

The list: 1. The Ethics and Anti-Corruption Commission (EACC) is the primary anti-corruption enforcement body in Kenya, with a broad mandate to investigate corruption cases and to reduce corruption generally. The EACC is empowered to deputise other law enforcement bodies- such as the police- for help in carrying out its investigations, and EACC agents have their own police powers to search and seize articles and documents that may help with an investigation. 2. The Office of the Director of Public Prosecutions is established under the Office of the Director of Public Prosecutions Act No. 2 of 2013. The Office is tasked with bringing criminal charges on behalf of the State, and thus plays a central role in anti-corruption proceedings. Its task is unique and powerful as it has the sole mandate to bring prosecutions to court. 3. The Asset Recovery Agency established under the Proceeds of Crime and Anti-Money Laundering Act and is tasked with among other things, the recovery of proceeds of economic crimes including corruption. The Agency receives proceeds of crime that have been confiscated by court, manages the assets and returns them to the exchequer, where possible. The Asset Recovery Agency manages funds that receive property/proceeds forfeited by wrongdoers under Court orders. 4. The High Court’s Anti-Corruption and Economic Crimes Division deals specifically with economic crimes, granting warrants to search and seize, orders for restraint and confiscation, and hearing cases brought against alleged wrongdoers. 5. The National Police Service has a general mandate to fight crime, including economic crime and corruption. Its detective unit- the Directorate of Criminal Investigations (DCI) is particularly involved in the fight against corruption and its detectives frequently work alongside EACC officials. 6. The Kenya Revenue Authority has wide-ranging powers to fight corruption in tax matters and customs. It is obliged to hand over information on potential graft to the EACC and/or the Financial Reporting Centre. 7. The Financial Reporting Centre is also established under the Proceeds of Crime and Anti Money Laundering Act. It receives reports on and analyses suspicious transactions, on its own initiative or as reported by reporting institutions (which are primarily banks but may include advocates and accountants). It can require transactions be suspended to facilitate investigations and maintain registers of suspicious transactions and transactors. It also has the power to make inspections and forward those results to other enforcement bodies (e.g., Police, EACC)

Internal investigations

Is there any duty to report the issue, for example to a regulator?

This is a question of degree based on the nature of the alleged infringement and the type of investigation to be undertaken. There is no general requirement for companies to report that an internal investigation has commenced, but certain activities and events can give rise to specific reporting obligations on a statute-specific basis.

The Environmental Management Co-ordination Act (EMCA) requires a business that has undertaken a project that requires the submission of an environmental impact assessment report to make annual reports to the National Environmental Management Authority describing:

  1. how far the project conforms in operation with the statements made in the environmental impact assessment study report; and
  2. all reasonable measures to mitigate any undesirable effects not contemplated in the environmental impact assessment study report.

EMCA also requires that any person or business granted an environmental impact assessment licence to submit reports containing information relating to the licence, activities undertaken under the licence and conditions imposed under the licence to the National Environmental Management Authority after every six months or whenever the Authority may demand.

The Bribery Act imposes a duty on Public and Private entities to put in measures to prevent Bribery. Further, every state officer, public officer or any other person holding a position of authority in a public or private entity is required to report to the Ethics and Anti-Corruption Commission any knowledge or suspicion or instances of bribery within 24 hours, failure to which the person has committed an offence under the Act. This may attract a fine of up to Kenya Shillings 5,000,000/-, imprisonment for up to 10 years, or both. The Act also requires companies- both public and private- to establish anti-corruption/bribery measures proportionate to their size and function.

The Proceeds of Crime and Anti Money Laundering Act designates certain institutions as ‘reporting institutions’. These include banks and financial institutions, but also entails “designated non-financial businesses and professionals”, a category that includes accountants and notaries, among others. The Act requires reporting of cash transactions above a certain amount ($10,000) and transactions flagged as ‘suspicious’ to the Financial Reporting Centre.

The Prevention of Terrorism Act requires financial institutions to report transactions which they suspect of being connected to terrorism to the FRC.

The Data Protection Act requires reporting of data breaches to the Office of the Data Protection Commissioner (see notes on data breaches).

The Computer Misuse and Cybercrimes Act requires reporting of incidents that affect ‘critical information infrastructure’ systems to the Computer and Cybercrimes Coordination Committee.

The Capital Markets (Corporate Governance) (Market Intermediaries) Regulations, 2011 also impose a reporting duty to market intermediaries. When a director or an officer is assessed and found not to be fit and proper to work for the affected market intermediary, they have a duty to report to the Capital Markets Authority.

Under the Central Depositories (Regulations of Central Depositories) Rules a Central Depository also has a duty to report to the Capital Markets Authority incidences of violation of the Capital Markets Act or rules issued thereunder and any arbitration of issues undertaken.

The Employment Act No. 11 of 2007 provides for how employees should be treated during investigations. Under Section 40, in instances where an employer terminates a contract of service on account of redundancy and the employee is a member of a trade union, the employer is obliged to inform the union to which the employee is a member and the labour officer in charge of the area where the employee is employed of the reasons for, and the extent of, the intended redundancy not less than a month prior to date intended for termination.

Section 11 (1) of the Occupational Safety and Health Act No. 15 of 2007 imposes the duty to report on the safety and health advisor. It states that the occupier of a workplace shall cause a thorough safety and health audit of his workplace to be carried out at least once in every period of twelve months by a safety and health advisor, who shall issue a report of such an audit containing the prescribed particulars to the occupier on payment of a prescribed fee and shall send a copy of the report to the Director.

Section 12 (d) of the Occupational Safety and Health Act No. 15 of 2007 imposes the duty to report on a self-employed person. It states that every self-employed person shall report to the Director (i) any situation which he has reason to believe would present imminent danger or hazard and which he cannot correct; and (ii) any incident or injury that arises in the course of or in connection with his work, as required under this Act.

What is the protection from disclosure for documents generated as part of the investigation (for example, privilege)?

Advocates’ privilege or legal privilege bars the disclosure of communications between clients and advocates created “in the course and for the purpose of” the advocate’s employment. Advocates’ privilege applies equally to an advocate’s servants and clerks. Documents/translations created by an interpreter in the course of their work also attract privilege in the same way as advocates.

Litigation preparations also appear to be a convincing reason to refuse to hand over documents, and an extension of advocates’ privilege; Kenyan courts have cited with approval UK courts’ ruling on the matter.

Public interest/secrecy is another ground for refusing to produce documents, though this will have to be supported by some justification, or by a signed statement from the Cabinet Secretary in the relevant area, per the Evidence Act. Some statutes, like the Public Officers Ethics Act and the Official Secrets Act, criminalise the sharing of confidential information, and resisting production of documents deemed confidential by law is permitted.

Confidentiality, pursuant to a confidentiality agreement between the holder and another party, is another recognised ground for rejecting disclosure of documents. Courts have repeatedly protected this right.

Documents generated as part of investigation will not be disclosed if they are privileged. Advocate client privilege protects all communication and documents between an advocate and client created in the context of seeking legal advice.

According to the Ethics and Anti-Corruption Commission Act, members/employees of the commission shall safeguard privileged information that comes into their possession and protect it from improper or inadvertent disclosure.

Further the Proceeds of Crime and Anti-Money Laundering Act provides for the protection of information and informers relating to offences under the Act

Is the advice given by an in-house lawyer in relation to the investigation privileged and/or confidential?

While this particular issue has not been litigated in Kenya, persuasive judgments from the United Kingdom (UK) and other Commonwealth jurisdictions suggest that in-house counsel will be covered by advocate’s privilege. Tentatively, the privilege will extend to registered advocates giving legal advice in their role as legal advisors. It is submitted, therefore, that the privilege will not attach to mere business advice or by the very fact that in-house counsel is privy to the conversation; there must be some element of legal advice to the relevant communication. This is in agreement with the current state of UK law. Advice must meet the requirements of attorney client privilege that the communication is not made in furtherance of any illegal purpose and that a crime or fraud has not been committed since the commencement of the advocates employment by the client.

The Proceeds of Crime and Anti Money Laundering Act provides that an advocate shall not be obligated to disclose privileged information between the advocate and the client. This however only applies in connection with the giving of advice to the client in the course and for purposes of the professional employment of the advocate or in connection and for the purpose of any legal proceedings on behalf of the client However a Judge of the High Court may, on application being made to him in relation to an investigation under the Act, order an advocate to disclose information available to him in respect of any transaction or dealing relating to the matter under investigation. Notwithstanding this nothing shall require an advocate to comply with an order if the same breaches the privileged information disclosed in connection with the giving of advice to the client in the course and for purposes of the professional employment of the advocate or in connection and for the purpose of any legal proceedings on behalf of the client.

Disclaimer: This guide contains summaries of general principles of law. It is not a substitute for specific legal advice and should not be relied upon in relation to the application of the law or subject matter covered.