Computer Misuse and Cybercrimes Act, 2018 (No. 5 of 2018)
ke-cyber-2018 · Act
The Computer Misuse and Cybercrimes Act, 2018 (Act No. 5 of 2018) is Kenya's principal cybercrime statute. It was assented to on 16 May 2018 and commenced on 30 May 2018, although 26 sections (chiefly the content/speech offences) were suspended by the High Court following a constitutional challenge by the Bloggers Association of Kenya; the suspension was lifted in February 2020 when the Court upheld the provisions, bringing the whole Act into force. The Act's stated purpose is to create offences relating to computer systems and to enable the timely detection, prohibition, prevention, response, investigation and prosecution of computer and cybercrimes, and to facilitate international cooperation. The Act criminalises unauthorised access (with aggravated forms where committed with intent to commit a further offence or against protected/critical systems), unauthorised interference with data or systems, unauthorised interception, illegal devices and access codes, and computer-related forgery and fraud. It contains a significant set of content and communication offences, including false publications, publication of false information, cyber-harassment, cyber-stalking, wrongful distribution of obscene or intimate images, and child pornography, which carry the Act's most significant digital-rights and free-expression implications. It also addresses cyber-espionage, identity theft and impersonation, SIM-card and telecommunications-related fraud, and phishing. On procedure, the Act equips investigators with powers to apply for search and seizure of stored computer data, production orders, expedited preservation of data, real-time collection of traffic data and interception of content data under judicial authorisation, and obligations on service providers to preserve and disclose data. Part V provides for international cooperation, including spontaneous information-sharing, mutual legal assistance, extradition and cross-border preservation requests, reflecting alignment with the Budapest Convention framework. Institutionally, the Act establishes the National Computer and Cybercrimes Co-ordination Committee (NC4), composed of senior public officers, to coordinate national cybercrime and cybersecurity policy, advise on critical information infrastructure, and oversee implementation; investigation and prosecution remain with the National Police Service and the Office of the Director of Public Prosecutions. Unauthorised-access and data-interference offences give the Act a clear data-protection overlap with the Data Protection Act, 2019.
- Criminalises unauthorised access, with aggravated penalties where committed to facilitate a further offence or against protected computer systems.
- Establishes offences of unauthorised interference and interception of data or systems, and illegal possession of devices/access codes.
- Creates contested content offences, false publications, publication of false information, cyber-harassment and cyberstalking, with significant free-expression implications (26 sections initially suspended, upheld 2020).
- Provides for computer-related fraud and forgery, identity theft, SIM-related fraud and child pornography offences.
- Grants search-and-seizure, production orders, expedited data preservation and real-time traffic/content interception under judicial authorisation.
- Provides for international cooperation, mutual legal assistance and cross-border data preservation.
- Establishes the National Computer and Cybercrimes Co-ordination Committee (NC4) to coordinate national cybercrime policy and CII protection.