A curated starting point for the Kenyan rules and official materials shaping payments, data protection, digital credit and financial-crime compliance.
How to use this page
Each entry links to a primary regulator or Kenya Law source and highlights a practical issue for management. It is not a complete statement of law or a substitute for advice.
7 monitored frameworks · Last legal review 20 July 2026
CBKPayments
National Payment System framework
The National Payment System Act and Regulations form the core Kenyan framework for payment systems and payment service providers.
Why it matters
Map the actual funds flow and service against the statutory perimeter before launch or structural change.
The Data Protection (General) Regulations identify processing operations associated with high risk, including certain automated decisions, biometrics, sensitive data, dataset matching and innovative technology.
Why it matters
Document the screening decision even where the conclusion is that a formal DPIA is not required.
Kenya’s Financial Reporting Centre states that reporting institutions must comply with applicable AML/CFT measures under POCAMLA and the Regulations.
Why it matters
Confirm reporting-institution status and translate obligations into risk-based onboarding, monitoring, escalation, reporting and recordkeeping controls.