Regulatory Radar

Watch the framework. Understand the action.

A curated starting point for the Kenyan rules and official materials shaping payments, data protection, digital credit and financial-crime compliance.

How to use this page

Each entry links to a primary regulator or Kenya Law source and highlights a practical issue for management. It is not a complete statement of law or a substitute for advice.

7 monitored frameworks · Last legal review 20 July 2026
CBKPayments

National Payment System framework

The National Payment System Act and Regulations form the core Kenyan framework for payment systems and payment service providers.

Why it matters

Map the actual funds flow and service against the statutory perimeter before launch or structural change.

View primary source
CBKLicensing

PSP authorisation checklist

CBK’s published checklist identifies preliminary engagement and application materials for prospective payment service providers.

Why it matters

Treat authorisation as an evidence-and-operating-readiness project, not only a form-filing exercise.

View primary source
ODPCPrivacy

Data protection impact assessments

Section 31 of the Data Protection Act requires a DPIA before processing likely to create high risk to individuals’ rights and freedoms.

Why it matters

Screen products early enough for risks and safeguards to influence design, procurement and contracts.

View primary source
ODPCPrivacy

High-risk processing indicators

The Data Protection (General) Regulations identify processing operations associated with high risk, including certain automated decisions, biometrics, sensitive data, dataset matching and innovative technology.

Why it matters

Document the screening decision even where the conclusion is that a formal DPIA is not required.

View primary source
ODPCData transfers

Cross-border data transfers

ODPC guidance addresses risk assessment and safeguards where personal data is transferred outside Kenya.

Why it matters

Map hosting, remote access and subprocessors instead of assuming that the main vendor’s address identifies every transfer.

View primary source
FRCAML/CFT

Reporting-institution compliance

Kenya’s Financial Reporting Centre states that reporting institutions must comply with applicable AML/CFT measures under POCAMLA and the Regulations.

Why it matters

Confirm reporting-institution status and translate obligations into risk-based onboarding, monitoring, escalation, reporting and recordkeeping controls.

View primary source
CBKDigital credit

Digital Credit Providers Regulations

The 2022 Regulations provide for CBK licensing and oversight of digital credit providers within their scope.

Why it matters

Assess the complete credit model, customer journey, data use, pricing and collection arrangements before market entry.

View primary source
Have a matter in mind?

Let’s build your next legal strategy.

info@snnyagaadvocates.co.ke+254 728 852 448Westpark Towers, 11th Floor, Mpesi Lane, Westlands, Nairobi
Book a consultation