Infrastructure engineering for East Africa's operators, platforms and regulators See the work →
Building a Private Cloud in Kenya: What Each Sector Needs
Cloud 9 min read

Building a Private Cloud in Kenya: What Each Sector Needs

Building a private cloud in Kenya starts with which rule catches you. What banks, government, hospitals, universities and ISPs each actually need.

AH
Amina Hassan
Cybersecurity, Compliance, Network Security
19 August 2026
private cloudopenstackdata residencycompliance

Nobody in Kenya builds a private cloud to save money. They build one because somebody told them the data cannot leave the country, and the shortest path to satisfying that is hardware you can point at in a room you can name.

The instruction is usually right and almost always vague. Two separate instruments create in-country obligations here, they demand different things, and the one most local commentary quotes is the weaker of the two. CloudSpinx designs and runs private cloud platforms for organisations across Kenya and East Africa, and the first hour of every one of those projects goes on the same question: which rule catches you, and does it catch the whole estate or one system.

Which rule actually catches you

Route one is regulation 28 of the Critical Information Infrastructure Regulations 2024. Where a system is designated critical information infrastructure, the infrastructure that critical information sits on has to be located in Kenya. Putting it abroad means applying to the Committee on Form CMCA 3, which consults the National Security Council and has thirty days to decide. That is a permission, not a checkbox, and you may not get it.

Route two is regulation 26 of the Data Protection (General) Regulations 2021. Personal data processed for a strategic interest of the state must run through a server and data centre in Kenya, or keep at least one serving copy in a Kenyan data centre. Six purposes are listed: civil registration and legal identity, the conduct of elections, oversight of public finances, running a protected computer system, early childhood and basic education, and primary or secondary health care.

Most pieces written locally about data residency argue from the Data Protection Act alone and never mention regulation 28. That gets the answer backwards for exactly the organisations with the most at stake, because regulation 28 is the harder of the two and the only one that can refuse you.

Which Kenyan rule decides where a private cloud has to sit
Which Kenyan rule decides where a private cloud has to sitThree routes compared. If a system is designated critical information infrastructure, regulation 28 of the Critical Information Infrastructure Regulations 2024 requires the infrastructure to be located in Kenya, and putting it abroad means applying to the Committee on Form CMCA 3 with a National Security Council view and a thirty day decision. If instead the workload processes personal data for one of the six strategic interest purposes in regulation 26 of the Data Protection General Regulations 2021, storing one serving copy in a Kenyan data centre satisfies the rule without moving the primary. If neither applies there is no residency obligation at all, only the cross border transfer conditions. Most Kenyan organisations are in the third group and build in country for reasons that have nothing to do with the law.ROUTE ONEDesignated CIIreg 28, CII Regs 2024The infrastructure is located in KenyaOffshore requires Form CMCA 3 to the Committee, aNational Security Council view, 30 days to decide.ROUTE TWOStrategic-interest datareg 26, DP Regs 2021One serving copy in Kenya is enoughSix listed purposes, including basic education andprimary or secondary health care. Primary can stay out.NEITHEREverything elseno residency rulePut it where the workload wants itCross-border transfer still needs a lawful basis andrecords the Data Commissioner can ask to see.
Two different instruments, two different obligations. Regulation 28 wants the infrastructure here. Regulation 26 will accept one serving copy here. Knowing which one catches you is worth more than any hardware decision that follows it.

Designation attaches to a named system, not to an industry, so being in a gazetted sector is the start of the question rather than the answer to it.

The sectors are not a matter of opinion either. Gazette Notice 1043 of 31 January 2022 designated the systems, in five groups:

  • Telecommunications, which includes ISP fibre networks, internet exchange points, .ke domain and IP management, data centres and in-country cloud infrastructure, and platforms centrally hosting or processing email as a service
  • Electoral, judicial, education, health, food, water and land
  • Energy, transport and industry, ending with a line that reads "systems supporting operations of Industries operating in Kenya"
  • Banking and finance, from IFMIS and county revenue systems through banking and saving services, NSE trading, insurance, and the payment rails including M-Pesa, Equitel and KEPSS
  • Defence, security and public safety

Read that list and almost every serious organisation in the country appears somewhere. The restraint you need is that designation attaches to a named system, not to an industry. Being a bank does not designate your HR database. Whether a specific system is in scope is a question of fact for NC4 and your sector regulator, and any vendor who tells you across a boardroom table that you are definitely CII is guessing.

The serving copy is the cheaper answer, until it is not

Regulation 26 accepting a serving copy is the single most valuable line in Kenyan data law for anyone holding a cloud budget. It means a workload caught by that route does not have to move. Keep the primary where it already runs, land one serving copy in a Nairobi facility, and the obligation is met.

Regulation 28 does not work that way. It wants the infrastructure here. A serving copy is not the infrastructure.

A serving copy in Kenya, or the whole primary in Kenya
A serving copy in Kenya, or the whole primary in KenyaTwo placements side by side. Keeping the primary database in a foreign region and holding one serving copy in a Nairobi data centre satisfies regulation 26 of the Data Protection General Regulations, because that regulation accepts a serving copy in the country. It does not satisfy regulation 28 of the Critical Information Infrastructure Regulations, which requires the infrastructure itself to be in Kenya. Running the primary in one Nairobi facility with a replica in a second Nairobi facility satisfies both, and is the only one of the two shapes that survives a system being designated.PRIMARY OFFSHORECape Town or Frankfurtprimary databasereplicatedNairobi data centreone serving copyREG 26 METREG 28 NOT METCheaper, and it breaks on designation.PRIMARY IN KENYANairobi facility Aprimary, live workloadreplicatedNairobi facility Breplica, separate siteREG 26 METREG 28 METCosts more, and answers both instruments.
The cheap shape and the safe shape answer different rules. A serving copy clears regulation 26 and fails regulation 28, so it is only defensible while nothing you run is designated.

The gap between these two is usually the entire budget conversation, which is why the designation question belongs at the start of the project rather than in the security review at the end.

We have watched teams spend six months designing a full in-country build for a workload that only ever needed the copy, and we have watched the reverse, which is worse. Ask the designation question in week one.

What you are actually building

A private cloud is three controllers before a single tenant workload boots, and those three servers will never run anything of yours. The database underneath needs a majority to accept writes, so two controllers are genuinely worse than one. Then two facilities rather than one, because a replica in the same building is a backup with extra steps. Nairobi makes that workable: LINX Nairobi peers across iXAfrica, Africa Data Centres, PAIX and iColo, so a two-site design stays local instead of hairpinning through Europe. The money in a private cloud build moves rather than disappears when the licence goes.

One constraint outranks all of that. Whatever your core application vendor supports is what you can build. Ask for their disaster recovery topology in writing before anyone draws a diagram, because an elegant architecture the vendor will not support is an audit finding waiting to happen.

Banks, microfinance and SACCOs: the regulator sets the shape

Banking and saving services sit in the gazette, so this is the sector most likely to meet regulation 28 for real. CBK adds two constraints on top. Prudential guideline PG/16 treats business continuity and disaster recovery as material outsourcing needing prior approval, which means buying managed DR is itself a regulated act rather than a purchase you make quietly. PG/14 dictates geography: the recovery site cannot be the same building, and it goes outside the city centre if the head office is inside the city limits, with test reports before and after.

Then regulation 42 of the CII Regulations asks for something almost nobody has. Backup restoration events must be recorded, including who performed the restore and what was restored. Not a backup policy, a log of actual restores. That single clause is the most common gap we find, and it is why the security and compliance work usually starts before the hardware conversation rather than after it.

Government, counties and parastatals: the mail server is the leak

Three of the six strategic interest purposes in regulation 26 are government functions, and the gazette adds land registration, IFMIS, county revenue collection and the tax systems. Public bodies generally know this about their core applications.

Where it goes wrong is email. The gazette explicitly names platforms centrally hosting or processing email as a service, and a public body that moved its mail to a foreign suite has usually done so without anyone treating mail as personal data processing at all. Correspondence, attachments, HR files and citizen complaints all live there. Running your own mail platform is the reason a large share of Kenyan government bodies, parastatals and universities still run Zimbra, and the honest caveat is the same one we give everyone: under about fifty mailboxes with no residency requirement, a hosted suite is the better answer.

Hospitals and health systems: the constraint is the night shift

Health is caught twice. Regulation 26 names primary and secondary health care, and the gazette covers emergency care, inpatient and outpatient hospital systems, pharmaceutical and blood supply, and epidemic control. So the placement question is settled early and it is rarely the hard part.

The hard part is that a hospital information system has to work at three in the morning when the fibre is cut and nobody technical is in the building. That pushes the design toward local compute with local storage, and it pushes the operating model toward somebody being reachable and accountable at that hour. A private cloud with no managed operations behind it is a rack that fails quietly. We would rather sell a smaller build with a real support arrangement than a bigger one nobody watches.

Universities: check what you already have first

Education is in both instruments, though read regulation 26 carefully, because it names early childhood and basic education rather than higher education. For most universities the residency question is softer than they assume.

Before commissioning anything, look at what your membership already buys. KENET runs community cloud and disaster recovery out of data centres at USIU, UoN and CUEA, with published prices before tax: 1U of colocation or a terabyte of offsite backup at KES 5,000 a month, a virtual server with 8 GB and 2 vCPU at KES 11,240. If that covers your recovery site, take it, and we will tell you so on the call rather than after the quote. Where a build is genuinely worth it is self-service for departments: research groups spinning up their own machines against a quota. That is a platform question, and for a single team with a single cluster it is usually answered by Proxmox rather than OpenStack.

Industry appears in the gazette through that broad "operations of Industries operating in Kenya" line, and food and water production have their own entries, so a large food processor should ask the designation question seriously. Most manufacturers and distributors will not be designated, and their real constraint is nothing to do with residency.

It is the link. A plant floor, a warehouse scanner or a till does not care where the server is until the circuit drops, and then it cares about nothing else. The March 2024 subsea cable cuts made that argument better than any vendor slide. If your ERP runs the warehouse, the question is what happens to picking, dispatch and invoicing during four hours with no path out of the country, and the answer is usually a local instance with a second circuit rather than a private cloud.

ISPs, hosting providers and telcos: you are selling it, not buying it

This sector is different because the cloud is the product. Telecommunications leads the gazette, and data centres and in-country cloud infrastructure are named in it, so an operator building capacity here is inside the framework by definition.

What changes technically is multi-tenancy. Isolation between customers, quotas, per-tenant networking and a self-service API are the whole offering, and that is the point where OpenStack earns its complexity instead of adding it. Most operators pair it with a managed Kubernetes platform for tenants who want containers rather than machines, because losing those customers to a hyperscaler is how the margin goes.

The three ways these builds fail

Procurement runs ahead of design. A tender specifies server models and core counts before anyone has asked the core application vendor what topology it supports, and the hardware arrives constraining an architecture that has not been drawn.

The recovery site is never proven. It exists, it is powered, it has been paid for, and no one has completed a restore from it. Under PG/14 and regulation 42 an untested site is not a recovery site, it is an asset.

Residency gets treated as a legal opinion rather than an input. Counsel produces a memo in month five, and the memo says the primary has to be in Kenya. Everything built by then is now a migration.

None of those are technical failures. They are sequencing failures, and sequencing is cheap to fix at the start.

Send us the systems you believe are designated and the ones you are unsure about, and we will come back with a placement, a platform and one monthly figure to run it. Use the scoping form or WhatsApp +254 713 403 044. The scoping call is free, it commits you to nothing, and if the answer is that you need one serving copy rather than a private cloud, that is what we will tell you.

WhatsApp