Infrastructure engineering for East Africa's operators, platforms and regulators See the work →
What a Managed IT Contract in Kenya Must Cover
IT Strategy 7 min read

What a Managed IT Contract in Kenya Must Cover

A managed IT contract in Kenya has to name who is data controller, who is processor, and two breach clocks in hours. The clauses to read before signing.

CT
CloudSpinx Team
Cloud, DevOps, Security, ERP, Managed IT
5 September 2026
managed ITIT contractsdata protectionSLA

Read the clause that says who the data controller is. If your managed IT contract does not have one, you have found the most expensive gap in the document, and it is nowhere near the page with the price on it.

CloudSpinx runs managed IT for organizations in Kenya and across East Africa, which means we sign these agreements from the supplier side and read a lot of them from the buyer's side while a client is switching away from somebody else. The pattern barely changes. The service description runs three pages, the commercials are precise to the shilling, and the parts Kenyan law actually specifies are either missing or lifted from a template written for another jurisdiction.

You are the controller. Your provider is the processor

That allocation is not a negotiating position. It follows from who decides why personal data gets processed, and you decide that: your staff records and your customer database exist because you say so, and a provider acts on your instructions. So you are the data controller, we are the data processor, and the Data Commissioner writes to you when something goes wrong.

Section 42(2) of the Data Protection Act requires that relationship to sit inside a written contract, and regulation 24 of the General Regulations sets out what the contract has to carry:

  • the subject matter, duration, nature and purpose of the processing, the type of personal data and the categories of data subjects
  • that the processor acts only on the controller's instructions
  • a confidentiality commitment from any third party the processor brings in
  • the technical and organizational security measures
  • deletion or return of the personal data when the contract ends
  • the controller's right to audit and inspect

The agreements we read during a switchover are almost always strong on confidentiality and quiet about instructions, audit rights and deletion. That last one is the one that bites, because a provider you left three months ago is still holding a copy of your HR data in a backup that no clause ever put an end date on.

The exposure stays with you regardless. The Data Commissioner can serve an enforcement notice requiring the problem to be fixed (section 58) and impose a penalty by notice (section 62), and section 63 caps that penalty at five million shillings or 1% of annual turnover for the preceding financial year, whichever is lower. For most businesses here the cap is therefore a function of turnover rather than the headline figure: at KES 200 million of turnover the ceiling is KES 2 million, not KES 5 million. Determinations are published by year, and the respondents are ordinary companies, an insurance broker, a recruitment firm, a credit provider, a restaurant business. Reading three of them is a better hour than reading another vendor comparison.

The two breach clocks, and the one your contract has to beat

Two deadlines live in section 43 of the Act and they are not the same deadline. A data processor that becomes aware of a personal data breach must tell the controller without delay and, where reasonably practicable, inside 48 hours. A data controller must notify the Data Commissioner without delay and inside 72 hours of becoming aware, and a filing that arrives late has to carry the reasons for the delay.

Nothing starts your 72 hours until you know.

Two breach notification clocks, and the 48 hours your contract owns
Two breach notification clocks, and the 48 hours your contract ownsTwo statutory clocks drawn on one 120 hour scale. The upper clock is the data processor duty under section 43(3): a provider that becomes aware of a personal data breach has up to 48 hours, where reasonably practicable, to tell the controller. The lower clock is the controller duty under section 43(1)(a): 72 hours from its own awareness to notify the Data Commissioner. The two clocks run in sequence rather than together, so the sections allow up to five days between a provider noticing a breach and the regulator hearing about it, and the first 48 hours of that are governed by whatever the contract says.THE PROVIDER'S DUTY · S.43(3)processor tells the controller0hthe provider becomesaware of a breach48houter limit, and onlywhere practicableTHE CONTRACT DECIDES THISAND ONLY THEN YOURSYOUR DUTY · S.43(1)(A)your 72 hours to notify48hyou become aware,so your clock starts120hData Commissionernotified
  • the provider's window
  • your 72 hours
The clocks run in sequence, not together. Read strictly, the two sections allow five days between a provider noticing a breach and the regulator hearing about it, and the first 48 hours belong to your contract.

Both clocks start at awareness, not at compromise. Nothing in section 43 runs while a breach sits undetected, which is why detection is a contract term as much as notification is.

Which is why a contract promising to notify you "promptly" or "as soon as reasonably possible" is worse than it looks. It converts a statutory 48 hours into an adjective, and the argument about what the adjective meant happens while your own clock is running. Name a number instead, put it in hours, and name the person who drafts the notification, because the first filing is a technical document about what was accessed and what has been contained. The people who can write it are the ones holding the logs.

Read the trigger closely too. The duty in section 43(1) is set off by unauthorized access or acquisition where there is a real risk of harm to the data subject, not by every security event on the network. A provider offering to report everything to the regulator on your behalf has misread the section, and over-reporting carries its own cost.

The clause that makes either clock mean anything is the one naming who is watching at 02:00 on a Sunday. On most agreements we read, security monitoring is a separate line item from patching and helpdesk, priced separately or not sold at all, and nobody points that out during the demo.

Response time is not resolution time

SLA tables in this market publish one number and let the reader assume it covers both. A one hour response means an engineer is working on it inside the hour. It says nothing about when a dead disk controller becomes a working server again, which depends on a spare part in a store somewhere, and a provider who promises you a resolution time on hardware is quoting a number they do not control.

What a contract can commit to is the response clock, the update cadence while an incident runs, who it escalates to by name, and whether anybody arrives on site. Ours are published rather than negotiated per client: one hour for a system-down incident around the clock, two hours for degraded service, same day on site in Nairobi where the job needs hands. Ask for the update interval as well. The second hour of an outage is when a client stops caring about the response target and starts caring about whether anyone is going to tell them anything.

Then read the exclusions, which is where the scope really lives. Whether outsourcing beats a hire is a separate question with its own arithmetic. This one is narrower: does the thing you are about to sign include the work you believe you are buying.

Two people going line by line through a printed service agreement, the cheapest place to find a missing clause

The sub-processors you never signed with

Your provider's tooling is somebody else's cloud. The monitoring agent on every laptop, the backup target, the ticket system holding your staff names and phone numbers, sometimes a night shift in another country. Regulation 24 requires the processor to obtain a confidentiality commitment from any third party it engages, and the processor stays liable to you for that third party's compliance. Correct allocation, and completely invisible unless the contract carries the list.

Ask for the list, then ask where the backup copy physically sits. Regulation 26 covers processing tied to a strategic interest of the state, which it defines to include education, health, public finances, civil registration and protected computer systems, and it requires either a server or data center in Kenya or at least one serving copy held in one. A school or a clinic that works this out after the backups are already in Frankfurt is looking at a migration rather than an amendment. Where data can legally live in this region is the wider version of that, and proving you can get the data back belongs in a recovery plan somebody has tested rather than in a support agreement.

What the exit clause has to say, written while everyone is still friendly

Credentials in your own password manager, in your ownership, from onboarding rather than at termination. Documentation, diagrams and monitoring configuration handed over as they are produced. Then regulation 24's deletion obligation with a date attached, so the copy of your data sitting in a former provider's backup has a point at which it stops existing.

That is how we scope managed IT support, and it is not generosity. It is the only version that survives a bad breakup. A provider holding the keys has priced the trap into the deal and you are the one paying for it, every month, in a line item that looks like support.

If you only get one round of redlines

Spend it on two clauses and let the rest go.

The first is the controller and processor allocation, with regulation 24's six particulars annexed rather than paraphrased. The second is an incident clock stated in hours, well inside the statutory 48, with a named person who writes the filing. Everything else on those pages is a commercial negotiation you can reopen at renewal. Those two decide what happens on the worst day of the year, and neither costs your provider anything except a willingness to be specific.

Send us the agreement you are about to sign, or the one you cannot get out of, and you get back the clauses we would change and why, in writing. No charge, and no expectation that you move the account. The scoping form is the quickest route, or WhatsApp +254 713 403 044 if you would rather describe the situation than fill in fields.

WhatsApp