Kenya is moving closer to joining the Budapest Convention on Cybercrime, a treaty that could make it easier for the country to work with foreign authorities investigating crimes that cross borders and digital networks.
The potential partners include countries such as the United States, the United Kingdom, Israel, and Germany. Joining does not necessarily mean handing foreign governments unrestricted access to Kenyans’ private messages or online accounts.
Since the Convention was built as a criminal-justice cooperation tool rather than a data-sharing pipeline, it works through defined legal channels, tied to specific investigations, not a standing arrangement for pulling anyone’s data on request.
The more complicated question is what safeguards get built around that cooperation once it starts.
What Is the Budapest Convention?
The Budapest Convention is an international framework for fighting cybercrime and handling electronic evidence across borders, setting common standards for offenses such as illegal access to computer systems, data interference, and online fraud.
It creates mechanisms for countries to cooperate when evidence sits outside their borders, since a Kenyan investigation might involve data held on a server in another country, while a foreign investigation could need information held here.

The Convention offers tools for preserving electronic evidence, sharing specified data through mutual legal assistance and setting up 24-hour contact points for urgent cross-border requests, all subject to the Convention itself and to each country’s domestic law.
Kenya was invited to accede in October 2024, and the Council of Europe’s current records still list it as a country invited to accede rather than a member.
This means the accession process has to be completed before the treaty applies here. The Cabinet approved the move in February, and Parliament is being asked to endorse it.
What Kenya Stands to Gain
The clearest benefit is speed.
Cross-border cybercrime cases get slowed down by geography; a fraudster may operate from one country, target victims in another, and rely on a platform whose servers sit somewhere else entirely.
Joining would give Kenyan investigators more established channels for requesting evidence abroad and give foreign authorities a similar route in, useful against SIM-swap fraud, ransomware, and account takeovers spread across jurisdictions.
Kenya already has a preview of that value through a different channel: INTERPOL’s Operation Red Card 2.0, an 8-week, 16-country effort spanning December 2025 to January 2026, produced 651 arrests, including 27 in Kenya tied to investment scams built on fabricated account statements.
INTERPOL credited intelligence-sharing as a key factor that gave a preview of what treaty-backed cooperation could add.
What Cross-Border Access Requires
Electronic evidence can include subscriber information, traffic data, and in some investigations, the actual content of communications. Could a chat or location history end up in a request?
Potentially, yes.
However, a foreign police officer cannot simply fire off one request and receive a Kenyan citizen’s entire digital history in return.
Requests, ideally and in practice, attach to specific criminal investigations, run through domestic law and established safeguards, and Kenya can refuse cooperation on grounds including sovereignty, security, or public order.
The real concern is not automatic mass surveillance; it is whether faster cooperation could erode privacy protections if the process behind it stays vague or poorly supervised.
Where Kenya’s Laws Come In
The Computer Misuse and Cybercrimes Act already sets out cybercrime offenses and investigative mechanisms, the Data Protection Act regulates how personal data gets processed, and the Constitution protects the privacy of communications directly.
Accession should slot into that existing framework rather than replace it. The real question is how these laws will apply once a foreign authority requests evidence held in Kenya, whether Kenyan courts, the Data Protection Act, or the Cybercrimes Act’s own procedures take precedence in shaping what gets handed over.
In March 2026, the Court of Appeal struck down two provisions of the Cybercrimes Act in Bloggers Association of Kenya v. Attorney General, finding them overly broad enough to risk catching satire and ordinary opinion, a reminder that enforcement cannot override constitutional freedoms.
The Sovereignty and Privacy Trade-off
There is a genuine trade-off in joining.
Kenya gains stronger access to international cooperation against criminals operating abroad but becomes more entangled in a system where foreign investigations can seek evidence connected to Kenyans, making oversight the deciding factor in:
- Who authorizes a request
- What gets disclosed
- Whether a court signs off
- How involved the Data Protection Commissioner is
The Convention does not hand over Kenya’s digital sovereignty or throw open everyone’s chats, but the privacy concerns are still real, since faster, more routine cooperation exposes weak safeguards at scale.
Kenya already investigates cybercrime across borders. The real question is whether it can achieve those benefits while maintaining the standards that govern their use.



























