# Kenya

> Kenya (Capital Markets Authority · Central Bank of Kenya · Data Protection Commissioner): The ban written into primary legislation, not a rulebook. Region: Middle East & Africa. Restricts anonymity: Anonymity-enhancing assets or unattributed transfers are barred outright, or barred for regulated firms.

Part of the Soda Labs Privacy Hub regulation map, which reads the instruments
themselves rather than summarising the summaries: https://www.sodalabs.xyz/privacy-hub/regulation

## Key facts

- Entry type: Jurisdiction
- Region: Middle East & Africa
- Subject: The ban written into primary legislation, not a rulebook
- Authority: Capital Markets Authority · Central Bank of Kenya · Data Protection Commissioner
- Stance on on-chain confidentiality: Restricts anonymity. Anonymity-enhancing assets or unattributed transfers are barred outright, or barred for regulated firms.
- Tags: statutory ban, mixers, anonymity-enhancing services, criminal penalty
- Canonical page: https://www.sodalabs.xyz/privacy-hub/regulation/jur-kenya

## What it actually says

Most prohibitions in this section live in rulebooks that a regulator can amend without going back to a legislature. Kenya's does not. The 2025 Act puts the restriction in primary law: a service provider may not undertake mixer or tumbler services, or anonymity-enhancing services, with the latter defined broadly enough to reach any transaction whose effect or intention is to conceal information. Breach is a criminal offence. That drafting choice matters more than its content, because it sets a much higher bar for reversal than the Gulf rulebooks that reach a similar result. Note also what the definition catches: it turns on effect, not on the name of an asset, so it is technique-neutral by design.

## The instruments that matter

- **Virtual Asset Service Providers Act, No. 20 of 2025**: assented 15 October 2025, gazetted 21 October and commenced 4 November 2025, amending the Capital Markets Act, the Central Bank of Kenya Act and the anti-money-laundering statute
- **Section 21(1)(a)**: a provider shall not undertake mixer or tumbler services or anonymity-enhancing services, the latter defined as transactions with the effect or intention of concealing information
- **Criminal, not administrative**: breach is an offence under section 40(3), which makes this materially harder to reverse than a regulator-made rule
- **Split supervision under section 5**: custody, payments and stablecoin issuance to the central bank; exchanges, brokerage, tokenisation and offerings to the markets authority

## Sources

- [VASP Act No. 20 of 2025](https://new.kenyalaw.org/akn/ke/act/2025/20)
- [VASP Regulations 2026, Legal Notice 134](https://new.kenyalaw.org/akn/ke/act/ln/2026/134)

## Related entries

- [Bahrain](https://www.sodalabs.xyz/privacy-hub/regulation/jur-bahrain): A listing test written against effects, not asset names
- [Qatar](https://www.sodalabs.xyz/privacy-hub/regulation/jur-qatar): Exclusion by perimeter rather than prohibition
- [South Africa](https://www.sodalabs.xyz/privacy-hub/regulation/jur-south-africa): A travel rule that starts at any value above zero
- [United Arab Emirates](https://www.sodalabs.xyz/privacy-hub/regulation/jur-uae): The most explicit prohibition anywhere in this section
- [Ghana](https://www.sodalabs.xyz/privacy-hub/regulation/jur-ghana): The regulator that put self-custody in writing
- [Israel](https://www.sodalabs.xyz/privacy-hub/regulation/jur-israel): Light on-chain, heavy on data protection
