Seven years is the easy half of Kenya's VASP record-keeping rule
Two obligations, not one
Kenya's Virtual Asset Service Providers Act, 2025 (Act No. 20 of 2025) has a record-keeping section that is usually summarised in four words: keep records seven years. Section 44(2) does say that — records at the principal place of business for not less than seven years. Section 44(1) carries a second obligation that is much harder to build, and it is almost never in the summaries: the records must be reachable by online or automated real-time read-only access on demand.
The distinction is architectural, not drafting colour. A retention period can be satisfied with an archive, a backup policy and a restore procedure measured in days. Read-only access on demand cannot. It is a standing interface into live systems, with an access model, an audit trail of the regulator's own reads, and someone accountable for it. Firms that treat section 44 as a retention rule tend to discover the second limb late, when it is a build and not a policy edit.
Where the seven years comes from, and how often
Seven years is not one rule that you cite once. Read end to end, the gazetted regulations — Legal Notice No. 134 of 2026, made 3 July 2026 by the Cabinet Secretary to the National Treasury and published in Kenya Gazette Supplement No. 185 (Special Issue 4253), Legislative Supplement No. 103, of 22 July 2026 — impose it in at least five separate places:
- reg. 22(1)(b), transaction records;
- reg. 26, the audit trail, which must also be securely stored;
- a trading-platform provision immediately preceding reg. 54, at sub-regulation (4) — we hold the text but have not confirmed the regulation number, so verify it in the gazette before you cite it;
- reg. 110(4), complaints records;
- a monies and virtual-asset ledger provision at page 54 of the gazette — text confirmed, number not.
Above those sits the statute itself at s.44(2). Beside them sits the anti-money-laundering track: under the Proceeds of Crime and Anti-Money Laundering Act (Cap. 59A), s.46(4) requires records for at least seven years from completion of the transaction or termination of the business relationship, and s.44(5) requires findings to be retained for seven years. That track applies to virtual asset service providers because the VASP Act 2025 Schedule inserted them into the s.2 definition of a reporting institution, with effect from 4 November 2025.
Why a policy that cites one rule reads as incomplete
A retention schedule anchored to a single regulation is the most common way this obligation is under-drafted. Different record classes sit under different provisions with different owners: transaction data, audit trails, trading records, complaints files and AML findings are not one repository and rarely one system. A reviewer reading a retention policy is checking whether the firm found all of the places the obligation lives, and whether each class has a named owner and a stated deletion control at the end of the period.
Kenya's seven years is also not the longest period a group will face. Brazil's assurance annex for virtual asset providers requires suspicious-transaction dossiers to be formalised with ten-year retention, so a group operating in both markets sets its floor by the longer rule and documents why.
What the real-time limb implies
Two things follow, and both are design decisions rather than paperwork. First, ownership: LN 134 requires a chief information security officer — that appears in the gazetted text, at page 56, and was not in the National Treasury draft circulated in March 2026. The read-only access path is the kind of control that role is expected to own. Second, data protection: the records in scope contain personal data, so the access design has to sit consistently with the Data Protection Act 2019 (No. 24 of 2019) and its 2021 General Regulations. The regulations do not prescribe how the two are reconciled, and we do not suggest a settled answer here; it is a question to work through and document, not to assume away.
The timing
The compliance deadline is 4 November 2026, under s.47 of the Act. There is no transitional provision, no savings clause and no deemed-licensing regulation anywhere in the 151 regulations of LN 134. As at the date of this article the application window had not opened. Systems obligations of this kind are the ones least able to absorb a short window, which is the argument for building against them now rather than after a form appears.
Checking this yourself
Two retrieval traps. The Kenya Law record for LN 134 is a PDF-only record with no HTML body, which is why so much of the market quotes commentary rather than the notice. And the version URL ending eng@2025-07-22 that circulates in search indexes is wrong and returns a 404 — the working version date is 2026-07-22. When you cite the notice, cite both the Gazette Supplement number (185) and the Legislative Supplement number (103); Kenyan supplements carry both and sources quote one or the other.
The checklist behind this article
Our Kenya VASP readiness checklist covers the licence file the way a reviewer reads it — every item cited to its regulation, every figure marked as instrument text or as reporting of it, and the points that are still genuinely open (including the application form and the window) marked as open rather than guessed. USD 79, and updated editions are free as the position develops.
If your record classes and regulator all sit in one place, the checklist is the whole of what you need. If you are licensed across both CBK and CMA categories, or running Kenyan records inside a group system held offshore, the 48-hour gap check exists for that narrower case.