Kenya’s A2P (Application-to-Person) SMS service is governed by a two-tier regulatory system: the upper tier consists of the “Kenya Information and Communications (Consumer Protection) Regulations, 2025”, while the lower tier comprises the “Consumer Protection Guidelines and Customer Care Standards” issued by the Communications Authority of Kenya (CA) in 2022. In July 2025, the Ministry of Information, Communications and the Digital Economy of Kenya released the new version of the regulations to replace the 2010 version. The regulations are designed to protect the interests and well-being of consumers in the information and communications sector.
1. User Consent: Opt-In as an Absolute Prerequisite
Article 15 of the 2025 Regulations specifically addresses “unsolicited communications”. The regulations explicitly require that all direct marketing programs must be based on the opt-in principle. Article 6.2.2.3 of the Guidelines further stipulates that service providers must maintain records to prove that consumers have actively initiated subscription requests via their MSISDN (mobile phone number). For customers who have not consented to receive marketing communications, service providers may only inform them of the existence of SMS services through non-SMS channels such as newspapers, television, and radio.
2. Sending Time Window: 7:00 a.m. to 7:00 p.m.
Article 6.2.2.5 of the Guidelines clearly specifies that marketing communications sent via SMS may only be delivered between 7:00 a.m. and 7:00 p.m. Exceptions apply where: the marketing communication is a response to a user’s actively initiated request and is sent within the time window when the user made the request; or the user has explicitly given prior consent to receiving messages outside the specified time.
3. Do Not Disturb (DND) Registry
Article 6.2.2.6 of the Guidelines requires all National Facility Providers (NFPs) at Tier 1, 2 and 3 to either establish their own “Do Not SMS, Do Not Call, Do Not Spam, Do Not Disturb” registry, or subscribe to a duly registered national-level registry. These service providers must ensure that all users can register their numbers in the aforementioned registry, must not send spam SMS or telemarketing calls to any number listed in the registry, and shall establish mechanisms to prevent content service providers identified by users from continuing to send harassing messages to users who have objected to receiving their SMS or calls.
4. Opt-Out Mechanism
Article 6.2.1.7 of the Guidelines provides that marketing and corporate communications sent via SMS or email must be free of charge and must include an opt-out option. The ODPC regards the absence of an opt-out option as an aggravating factor for penalties.
5. Sender ID and Content Pre-Registration
The CA requires all alphanumeric Sender IDs (up to 11 characters) and message templates to be pre-registered with the CA. Unregistered Sender IDs will be silently dropped by the network or replaced with random short codes.
6. Consequences of Non-Compliance
Article 22 of the 2025 Regulations stipulates that any person who contravenes the relevant provisions shall, upon conviction, be liable to a fine not exceeding one million Kenyan shillings (approximately US$7,700). In addition, under the “Kenya Information and Communications (Consumer Protection) Regulations”, the CA may impose a fine of up to 300,000 shillings.
