Qubicweb reading view
Kenya Issues New Cross-Border Data Transfer Guidance: Familiar Concepts, but Important Local Differences
Internal Read means the full piece stays on Qubicweb, with its source path and context still visible.
Brief points
- On September 8, 2026, Kenya’s Office of the Data Protection Commissioner (“ODPC”) published new Guidance Notes for Cross-border Data Transfers (“Guidance...
- Kenya and the European Union are currently engaged in an adequacy process, and in June 2026 the European Commission welcomed progress in that process, noting the “positive...
- Against that backdrop, several features of the Guidance will look familiar to organizations accustomed to the EU General Data Protection Regulation (“GDPR”), includi...
On September 8, 2026, Kenya’s Office of the Data Protection Commissioner (“ODPC”) published new Guidance Notes for Cross-border Data Transfers (“Guidance”), providing organizations with more detailed guidance on the application of Kenya’s rules governing transfers of personal data outside the country.
The Guidance arrives at an interesting time for Kenya’s data protection framework. Kenya and the European Union are currently engaged in an adequacy process, and in June 2026 the European Commission welcomed progress in that process, noting the “positive assessment so far” and its intention to conclude the process as soon as possible. Against that backdrop, several features of the Guidance will look familiar to organizations accustomed to the EU General Data Protection Regulation (“GDPR”), including its treatment of adequacy, appropriate safeguards, Binding Corporate Rules (“BCRs”), assessments of third-country laws, and supplementary safeguards. But the comparison only goes so far. The Guidance also illustrates several important differences between Kenya’s cross-border transfer framework and the GDPR, including in relation to sensitive personal data, data localization, legitimate interests, and onward transfers. For multinational organizations seeking to use global transfer frameworks across jurisdictions, those differences are important.
An Increasingly Familiar Transfer Architecture
Kenya’s Data Protection Act, 2019 (“DPA”) and Data Protection (General) Regulations, 2021 (“General Regulations”) already establish the basic architecture for transfers outside Kenya. Before transferring personal data, a controller or processor must establish that the transfer is based on appropriate data protection safeguards, an adequacy decision, necessity, or the consent of the data subject.
That structure has obvious parallels with Chapter V of the GDPR, which similarly distinguishes between adequacy decisions, appropriate safeguards (including Standard Contractual Clauses and BCRs), and specified derogations where those mechanisms are unavailable.
The Guidance adds considerably more operational detail to the Kenyan framework. Among other things, it includes separate Standard Clauses for Legal Instruments Containing Appropriate Safeguards for controller-to-controller and controller-to-processor transfers and an application process for the approval of BCRs. There are, however, differences even at this level. The EU’s 2021 SCCs use four modules, covering controller-to-controller, controller-to-processor, processor-to-processor, and processor-to-controller transfers. The Kenyan Guidance provides clauses for the first two relationships only. In addition, while the core text of the EU SCCs generally cannot be altered if the parties wish to rely on their pre-approved status, the Kenyan Guidance encourages organizations to incorporate its clauses into their legal instruments and adapt them where necessary to the circumstances of the transfer, subject to maintaining the required level of protection.
Transfer Assessments Bring Schrems II-Type Questions into the Kenyan Framework
Perhaps the clearest point of convergence with the EU approach is the Guidance’s treatment of third-country risk.
The Kenyan Standard Clauses require the parties, before relying on them, to assess whether a transfer can be carried out consistently with the DPA and General Regulations. That assessment should consider the nature and purposes of the transfer; the categories of data and data subjects involved; the legal and regulatory framework applicable to the recipient; laws or practices that may affect the recipient’s ability to comply, including legally binding government access requests; and whether supplementary technical, organizational, or contractual measures are required. The assessment must be documented and reviewed if material circumstances change.
That approach closely resembles the transfer impact assessment that has become familiar under the GDPR following the Court of Justice’s Schrems II judgment. Clause 14 of the EU SCCs similarly requires the parties to assess whether the laws and practices of the destination country may prevent the importer from complying with the SCCs and, where necessary, to implement supplementary measures. The practical point is that the Kenyan regime is moving away from a model in which signing a transfer agreement is, by itself, the compliance exercise. Organizations relying on contractual safeguards will increasingly need to understand and document the actual transfer, the recipient environment, relevant foreign law, government access risks, and the effectiveness of supplementary measures.
A Different Approach to “Necessity” and Legitimate Interest
There is also a less obvious difference that may be important for multinational organizations.
The DPA includes within transfers based on “necessity” a transfer necessary for compelling legitimate interests pursued by the controller or processor that are not overridden by the rights and freedoms of the data subject. The Guidance goes further in illustrating how the ODPC understands this route: it states that a compelling legitimate interest may arise, for example, where an organization hosts personal data on cloud servers outside Kenya to improve operational efficiency, service effectiveness, and convenience.
That is notably different from the GDPR. Under Article 49, compelling legitimate interests provide a narrow residual transfer derogation, available only where the transfer cannot be based on adequacy or appropriate safeguards and none of the other Article 49 derogations applies. The transfer must also be non-repetitive, concern only a limited number of data subjects, and satisfy additional safeguards and notification requirements. The Kenyan Guidance therefore appears to contemplate a potentially more practical role for compelling legitimate interests in supporting international data flows than the GDPR does. Organizations should nevertheless be cautious about treating this as a general cloud-transfer exemption: the DPA requires the interest to be “compelling,” and the General Regulations require necessity to be established in the circumstances of the particular transfer.
Sensitive Data Is an Important Point of Divergence
In other respects, the Kenyan regime is more restrictive.
Section 49 of the DPA provides that sensitive personal data may be processed outside Kenya only after obtaining the data subject’s consent and confirmation of appropriate safeguards. The Guidance reinforces this position and states that the consent and safeguards requirements should be reflected expressly in the relevant contract and transfer documentation, together with enhanced technical, organizational, administrative, and contractual safeguards.
This is not the approach taken by the GDPR. Special-category data transferred outside the EEA must satisfy both the GDPR’s rules on processing special categories of data under Article 9 and the applicable Chapter V transfer requirements, but the fact that the data is special-category data does not itself require explicit consent as the transfer mechanism. Article 9 provides several possible grounds for processing special-category data, of which explicit consent is only one.
For multinational organizations, an EU-compliant transfer arrangement therefore should not simply be assumed to satisfy the Kenyan requirements where the transfer involves health, biometric, genetic, or other sensitive personal data.
Data Localization Adds Another Layer
Kenya’s data localization rules create a further distinction.
The Guidance reiterates that processing relating to specified “strategic interests of the State” is subject to localization requirements. Under the General Regulations, these categories include, among others, civil registration, elections, certain public-finance systems, basic education, and the provision of primary or secondary healthcare in Kenya. In those circumstances, personal data must be processed through a server and data center located in Kenya, or at least one serving copy must be stored in a Kenyan data center. The GDPR does not impose an equivalent general localization requirement. For businesses operating global infrastructure, this means the transfer question in Kenya cannot always be answered simply by identifying a valid transfer mechanism. Organizations first need to determine whether an applicable Kenyan localization requirement constrains the architecture of the processing itself.
Remote Access, Cloud Services, and Onward Transfers Are Squarely in Scope
The Guidance is also explicit that a transfer is not confined to physically moving a database from Kenya to another country. It describes a cross-border transfer as including the transmission, access, or making available of personal data from Kenya to a recipient outside Kenya, and expressly states that processing personal data in a cloud environment with servers outside Kenya constitutes a cross-border transfer.
This approach is broadly consistent with the direction taken by European regulators in relation to international access to personal data, but it is particularly significant for businesses that may still map transfers primarily by reference to the location of data centers.
The Guidance also takes a detailed approach to onward transfers. It contemplates prior written authorization, an assessment of the onward recipient and jurisdiction, equivalent protection, transfer documentation, and continued responsibility of the initial recipient. Particularly noteworthy is the Guidance’s statement that onward transfers for the recipient’s own purposes, including analytics, profiling, product improvement, or marketing, are strictly prohibited.
That provision may deserve particular attention from organizations using technology and AI providers, where service-provider terms may permit data, telemetry, or related information to be used for secondary purposes.
Key Takeaways from the Guidance
The Guidance does not replace the DPA or General Regulations, and organizations should be careful to distinguish between statutory requirements and the ODPC’s guidance on how those requirements should be implemented. But it provides a considerably clearer indication of the ODPC’s expectations for international transfers.
For multinational organizations, the broader message is that an existing GDPR transfer program provides a useful starting point for Kenya, but not necessarily an end point. Transfer assessments, contractual safeguards, BCRs, controls on onward transfers, and supplementary measures will all be familiar concepts. However, Kenyan requirements concerning sensitive personal data, localization, compelling legitimate interests, and the documentation of transfers need to be considered separately.
The significance of that convergence, and those remaining differences, may increase further if the ongoing EU-Kenya adequacy process is successfully concluded.