Skip to content

Menu

Network by SubjectChannelsBlogsHomeAboutContact
AI Legal Journal logo
Subscribe
Search
Close
PublishersBlogsNetwork by SubjectChannels
Subscribe

Kenya Issues New Cross-Border Data Transfer Guidance: Familiar Concepts, but Important Local Differences

By Dan Cooper, Deon Govender & Ahmed Mokdad on September 16, 2026
Email this postTweet this postLike this postShare this post on LinkedIn

On September 8, 2026, Kenya’s Office of the Data Protection Commissioner (“ODPC”) published new Guidance Notes for Cross-border Data Transfers (“Guidance”), providing organizations with more detailed guidance on the application of Kenya’s rules governing transfers of personal data outside the country.

The Guidance arrives at an interesting time for Kenya’s data protection framework. Kenya and the European Union are currently engaged in an adequacy process, and in June 2026 the European Commission welcomed progress in that process, noting the “positive assessment so far” and its intention to conclude the process as soon as possible. Against that backdrop, several features of the Guidance will look familiar to organizations accustomed to the EU General Data Protection Regulation (“GDPR”), including its treatment of adequacy, appropriate safeguards, Binding Corporate Rules (“BCRs”), assessments of third-country laws, and supplementary safeguards. But the comparison only goes so far. The Guidance also illustrates several important differences between Kenya’s cross-border transfer framework and the GDPR, including in relation to sensitive personal data, data localization, legitimate interests, and onward transfers. For multinational organizations seeking to use global transfer frameworks across jurisdictions, those differences are important.

An Increasingly Familiar Transfer Architecture

Kenya’s Data Protection Act, 2019 (“DPA”) and Data Protection (General) Regulations, 2021 (“General Regulations”) already establish the basic architecture for transfers outside Kenya. Before transferring personal data, a controller or processor must establish that the transfer is based on appropriate data protection safeguards, an adequacy decision, necessity, or the consent of the data subject.

That structure has obvious parallels with Chapter V of the GDPR, which similarly distinguishes between adequacy decisions, appropriate safeguards (including Standard Contractual Clauses and BCRs), and specified derogations where those mechanisms are unavailable.

The Guidance adds considerably more operational detail to the Kenyan framework. Among other things, it includes separate Standard Clauses for Legal Instruments Containing Appropriate Safeguards for controller-to-controller and controller-to-processor transfers and an application process for the approval of BCRs. There are, however, differences even at this level. The EU’s 2021 SCCs use four modules, covering controller-to-controller, controller-to-processor, processor-to-processor, and processor-to-controller transfers. The Kenyan Guidance provides clauses for the first two relationships only. In addition, while the core text of the EU SCCs generally cannot be altered if the parties wish to rely on their pre-approved status, the Kenyan Guidance encourages organizations to incorporate its clauses into their legal instruments and adapt them where necessary to the circumstances of the transfer, subject to maintaining the required level of protection.

Transfer Assessments Bring Schrems II-Type Questions into the Kenyan Framework

Perhaps the clearest point of convergence with the EU approach is the Guidance’s treatment of third-country risk.

The Kenyan Standard Clauses require the parties, before relying on them, to assess whether a transfer can be carried out consistently with the DPA and General Regulations. That assessment should consider the nature and purposes of the transfer; the categories of data and data subjects involved; the legal and regulatory framework applicable to the recipient; laws or practices that may affect the recipient’s ability to comply, including legally binding government access requests; and whether supplementary technical, organizational, or contractual measures are required. The assessment must be documented and reviewed if material circumstances change.

That approach closely resembles the transfer impact assessment that has become familiar under the GDPR following the Court of Justice’s Schrems II judgment. Clause 14 of the EU SCCs similarly requires the parties to assess whether the laws and practices of the destination country may prevent the importer from complying with the SCCs and, where necessary, to implement supplementary measures. The practical point is that the Kenyan regime is moving away from a model in which signing a transfer agreement is, by itself, the compliance exercise. Organizations relying on contractual safeguards will increasingly need to understand and document the actual transfer, the recipient environment, relevant foreign law, government access risks, and the effectiveness of supplementary measures.

A Different Approach to “Necessity” and Legitimate Interest

There is also a less obvious difference that may be important for multinational organizations.

The DPA includes within transfers based on “necessity” a transfer necessary for compelling legitimate interests pursued by the controller or processor that are not overridden by the rights and freedoms of the data subject. The Guidance goes further in illustrating how the ODPC understands this route: it states that a compelling legitimate interest may arise, for example, where an organization hosts personal data on cloud servers outside Kenya to improve operational efficiency, service effectiveness, and convenience.

That is notably different from the GDPR. Under Article 49, compelling legitimate interests provide a narrow residual transfer derogation, available only where the transfer cannot be based on adequacy or appropriate safeguards and none of the other Article 49 derogations applies. The transfer must also be non-repetitive, concern only a limited number of data subjects, and satisfy additional safeguards and notification requirements. The Kenyan Guidance therefore appears to contemplate a potentially more practical role for compelling legitimate interests in supporting international data flows than the GDPR does. Organizations should nevertheless be cautious about treating this as a general cloud-transfer exemption: the DPA requires the interest to be “compelling,” and the General Regulations require necessity to be established in the circumstances of the particular transfer.

Sensitive Data Is an Important Point of Divergence

In other respects, the Kenyan regime is more restrictive.

Section 49 of the DPA provides that sensitive personal data may be processed outside Kenya only after obtaining the data subject’s consent and confirmation of appropriate safeguards. The Guidance reinforces this position and states that the consent and safeguards requirements should be reflected expressly in the relevant contract and transfer documentation, together with enhanced technical, organizational, administrative, and contractual safeguards.

This is not the approach taken by the GDPR. Special-category data transferred outside the EEA must satisfy both the GDPR’s rules on processing special categories of data under Article 9 and the applicable Chapter V transfer requirements, but the fact that the data is special-category data does not itself require explicit consent as the transfer mechanism. Article 9 provides several possible grounds for processing special-category data, of which explicit consent is only one.

For multinational organizations, an EU-compliant transfer arrangement therefore should not simply be assumed to satisfy the Kenyan requirements where the transfer involves health, biometric, genetic, or other sensitive personal data.

Data Localization Adds Another Layer

Kenya’s data localization rules create a further distinction.

The Guidance reiterates that processing relating to specified “strategic interests of the State” is subject to localization requirements. Under the General Regulations, these categories include, among others, civil registration, elections, certain public-finance systems, basic education, and the provision of primary or secondary healthcare in Kenya. In those circumstances, personal data must be processed through a server and data center located in Kenya, or at least one serving copy must be stored in a Kenyan data center. The GDPR does not impose an equivalent general localization requirement. For businesses operating global infrastructure, this means the transfer question in Kenya cannot always be answered simply by identifying a valid transfer mechanism. Organizations first need to determine whether an applicable Kenyan localization requirement constrains the architecture of the processing itself.

Remote Access, Cloud Services, and Onward Transfers Are Squarely in Scope

The Guidance is also explicit that a transfer is not confined to physically moving a database from Kenya to another country. It describes a cross-border transfer as including the transmission, access, or making available of personal data from Kenya to a recipient outside Kenya, and expressly states that processing personal data in a cloud environment with servers outside Kenya constitutes a cross-border transfer.

This approach is broadly consistent with the direction taken by European regulators in relation to international access to personal data, but it is particularly significant for businesses that may still map transfers primarily by reference to the location of data centers.

The Guidance also takes a detailed approach to onward transfers. It contemplates prior written authorization, an assessment of the onward recipient and jurisdiction, equivalent protection, transfer documentation, and continued responsibility of the initial recipient. Particularly noteworthy is the Guidance’s statement that onward transfers for the recipient’s own purposes, including analytics, profiling, product improvement, or marketing, are strictly prohibited.

That provision may deserve particular attention from organizations using technology and AI providers, where service-provider terms may permit data, telemetry, or related information to be used for secondary purposes.

Key Takeaways from the Guidance

The Guidance does not replace the DPA or General Regulations, and organizations should be careful to distinguish between statutory requirements and the ODPC’s guidance on how those requirements should be implemented. But it provides a considerably clearer indication of the ODPC’s expectations for international transfers.

For multinational organizations, the broader message is that an existing GDPR transfer program provides a useful starting point for Kenya, but not necessarily an end point. Transfer assessments, contractual safeguards, BCRs, controls on onward transfers, and supplementary measures will all be familiar concepts. However, Kenyan requirements concerning sensitive personal data, localization, compelling legitimate interests, and the documentation of transfers need to be considered separately.

The significance of that convergence, and those remaining differences, may increase further if the ongoing EU-Kenya adequacy process is successfully concluded.

Photo of Dan Cooper Dan Cooper

Daniel Cooper heads up the firm’s growing Data Privacy and Cybersecurity practice in London, and counsels clients in the information technology, pharmaceutical research, sports and financial services industries, among others, on European and UK data protection, data retention and freedom of information laws…

Daniel Cooper heads up the firm’s growing Data Privacy and Cybersecurity practice in London, and counsels clients in the information technology, pharmaceutical research, sports and financial services industries, among others, on European and UK data protection, data retention and freedom of information laws, as well as associated information technology and e-commerce laws and regulations. Mr. Cooper also regularly counsels clients with respect to Internet-related liabilities under European and US laws. Mr. Cooper sits on the advisory boards of a number of privacy NGOs, privacy think tanks, and related bodies.

Read more about Dan Cooper
Show more Show less
Photo of Deon Govender Deon Govender

Deon Govender focuses his practice on project development and corporate and project finance transactions across Africa, with particular emphasis on southern Africa. His experience ranges from advising on the development and financing of renewable energy and thermal power projects and various other infrastructure…

Deon Govender focuses his practice on project development and corporate and project finance transactions across Africa, with particular emphasis on southern Africa. His experience ranges from advising on the development and financing of renewable energy and thermal power projects and various other infrastructure assets in the transportation and telecommunications sectors. Mr. Govender’s experience additionally includes advising on financing independent power producer projects under the South African government’s Renewable Energy Independent Power Producer Procurement Programme.

Read more about Deon Govender
Show more Show less
Photo of Ahmed Mokdad Ahmed Mokdad

Ahmed Mokdad is an associate in the firm’s compliance and investigations practice in Africa. As a seasoned investigative specialist with deep experience representing clients across various sectors, he regularly assists clients across the continent navigate and mitigate a broad spectrum of regulatory and…

Ahmed Mokdad is an associate in the firm’s compliance and investigations practice in Africa. As a seasoned investigative specialist with deep experience representing clients across various sectors, he regularly assists clients across the continent navigate and mitigate a broad spectrum of regulatory and compliance risks and challenges.

Adding to his on the ground investigative, regulatory and compliance advisory experience, Mr. Mokdad has also extensively advised on litigious matters and financial transactions. Mr. Mokdad has been involved in several high profile litigious matters and international arbitrations relating to, amongst others, tax disputes and exchange control violations, corporate and commercial disputes, public procurement and white collar crime. He regularly performs risk and compliance program assessments, third-party risk due diligence, advising on pre-acquisition diligence and post-acquisition integration.

Read more about Ahmed Mokdad
Show more Show less
  • Posted in:
    Privacy & Data Security
  • Blog:
    Inside Privacy
  • Organization:
    Covington & Burling LLP
  • Article: View Original Source

LexBlog logo
Copyright © 2026, LexBlog. All Rights Reserved.
Legal content Portal by LexBlog LexBlog Logo