Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupportContact
Search
Close

Kenya Issues New Cross-Border Data Transfer Guidance: Familiar Concepts, but Important Local Differences

By Dan Cooper, Deon Govender & Ahmed Mokdad on September 16, 2026
Email this postTweet this postLike this postShare this post on LinkedIn

Table of Contents

  • An Increasingly Familiar Transfer Architecture
  • Transfer Assessments Bring Schrems II-Type Questions into the Kenyan Framework
  • A Different Approach to “Necessity” and Legitimate Interest
  • Sensitive Data Is an Important Point of Divergence
  • Data Localization Adds Another Layer
  • Remote Access, Cloud Services, and Onward Transfers Are Squarely in Scope
  • Key Takeaways from the Guidance

On September 8, 2026, Kenya’s Office of the Data Protection Commissioner (“ODPC”) published new Guidance Notes for Cross-border Data Transfers (“Guidance”), providing organizations with more detailed guidance on the application of Kenya’s rules governing transfers of personal data outside the country.

The Guidance arrives at an interesting time for Kenya’s data protection framework. Kenya and the European Union are currently engaged in an adequacy process, and in June 2026 the European Commission welcomed progress in that process, noting the “positive assessment so far” and its intention to conclude the process as soon as possible. Against that backdrop, several features of the Guidance will look familiar to organizations accustomed to the EU General Data Protection Regulation (“GDPR”), including its treatment of adequacy, appropriate safeguards, Binding Corporate Rules (“BCRs”), assessments of third-country laws, and supplementary safeguards. But the comparison only goes so far. The Guidance also illustrates several important differences between Kenya’s cross-border transfer framework and the GDPR, including in relation to sensitive personal data, data localization, legitimate interests, and onward transfers. For multinational organizations seeking to use global transfer frameworks across jurisdictions, those differences are important.

Link to An Increasingly Familiar Transfer Architecture An Increasingly Familiar Transfer Architecture

Kenya’s Data Protection Act, 2019 (“DPA”) and Data Protection (General) Regulations, 2021 (“General Regulations”) already establish the basic architecture for transfers outside Kenya. Before transferring personal data, a controller or processor must establish that the transfer is based on appropriate data protection safeguards, an adequacy decision, necessity, or the consent of the data subject.

That structure has obvious parallels with Chapter V of the GDPR, which similarly distinguishes between adequacy decisions, appropriate safeguards (including Standard Contractual Clauses and BCRs), and specified derogations where those mechanisms are unavailable.

The Guidance adds considerably more operational detail to the Kenyan framework. Among other things, it includes separate Standard Clauses for Legal Instruments Containing Appropriate Safeguards for controller-to-controller and controller-to-processor transfers and an application process for the approval of BCRs. There are, however, differences even at this level. The EU’s 2021 SCCs use four modules, covering controller-to-controller, controller-to-processor, processor-to-processor, and processor-to-controller transfers. The Kenyan Guidance provides clauses for the first two relationships only. In addition, while the core text of the EU SCCs generally cannot be altered if the parties wish to rely on their pre-approved status, the Kenyan Guidance encourages organizations to incorporate its clauses into their legal instruments and adapt them where necessary to the circumstances of the transfer, subject to maintaining the required level of protection.

Link to Transfer Assessments Bring Schrems II-Type Questions into the Kenyan Framework Transfer Assessments Bring Schrems II-Type Questions into the Kenyan Framework

Perhaps the clearest point of convergence with the EU approach is the Guidance’s treatment of third-country risk.

The Kenyan Standard Clauses require the parties, before relying on them, to assess whether a transfer can be carried out consistently with the DPA and General Regulations. That assessment should consider the nature and purposes of the transfer; the categories of data and data subjects involved; the legal and regulatory framework applicable to the recipient; laws or practices that may affect the recipient’s ability to comply, including legally binding government access requests; and whether supplementary technical, organizational, or contractual measures are required. The assessment must be documented and reviewed if material circumstances change.

That approach closely resembles the transfer impact assessment that has become familiar under the GDPR following the Court of Justice’s Schrems II judgment. Clause 14 of the EU SCCs similarly requires the parties to assess whether the laws and practices of the destination country may prevent the importer from complying with the SCCs and, where necessary, to implement supplementary measures. The practical point is that the Kenyan regime is moving away from a model in which signing a transfer agreement is, by itself, the compliance exercise. Organizations relying on contractual safeguards will increasingly need to understand and document the actual transfer, the recipient environment, relevant foreign law, government access risks, and the effectiveness of supplementary measures.

Link to A Different Approach to “Necessity” and Legitimate Interest A Different Approach to “Necessity” and Legitimate Interest

There is also a less obvious difference that may be important for multinational organizations.

The DPA includes within transfers based on “necessity” a transfer necessary for compelling legitimate interests pursued by the controller or processor that are not overridden by the rights and freedoms of the data subject. The Guidance goes further in illustrating how the ODPC understands this route: it states that a compelling legitimate interest may arise, for example, where an organization hosts personal data on cloud servers outside Kenya to improve operational efficiency, service effectiveness, and convenience.

That is notably different from the GDPR. Under Article 49, compelling legitimate interests provide a narrow residual transfer derogation, available only where the transfer cannot be based on adequacy or appropriate safeguards and none of the other Article 49 derogations applies. The transfer must also be non-repetitive, concern only a limited number of data subjects, and satisfy additional safeguards and notification requirements. The Kenyan Guidance therefore appears to contemplate a potentially more practical role for compelling legitimate interests in supporting international data flows than the GDPR does. Organizations should nevertheless be cautious about treating this as a general cloud-transfer exemption: the DPA requires the interest to be “compelling,” and the General Regulations require necessity to be established in the circumstances of the particular transfer.

Link to Sensitive Data Is an Important Point of Divergence Sensitive Data Is an Important Point of Divergence

In other respects, the Kenyan regime is more restrictive.

Section 49 of the DPA provides that sensitive personal data may be processed outside Kenya only after obtaining the data subject’s consent and confirmation of appropriate safeguards. The Guidance reinforces this position and states that the consent and safeguards requirements should be reflected expressly in the relevant contract and transfer documentation, together with enhanced technical, organizational, administrative, and contractual safeguards.

This is not the approach taken by the GDPR. Special-category data transferred outside the EEA must satisfy both the GDPR’s rules on processing special categories of data under Article 9 and the applicable Chapter V transfer requirements, but the fact that the data is special-category data does not itself require explicit consent as the transfer mechanism. Article 9 provides several possible grounds for processing special-category data, of which explicit consent is only one.

For multinational organizations, an EU-compliant transfer arrangement therefore should not simply be assumed to satisfy the Kenyan requirements where the transfer involves health, biometric, genetic, or other sensitive personal data.

Link to Data Localization Adds Another Layer Data Localization Adds Another Layer

Kenya’s data localization rules create a further distinction.

The Guidance reiterates that processing relating to specified “strategic interests of the State” is subject to localization requirements. Under the General Regulations, these categories include, among others, civil registration, elections, certain public-finance systems, basic education, and the provision of primary or secondary healthcare in Kenya. In those circumstances, personal data must be processed through a server and data center located in Kenya, or at least one serving copy must be stored in a Kenyan data center. The GDPR does not impose an equivalent general localization requirement. For businesses operating global infrastructure, this means the transfer question in Kenya cannot always be answered simply by identifying a valid transfer mechanism. Organizations first need to determine whether an applicable Kenyan localization requirement constrains the architecture of the processing itself.

Link to Remote Access, Cloud Services, and Onward Transfers Are Squarely in Scope Remote Access, Cloud Services, and Onward Transfers Are Squarely in Scope

The Guidance is also explicit that a transfer is not confined to physically moving a database from Kenya to another country. It describes a cross-border transfer as including the transmission, access, or making available of personal data from Kenya to a recipient outside Kenya, and expressly states that processing personal data in a cloud environment with servers outside Kenya constitutes a cross-border transfer.

This approach is broadly consistent with the direction taken by European regulators in relation to international access to personal data, but it is particularly significant for businesses that may still map transfers primarily by reference to the location of data centers.

The Guidance also takes a detailed approach to onward transfers. It contemplates prior written authorization, an assessment of the onward recipient and jurisdiction, equivalent protection, transfer documentation, and continued responsibility of the initial recipient. Particularly noteworthy is the Guidance’s statement that onward transfers for the recipient’s own purposes, including analytics, profiling, product improvement, or marketing, are strictly prohibited.

That provision may deserve particular attention from organizations using technology and AI providers, where service-provider terms may permit data, telemetry, or related information to be used for secondary purposes.

Link to Key Takeaways from the Guidance Key Takeaways from the Guidance

The Guidance does not replace the DPA or General Regulations, and organizations should be careful to distinguish between statutory requirements and the ODPC’s guidance on how those requirements should be implemented. But it provides a considerably clearer indication of the ODPC’s expectations for international transfers.

For multinational organizations, the broader message is that an existing GDPR transfer program provides a useful starting point for Kenya, but not necessarily an end point. Transfer assessments, contractual safeguards, BCRs, controls on onward transfers, and supplementary measures will all be familiar concepts. However, Kenyan requirements concerning sensitive personal data, localization, compelling legitimate interests, and the documentation of transfers need to be considered separately.

The significance of that convergence, and those remaining differences, may increase further if the ongoing EU-Kenya adequacy process is successfully concluded.

Tags: AI
Photo of Dan Cooper Dan Cooper

Daniel Cooper is co-chair of Covington’s Data Privacy and Cyber Security Practice, and advises clients on information technology regulatory and policy issues, particularly data protection, consumer protection, AI, and data security matters. He has over 20 years of experience in the field, representing…

Daniel Cooper is co-chair of Covington’s Data Privacy and Cyber Security Practice, and advises clients on information technology regulatory and policy issues, particularly data protection, consumer protection, AI, and data security matters. He has over 20 years of experience in the field, representing clients in regulatory proceedings before privacy authorities in Europe and counseling them on their global compliance and government affairs strategies. Dan regularly lectures on the topic, and was instrumental in drafting the privacy standards applied in professional sport.

According to Chambers UK, his “level of expertise is second to none, but it’s also equally paired with a keen understanding of our business and direction.” It was noted that “he is very good at calibrating and helping to gauge risk.”

Dan is qualified to practice law in the United States, the United Kingdom, Ireland and Belgium. He has also been appointed to the advisory and expert boards of privacy NGOs and agencies, such as the IAPP’s European Advisory Board, Privacy International and the European security agency, ENISA.

Read more about Dan CooperEmail
Show more Show less
Photo of Deon Govender Deon Govender

Deon Govender is a vice chair of the Africa Practice Group. He focuses his practice on project development and corporate and project finance transactions across Africa, with particular emphasis on southern Africa. His experience ranges from advising on the development and financing of…

Deon Govender is a vice chair of the Africa Practice Group. He focuses his practice on project development and corporate and project finance transactions across Africa, with particular emphasis on southern Africa. His experience ranges from advising on the development and financing of renewable energy and thermal power projects and various other infrastructure assets in the transportation and telecommunications sectors. Deon’s experience additionally includes advising on financing independent power producer projects under the South African government’s Renewable Energy Independent Power Producer Procurement Programme.

Read more about Deon GovenderEmail
Show more Show less
Photo of Ahmed Mokdad Ahmed Mokdad

Ahmed Mokdad is an associate based in the Johannesburg office, and a member of the firm’s White Collar Defense and Investigations and Anti-Corruption Practice Groups, as well as the Privacy and Cyber Security Practice Group. With a depth of experience representing clients across…

Ahmed Mokdad is an associate based in the Johannesburg office, and a member of the firm’s White Collar Defense and Investigations and Anti-Corruption Practice Groups, as well as the Privacy and Cyber Security Practice Group. With a depth of experience representing clients across various sectors, Ahmed regularly assists clients navigate and mitigate a broad spectrum of regulatory and compliance risks.

Ahmed’s investigations practice includes internal and government investigations into anti-corruption, anti-money laundering, fraud, and financial crimes matters more generally. Complementing his investigations practice, Ahmed has a broad-based compliance advisory practice in these areas and in data protection and information security matters. This includes assisting clients in numerous sectors with compliance under South Africa’s Protection of Personal Information Act (POPIA).

Adding to his investigative, regulatory and compliance advisory experience, Ahmed has extensive experience advising on numerous M&A and complex financial transactions. He has also been involved in several high profile international arbitrations, and litigious matters before the South African courts relating to, among other things, commercial and tax disputes, exchange control violations, government procurement irregularities, and defending white collar crimes. This experience gives Ahmed valuable perspectives and insights when advising on compliance advisory matters.

For international clients facing compliance issues cutting into Africa, Ahmed regularly advises on a range of issues that can arise in such context, e.g., labor and employment considerations, legal professional privilege, whistleblower protections, corporate governance reporting obligations, and control processes and protocols for engaging with government and law enforcement agencies. Ahmed is recognized by clients for providing practical advice and solutions on complex legal issues in ambiguous statutory regimes.

Read more about Ahmed MokdadEmail
Show more Show less
  • Posted in:
    Privacy and Cybersecurity
  • Blog:
    Cov Africa
  • Organization:
    Covington & Burling LLP
  • Article: View Original Source

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
The Library at LexBlog
  • About LexBlog
  • The Field We Built
  • Library at LexBlog
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo