Kenya’s Office of the Data Protection Commissioner has published Guidance Notes for Cross-Border Data Transfers (2026). Data Commissioner Immaculate Kassait, SC, MBS, said the note is meant to help controllers and processors understand Part VI of the Data Protection Act, 2019, and Regulation 40 of the Data Protection (General) Regulations, 2021. It does not replace the statute. It tells firms how ODPC expects the statute to work in contracts, cloud deals, group transfers, and paper trails.
Four lawful routes out of Kenya
Regulation 40 lists the bases a transferring entity may use:
Appropriate safeguards. Adequacy decided by the Data Commissioner. Transfer as a necessity. Explicit consent after the person is told the risks, used when the other three are not available.
Safeguards can be a binding legal instrument that gives protection essentially equivalent to the Act, or a documented conclusion that the facts of the transfer already provide that protection. For the first path, ODPC annexed two sets of Standard Clauses: controller-to-controller and controller-to-processor. They are meant to be dropped into the contract, then completed with Annex I (what moves, to whom, why), Annex II (security measures), and either an onward-transfer log or a sub-processor register.
When judging “adequate safeguards” without those clauses, ODPC wants the legal regime in the destination country, sensitivity of the data, whether the promises can be enforced, the recipient’s technical and organisational measures, the chance of onward transfers, and whether data subjects can get a remedy.
Three country-level facts can support a safeguards finding: the destination has ratified and fully implemented the African Union Malabo Convention; Kenya has a reciprocal data protection agreement with that jurisdiction; or the group uses Binding Corporate Rules. Ratifying Malabo is not an automatic green light. Section 49(2) still lets the Commissioner look at the transfer case by case. Section 49(3) lets her prohibit, suspend, or condition a transfer even when the exporter thinks Sections 48 and 49 are met.
Part 5 of the Data Sharing Code, 2025, repeats the same idea: if the recipient country is not adequate, put safeguards in place. Controllers and processors that send personal data out of Kenya must notify ODPC of the transfer so the office can see the flows. Non-compliance with the Sharing Code is enforced under Section 58.
BCRs are now an application pack, not a slogan
Regulation 42 treats Binding Corporate Rules as a safeguard for intra-group transfers or groups in a joint economic activity. ODPC will not accept one document that tries to cover both controller BCRs and processor BCRs. Separate forms, separate packs.
Valid BCRs have to state scope (categories, purposes, countries, data-subject rights), bind every group member and its staff, name the group structure, assign accountability, run a complaint desk, report third-country laws that undercut the rules, defer to stricter local law, cooperate with ODPC, and name who pays when a member breaches.
Approval sits with ODPC. Material changes (new countries, weaker safeguards, different rights, a bigger processing scope) need a fresh approval. Audits must cover the whole BCR set and report to the parent board or the DPO. The application form on odpc.go.ke asks for the Kenyan entity’s ODPC registration number, data-flow maps, how employees are bound, financial capacity to take liability in Kenya, and whether the same BCRs are pending before another authority. Questions go to compliance@odpc.go.ke before you file.
Adequacy, necessity, consent
The Commissioner may publish a list of adequate countries, regions, sectors, or international organisations. Until that list exists, adequacy is not a self-serve box.
Necessity covers performance of a contract with the data subject (or a contract in their interest with a third party), legal claims, compelling legitimate interests that do not override the person’s rights, vital interests when the person cannot consent, and public interest under a clear legal mandate. ODPC gives cloud hosting abroad as an example of a possible legitimate-interest case, not a free pass. Public-interest examples in the note include a pandemic, an outbreak, or a terrorist threat. Document the mandate and the proportionality.
Consent is the leftover route. It must be explicit, and the person must be told the risks of the destination. Sensitive data still has to meet Section 49: explicit consent plus confirmation that appropriate safeguards exist, written into the contract and the transfer file.
Onward transfers are a second export
Once data leaves Kenya, the recipient may not send it on unless every condition in the note is met: prior written authorisation from the Kenyan transferring entity naming the third party, place, categories, and purpose; a risk assessment that the next country is essentially equivalent; the onward party accedes to the same contract (audits, liability, sensitive-data rules, breach notice); a Regulation 41(2) record (date and time, recipient identity and location, justification, categories and purposes, safeguards); full liability of the first recipient for the onward party; audit rights that reach the onward party; no use of the data for the recipient’s own analytics, product improvement, or marketing; and a duty to suspend or kill the chain if the next party can no longer comply.
That list is stricter than a casual “we use subprocessors listed on our website.”
Some data is not supposed to leave
Section 50 and Regulation 26 require localisation for strategic interests of the state. Process through a server and data centre in Kenya, or keep at least one serving copy in a Kenyan data centre, when you run civil registration and legal identity, elections, public-finance systems, a protected computer system under section 20 of the Computer Misuse and Cybercrime Act, early childhood or basic education under the Basic Education Act, or primary or secondary health care in the country.
Before any export, check whether the purpose sits on that list and whether the system is designated critical infrastructure under Gazette Notice No. 1043 of 31 January 2022.
Kenya’s definition of sensitive personal data is wider than GDPR special categories. It includes race, health, ethnic or social origin, conscience, belief, genetic and biometric data, property details, marital status, family names (children, parents, spouses), sex, and sexual orientation, plus any extra classes the Commissioner specifies under Section 47. Those transfers need tighter technical and contractual controls than ordinary personal data.
Paper the file before the packet leaves
Regulation 41(2) requires a transfer record: date and time, recipient name, justification, description of the data. Produce it if the Commissioner asks. High-risk transfers need a DPIA under Section 31 and Part VIII of the General Regulations. ODPC has a separate DPIA guidance note on odpc.go.ke. Safeguards must be demonstrable before, during, and after the transfer.
A safeguards instrument should cover legal basis, roles, categories and purposes, security measures, onward-transfer limits, data-subject rights, audit, breach notice, liability, return or deletion on exit, and governing law. The standard clauses already write most of that. Kenyan law governs the clauses. Data subjects can enforce the protective terms. ODPC’s powers are not contracted away.
Cloud is an export plus a vendor
IaaS and PaaS leave the customer more control. SaaS leaves more with the provider, so ODPC wants a risk assessment before you lean on it. Public cloud needs a privacy risk assessment before you put personal data on shared iron. Private cloud is treated as the tighter option.
Expected controls: retain provider audit logs and review them; configure access correctly; encrypt in transit and at rest; use MFA; anonymise where it still leaves a usable dataset; keep an offline backup of critical personal data. Before go-live: lawful basis and transfer conditions, a provider that can show safeguards, a DPA, sub-processor review, a way for people to exercise rights wherever the disk sits, a DPIA if the storage is high risk, a retention and deletion schedule, staff training, and a process to reassess when the provider changes terms.
The 2025 Kenya Cloud Policy is listed in the legislative stack next to the Constitution (Article 31 privacy; Article 35 access to information), the Act, the General Regulations, the Complaints Handling Regulations, and the Computer Misuse and Cybercrime (Amendment) Act, 2024.
If you already move Kenyan HR, customer, or health data to a regional HQ, a US SaaS tool, or an EU processor, the practical sequence is: pick a Regulation 40 basis, fill Annex I honestly, stop silent onward sharing, notify ODPC of the export, and check Section 50 before you assume a “serving copy in Dublin” is enough for identity, elections, public finance, or in-country care records.