Cross-Border Data Transfer
Data Protection Act, 2019 — transfer of personal data outside Kenya
Kenya · November 25, 2019 (Act); Regulations in force from February 2022
Verify detailsKenya combines a safeguards test with a residual localisation power, and the two are easy to conflate. s. 48 permits transfer where the controller or processor gives the Data Commissioner proof of appropriate safeguards — in practice, that the destination affords protection at least comparable to the Act's — or where the transfer is necessary for one of the listed grounds (performance of a contract with the data subject or pre-contractual steps, a contract concluded in the data subject's interest, vital interests, or a compelling legitimate interest not overridden by the data subject's rights). s. 49 adds requirements around processing sensitive personal data outside Kenya, and s. 50 empowers a localisation requirement for processing the Cabinet Secretary designates as involving strategic interests of the state or protected critical infrastructure, elaborated at reg. 40 of the 2021 General Regulations. Marked 'check': the interaction between ss. 48 and 49 is reported inconsistently across secondary sources, and the ODPC has continued issuing transfer guidance — read the statutory text and current ODPC guidance directly before designing a transfer route.
This is a general reference, not legal advice or a determination that this law applies to your specific business. Run the full questionnaire to check against your actual presence, activities, and data types.