A Kenyan tech startup that stores data on a foreign cloud provider, uses an overseas analytics tool, or shares data with a parent company abroad is transferring personal data outside Kenya, and that triggers a distinct set of obligations under the Data Protection Act, 2019 on top of the Act’s general rules. Kenya’s cross-border transfer regime is real and enforced, but it is also less developed in some specific respects than founders sometimes assume, particularly around adequacy and standard contractual clauses, and overstating what exists is as much a risk as ignoring the rules altogether.
The basic rule: safeguards, adequacy, or a specific necessity ground
Section 25(h) of the Act states the general principle plainly: personal data must not be transferred outside Kenya unless there is proof of adequate data protection safeguards or the data subject’s consent. Section 48 sets out how that plays out in practice, permitting a transfer where the controller demonstrates appropriate safeguards to the Data Commissioner, where the destination jurisdiction has commensurate data protection laws, or where the transfer falls within specific necessity grounds such as contract performance, protection of vital interests, or the establishment of a legal claim. The Data Protection (General) Regulations, 2021 flesh this out further in a dedicated part covering transfers on the basis of appropriate safeguards, deemed safeguards where the destination country is treated as adequate, binding corporate rules, formal adequacy decisions, necessity, and consent, and separately require that any transfer or processing agreement include specified minimum content, such as records of the transfer date, the recipient’s identity, the justification for the transfer, and a description of the data transferred.
Sensitive data crossing the border faces a stricter rule
Where the data being transferred is sensitive personal data, section 49 imposes an additional, stricter requirement: the transfer may only proceed on obtaining the data subject’s consent and confirming appropriate safeguards, both together, not either alone. A startup transferring health records, biometric data, or similar categories to a processor or affiliate abroad needs to satisfy this specific consent-plus-safeguards test, not just the general section 48 conditions that would suffice for ordinary personal data.
There is no adequacy list, and no EU adequacy decision, yet
Kenya has not published a list of countries deemed to offer adequate data protection, and businesses should not plan a transfer strategy around one existing. ODPC’s own guidance describes adequacy assessments as case-by-case, discretionary determinations, explicitly framing adequacy as something that is not a self-serve checkbox, while noting the Commissioner may publish a list of adequate jurisdictions in future. Separately, ODPC has been engaged since June 2024 in what it describes as an “Adequacy Dialogue” with the European Union, the first such process on the African continent, but this is a negotiation in progress, not a concluded adequacy decision. Kenya has also not yet ratified the African Union’s Malabo Convention on cybersecurity and data protection, though stakeholder consultations toward accession were underway as of late 2025. None of these processes currently gives a Kenyan business a shortcut around the section 48 safeguards analysis for a transfer to the EU or elsewhere.
No published Standard Contractual Clauses, despite some commentary suggesting otherwise
Some secondary commentary has described ODPC’s cross-border transfer guidance as including its own Standard Contractual Clauses, similar to the EU or UK model. On direct review of the guidance note itself, we did not find any such template: the document’s annexes consist of a compliance checklist, an unrelated gazette notice on critical information infrastructure, and a binding corporate rules application form, not a set of ready-to-use model clauses. What the guidance note does require is that a transfer or processing agreement contain specific safeguard provisions, including audit rights and identification of the recipient and destination country, which is a substantive requirement but not the same thing as a government-issued clause template a business can simply insert into a contract. A startup relying on a data processing agreement or intra-group transfer agreement as its section 48 safeguard should have that agreement drafted to meet the Regulations’ specified content requirements directly, rather than assuming a Kenyan equivalent of EU-style Standard Contractual Clauses exists to be adopted off the shelf. We would also flag that this guidance note itself appears, as of this research, to carry an internal inconsistency between being dated as a live document and still appearing on ODPC’s own list of drafts open for public comment; treat it as guidance still subject to change rather than settled, final ODPC policy.
Data localisation is a separate, narrower issue
Independent of the cross-border transfer conditions, section 50 of the Act allows the Cabinet Secretary to require that certain categories of processing, on grounds of state strategic interest or revenue protection, take place only through a server or data centre physically located in Kenya. This has been applied to specific strategic sectors, including civil registration, elections, public finance, and healthcare-adjacent categories, rather than as a general rule. Most tech startups’ data will not fall within these localisation categories, but a business operating in a sector adjacent to critical government functions should check this specifically rather than assume the general cross-border transfer rules are the only relevant restriction.
How We Can Help
Clay & Associates Advocates advises technology companies on structuring cross-border data flows, cloud storage arrangements, and intra-group data sharing to comply with Kenya’s Data Protection Act. Our companion piece on Data Protection for AI Training Under the DPA covers the related domestic processing obligations that apply before any transfer question arises. Contact our Technology & Startups team to review whether your cloud provider or intra-group data sharing arrangements meet the Regulations’ specific safeguard requirements.
Sources: Data Protection Act, 2019, sections 25, 48, 49, and 50, Kenya Law; Data Protection (General) Regulations, 2021, Part VII, Kenya Law; Office of the Data Protection Commissioner, Guidance Note on Cross-Border Data Transfers, April 2026.
Frequently asked questions
Does Kenya have a list of countries approved for personal data transfers?
No. ODPC has not published an adequacy list, and adequacy assessments are made case by case. A dialogue toward a possible EU adequacy decision is underway but has not concluded.
Does ODPC provide Standard Contractual Clauses I can use for a data transfer agreement?
No confirmed template exists. ODPC’s guidance requires transfer agreements to contain specific safeguard provisions, but does not publish a ready-to-use model clause document.
What extra requirement applies to transferring sensitive personal data abroad?
Section 49 requires both the data subject’s consent and confirmed appropriate safeguards together, a stricter test than applies to ordinary personal data transfers.
Can the government require my company to store data only in Kenya?
Only in specific strategic sectors designated under section 50, such as civil registration, elections, and public finance; this is not a general rule applicable to most tech startups.



