Insights / Regulatory & Compliance

Kenya’s Cross-Border Data Transfer Compliance Regime: What ODPC’s 2026 Guidance Requires

By Clay & Associates Advocates · 5 min read ·

African businessman in a glass-walled office typing on a laptop, representing corporate compliance with cross-border data transfer rules in Kenya

The Office of the Data Protection Commissioner quietly published a substantially expanded guidance note on cross-border data transfers in September 2026, complete with Kenya’s own standard contractual clauses for the first time. Any business moving personal data out of Kenya, a bank sending customer records to a regional processing hub, a BPO transmitting call recordings to an overseas client, a multinational syncing HR data to a foreign headquarters, now has a considerably more detailed rulebook to work against than the bare text of the Data Protection Act suggested.

The Statutory Floor: Four Grounds, Not a Free Choice

Section 48 of the Data Protection Act, 2019 permits a transfer out of Kenya only where the controller or processor has proven appropriate safeguards to the Data Commissioner, or where the transfer is necessary for one of six specific purposes, contract performance, a contract in the data subject’s interest, public interest, legal claims, vital interests, or compelling legitimate interests. Regulation 40 of the Data Protection (General) Regulations, 2021 restates this as four grounds: appropriate safeguards, an adequacy decision by the Data Commissioner, necessity, or consent. Consent is very much the residual option, not a default. Regulation 46 makes clear it applies only “in the absence of an adequacy decision, appropriate safeguards or prerequisites for transfer as a necessity,” meaning a controller cannot reach for a consent checkbox simply because it is the easiest ground to document.

What Counts as an Appropriate Safeguard, and Kenya’s Own Template

Regulation 41 allows a transfer where a binding legal instrument gives protection “essentially equivalent” to Kenyan standards, or where the controller has itself assessed the circumstances and concluded appropriate safeguards exist. Until recently, Kenya offered no template for the first route, leaving controllers to adapt instruments built for other jurisdictions. The ODPC’s current guidance note changes that: it now annexes the Commissioner’s own Standard Clauses, one set for controller-to-controller transfers and a separate set for controller-to-processor transfers, expressly grounded in Part VI of the Act and Regulation 40(a), with a stated hierarchy that the Act and Regulations prevail over the Clauses wherever the two conflict. Using them is one way to satisfy the appropriate-safeguards ground, not the only way; regulation 42 separately deems safeguards to exist where the recipient’s country has ratified the African Union’s Malabo Convention, has a reciprocal data protection agreement with Kenya, or is bound by approved binding corporate rules within a corporate group.

Documentation Is Reactive, Not a Filing Requirement

A common assumption is that a cross-border transfer must be pre-cleared or filed with the ODPC before it happens. That overstates the regime. Regulation 41(2) requires that a transfer relying on appropriate safeguards be documented, recording the date and time, the recipient’s identity, the justification, and a description of the data transferred, but that documentation is produced to the Commissioner on request, not submitted proactively as a condition of transferring. The practical obligation is to keep the paper trail current and retrievable, not to seek advance approval for each transfer.

When a Transfer Triggers a Mandatory Impact Assessment

Regulation 49 lists ten categories of processing that automatically require a data protection impact assessment before the processing begins, not a numeric threshold but a category test. Several land squarely on ordinary cross-border data flows: large-scale processing of personal data for a purpose different from the one it was originally collected for, processing of sensitive personal data, and combining or cross-referencing datasets from different sources for different purposes. A business moving HR records, customer financial data, or biometric identifiers abroad should assume a DPIA is required rather than treating it as an edge case, and regulation 51 requires prior consultation with the Data Commissioner within sixty days where the assessment flags a high residual risk.

Data That Cannot Leave a Kenyan Server at All

Section 50 of the Act lets the Cabinet Secretary require that certain processing, on grounds of state strategic interest or revenue protection, be carried out only through a server or data centre located in Kenya. The current guidance note ties this to six specific categories: civil registration and legal identity management, election administration, public finance administration systems, protected computer systems under the Computer Misuse and Cybercrime Act, early childhood and basic education, and primary or secondary healthcare provision for a data subject in Kenya. A business operating in any of these six areas needs to confirm, before designing a cross-border architecture, whether its processing falls inside this localisation requirement, since the compliance answer there is not a safeguard or a consent form but keeping a serving copy of the data on Kenyan infrastructure.

How We Can Help

Clay & Associates Advocates advises banks, BPOs, SaaS providers and multinational employers on structuring cross-border data transfers, drafting transfer agreements, and complying with ODPC guidance in Kenya. See our companion piece on the ODPC’s new sensitive-data category for political affiliation and trade union membership, a narrower but time-sensitive rule affecting data transferred into Kenya. Contact our Regulatory & Compliance or Technology & Startups practice to review a data transfer agreement or DPIA obligation.

Sources: Data Protection Act, 2019, sections 47 to 50; Data Protection (General) Regulations, 2021, regulations 40 to 51; ODPC, Guidance Notes for Cross-Border Data Transfers (current, September 2026); ODPC Guidelines index.

Frequently asked questions

Can a business rely on consent alone to transfer personal data out of Kenya?
Only as a last resort. Regulation 46 of the Data Protection (General) Regulations makes consent available only where no adequacy decision, appropriate safeguards, or necessity ground applies, so it should not be treated as the default or easiest compliance route.

Does ODPC’s guidance note require using its own Standard Clauses for every transfer?
No. The Standard Clauses annexed to the current guidance note are one way to demonstrate appropriate safeguards under regulation 41, alongside a controller’s own assessment, African Union Convention ratification by the recipient country, a reciprocal agreement, or approved binding corporate rules.

Do businesses need to notify ODPC before every cross-border transfer?
No. Regulation 41(2) requires documentation of transfers relying on appropriate safeguards, including the date, recipient, justification and data description, but this is produced to the Commissioner on request rather than filed in advance.

What kind of data must stay on servers located in Kenya?
Processing tied to civil registration, election administration, public finance systems, protected computer systems, early childhood and basic education, or primary and secondary healthcare must be carried out through a server or data centre in Kenya, or with a serving copy kept there, under section 50 of the Act.

&

Clay & Associates Advocates
This article is general information, not legal advice. For advice on your matter, speak to counsel.

Related Insights

Discover more