On September 8, 2026, Kenya’s Office of the Data Protection Commissioner (“ODPC”) published new Guidance Notes for Cross-border Data Transfers (“Guidance”), providing organizations with more detailed guidance on the application of Kenya’s rules governing transfers of personal data outside the country.
The Guidance arrives at an interesting time for Kenya’s data protection framework. Kenya and the European Union are currently engaged in an adequacy process, and in June 2026 the European Commission welcomed progress in that process, noting the “positive assessment so far” and its intention to conclude the process as soon as possible. Against that backdrop, several features of the Guidance will look familiar to organizations accustomed to the EU General Data Protection Regulation (“GDPR”), including its treatment of adequacy, appropriate safeguards, Binding Corporate Rules (“BCRs”), assessments of third-country laws, and supplementary safeguards. But the comparison only goes so far. The Guidance also illustrates several important differences between Kenya’s cross-border transfer framework and the GDPR, including in relation to sensitive personal data, data localization, legitimate interests, and onward transfers. For multinational organizations seeking to use global transfer frameworks across jurisdictions, those differences are important.
Continue Reading Kenya Issues New Cross-Border Data Transfer Guidance: Familiar Concepts, but Important Local Differences