Kenya publishes new guidance on cross‑border data transfers
The guidance signals stricter requirements for international data flows from Kenya, affecting multinational organisations’ transfer mechanisms and compliance programs.
ADTP Regulatory Watch· September 16, 2026· Office of the Data Protection Commissioner (ODPC)
ImpactModerate 44
Type🧭 Regulatory Guidance
Statuspublishedenacted, check the effective date
JurisdictionKE
What happened
On 8 September 2026 Kenya’s Office of the Data Protection Commissioner released detailed Guidance Notes on cross‑border data transfers. The guidance clarifies Kenya’s transfer framework, adds operational detail, and highlights differences from the EU GDPR, especially regarding sensitive data, localization, and onward transfers.
Why it matters for trust and compliance
Its status is published. It is enacted but may not be in force yet. Check the effective date before planning around it.
The guidance signals stricter requirements for international data flows from Kenya, affecting multinational organisations’ transfer mechanisms and compliance programs.
It relates to GDPR. The regulations library explains what that law requires.
Who is affected
technologycontrollerprocessor
Recommended actions
Review consent, cookie and tracking practices against the requirement.
Check that privacy notices describe the practices this addresses.
Review the transfer mechanisms relied on for affected data flows.
Inventory AI or automated decision systems in scope and their assessments.
Confirm handling of sensitive data categories meets the stricter rules.