REGULATORY WATCH BRIEF Moderate 44 🧭 Regulatory Guidance published

Kenya publishes new guidance on cross‑border data transfers

The guidance signals stricter requirements for international data flows from Kenya, affecting multinational organisations’ transfer mechanisms and compliance programs.

ImpactModerate 44
Type🧭 Regulatory Guidance
Statuspublished enacted, check the effective date
JurisdictionKE

What happened

On 8 September 2026 Kenya’s Office of the Data Protection Commissioner released detailed Guidance Notes on cross‑border data transfers. The guidance clarifies Kenya’s transfer framework, adds operational detail, and highlights differences from the EU GDPR, especially regarding sensitive data, localization, and onward transfers.

Why it matters for trust and compliance

  • Its status is published. It is enacted but may not be in force yet. Check the effective date before planning around it.
  • The guidance signals stricter requirements for international data flows from Kenya, affecting multinational organisations’ transfer mechanisms and compliance programs.
  • It relates to GDPR. The regulations library explains what that law requires.

Who is affected

technology controller processor

Recommended actions

  1. Review consent, cookie and tracking practices against the requirement.
  2. Check that privacy notices describe the practices this addresses.
  3. Review the transfer mechanisms relied on for affected data flows.
  4. Inventory AI or automated decision systems in scope and their assessments.
  5. Confirm handling of sensitive data categories meets the stricter rules.