What happened
On 8 September 2026 Kenya’s Office of the Data Protection Commissioner released detailed Guidance Notes on cross‑border data transfers. The guidance clarifies Kenya’s transfer framework, adds operational detail, and highlights differences from the EU GDPR, especially regarding sensitive data, localization, and onward transfers.
Why it matters for trust and compliance
- Its status is published. It is enacted but may not be in force yet. Check the effective date before planning around it.
- The guidance signals stricter requirements for international data flows from Kenya, affecting multinational organisations’ transfer mechanisms and compliance programs.
- It relates to GDPR. The regulations library explains what that law requires.
Who is affected
technology controller processor
Recommended actions
- Review consent, cookie and tracking practices against the requirement.
- Check that privacy notices describe the practices this addresses.
- Review the transfer mechanisms relied on for affected data flows.
- Inventory AI or automated decision systems in scope and their assessments.
- Confirm handling of sensitive data categories meets the stricter rules.