OOC Advocates logo
OOC Advocates logo

JUSTIN OKARA

Partner

How do we navigate the complexities of cross-border information flows in a data-driven world? From GPS navigation to cloud-based services, the modern digital landscape relies heavily on seamless data transfer across national boundaries. But what happens to our personal information when it leaves our home jurisdiction? This post explores the mechanisms governing international data transfers, shedding light on the crucial data protection rights and the robust safeguards to secure our digital footprint, ensuring your peace of mind.


The ability to independently establish data adequacy agreements empowers nations to shape their international data transfer policies, aligning with a growing trend of countries asserting sovereignty over the handling of their citizens' data across borders. An "adequacy decision" formally recognises that another country or jurisdiction possesses robust data protection standards. This designation facilitates cross-border collaboration and commerce, ensuring the safeguarding of personal data within the recipient territory.


Kenya prioritises the protection of personal data during cross-border transfers. This is achieved through a stringent regulatory framework that requires data controllers and processors to demonstrate the presence of robust safeguards in the recipient country. The individual's explicit consent is also mandatory for transferring sensitive personal data (such as health or financial information). Kenya's regulatory framework asserts control over data flows, emphasising data localisation when necessary. The Office of the Data Protection Commissioner (ODPC) holds the authority to scrutinise and potentially prohibit international data transfers that fail to uphold robust data protection standards. Additionally, the Cabinet Secretary may mandate certain types of data processing exclusively within Kenya for strategic or revenue-related considerations, reflecting a commitment to data sovereignty.


Kenya employs specific criteria to evaluate the adequacy of data protection regimes in recipient countries. Primarily, ratifying the African Union Convention on Cyber Security and Personal Data Protection (the Malabo Convention) or a reciprocal data protection agreement with Kenya serves as a strong indicator of alignment with Kenyan standards. Besides, the ODPC can determine if a foreign country, territory, sector within a country, or an international organisation upholds adequate data protection. These “adequacy decisions” provide the legal basis for cross-border data transfers.


Importantly, data transfers can still occur even without an adequacy decision. Alternative mechanisms include Standard Contractual Clauses (SCCs), consent, or other legal bases outlined within the Data Protection Act 2019.


Botswana's Transfer of Personal Data Order 2022 recognises Kenya as providing adequate data protection standards, placing it among 45 designated countries. Significantly, Kenya is one of only two African nations, alongside South Africa, currently holding this distinction.


The UK's independent data protection framework, established post-EU, has designated Kenya as a priority destination for an adequacy agreement. This recognition underscores the robustness of Kenya's data protection laws and paves the way for enhanced trade and collaboration between the two nations.


This week, EU Deputy Ambassador to Kenya Ondrej Šimek, at the Network of African Data Protection Authorities (NADPA) Conference, revealed a ground-breaking development. Kenya has entered an Adequacy Dialogue with the European Union – a first for the African continent. If successful, this could lead to Kenya receiving an adequacy decision, streamlining data flows from the EU, and effectively aligning Kenya's data protection regime with EU standards. This significant step forward underscores the rapid progress of the ODPC since its establishment in 2020, offering a promising outlook for the future of data protection.


Undoubtedly, Kenya’s commitment to robust data protection extends beyond its borders. Through active collaboration with regional and international data protection authorities, the nation is steadfast in its efforts to align its framework with global standards. This proactive approach strengthens the foundation for secure international data transfers and instils confidence, opening new opportunities as Kenya's digital economy grows.

  • Kenya has established a comprehensive framework for international data transfers, requiring data controllers to ensure adequate safeguards in recipient countries, with the Office of the Data Protection Commissioner (ODPC) empowered to evaluate and potentially restrict transfers that don't meet standards, while also maintaining provisions for data localisation through the Cabinet Secretary.
     

  • The country is making significant strides in global data protection recognition, evidenced by Botswana's designation of Kenya as an adequate jurisdiction, the UK's prioritization of an adequacy agreement, and notably, Kenya's ground-breaking entry into the Adequacy Dialogue with the European Union—marking the first such dialogue between the EU and an African nation.

Data Protection

a person holding a cell phone in their hand
09 May 2024

Understanding Adequacy Decisions: How Kenya is Shaping its Data Future

OOC Advocates Logo

© 2025 Okara & Onuko Company Advocates. All rights reserved. The information on this website is for general information purposes only and should not be construed as legal advice. No action based on this content should be taken or omitted without seeking professional legal counsel.

LinkedIn OOC Advocates