On 8 September 2026 Kenya’s Office of the Data Protection Commissioner released detailed Guidance Notes on cross‑border data transfers. The guidance clarifies Kenya’s transfer framework, adds operational detail, and highlights differences from the EU GDPR, especially regarding sensitive data, localization, and onward transfers.
Why it matters: The guidance signals stricter requirements for international data flows from Kenya, affecting multinational organisations’ transfer mechanisms and compliance programs.
Summary generated from the sources below. Check the primary source before relying on it; this is not legal advice.