Law / Kenya

Data Protection Act, 2019, transfer of personal data outside Kenya

Data Protection Act, 2019 (No. 24 of 2019), Part VI (ss. 48-54)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force since 25 November 2019.

A cross border transfer rule binding public and private bodies.

As of 4 September 2026.

What it requires

  • Give the Data Commissioner proof of appropriate safeguards, or otherwise satisfy a condition under section 48, before transferring personal data outside Kenya.
  • Check whether the Cabinet Secretary has designated your category of processing for mandatory handling on a server or data centre located in Kenya.

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

A data controller or processor may transfer personal data outside Kenya only where it has given the Data Commissioner proof of appropriate safeguards, or another condition such as the data subject's consent applies, and the Commissioner may prohibit, suspend or condition a transfer to protect data subjects' rights.

The Cabinet Secretary may prescribe that certain processing, on grounds of strategic state interest or protection of revenue, be carried out only through a server or data centre located in Kenya.

When LexLint raises it

  • crawls_web
  • trains_models

Read the law

official consolidated Act text, Kenya Law (National Council for Law Reporting)

Back to the example  ·  Lint your app