What Boards of regionally active institutions need to know about where their data actually goes.
Download PDFVery few institutions of any size operate inside a single jurisdiction’s data perimeter any more. A Nairobi-based bank’s core banking platform may be hosted in Europe; a hospital group’s patient records may sync to a regional data centre; a fintech’s investors may sit in three different countries, each asking questions about where client data lives.
Kenya’s Data Protection Act restricts the transfer of personal data outside the country unless specific safeguards are met — yet in practice, a great deal of cross-border data movement happens through everyday tools, cloud storage, email and SaaS platforms, that were never formally reviewed against that requirement.
This analysis sets out what Kenyan law expects of cross-border data transfers, where the most common blind spots sit, and the questions a Board should be asking about data it may not realise has already left the country.
When personal data leaves Kenya, the institution that collected it does not leave with it. Kenyan law, contractual obligations and reputational exposure all travel with the data, regardless of which country now holds it.
A transfer that seemed like a routine IT decision — moving to a foreign-hosted platform, syncing to a regional office — can quietly create legal exposure the Board never approved.
02The Data Protection Act, 2019 permits the transfer of personal data outside Kenya only where the receiving country or organisation offers appropriate safeguards, where the data subject has given informed consent, or where another lawful basis applies.
In practice, this means institutions need to know, and be able to demonstrate, exactly where personal data goes once it leaves their own systems — not simply assume a vendor’s terms of service have that covered.
03The riskiest cross-border transfers are rarely the deliberate ones. They are the SaaS subscription a department signed up for without informing IT, the email attachment sent to a foreign consultant, the cloud backup that defaults to a data centre nobody selected.
Individually minor, collectively these shadow flows can mean an institution is transferring personal data internationally in dozens of ways its own Board could not list.
You cannot govern a data flow you do not know exists.
Every Board should be able to put the following questions to management, and expect a considered answer:
Do we know every country our personal data is currently stored or processed in?
Which of our vendor contracts include data transfer safeguards, and which don’t?
Who owns cross-border data governance at Board level?
How would we detect an unauthorised or undocumented data transfer?
Have our SaaS tools been reviewed for where they store data by default?
What is our lawful basis for each material cross-border transfer we rely on?
Cross-border data governance is not a barrier to operating regionally or globally — most institutions of any scale need to move data across borders to function. The governance question is not whether data crosses borders, but whether the Board can say, with confidence, exactly where it goes and why that is lawful.
“Does your Board know, with confidence, which countries currently hold your organisation’s data?”
If that map does not yet exist, building it is the logical starting point for cross-border governance.
We help leadership teams understand, govern and continuously improve Digital Trust through structured, evidence-based advisory engagements.
A short monthly briefing from the Kenya Privacy Law Review — new ODPC determinations, guidance notes, and compliance deadlines. No spam, unsubscribe anytime.