MP Muchangi Patrick& Associates Advocates
Talk to an Expert
Practice Areas Case Digest Knowledge Centre Insights About Contact Talk to an Expert
Home / Regulatory Analysis / Series No. 004
Regulatory Analysis Series — No. 004

Cross-Border Data Governance: Managing Risk Beyond Kenya’s Borders

What Boards of regionally active institutions need to know about where their data actually goes.

Download PDF
Executive Summary

Very few institutions of any size operate inside a single jurisdiction’s data perimeter any more. A Nairobi-based bank’s core banking platform may be hosted in Europe; a hospital group’s patient records may sync to a regional data centre; a fintech’s investors may sit in three different countries, each asking questions about where client data lives.

Kenya’s Data Protection Act restricts the transfer of personal data outside the country unless specific safeguards are met — yet in practice, a great deal of cross-border data movement happens through everyday tools, cloud storage, email and SaaS platforms, that were never formally reviewed against that requirement.

This analysis sets out what Kenyan law expects of cross-border data transfers, where the most common blind spots sit, and the questions a Board should be asking about data it may not realise has already left the country.

48
Countries and counting now operate cross-border transfer regimes similar to Kenya’s
Most
Cross-border transfers happen through everyday SaaS tools, not formal agreements
1
Board-level owner every institution should name for cross-border data flows
0
Transfers that should occur without a documented lawful basis
01

Why Cross-Border Data Flows Are a Board Matter

When personal data leaves Kenya, the institution that collected it does not leave with it. Kenyan law, contractual obligations and reputational exposure all travel with the data, regardless of which country now holds it.

A transfer that seemed like a routine IT decision — moving to a foreign-hosted platform, syncing to a regional office — can quietly create legal exposure the Board never approved.

02

What Kenyan Law Requires Today

The Data Protection Act, 2019 permits the transfer of personal data outside Kenya only where the receiving country or organisation offers appropriate safeguards, where the data subject has given informed consent, or where another lawful basis applies.

In practice, this means institutions need to know, and be able to demonstrate, exactly where personal data goes once it leaves their own systems — not simply assume a vendor’s terms of service have that covered.

03

The Governance Blind Spot: Shadow Data Flows

The riskiest cross-border transfers are rarely the deliberate ones. They are the SaaS subscription a department signed up for without informing IT, the email attachment sent to a foreign consultant, the cloud backup that defaults to a data centre nobody selected.

Individually minor, collectively these shadow flows can mean an institution is transferring personal data internationally in dozens of ways its own Board could not list.

You cannot govern a data flow you do not know exists.

04

Sector Snapshots

Financial Services

  • Core banking, KYC verification and payment processing frequently run through regional or global platforms
  • Each integration is a potential cross-border transfer requiring its own lawful basis

Healthcare

  • Patient records shared with regional referral hospitals, labs or telemedicine partners
  • Among the most sensitive data categories under the Act, and the highest reputational cost if mishandled
05

Building Cross-Border Governance That Holds Up

06

What Boards Should Ask Management

Every Board should be able to put the following questions to management, and expect a considered answer:

Do we know every country our personal data is currently stored or processed in?

Which of our vendor contracts include data transfer safeguards, and which don’t?

Who owns cross-border data governance at Board level?

How would we detect an unauthorised or undocumented data transfer?

Have our SaaS tools been reviewed for where they store data by default?

What is our lawful basis for each material cross-border transfer we rely on?


Conclusion

The Question Is Not Whether, But Where

Cross-border data governance is not a barrier to operating regionally or globally — most institutions of any scale need to move data across borders to function. The governance question is not whether data crosses borders, but whether the Board can say, with confidence, exactly where it goes and why that is lawful.

Board Consideration

“Does your Board know, with confidence, which countries currently hold your organisation’s data?”

If that map does not yet exist, building it is the logical starting point for cross-border governance.

M

About the Author

Muchangi Patrick & Associates Advocates is a Kenyan law firm specialising in Digital Trust Assurance, data protection, technology law, AI governance and regulatory advisory. We help Boards understand, govern and continuously improve how their organisations manage information, technology, artificial intelligence and legal risk.

Is your Board receiving independent assurance
over its digital environment?

We help leadership teams understand, govern and continuously improve Digital Trust through structured, evidence-based advisory engagements.

Stay ahead of Kenya's data protection & AI regulation

A short monthly briefing from the Kenya Privacy Law Review — new ODPC determinations, guidance notes, and compliance deadlines. No spam, unsubscribe anytime.