Sections 48-50 of the Kenya DPA govern cross-border transfers of personal data outside Kenya territory. (1) Section 48 General Framework: Cross-border transfer permitted only on specific grounds (a) Adequacy Determination by Cabinet Secretary; (b) Subject consent (express written for sensitive data + specific for transfer); (c) Performance of contract to which subject is party; (d) Vital interests of subject; (e) Public interest as defined by law; (f) Statutory authority; (g) Cabinet Secretary approval for specific transfer mechanism. (2) Section 49 Adequacy Determinations: (a) Cabinet Secretary determines third country provides adequate level of protection; (b) Consideration includes (i) rule of law + respect for human rights; (ii) data protection legislation + enforcement; (iii) supervisory authority independence; (iv) international commitments; (v) Convention 108+ accession; (c) Reciprocity-based adequacy emerging (e.g. EAC member states); (d) Sector-specific adequacy may be issued; (e) EU GDPR adequacy decisions referenced as guidance. (3) Section 50 Data Localisation for Strategic Interests: (a) Cabinet Secretary may direct certain categories of personal data deemed of strategic interest to Kenya MUST be stored on servers in Kenya territory; (b) Strategic interests include national security + critical infrastructure + financial stability + public health + tax revenue; (c) Categories specified by Cabinet Secretary in consultation with ODPC; (d) Enforcement against controllers + processors; (e) Foreign cloud providers must establish Kenya region presence for strategic data. (4) East African Community (EAC) Regional Coordination: (a) Kenya + Tanzania + Uganda + Rwanda + Burundi + South Sudan + Democratic Republic of Congo coordination; (b) EAC Data Protection initiative; (c) East African Court of Justice intersection; (d) Mutual recognition emerging; (e) Common Market data flow easements. (5) African Union Convention on Cyber Security and Personal Data Protection (Malabo Convention 2014): (a) Kenya ratification; (b) Continental data protection framework; (c) Coordination mechanism for African DPAs; (d) Capacity building. (6) Specific Country Adequacy Considerations: (a) EU + UK - convergence considerations; (b) USA - Schrems II considerations; (c) China - emerging trade considerations; (d) UAE - bilateral arrangements; (e) South Africa - Convention 108+ + POPIA alignment; (f) India - bilateral arrangements; (g) Other EAC members. (7) Transfer Impact Assessment (TIA): (a) Risk assessment for each transfer destination; (b) Legal regime evaluation; (c) Supplementary measures (encryption + pseudonymisation + access restriction); (d) Periodic review; (e) ODPC consultation for high-risk. (8) Standard Contractual Clauses + Binding Corporate Rules: (a) Kenya-approved SCCs emerging (currently bespoke); (b) BCRs for multinational corporate transfers; (c) Code of Conduct approved + binding; (d) Certification mechanism approved; (e) Ad hoc contractual clauses authorised. (9) Cabinet Secretary Approval Process: (a) Application to Ministry of ICT through ODPC; (b) Risk assessment + legal review; (c) Public consultation for material transfers; (d) Decision within 30-90 days; (e) Conditions may be attached; (f) Periodic review + revocation power; (g) Public register of approved mechanisms. (10) Cloud-Based Processing: (a) Hyperscaler cloud (AWS + Azure + GCP) with Kenya-region availability emerging; (b) South Africa region commonly used; (c) Sub-processor chain transparency required; (d) ODPC awareness + approval for material cloud arrangements; (e) Section 50 localisation requirement for strategic data. (11) Sectoral Cross-Border: (a) Banking + Central Bank of Kenya regulations; (b) Health data cross-border to EAC + global; (c) Insurance data; (d) Telecommunications data; (e) Government data sovereignty considerations; (f) Mobile money (M-Pesa) cross-border. (12) Penalties for Unlawful Transfers: (a) Section 63 administrative penalties; (b) Localisation violations heightened; (c) Civil compensation; (d) Injunctive relief; (e) Section 50 localisation specific. Coordinates with EU GDPR Chapter V Articles 44-50 + UK DPA 2018 + Convention 108+ + East African Community + African Union Convention on Cyber Security and Personal Data (Malabo Convention 2014) + COMESA + Central Bank of Kenya + Communications Authority of Kenya + Ministry of ICT + Cabinet Secretary + South Africa POPIA + India + bilateral arrangements + Section 48 + 49 + 50. Kenya DPA Cross-Border + Sections 48-50 applies.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.