Cloud Computing 2026 Comparisons

Last Updated October 06, 2026

Contributed By KMK Africa Advocates LLP

Law and Practice

Authors



KMK Africa Advocates LLP is a full-service law firm based in Nairobi, Kenya, with a further presence in Abuja and Lagos in Nigeria, and in Singapore City, Singapore. With expertise across diverse practice areas, the firm delivers solution-oriented legal services tailored to each client’s unique needs. The firm’s legal practitioners possess combined backgrounds in law, economics and finance, allowing the firm to craft solutions framed around commercial viability, return on investment, and operational realities. In corporate and commercial law, the firm advises clients ranging from emerging start-ups to multinational enterprises on corporate set-up, regulatory compliance, domestic and cross-border mergers and acquisitions, joint ventures and complex commercial contracting. The banking and finance practice assists commercial lenders, corporate borrowers and institutional investors with capital raising, debt financing structures and cross-border transactions. In response to Africa’s rapidly evolving digital economy, the firm’s technology, intellectual property and data protection division focuses on safeguarding brand assets and digital innovations.

Kenya’s data privacy framework for cloud computing rests on constitutional protections, a dedicated statute and sector-specific rules.

  • The Constitution of Kenya, 2010 (Article 31(c) and (d)) guarantees every person the right to privacy, including protection against the unnecessary disclosure of private information and against infringement of the privacy of communications.
  • The Data Protection Act, Cap 411C (DPA) is the primary statute giving effect to Article 31(c) and (d) of the Constitution. It regulates the collection, processing, storage and cross-border transfer of personal data; sets out the rights of data subjects and the obligations of data controllers and processors; and establishes the Office of the Data Protection Commissioner (ODPC) as the sector regulator.
  • The Data Protection (General) Regulations, 2021 (DPGR) operationalise the DPA by detailing data subject rights, controller and processor obligations, security standards, cross-border transfer conditions, data localisation requirements, and Data Protection Impact Assessment (DPIA) procedures.
  • The Data Protection (Registration of Data Controllers and Data Processors) Regulations, 2021 require cloud customers and cloud service providers (CSPs) operating in Kenya to register with the ODPC as data controllers or data processors, as applicable.
  • The Data Protection (Complaints Handling Procedure and Enforcement) Regulations, 2021 set out the procedures for lodging complaints with the ODPC, conducting inspections, issuing enforcement notices, and imposing administrative fines.
  • The Computer Misuse and Cybercrimes Act, Cap 79C (CMCA) criminalises unauthorised access to computer systems, system interference and cyber-espionage. It also provides for the designation and protection of Critical Information Infrastructure (CII), which is directly relevant where CII is hosted in cloud environments.
  • The Kenya Cloud Policy 2024 is a national policy framework intended to guide the transition from on-premises data centre infrastructure to cloud computing, facilitate cross-border data transmission, promote interoperability, and strengthen inter-agency collaboration. The Policy complements existing statutory instruments.
  • Sectoral regulations – industry-specific rules impose additional cloud adoption requirements. The Central Bank of Kenya (CBK) Prudential Guidelines and the CBK Operational Risk Management Guidelines, for example, govern outsourcing and cloud adoption by licensed financial institutions, requiring prior regulatory notification and ongoing oversight.

Section 2 of the DPA provides the following definitions.

  • Personal data is any information relating to an identified or identifiable natural person (data subject). This covers direct identifiers (name, national ID number, passport number) and indirect identifiers (IP addresses, cloud account IDs, location data, unique online identifiers) stored in cloud databases.
  • Sensitive personal data is data revealing a natural person’s race, health status, ethnic or social origin, conscience, belief, genetic data, biometric data, property details, marital status, family details (including names of children, parents and spouses), sex, sexual orientation or criminal record. Sensitive data attracts heightened protection because its loss or unauthorised disclosure carries more serious social, reputational and legal consequences. The ODPC has recently issued a Further Notice inviting public comments on a proposal to add political party affiliation and trade union membership to the list of sensitive personal data categories.

General Personal Data Processing Requirements

Processing personal data in the cloud requires a lawful basis under Section 30 of the DPA. The recognised bases are:

  • explicit consent of the data subject;
  • performance of a contract to which the data subject is a party;
  • compliance with a legal obligation;
  • protection of the vital interests of the data subject or another natural person;
  • performance of a task carried out in the public interest or in the exercise of official authority;
  • legitimate interests of the controller or a third party; and
  • processing for historical, statistical, artistic, literary or scientific research purposes.

All cloud processing must comply with the following data protection principles set out in Section 25 of the DPA.

  • Lawfulness, fairness and transparency: data subjects must receive clear notice about how their data will be processed, including the location of cloud storage.
  • Purpose limitation: data uploaded to the cloud must not be further processed for purposes incompatible with the original collection purpose.
  • Data minimisation: only data that is necessary for the defined processing purpose should be uploaded to the cloud.
  • Accuracy: data held in cloud infrastructure must be kept up to date, with inaccurate information rectified or erased without delay.
  • Storage limitation: data must be deleted or anonymised once the applicable retention period expires.
  • Integrity and confidentiality: appropriate technical and organisational security measures must be implemented to guard against unauthorised access, alteration or destruction.
  • Privacy rights: personal data must be processed in a manner that respects the data subject’s right to privacy.
  • Cross-border transfer: personal data must not be transferred outside Kenya unless adequate data protection safeguards are in place in the recipient country or the data subject has given consent, subject to additional conditions under Sections 48–50 of the DPA.

Data Protection Impact Assessment (DPIA)

Under Section 31 of the DPA and Regulation 35 of the DPGR, a data controller must carry out a DPIA before carrying out processing that is likely to result in high risk to the rights and freedoms of data subjects. In the cloud context, this obligation is triggered by activities such as migrating large-scale datasets or sensitive personal data to third-party public cloud platforms.

In Republic v Mucheru, Cabinet Secretary Ministry of Information Communication and Technology & 2 others; Katiba Institute & another (Ex parte); Immaculate Kasait, Data Commissioner (Interested Party) (Judicial Review Application E1138 of 2020) [2021] KEHC 122 (KLR), the High Court at Nairobi halted the government’s processing of the Huduma Card on the ground, among others, that no data protection impact assessment had been conducted.

Obligations of Controllers and Processors in the Cloud

The data controller (cloud customer) determines the purpose and means of processing. The controller bears primary legal responsibility for obtaining lawful consent, conducting DPIAs, responding to data subject requests, and instructing the cloud provider on the scope and manner of processing.

The data processor (cloud service provider – CSP) processes personal data on behalf of, and under the documented instructions of, the data controller (Section 42 of the DPA). A CSP may not process customer data for its own independent analytics or commercial purposes without prior written authorisation from the controller.

Key Statutory Obligations

  • Duty of confidentiality: all employees and sub-processors of both the controller and the processor must be bound by written confidentiality agreements.
  • Sub-processor controls: under Section 42(2) of the DPA, a CSP may not engage a third-party sub-processor without the data controller’s prior written authorisation.
  • Assistance mandates: CSPs must provide the technical and organisational support necessary for the data controller to fulfil data subject rights, carry out audits, and manage breach notifications.

Please see 6.1 Cross-Border Transfer Regulation and 6.3 Conflicts of Law.

Please see 7.1 Cloud Computing and Compliance/Audits.

Key Security Measures

The following measures are required by law for data stored in the cloud.

  • Logging: data controllers must ensure that audit trails generated by cloud service providers are retained. These include user login histories and records of changes to personal data. Logs should be reviewed regularly to detect anomalous activity and to support investigations in the event of unauthorised access.
  • Appropriate user configuration: data controllers must understand the configuration options available within the cloud service and verify that access settings are correctly applied. Access should be restricted to authorised individuals with a demonstrated operational need.
  • Encryption in transit and at rest: unprotected data, whether in transit or at rest, exposes an organisation to interception and breach. Because cloud services operate over public internet infrastructure, personal data must be encrypted during transmission to guard against eavesdropping and man-in-the-middle attacks. Data at rest should likewise be encrypted on cloud storage to prevent unauthorised access. Data controllers should select CSPs that offer encryption at rest as a standard service feature.
  • Multi-factor authentication (MFA) should be enabled for all accounts with access to personal data in the cloud, and extended to as many user accounts as practicable.
  • Anonymisation adds a further layer of protection to personal data stored in the cloud. It involves stripping a dataset of all information from which an individual could be identified, taking re-identification risks into account. Where properly implemented, anonymised data falls outside the scope of the DPA.

Data Subject Rights in Cloud Environments

Data subjects retain the following rights over personal data stored in cloud infrastructure, under Sections 26 to 40 of the DPA.

  • Right to access: a data subject may request confirmation of whether personal data is being processed, and may obtain copies of that data from cloud servers.
  • Right to rectification: inaccurate or incomplete personal data held in the cloud must be corrected without undue delay upon request.
  • Right to erasure (“right to be forgotten”): where personal data is no longer necessary for the purpose for which it was collected or if consent has been withdrawn, the data must be permanently deleted from active cloud databases, back-ups and index structures.
  • Right to object and restrict processing: a data subject may object to automated profiling or commercial exploitation of data held in the cloud, and may request that processing be restricted in specified circumstances.
  • Right to data portability (Section 38): a data subject may receive personal data in a structured, commonly used and machine-readable format, or may request direct transfer of the data from one CSP to another where technically feasible.

Data Ownership, Retention and Deletion Policies

  • Data ownership: under Kenyan law, uploading personal data to a third-party cloud does not transfer ownership of that data to the CSP. Cloud agreements must contain express provisions confirming that customer data remains the exclusive property of the data controller.
  • Retention limitations: Section 25(e) of the DPA requires that personal data be retained only for as long as necessary to fulfil the purpose for which it was originally collected.
  • Deletion management: cloud contracts must prescribe secure data erasure standards to ensure that data distributed across cloud storage blocks and secondary back-ups is irreversibly destroyed or de-identified upon the expiry or termination of the agreement.

Measures Ensuring Data Portability in the Cloud

Under Section 38 of the DPA, data subjects have the right to receive their personal data stored in the cloud in a structured, commonly used and machine-readable format. They may also request the direct transmission of that data from one CSP or controller to another, provided this is technically feasible.

Technical and Operational Measures

  • Open standard formats and API integration: data controllers should select CSPs that support open, interoperable APIs and non-proprietary data schemas to avoid technical vendor lock-in and facilitate seamless data migration.
  • Contractual guarantees: Data Processing Agreements must obligate the CSP to provide data extraction tools and support orderly data offboarding without imposing unreasonable financial penalties or bandwidth egress charges.
  • Schema and metadata integrity: when executing cloud-to-cloud portability requests, processing workflows must preserve data structures, associations and metadata so that the data remains functionally usable in the destination system.

Storage Limitation Principle (Section 25(g) of the DPA)

Personal data stored in cloud databases and object storage must not be retained beyond the period necessary to fulfil the specific, lawful purpose for which it was collected, unless a specific written law requires prolonged retention.

Retention Policy Management

  • Mandatory data retention schedules: under Regulation 19 of the DPGR, data controllers and processors must maintain a formal retention schedule specifying the legal basis for holding each category of data, the applicable retention period, and periodic review dates.
  • Automated cloud life cycle policies: in practice, system administrators deploy cloud-native object life cycle rules that automatically transition data from active storage to cold archives and trigger permanent deletion at the end of the retention cycle.

Deletion and Sanitisation Protocols

  • Right to erasure implementation: once a retention period expires or a data subject requests erasure under Sections 26 and 40 of the DPA, the data must be permanently destroyed, erased or anonymised across all primary and secondary cloud storage.
  • Cryptographic erasure: in distributed, multi-tenant public cloud environments, data controllers may effect deletion by destroying the Customer-Managed Encryption Keys (CMKs) used to encrypt data at rest, thereby rendering the underlying storage blocks unrecoverable.
  • Sanitisation standards and verification: CSP agreements should require adherence to recognised data sanitisation standards for purging residual data from physical media, active back-ups and index logs. The CSP should issue a formal, verifiable Certificate of Data Destruction upon completion.

Selecting a CSP in Kenya calls for a structured due diligence process that measures the provider’s commercial capabilities against the requirements of the DPA and the DPGR. The principal due diligence areas are as follows.

Regulatory and Licensing Verification

  • ODPC registration: confirm that the CSP is registered with the ODPC as a data processor or data controller under the Registration Regulations, 2021.
  • Sectoral approvals: where the customer operates in a regulated sector, verify that the CSP’s deployment model complies with applicable sector-specific rules, such as the CBK Prudential Guidelines on Outsourcing for financial institutions.

Data Sovereignty and Residency Auditing

  • Localisation mandates: establish where the CSP’s primary, secondary, back-up and log storage servers are located. For strategic public records, health, education and critical infrastructure datasets, confirm that the CSP maintains at least one serving copy within Kenya in accordance with Regulations 25 and 26 of the DPGR.
  • Cross-border transfer compliance: if customer data will leave Kenya, audit the destination jurisdictions against Sections 48–50 of the DPA and ensure the CSP executes ODPC-aligned Standard Contractual Clauses (SCCs) or Binding Corporate Rules (BCRs).

Contractual and Sub-Processor Controls

  • Mandatory DPA execution: require the CSP to enter into a tailored Data Processing Agreement binding it to act strictly on the controller’s documented instructions.
  • Sub-processor transparency: review the CSP’s sub-processor chain. The contract must require prior written notice to, and approval from, the data controller before any sub-processor is granted access to personal data.

Technical Security Architecture and Industry Standards

  • Cryptographic and access standards: confirm that the CSP supports encryption for data at rest, TLS 1.2 or higher for data in transit, CMKs and zero-trust identity and access management architectures.
  • Independent certifications: obtain current third-party audit reports confirming compliance with global security baselines, such as ISO/IEC 27001, ISO/IEC 27017 (Cloud Security), ISO/IEC 27018 (Cloud Privacy) and SOC 2 Type II.

Incident Management and Auditability SLAs

  • Breach reporting timelines: bind the CSP contractually to report security incidents without delay (and in any event within 24–48 hours of detection), so that the data controller can meet the 72-hour notification deadline under Section 43 of the DPA.
  • Immutable logging: verify that the CSP provides tamper-evident audit logs recording user access, API calls and privilege changes. These logs must be accessible to the controller and sufficient to substantiate compliance during ODPC audits or to satisfy evidentiary requirements under Section 106B of the Evidence Act (Cap 80).

Exit Strategy, Portability and Sanitisation

  • Data portability (Section 38 of the DPA): assess the CSP’s data extraction tools to confirm that data can be exported in standardised, machine-readable formats without unreasonable financial or technical barriers.
  • Sanitisation protocols: require the CSP to carry out cryptographic erasure of all residual customer data across distributed storage blocks and secondary back-ups upon contract termination, and to issue a formal Certificate of Data Destruction.

Data protection requirements are incorporated into Cloud Service Agreements in Kenya through a mandatory Data Processing Agreement or a dedicated data protection schedule, as required by Regulation 22 of the DPGR. The specific contents of a Data Processing Agreement are addressed in 4.3 Data Processing Agreements and the Cloud.

Measures Ensuring CSP Compliance With Data Privacy Regulations

  • Statutory shift of liability: under Section 42(3) of the DPA, a CSP that processes personal data outside or contrary to the data controller’s instructions is treated as a data controller in respect of that processing. This subjects the CSP to direct statutory duties and liability for any resulting violations.
  • Mandatory ODPC registration: CSPs operating in or serving customers in Kenya must register with the ODPC under the Data Protection (Registration of Data Controllers and Data Processors) Regulations, 2021.
  • Regulatory audits and inspections: the ODPC holds statutory powers under Sections 60–62 of the DPA and the Data Protection (Compliance and Enforcement) Regulations, 2021 to conduct unannounced compliance audits, request access to cloud logs, and issue binding Enforcement Notices.
  • DPIAs: a controller migrating workloads to a public cloud must carry out a DPIA under Section 31 of the DPA, assessing the CSP’s compliance posture and security architecture before deployment.
  • Independent certifications: CSPs demonstrate ongoing compliance by maintaining accredited third-party security certifications, such as ISO/IEC 27001, ISO/IEC 27018 and SOC 2 Type II, and by making the corresponding audit reports available to customers.
  • Administrative fines, compensation and offences: a non-compliant CSP faces administrative fines imposed by the ODPC, as well as potential civil damages under Section 65 of the DPA for unlawful disclosure of personal data or obstruction of an ODPC investigation.

A contract between a cloud customer and a CSP must satisfy the requirements of Section 42 of the DPA and Regulation 22 of the DPGR. At a minimum, it must address the following.

  • Subject matter and duration: a clear description of the cloud services to be provided and the term of the engagement.
  • Instruction-bound processing: an express obligation that the CSP will process personal data only on the controller’s written instructions.
  • Security guarantees: an obligation on the CSP to implement and maintain appropriate technical and organisational security measures.
  • Sub-processor authorisations: a requirement for the CSP to obtain the controller’s prior written consent before engaging or changing any sub-processor.
  • Audit assistance: a right for the controller (or its designated auditor) to inspect the CSP’s cloud infrastructure and security logs.
  • Data subject rights assistance: an obligation on the CSP to provide the system tools and technical support needed for the controller to respond to access, rectification, deletion and portability requests (Sections 26–40 of the DPA).
  • Breach notification and incident response: a contractual requirement for the CSP to notify the controller without undue delay (and within 24–48 hours) of any security compromise, enabling the controller to meet the 72-hour ODPC reporting obligation (Section 43 of the DPA).
  • Data return and deletion: pursuant to Regulation 22(d) of the DPGR, the agreement must provide that all personal data will be permanently erased or returned to the controller upon expiry or termination, at the controller’s election.

Termination and Exit Strategies in Cloud Agreements

A properly structured exit strategy safeguards operational continuity, prevents vendor lock-in, and ensures regulatory compliance during offboarding.

Common Termination Triggers

  • Termination for cause: material breach of contract, persistent failure to meet SLA benchmarks, unresolved data security incidents, or non-compliance with the DPA.
  • Termination for convenience: a contractual right (typically exercisable by the cloud customer) to terminate on advance written notice, commonly 30 to 90 days.
  • Regulatory imperative: an ODPC enforcement notice, a regulatory order, or a directive from a sector regulator requiring immediate termination or relocation of data.

Essential Exit Contractual Terms

  • Transition assistance period: the outgoing CSP must maintain baseline services and system access for a run-off period (typically 60–180 days) after termination to avoid service disruption.
  • Data portability (Section 38 of the DPA): the outgoing CSP must extract and return all customer data and associated metadata in a structured, commonly used and machine-readable format without functional degradation.
  • Technical and migration support: the outgoing CSP must assist the incoming provider or the customer’s in-house IT team by supplying system schemas, API documentation and operational logs.
  • Secure data sanitisation and destruction: under Sections 25 and 42 of the DPA, the outgoing CSP must irreversibly purge all active data, redundant copies and secondary back-ups, and issue a formal Certificate of Data Destruction.
  • Exit cost schedules: pre-negotiated fee caps for egress bandwidth and professional migration support, to prevent punitive exit charges.

Data and Service Migration Protocol (Cloud-to-Cloud)

Cloud-to-cloud data migration typically proceeds in four phases.

Phase 1: discovery, assessment and compliance

  • Data mapping: a comprehensive audit of all cloud assets, classifying data by type (personal, sensitive, corporate), charting application dependencies, and documenting metadata structures.
  • Residency and localisation verification: confirm that the target CSP complies with Kenya’s data localisation rules under Regulations 25 and 26 of the DPGR and cross-border transfer conditions under Section 48 of the DPA.

Phase 2: technical pipeline execution

  • Direct cloud-to-cloud API transfer: secure, encrypted network pipelines are established directly between the outgoing and incoming CSP storage endpoints.
  • Physical data transfer: for large datasets where bandwidth constraints make online transfer impracticable, data is loaded onto encrypted physical storage appliances and shipped to the target CSP’s data centre.
  • Service re-architecture: microservices, serverless functions and containerised applications are adapted to the target CSP’s runtime environment.

Phase 3: validation, checksum verification and dual-run

  • Integrity auditing: automated hash and checksum comparisons are run against source and target datasets to confirm complete, error-free replication.
  • Parallel/dual-run execution: critical workloads run concurrently on both platforms for load testing, latency verification and zero-downtime cutover planning.

Phase 4: final cutover and decommissioning

  • DNS and traffic redirection: domain routing, API gateways and user endpoints are updated to point exclusively to the target CSP.
  • Credential revocation: all IAM accounts, API keys and access permissions tied to the outgoing CSP are deactivated.
  • Verification of destruction: the data controller obtains a final audit confirmation verifying that all residual customer data has been purged from the outgoing CSP’s physical and virtual storage.

Specific Requirements for Reporting Data Breaches in the Cloud

Mandatory content of ODPC breach notifications (Section 43(5) of the DPA)

  • Incident summary: the root cause and nature of the breach (for example, a misconfigured cloud storage bucket, compromised IAM credentials, or a ransomware attack).
  • Impact scope: the categories of personal data affected and the approximate number of data subjects and cloud records involved.
  • Contact information: the name and direct contact details of the Data Protection Officer (DPO) or lead incident manager.
  • Consequence assessment: the likely risks and adverse impact on the affected data subjects.
  • Remediation plan: the immediate containment steps already taken (such as IP blocking, key rotation or isolation of compromised virtual machines) and the long-term preventative measures proposed.

Cloud provider co-ordination and verification protocol

  • Contractual SLA alignment: the data controller should oblige the CSP to deliver automated incident alerts within 24 hours of detection, preserving the controller’s 72-hour window for filing with the ODPC.
  • Forensic evidence sharing: the CSP should supply SIEM audit logs, API telemetry and access records to enable the controller to substantiate its breach report to the ODPC.

Penalties for Non-Reporting of a Data Breach in the Cloud

Failure to report a breach is an offence under the DPA. It exposes the entity to ODPC enforcement notices and administrative fines of up to KES5 million (approximately USD38,600) under Section 63.

Investigating and remediating a data breach in a cloud environment requires co-ordinated action between the data controller, the CSP (as data processor) and the relevant regulatory authorities.

Cloud-Level Technical Investigation and Forensic Preservation

The CSP, as data processor, is legally obligated under Section 42 of the DPA to assist the controller in meeting its compliance obligations. During a breach, the CSP must assist in extracting system audit logs, API access records and SIEM telemetry to establish the attack vector, timeline and scope of the unauthorised access.

Remediation Protocol

  • Short-term containment: immediate isolation of compromised cloud storage buckets or virtual machines, revocation of compromised IAM credentials, rotation of cryptographic keys, and blocking of compromised IP ranges.
  • Medium-term restoration: application of outstanding security patches, hardening of system configurations, and restoration of data from verified clean back-ups.
  • Long-term prevention: review of access policies, amendment of Cloud Service Agreements, reassessment of sub-processor access rights, and completion of a post-incident risk audit.

Regulatory Investigation Powers

  • ODPC inquiries: under Regulations 4–15 of the Data Protection (Compliance and Enforcement) Regulations, 2021, the ODPC may open a formal investigation upon receiving a breach notification or a data subject complaint.
  • Search warrants and inspection: the ODPC may apply to court for warrants to enter premises, access cloud management consoles, request audit logs or inspect physical servers located in Kenya.
  • Cybercrime escalation: where a breach results from a malicious hack, ransomware or other unauthorised system intrusion, a parallel investigation is triggered under the Computer Misuse and Cybercrimes Act, led by the National Kenya Computer Incident Response Team – Coordination Centre (KE-CIRT/CC).

The breach notification regime is governed by Section 43 of the DPA and Regulations 35–39 of the DPGR, as follows.

  • CSP to controller notification: the cloud processor must notify the data controller immediately (without undue delay) upon confirming a security incident or unauthorised access affecting personal data.
  • Controller to ODPC notification: the data controller must notify the ODPC within 72 hours of becoming aware of a personal data breach, unless the breach is unlikely to pose a risk to the rights and freedoms of data subjects.
  • Notification to data subjects: where a breach is likely to result in a high risk to data subjects’ rights and freedoms, the controller must communicate the breach to the affected individuals in writing and without delay.
  • Required notification contents: the notification must include:
    1. a description of the breach;
    2. the categories and approximate number of affected data subjects;
    3. the DPO’s contact details;
    4. an assessment of the likely consequences;
    5. the remedial measures taken or proposed; and
    6. any supporting documentation, such as incident response logs and reports filed with regulators.

Special Exceptions and Public Disclosure

  • Delayed ODPC notification: where reporting exceeds 72 hours, the controller must provide the Data Commissioner with documented justification for the delay (for instance, the need to complete forensic isolation before disclosing details).
  • Law enforcement deferral: notification to affected data subjects may be delayed on the direction of the ODPC or law enforcement agencies where disclosure would compromise an active criminal investigation (Regulation 37 of the DPGR).
  • Public announcements: where direct written communication to each affected data subject is impracticable because of the number of individuals involved, the ODPC may authorise public notices in national media as a substitute.

Before transferring personal data to a cloud environment hosted outside Kenya, data controllers and processors should:

  • establish a lawful basis for the processing and verify that the cross-border transfer conditions under the DPA are met;
  • engage only CSPs that maintain adequate technical and organisational safeguards;
  • execute Data Processing Agreements specifying each party’s role, responsibilities and compliance obligations;
  • periodically review the CSP’s terms of service and sub-processor arrangements to confirm continued compliance;
  • ensure data subjects can exercise their statutory rights regardless of where the data is stored, supported by documented response procedures;
  • conduct DPIAs for all cloud deployments involving cross-border data transfers;
  • maintain a data retention policy specifying retention periods and secure deletion timelines, supported by life cycle automation;
  • provide periodic staff training on secure cloud data handling and DPA compliance; and
  • monitor provider changes, update system configurations, and reassess risks to maintain continuous compliance.

International Data Transfer Mechanisms

Under Part VI (Sections 48–50) of the DPA and Part VIII of the DPGR, transferring personal data outside Kenya to offshore cloud servers requires one of the following legal mechanisms.

  • Adequacy decision (Section 48(a)): transfer to a country whose data protection framework the ODPC has assessed as providing comparable safeguards. The ODPC evaluates adequacy on a case-by-case basis; no published “white list” of adequate jurisdictions exists at present.
  • Appropriate safeguards (Section 48(b)): enforceable SCCs approved by the ODPC, or BCRs for intra-group transfers.
  • Explicit consent (Section 49): required for transfers of sensitive personal data abroad, or as a derogation of last resort after the data subject has been informed of the specific cross-border risks.
  • Necessity: transfer that is necessary for the performance of a contract, the establishment or exercise of legal claims, or the protection of a vital public interest.

Written international transfer agreements must define the roles and responsibilities of both the transferring and receiving entities. Key obligations include the following:

  • both parties must implement appropriate technical and organisational measures – covering data integrity, availability and confidentiality – to protect personal data during and after the transfer;
  • the receiving party must co-operate with relevant authorities in the event of audits, investigations or legal inquiries;
  • both parties must establish procedures for reporting data breaches in accordance with the DPA;
  • the agreement must require the maintenance of processing activity records and provide for audit rights to verify compliance;
  • on termination of the agreement, the receiving party must delete or return all personal data, as instructed by the transferring entity; and
  • the agreement must allocate liability between the parties for non-compliance and data breaches, including obligations to compensate affected data subjects.

Data Localisation Mandates

Section 50 of the DPA read with Regulations 25 and 26 of the DPGR imposes strict localisation requirements for specific categories of data, including mandatory local storage/processing. Processing must take place on servers physically located within Kenya, or at least one serving copy of the data must be maintained in a Kenyan data centre, for the following categories:

  • strategic public records and national population registers;
  • civil registration and identity management data;
  • national education and health data infrastructure; and
  • systems designated as CII under the CMCA.

Implications of Data Localisation Requirements on Cloud Computing in Kenya

  • Shift toward hybrid and multi-cloud architectures: organisations processing regulated data categories can no longer rely exclusively on public clouds hosted offshore. Cloud deployments for such data must adopt hybrid or localised models, maintaining primary databases or a serving copy on in-country infrastructure (such as a local colocation facility) while using global cloud regions only for non-restricted processing or analytics.
  • Expansion of local data centre infrastructure: localisation requirements have accelerated capital investment in Kenya’s digital infrastructure. Several global CSPs and colocation operators have begun building or expanding carrier-neutral data centres in Nairobi and other locations, offering localised availability zones that enable enterprise and public sector compliance without triggering cross-border transfer restrictions.
  • Increased operational and compliance costs: maintaining local serving copies and dual-cloud environments introduces additional expenditure.
    1. Infrastructure costs: dual-hosting fees, bandwidth egress charges between local nodes and global cloud regions, and licensing costs for local cloud appliances.
    2. Administrative costs: DPIAs under Section 31 of the DPA, ongoing data mapping audits, and verification of real-time synchronisation between offshore databases and local serving copies.
  • Public sector and regulated vendor selection constraints: SaaS and PaaS vendors bidding for Kenyan government, financial institution or healthcare contracts must demonstrate localised data residency options. Foreign cloud providers without a local hosting node or local partner infrastructure risk exclusion from public procurement under the government’s “Cloud-First” guidelines.
  • Statutory risk and enforcement exposure: non-compliance with localisation rules constitutes an offence under the DPA, attracting administrative fines of up to KES5 million (approximately USD38,600) or 1% of annual turnover (whichever is lower) under Section 63. Failure to secure infrastructure designated as CII under the CMCA may also expose system administrators and cloud operators to criminal liability.

Conflicts of Law and Risk Mitigation

Where a foreign-headquartered CSP is subject to extra-territorial legislation such as the EU GDPR or the US CLOUD Act, international transfer agreements must include governing law clauses that give primacy to Kenyan statutory protections and oblige the CSP to challenge foreign court orders that conflict with Kenyan data protection law.

Addressing Conflicts of Law in Cross-Border Data Transfers

Under the DPA and the DPGR, conflicts of law arising from international cloud transfers are addressed through a combination of statutory primacy, mandatory contractual mechanisms, and technical safeguards.

  • Mandatory primary jurisdiction: under Section 48 of the DPA, Kenyan data protection law applies to all processing of personal data collected from data subjects in Kenya. Controllers cannot waive or override these statutory protections by inserting foreign choice-of-law or exclusive foreign jurisdiction clauses into Cloud Service Agreements.
  • SCCs and ODPC oversight: where data is transferred abroad under “appropriate safeguards” (Section 48(b)), the DPA must incorporate ODPC-aligned SCCs. These clauses must stipulate that in any conflict between the contractual terms (or a foreign legal order) and the DPA, the statutory protections of Kenyan law prevail.
  • Foreign government access and subpoenas: a central conflict arises when a foreign government compels a foreign-headquartered CSP to disclose data stored in or originating from Kenya. The ODPC’s Cross-Border Transfer Guidance requires cloud contracts to include clauses obliging the CSP to:
    1. notify the Kenyan data controller immediately upon receiving a foreign judicial or governmental data request (unless strictly prohibited by foreign law from doing so);
    2. exhaust all available legal remedies to challenge foreign disclosure orders that conflict with Kenyan privacy law; and
    3. require foreign authorities to use official Mutual Legal Assistance Treaty (MLAT) channels rather than direct administrative subpoenas.
  • Supplementary technical measures: to mitigate jurisdiction conflicts in practice, organisations hold encryption keys locally within Kenya using CMKs. This ensures that even if a foreign court compels a CSP to hand over cloud data blocks, the encrypted data remains unreadable without the locally held key.
  • Constitutional supremacy: under Article 31(c) and (d) of the Constitution of Kenya, the right to privacy is a fundamental right. As the High Court affirmed in Republic v Tools for Humanity Corporation (US) & 9 others; Katiba Institute & 4 others (Ex parte Applicants) (Judicial Review Application E119 of 2023) [2025] KEHC 5629 (KLR), cross-border data transfers cannot circumvent constitutional scrutiny through private commercial arrangements.

Risks and Challenges of Cross-Border Cloud Data Transfers

  • Extraterritorial foreign surveillance: hosting Kenyan personal data in jurisdictions without comprehensive privacy legislation exposes said data to broad foreign intelligence and law enforcement monitoring, with limited judicial oversight or redress available to Kenyan data subjects.
  • Regulatory asymmetry and enforcement gaps: enforcing data subject rights (such as rectification or erasure under Section 26 of the DPA) becomes difficult when servers or sub-processors are located in jurisdictions the ODPC has not assessed as adequate. The ODPC’s enforcement powers face practical and diplomatic limitations outside Kenya.
  • Multi-tiered sub-processor supply chains: CSPs routinely route, replicate and back up data across dynamic global data centre networks. Tracking these cascade transfers to lower-tier sub-processors creates visibility gaps, and risks unauthorised secondary processing without the controller’s knowledge or a valid legal basis.
  • Vendor lock-in and high egress costs: migrating data from a foreign cloud platform to a local data centre or an alternative provider frequently involves steep bandwidth and egress charges and formatting barriers. These costs can impair the controller’s ability to comply with portability obligations under Section 38 or to execute an emergency vendor exit.
  • Complex Transfer Impact Assessments: demonstrating compliance with Section 48 requires continuous legal and technical evaluation of foreign legal systems. For Kenyan small and medium-sized enterprises, the cost of conducting thorough Transfer Impact Assessments and enforcing cross-border contractual guarantees can be prohibitive.

Compliance Audits, Audit Trails and Statutory Penalties

Cloud compliance audits

Under Section 23 of the DPA, the ODPC has statutory authority to conduct periodic compliance audits of cloud operations. Cloud compliance audits assess security controls, data privacy measures and legal adherence within the shared responsibility model that applies between the CSP and the cloud customer.

Audit procedures

  • Scoping and shared responsibility mapping: the audit begins by delineating the boundary between provider-managed physical infrastructure and customer-managed controls (IAM policies, database encryption settings and network security groups).
  • Automated evidence collection: auditors use Cloud Security Posture Management (CSPM) tools and native logging services to pull configuration states, API call histories and access records.
  • Framework assessment: systems are benchmarked against statutory requirements (the DPA and ODPC audit regulations) alongside international security frameworks such as ISO/IEC 27001.
  • Regulatory and third-party review: independent auditors or the ODPC inspect Data Processing Agreements, DPIAs and cross-border transfer documentation for compliance.

Audit focus areas

Audits tend to focus on:

  • technical security architecture;
  • cross-border transfer authorisations;
  • verification that DPIAs have been carried out;
  • user consent records; and
  • sub-processor verification.

Audit logs and trails

Cloud systems must generate immutable, time-stamped log files recording data access events, modifications, administrative privilege changes, and data export operations.

Integrity measures

Write Once Read Many (WORM) storage, centralised log management through SIEM platforms, and digital signatures are used to prevent tampering with audit logs and to preserve the integrity of audit reports.

Addressing audit findings and recommendations

  • Risk triage and prioritisation: findings (such as unencrypted storage buckets or overly permissive IAM roles) are classified by severity based on exploitability, data sensitivity and legal exposure.
  • Corrective action plans: clear ownership is assigned to the responsible engineering or security lead, with explicit remediation deadlines (critical exposure risks are typically expected to be addressed within 24–48 hours).
  • Infrastructure-as-code remediation: where applicable, fixes are applied upstream within deployment pipelines to ensure system-wide, repeatable corrections across all environments.
  • Validation and evidence preservation: automated re-scans, configuration comparisons and secondary penetration tests are run to verify that findings have been resolved, and cryptographic evidence is logged for future audit cycles.
  • Preventative guardrails: organisation-wide policy controls are applied to enforce security baselines automatically and prevent compliance drift between audit cycles.

Penalties for non-compliance

  • Statutory penalties v contractual remedies: statutory fines are imposed by the ODPC or the courts, and cannot be limited or excluded by contract. Contractual penalties (such as SLA credit deductions or liquidated damages) are separate private law remedies agreed between the cloud customer and the CSP.
  • Administrative fines (Section 63): a maximum fine of up to KES5 million (approximately USD38,600) or 1% of annual turnover, whichever is lower, for general compliance breaches.
  • Offences and criminal fines (Section 65): obstruction of an ODPC investigation, unlawful disclosure of cloud-hosted personal data, or failure to comply with an ODPC Enforcement Notice carries fines of up to KES5 million (approximately USD38,600), imprisonment of up to ten years, or both.
  • Civil compensation (Section 65): data subjects who suffer material or non-material damage (including distress) as a result of a breach of the DPA by a cloud controller or processor may seek compensation through the courts or through ODPC dispute resolution proceedings.
KMK Africa Advocates LLP

No. 8 East Church Road
Opposite Magnate Centre
Westlands Nairobi
Kenya

+254 115 498 073; +254 773 669 192;

info@kmkadvocates.co.ke www.kmkadvocates.co.ke
Author Business Card

Law and Practice in Kenya

Authors



KMK Africa Advocates LLP is a full-service law firm based in Nairobi, Kenya, with a further presence in Abuja and Lagos in Nigeria, and in Singapore City, Singapore. With expertise across diverse practice areas, the firm delivers solution-oriented legal services tailored to each client’s unique needs. The firm’s legal practitioners possess combined backgrounds in law, economics and finance, allowing the firm to craft solutions framed around commercial viability, return on investment, and operational realities. In corporate and commercial law, the firm advises clients ranging from emerging start-ups to multinational enterprises on corporate set-up, regulatory compliance, domestic and cross-border mergers and acquisitions, joint ventures and complex commercial contracting. The banking and finance practice assists commercial lenders, corporate borrowers and institutional investors with capital raising, debt financing structures and cross-border transactions. In response to Africa’s rapidly evolving digital economy, the firm’s technology, intellectual property and data protection division focuses on safeguarding brand assets and digital innovations.