Contributed By KMK Africa Advocates LLP
Kenya’s data privacy framework for cloud computing rests on constitutional protections, a dedicated statute and sector-specific rules.
Section 2 of the DPA provides the following definitions.
General Personal Data Processing Requirements
Processing personal data in the cloud requires a lawful basis under Section 30 of the DPA. The recognised bases are:
All cloud processing must comply with the following data protection principles set out in Section 25 of the DPA.
Data Protection Impact Assessment (DPIA)
Under Section 31 of the DPA and Regulation 35 of the DPGR, a data controller must carry out a DPIA before carrying out processing that is likely to result in high risk to the rights and freedoms of data subjects. In the cloud context, this obligation is triggered by activities such as migrating large-scale datasets or sensitive personal data to third-party public cloud platforms.
In Republic v Mucheru, Cabinet Secretary Ministry of Information Communication and Technology & 2 others; Katiba Institute & another (Ex parte); Immaculate Kasait, Data Commissioner (Interested Party) (Judicial Review Application E1138 of 2020) [2021] KEHC 122 (KLR), the High Court at Nairobi halted the government’s processing of the Huduma Card on the ground, among others, that no data protection impact assessment had been conducted.
Obligations of Controllers and Processors in the Cloud
The data controller (cloud customer) determines the purpose and means of processing. The controller bears primary legal responsibility for obtaining lawful consent, conducting DPIAs, responding to data subject requests, and instructing the cloud provider on the scope and manner of processing.
The data processor (cloud service provider – CSP) processes personal data on behalf of, and under the documented instructions of, the data controller (Section 42 of the DPA). A CSP may not process customer data for its own independent analytics or commercial purposes without prior written authorisation from the controller.
Key Statutory Obligations
Please see 6.1 Cross-Border Transfer Regulation and 6.3 Conflicts of Law.
Please see 7.1 Cloud Computing and Compliance/Audits.
Key Security Measures
The following measures are required by law for data stored in the cloud.
Data Subject Rights in Cloud Environments
Data subjects retain the following rights over personal data stored in cloud infrastructure, under Sections 26 to 40 of the DPA.
Data Ownership, Retention and Deletion Policies
Measures Ensuring Data Portability in the Cloud
Under Section 38 of the DPA, data subjects have the right to receive their personal data stored in the cloud in a structured, commonly used and machine-readable format. They may also request the direct transmission of that data from one CSP or controller to another, provided this is technically feasible.
Technical and Operational Measures
Storage Limitation Principle (Section 25(g) of the DPA)
Personal data stored in cloud databases and object storage must not be retained beyond the period necessary to fulfil the specific, lawful purpose for which it was collected, unless a specific written law requires prolonged retention.
Retention Policy Management
Deletion and Sanitisation Protocols
Selecting a CSP in Kenya calls for a structured due diligence process that measures the provider’s commercial capabilities against the requirements of the DPA and the DPGR. The principal due diligence areas are as follows.
Regulatory and Licensing Verification
Data Sovereignty and Residency Auditing
Contractual and Sub-Processor Controls
Technical Security Architecture and Industry Standards
Incident Management and Auditability SLAs
Exit Strategy, Portability and Sanitisation
Data protection requirements are incorporated into Cloud Service Agreements in Kenya through a mandatory Data Processing Agreement or a dedicated data protection schedule, as required by Regulation 22 of the DPGR. The specific contents of a Data Processing Agreement are addressed in 4.3 Data Processing Agreements and the Cloud.
Measures Ensuring CSP Compliance With Data Privacy Regulations
A contract between a cloud customer and a CSP must satisfy the requirements of Section 42 of the DPA and Regulation 22 of the DPGR. At a minimum, it must address the following.
Termination and Exit Strategies in Cloud Agreements
A properly structured exit strategy safeguards operational continuity, prevents vendor lock-in, and ensures regulatory compliance during offboarding.
Common Termination Triggers
Essential Exit Contractual Terms
Data and Service Migration Protocol (Cloud-to-Cloud)
Cloud-to-cloud data migration typically proceeds in four phases.
Phase 1: discovery, assessment and compliance
Phase 2: technical pipeline execution
Phase 3: validation, checksum verification and dual-run
Phase 4: final cutover and decommissioning
Specific Requirements for Reporting Data Breaches in the Cloud
Mandatory content of ODPC breach notifications (Section 43(5) of the DPA)
Cloud provider co-ordination and verification protocol
Penalties for Non-Reporting of a Data Breach in the Cloud
Failure to report a breach is an offence under the DPA. It exposes the entity to ODPC enforcement notices and administrative fines of up to KES5 million (approximately USD38,600) under Section 63.
Investigating and remediating a data breach in a cloud environment requires co-ordinated action between the data controller, the CSP (as data processor) and the relevant regulatory authorities.
Cloud-Level Technical Investigation and Forensic Preservation
The CSP, as data processor, is legally obligated under Section 42 of the DPA to assist the controller in meeting its compliance obligations. During a breach, the CSP must assist in extracting system audit logs, API access records and SIEM telemetry to establish the attack vector, timeline and scope of the unauthorised access.
Remediation Protocol
Regulatory Investigation Powers
The breach notification regime is governed by Section 43 of the DPA and Regulations 35–39 of the DPGR, as follows.
Special Exceptions and Public Disclosure
Before transferring personal data to a cloud environment hosted outside Kenya, data controllers and processors should:
International Data Transfer Mechanisms
Under Part VI (Sections 48–50) of the DPA and Part VIII of the DPGR, transferring personal data outside Kenya to offshore cloud servers requires one of the following legal mechanisms.
Written international transfer agreements must define the roles and responsibilities of both the transferring and receiving entities. Key obligations include the following:
Data Localisation Mandates
Section 50 of the DPA read with Regulations 25 and 26 of the DPGR imposes strict localisation requirements for specific categories of data, including mandatory local storage/processing. Processing must take place on servers physically located within Kenya, or at least one serving copy of the data must be maintained in a Kenyan data centre, for the following categories:
Implications of Data Localisation Requirements on Cloud Computing in Kenya
Conflicts of Law and Risk Mitigation
Where a foreign-headquartered CSP is subject to extra-territorial legislation such as the EU GDPR or the US CLOUD Act, international transfer agreements must include governing law clauses that give primacy to Kenyan statutory protections and oblige the CSP to challenge foreign court orders that conflict with Kenyan data protection law.
Addressing Conflicts of Law in Cross-Border Data Transfers
Under the DPA and the DPGR, conflicts of law arising from international cloud transfers are addressed through a combination of statutory primacy, mandatory contractual mechanisms, and technical safeguards.
Risks and Challenges of Cross-Border Cloud Data Transfers
Compliance Audits, Audit Trails and Statutory Penalties
Cloud compliance audits
Under Section 23 of the DPA, the ODPC has statutory authority to conduct periodic compliance audits of cloud operations. Cloud compliance audits assess security controls, data privacy measures and legal adherence within the shared responsibility model that applies between the CSP and the cloud customer.
Audit procedures
Audit focus areas
Audits tend to focus on:
Audit logs and trails
Cloud systems must generate immutable, time-stamped log files recording data access events, modifications, administrative privilege changes, and data export operations.
Integrity measures
Write Once Read Many (WORM) storage, centralised log management through SIEM platforms, and digital signatures are used to prevent tampering with audit logs and to preserve the integrity of audit reports.
Addressing audit findings and recommendations
Penalties for non-compliance
No. 8 East Church Road
Opposite Magnate Centre
Westlands Nairobi
Kenya
+254 115 498 073; +254 773 669 192;
info@kmkadvocates.co.ke www.kmkadvocates.co.ke