Module X: Data Protection in Practice-East
African and African Perspectives
Introduction to the Module- Sets the context of the module by explaining why regional and
continental perspectives matter for Kenyan organisations: cross-border operations, cloud
services, regional markets, regulatory harmonisation and convergence.
Learning outcomes:
Understand key regional data protection trends across East Africa and the continent.
Identify similarities and divergences across East African regimes.
Identify compliance implications for Kenyan entities operating regionally and continentally.
The East African Data Protection Landscape
[Link] of East Africa for the purposes of this module: EAC Partner States (Kenya,
Uganda, Tanzania, Rwanda, Burundi, DRC, Somalia, South Sudan) and Ethiopia, including
the rationale for Ethiopia's inclusion.
[Link] status of data protection laws and enforcement across the region (visual overview).
[Link] themes cutting across East African national data protection laws, with reference
to the GDPR and Malabo Convention as shared reference models.
[Link] divergences across East African national data protection laws:
Varying approaches to data localisation (Kenya, Rwanda, Tanzania, Ethiopia).
Registration requirements for controllers and processors (Kenya, Uganda, Tanzania, Rwanda).
Page 1 of 4
Overview of African Data Protection Frameworks
Continental instruments
[Link] Malabo Convention: status, binding nature, ratification uptake, and influence beyond
formal ratification.
[Link] AU Digital Transformation Strategy (2020–2030): harmonisation objectives, cross-
cutting treatment of data protection, and reliance on member-state political will.
[Link] AU Data Policy Framework (2022): objectives, non-binding nature, relationship to the
Malabo Convention, and relevance for member states including Kenya.
[Link] AfCFTA Digital Trade Protocol (2024–2025): adoption status, scope, anticipated impact
on cross-border data transfer rules, and the challenge of overlapping standards with
Malabo and national regimes.
Regional Economic Community (REC) frameworks:
[Link]: Legal Framework for Cyber Laws (2008) and the Data Governance Policy Framework
validated October 2024.
[Link]: Supplementary Act on Personal Data Protection (2010), binding on member
states.
[Link]: HIPSSA Model Data Protection Act (2013) and South Africa's POPIA as the regional
benchmark.
Human rights instruments and other frameworks:
[Link] Charter on Human and Peoples' Rights, Art. 9.
[Link] Declaration on Freedom of Expression and Access to Information (2019).
[Link] of African Data Protection Authorities (NADPA).
[Link] AI Strategy (2024) and the framing of data protection as a prerequisite for AI
governance.
Page 2 of 4
Cross-Border Data Transfer Practices in Africa
a. Definition and legal framework for cross-border data transfers under Kenyan
law (Reg. 40, Data Protection General Regulations 2021): four recognised
transfer bases — appropriate safeguards, adequacy decision, necessity, and
consent.
b. Regional Economic Community (REC) frameworks:
The majority of African data processed outside the continent, primarily in US and EU-based
cloud infrastructure.
Intra-African transfers driven by regional businesses, mobile money, and e-commerce.
c. Data sovereignty and localisation as an emerging concern:
Growing localisation mandates across the continent.
Tension between sovereignty-driven localisation and the free flow of data needed for
economic integration.
Implications for Kenyan Organisations and Practitioners
For organisations operating regionally:
No regional adequacy framework: each cross-border transfer requires its own legal basis,
multiplying compliance costs.
Enforcement asymmetry: cross-border processing does not displace Kenyan jurisdiction;
the ODPC retains enforcement authority where regional partners process Kenyan personal
data abroad.
Multiple overlapping regimes: simultaneous exposure to several national frameworks with
differing transfer rules, registration requirements and enforcement postures.
Recommendations for Data Protection Officers and practitioners
Map all cross-border data flows and document the legal basis for each transfer under Reg.
40.
Include data protection clauses and transfer mechanism provisions in contracts with
regional counterparts.
Page 3 of 4
Monitor EAC and AfCFTA developments.
Engage ODPC guidance notes proactively.
Build multi-jurisdiction compliance registers updatable as new laws come into force.
Implications for Kenyan Organisations and Practitioners
Recommendations for Data Protection Officers and practitioners
The GDPR's influence on African data protection frameworks through legislative design,
adequacy ambitions, and the AfCFTA Digital Trade Protocol's draw on GDPR-style
adequacy mechanisms.
Kenya's EU adequacy discussions and the compliance incentive to maintain GDPR
alignment.
Future Trends in East African Data Governance
Finalisation of EAC Cross-Border Data Flow Frameworks and their impact on adequacy.
Burundi's law entering into force; anticipated legislative process in South Sudan.
AU Digital Transformation Strategy 2030 harmonisation target.
Possibility of a Kenya-EU adequacy decision.
Conclusion and Key Takeaways
Kenya as a regional leader: the ODPC as the most mature regulator in the region.
Strategic shift toward cross-border governance: building multi-jurisdictional frameworks
that address the tension between free data flows, data subject rights and national
sovereignty.
Convergence and alignment are ongoing: the EAC Framework, AfCFTA Protocol, AU
Strategy and NADPA expansion all signal significant regional and continental integration
efforts.
Page 4 of 4